Dismiss this notice
Master PDF Editor Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6240

Dismiss this notice
Avast Premier Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6095

Dismiss this notice
Ashampoo Snap 10 Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6241

Dismiss this notice
Backup4all Professional Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6464


Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Update Logic Mishandle in Zemana AntiMalware 2.0: Fixed
#1
Information 
Quote:Yes, it is true we that there was a critical vulnerability discovered in ZAM 2.0 update integrity check. Some of you probably read about it in one of the threads on Malware Tips or other websites.

However, keep in mind that this vulnerability is not and never was present in our Zemana AntiMalware 3.0 Beta version.

In this blog post, we want to share with you the resolution to this concern. Yesterday, we fixed the issue and released a new update of ZAM 2.0, where we successfully fixed the update logic mishandle.

In the text below, you can find more information.

Update Integrity Check Vulnerability

A remote code execution vulnerability has been discovered related to update file integrity check. This vulnerability, caused by mishandling update logic, resulted in Zemana AntiMalware version 2.74.2.150 providing a weaker security than expected.

It allowed man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable. Due to this flaw, a remote attacker (only on the same network) could launch further attacks on the system by bypassing applications update file integrity check and executing any file with system rights.

This vulnerability has been assigned the CVE identifier CVE-2019-6440

ZAM 2.0 New Update

Some of you are probably still concerned or wondering if the vulnerability still exists, but we assure you there is no need to worry because we successfully fixed it.
In order to resolve the issue and improve our product, we released a new update of Zemana AntiMalware 2.0, which includes fixes for this vulnerability.
You can download it here.

What About ZAM 3.0?

As mentioned above, there never was an update logic mishandle or any critical vulnerabilities in our latest Zemana AntiMalware 3.0 Beta version. You can check out our release notes here and see what’s new in ZAM 3.0.
If you have any questions or concerns related to this vulnerability or anything else, know that you can always contact us at: [email protected]. Our team members will be happy to talk to you and help you out.
Original source: https://blog.zemana.com/zemana-antimalwa...ate-logic/
[-] The following 3 users Like harlan4096's post:
  • jasonX, JM Safe, silversurfer
Reply
#2
Great information! Thanks so much!
[-] The following 2 users Like jasonX's post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Latest Threads
Try Out the Reader Mode in Microsoft’s N...
Last Post: silversurfer
Yesterday 14:13
» Replies: 0
» Views: 31
Microsoft Brings a Key Security Feature ...
Last Post: silversurfer
Yesterday 14:13
» Replies: 0
» Views: 30
PC Game Giveaway:Assassins Creed Unity
Last Post: sinanogz
Yesterday 10:57
» Replies: 0
» Views: 27
LibreOffice 6.1.2
Last Post: JM Safe
Yesterday 09:53
» Replies: 5
» Views: 200
WhatsApp Will Allow Users to Block Conve...
Last Post: JM Safe
Yesterday 09:51
» Replies: 1
» Views: 32
Avast Blog_Security News: Facebook wants...
Last Post: harlan4096
Yesterday 07:51
» Replies: 0
» Views: 29
Avast Blog_Tips & Advices: Are budget-tr...
Last Post: harlan4096
Yesterday 07:49
» Replies: 0
» Views: 24
Emsisoft Anti-Malware named one of AVLab...
Last Post: harlan4096
Yesterday 07:41
» Replies: 0
» Views: 52
Next generation antivirus: the future of...
Last Post: harlan4096
Yesterday 07:38
» Replies: 0
» Views: 38
10 Chrome Extensions to Boost Your Onlin...
Last Post: harlan4096
Yesterday 07:31
» Replies: 0
» Views: 26
Microsoft Announces Surface Hub 2S: 50-I...
Last Post: harlan4096
Yesterday 07:26
» Replies: 0
» Views: 21
AMD 50th Anniversary Ryzen CPUs Listed A...
Last Post: harlan4096
Yesterday 07:24
» Replies: 0
» Views: 17
The Huawei P30 & P30 Pro Reviews: Photog...
Last Post: harlan4096
Yesterday 07:22
» Replies: 0
» Views: 28
Samsung Completes Development of 5nm EUV...
Last Post: harlan4096
Yesterday 07:20
» Replies: 0
» Views: 26
TSMC Reveals 6 nm Process Technology: 7 ...
Last Post: harlan4096
Yesterday 07:16
» Replies: 0
» Views: 23
8 ways in which Microsoft Edge (Chromium...
Last Post: harlan4096
Yesterday 07:11
» Replies: 0
» Views: 28
Google to present browser and search cho...
Last Post: harlan4096
Yesterday 07:09
» Replies: 0
» Views: 22
Ubuntu 19.04 is out
Last Post: harlan4096
Yesterday 07:07
» Replies: 0
» Views: 19
Start Menu gets its own process and a pe...
Last Post: harlan4096
Yesterday 07:04
» Replies: 0
» Views: 25
Microsoft explains how Dynamic Updates w...
Last Post: harlan4096
Yesterday 07:02
» Replies: 0
» Views: 25

[-]
Staffs Online
There are no staff members currently online.