Symantec recommends disabling pcAnywhere and waiting for security patches
- 27 January, 2012 01:24
- Comments
Security vendor Symantec has advised users of its pcAnywhere remote control software to disable it, because hackers with access to the product's source code could exploit security holes identified in the application.
Earlier this month Symantec confirmed that the source code for the 2006 versions of Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks and pcAnywhere was stolen by hackers.
The security vendor said at the time that because the code is old, customers running Norton products today should not be in any increased danger of cyberattacks. However, the company admitted that users of pcAnywhere, which has not changed as much as the Norton products over the past few years, might face an increased risk because of the leak.
In a white paper published on Monday, Symantec revealed that encoding and encryption elements used by pcAnywhere to secure PC to PC communications were found to be vulnerable. "Therefore it is possible that successful man-in-the-middle attacks may occur depending on the configuration and use of the product," the company said.
If attackers manage to obtain the cryptographic key used by the application they can launch unauthorized remote control sessions and potentially gain access to other data stored on an internal network.
The application's login credentials can also be intercepted with the help of a network sniffer. However, for this to happen, the attacker must already have access to the network via a malware-compromised computer or some other method.
"At this time, Symantec recommends disabling the product until we release a final set of software updates that resolve currently known vulnerability risks," Symantec said in a statement.
"For customers that require pcAnywhere for business critical purposes, it is recommended that customers understand the current risks, ensure pcAnywhere 12.5 is installed, apply all relevant patches as they are released, and follow general security best practices," the company said.
Symantec's white paper includes general and pcAnywhere-specific security recommendations, as well as links to instructions for disabling or uninstalling the product.
In addition to being sold as a stand-alone program, pcAnywhere is also bundled with other Syamantec products like Altiris Client Management Suite version 7.0 or later, Altiris IT Management Suite version 7.0 or later and Altiris Deployment Solution with Remote v7.1.
"Our current analysis shows that all pcAnywhere 12.0, 12.1 and 12.5 customers are at increased risk, as well as customers with prior, unsupported versions of the product," Symantec said in its white paper.
A patch for pcAnywhere 12.5 was released on Tuesday in order to address two security vulnerabilities that could lead to arbitrary code execution or privilege escalation. The flaws were reported privately to Symantec by security researchers Tal Seltzer and Edward Torkington.
"Additional patches are planned for release during the week of January 23 for pcAnywhere 12.0, pcAnywhere 12.1 and pcAnywhere 12.5," Christine Ewing, director of product marketing for Symantec's Endpoint Management group, said in a blog post on Tuesday. "Symantec will continue to issue patches as needed until a new version of pcAnywhere that addresses all currently known vulnerabilities is released."
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Symantec backtracks, admits own network hacked - Computerworld
- white paper
- Enterprise Support - Symantec Corp. - pcAnywhere hotfix
- Security Advisories Relating to Symantec Products - Symantec pcAnywhere Remote Code Execution, Local Access File Tampering - January 24, 2012 : Symantec
- Important Information on pcAnywhere : Symantec Connect Community
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Bend or break: Flexible Policy
DON’T. PANIC. Aligning business and IT needs has always been a challenge. Finding the right balance between ensuring the safety of sensitive data and enabling the free flow of information is increasingly difficult in today’s evolving regulatory and threat environment. Read on. -
Case Study: Keeping information on the move: Clearswift protects Maman, the logistics experts
Time is money. Every minute a consignment is held up in transit costs money and causes problems. Web and email are mission critical business tools that enable Maman, and their customers, to efficiently collaborate with partners across the globe. Spam, and other web based threats can result in delays that ultimately lead to missed deadlines - keeping the lines of communication open is therefore a key priority for Maman. Read on. -
Oracle SOA vs. IBM SOA - Customer Perspectives on Evaluating Complexity and Business Value
The Service-Oriented Architecture (SOA) model has become the cornerstone of business computing. Its ability to greatly accelerate the development of business-critical applications promotes business agility, decreases time-to-value and total cost of ownership (TCO), and greatly increases the efficiency and strategic value of IT. SOA implementations tend to be complex, IT decision makers should carefully consider their choice of a SOA platform in terms of its ability to simplify the fundamental development, deployment, and management tasks involved. Read on.
-
Professional Infopath 2003
-
Visual Basic .Net Programming
-
Outdoor Photographer Landscape and Nature Photography with Photoshop CS2
-
The Game Artist's Guide to Maya (Includes CD-ROM)
-
Dreamweaver MX for Dummies
-
HTML, XHTML, and Css
-
Access 2000 VBA Handbook
-
Effective Project Management
-
Data Structures and Algorithms in C++ WIE








Comments
Post new comment