19 Jan 2012
Security vendor McAfee has revealed it is in the process of rolling out a patch to fix two newly discovered flaws in its hosted anti-malware service SaaS for Total Protection.
McAfeeLabs director of security research Dave Marcus, explained that the patch would be rolled out automatically in the next day.
"Two issues in SaaS for Total Protection have arisen in the past few days. In the first, an attacker might misuse an ActiveX control to execute code," he explained.
"The second involves a misuse of our ‘rumor' technology to allow an attacker to use an affected machine as an ‘open relay', which could be used to send spam."
Marcus said that the first issue cannot actually be exploited by hackers thanks to a path rolled out in August 2011, which addressed a similar flaw.
"The second issue has been used to allow spammers to bounce off affected machines, resulting in an increase of outgoing email from them," he added.
"Although this issue can allow the relaying of spam, it does not give access to the data on an affected machine. The forthcoming patch will close this relay capability."
News of the vulnerability was first disclosed on Monday by the unusual source of art and design web site Kamaar.com.
It's not been a good week for the big two of the security industry, McAfee and Symantec. Alongside Intel-owned McAfee's disclosure on Wednesday, market leader Symantec was forced to back-track on previous statements and admit that its network was breached in an attack in 2006.
The security giant is also being sued in the US by a consumer claiming the firm uses scareware tactics to persuade potential customers to buy its products.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
The Role: As a Field Service Engineer working from...
The Role: Make the most of your IT knowledge in one...
Head of IT / Infrastructure Manager (Marketing Services...
A Multi-national data analytic's and cloud computing...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?