Dell diagnostic software getting flagged as malware due to security problems

hacker attack


Computers come with a lot of pre-installed software these days -- it's a trade-off for low pricing that forces OEMs to make deals with companies like McAfee, Norton and others. However, some of what comes with that new desktop or laptop is actually there to help you. Dell pre-installs diagnostic software to aid in a problematic situation.


Apparently Malwarebytes doesn't see it that way. The security software is recognizing this as a problem for your system -- and it is, or was. The problem is that older versions had a vulnerability that could allow malicious code execution. Dell has since updated its software to close the hole, which was recently discovered by a security researcher.


"The application known as Dell System Detect failed to validate code before downloading and running it, according to a report published last month by researcher Tom Forbes. Because the program starts itself automatically, a malicious hacker could use it to infect vulnerable machines by luring users to a booby-trapped website. According to researchers with AV provider F-Secure, the malicious website need only have contained the string 'dell' somewhere in its domain name to exploit the weakness", Dell states.


That wasn't the end of the problems, though. A hole still existed that allowed for the code execution. A second update was issued by Dell, hopefully sealing things up for good. At least, for those who bothered to install the updates. The company laments that "The problem is that few people are running the patched version of Dell System Detect. As of Thursday, less than one percent of F-Secure customers had it installed. As a result, Malwarebytes software that detects a vulnerable version of the software will display a warning along with a link".


Computer security is an ongoing battle, but folks should certainly install updates, though perhaps wait a few days and check that others haven't had problems with the new version. It's a double-edged sword -- install right away and wait a bit at the same time.


Image Credit: lolloj/Shutterstock






from BetaNews http://feeds.betanews.com/~r/bn/~3/ei2apJe9vno/

via IFTTT

0 коммент.:

Отправить комментарий