News

Flaws in McAfee Security Programs May Expose Data, Researchers Say

Consumer versions of McAfee Inc.'s leading software for securing PCs is susceptible to a flaw that can expose passwords and other sensitive information stored on personal computers, researchers said Monday.

The vulnerability affects many of McAfee's most popular consumer products, including its Internet Security Suite, SpamKiller, Privacy Service and Virus Scan Plus titles, said Marc Maiffret, chief hacking officer at eEye Digital Security Inc., a competing maker of security products.

McAfee spokeswoman Siobhan MacDermott confirmed the vulnerability and said software engineers were testing a fix. She said officials expected to release the patch Wednesday using a feature that automatically updates McAfee products over the Internet. The flaw does not affect 2007 versions of McAfee products, which were released Saturday, she said.

Maiffret said he has found a way to connect to PCs running the flawed McAfee products over the Internet and make them run code of his choosing. The flaw, if exploited, would make it possible for a criminal to track bank account numbers, and access, modify and delete sensitive files and do other damage on machines running the McAfee products, he said.

The reported flaw came on the same day that McAfee posted an item on its Web site taking a swipe at Microsoft Corp., whose products increasingly compete with the offerings of McAfee, Symantec Corp. and other security companies. It warned that code had been released that exploited flaws in a feature used to automate certain administrative tasks in Microsoft's Windows operating system.

"Microsoft products have always been an attractive target for hackers and malware authors," according a posting on the McAfee Web log.

Maiffret's company, which in the past has discovered embarrassing flaws in products sold by Apple Computer Inc., Microsoft, Symantec and McAfee, said he was withholding technical details of Monday's vulnerability to prevent criminals from learning how to exploit it.

The flaw comes two weeks after Aliso Viejo, Calif.-based eEye disclosed a hole in McAfee program for protecting business computers. In that case, Santa Clara, Calif.-based McAfee said it had fixed the defect three months earlier but did not warn customers about it until eEye made it public.

In May, eEye uncovered a similarly dangerous flaw in security software by Symantec.

Neither Maiffret nor McAfee said they were aware of any attacks that target the flaw disclosed on Monday.

"The vulnerability isn't public, so you shouldn't see exploits for it," Maiffret said, adding that users of McAfee products should make sure they are configured to automatically check for updates each day.

Featured

  • Report: Cost, Sustainability Drive DaaS Adoption Beyond Remote Work

    Gartner's 2025 Magic Quadrant for Desktop as a Service reveals that while secure remote access remains a key driver of DaaS adoption, a growing number of deployments now focus on broader efficiency goals.

  • Windows 365 Reserve, Microsoft's Cloud PC Rental Service, Hits Preview

    Microsoft has launched a limited public preview of its new "Windows 365 Reserve" service, which lets organizations rent cloud PC instances in the event their Windows devices are stolen, lost or damaged.

  • Hands-On AI Skills Now Outshine Certs in Salary Stakes

    For AI-related roles, employers are prioritizing verifiable, hands-on abilities over framed certificates -- and they're paying a premium for it.

  • Roadblocks in Enterprise AI: Data and Skills Shortfalls Could Cost Millions

    Businesses risk losing up to $87 million a year if they fail to catch up with AI innovation, according to the Couchbase FY 2026 CIO AI Survey released this month.