Tuesday, November 2, 2010

Critical vulnerability revealed in Outpost 7.0, 7.0.1 and 7.0.2

ST. PETERSBURG, RUSSIA, November 2, 2010 — We’d like to immediately inform the users of Outpost 7 product versions — 7.0, 7.0.1 and 7.0.2 — about the potential vulnerability in the respective Outpost editions which was brought to our attention as a result of yesterday’s in-house research.

Since Agnitum Research Lab conducts proactive and regular monitoring of its solutions as well as critical system and registry objects for potential exploits, we can take a few steps ahead of malware writers who may take advantage of veiled system flaws. After a painstaking analysis of registry hives covered by Outpost protection we detected a potential system vulnerability which may affect users of Outpost, versions 7.0 to 7.0.2. To our best knowledge, this previously unnoticed security hole has not been exploited by modern malware so far, but it’s better prevent than cure.

Having checked the latest Outpost versions — 7.0.3 and 7.0.4 — for the same issue, we discovered these editions were not affected due to a different algorithm of system object protection employed in these latest solutions. As for now, we have to withhold technical details for security reasons. More information will be revealed as our investigation continues.

In the meantime, it’s highly important the affected users download and install Outpost 7.0.4 and stay fully protected.

For more information, please contact:

Peter Lance
VP, International Sales, AVG Security (Asia-Pacific)