Permission problems in antivirus software
The following are two examples of permission problems that can arise with antivirus software.
Insufficient permissions on the static signature file
During our research, we found antivirus software whose static signature file had insufficient permissions. This meant that any low-privileged user could erase the contents of the file. When the antivirus software then scanned files, it would be comparing them to an empty signature file.
We notified the antivirus vendor about this vulnerability and they released an update with a patch that fixed the vulnerability.
Improper privileges
Permission problems can occur not only in antivirus software but in all kinds of security solutions. In one of our research journies, we researched a Data Loss Prevention (DLP) security solution of company named Symantec. This software's primary goal is to block and prevent the leakage of sensitive data from the organization's network endpoints...