Trend Micro Antivirus Software Exposed Users to Attack

Password-management software helps people handle lengthy lists of complex passwords, but it also presents a giant target for hackers to hit for optimal bounty. The Tokyo-based antivirus maker Trend Micro just learned this the hard way, as a troubling flaw in its password manager opened users up to remote attacks and the theft of entire password databases. 

Image: Zsolt Biczo/Shutterstock

Image: Zsolt Biczo/Shutterstock

Tavis Ormandy, a researcher with Google's Project Zero vulnerability research team, discovered the flaw in Trend Micro's Windows antivirus programs and blogged about it Jan. 5 after sending notice of the flaw to the company. At first, Ormandy showed that it was possible to execute code remotely on systems that have Trend Micro installed, which was already pretty bad.

MORE: 10 Desktop Password Managers

But the more he dug into Trend Micro's software, the more problems he found. Among other things, Ormandy discovered what he called "a nice clean API" inside the antivirus software that was exposed to the Internet and made it easy for anyone to "just read all of the stored passwords."

He also found that Trend Micro's "secure" browser was an old version of Chromium (which Google Chrome is based on) that had disabled its software sandbox, which might make it easier for malicious software to infect a computer.

Never one to mince words, Ormandy seems to have made no effort to hide his disgust with the flaws in emails to Trend Micro representatives that he shared in his blog posts.

"That is the most ridiculous thing I've ever seen," Ormandy wrote in regard to the secure browser. "I don't even know what to say — how could you enable this thing *by default* on all your customer machines without getting an audit from a competent security consultant?"

"You need to come up with a plan for fixing this right now," he added. "Frankly, it also looks like you're exposing all the stored passwords to the Internet, but let's worry about that screw-up after you get the remote code execution under control."

As of late, Ormandy has been on a one-man campaign to protect users from flawed antivirus software, recently revealing a mistake in AVG software that exposed users' Web-browsing activities. 

Fortunately, Trend Micro has issued updates to patch most of the vulnerabilities Ormandy found. All users of Trend Micro antivirus products on Windows should open the program immediately and download the update, as their systems are vulnerable to the remotely executed code flaw, even if they do not use the suite's password manager.

A full and unlocked version of Trend Micro's password manager is included with the Premium Security and Maximum Security edition of the company's antivirus software. The password manager can also be downloaded and installed separately, in both free and paid versions.

Users of Trend Micro's other Windows antivirus products, Internet Security and Antivirus + Security, don't have the password manager or secure browser enabled. But the products may still contain the flawed code, as some antivirus products install the most fully-featured version but keep certain features disabled until the user pays to activate them.

While we recommend all users install strong and robust antivirus solutions on their PCs, the high system privileges accorded to antivirus software mean that compromises of the software could be catastrophic. A study of antivirus-software security conducted this past fall by German testing lab AV-TEST gave scores below 90 percent to Bitdefender Internet Security (87.9 percent), Panda Security Free Antivirus (87.4 percent) and Trend Micro Internet Security (76.0 percent). 

We also recommend users weigh the pros and cons of using password managers, which place all of a user's account credentials into a single program. Recent history has shown us that password managers, including KeePass and LastPass, can be hacked.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Antivirus
A woman using her laptop securely with a cup of coffee in hand
5 common mistakes people make when shopping for antivirus software
Best antivirus software
How does antivirus software work?
Avast software on a webpage
FTC rules Avast customers entitled to $16.5 million settlement — how to claim your share
A laptop with the screen displaying both the logos for Norton antivirus and McAfee antivirus softwares.
I compared Norton vs McAfee’s antivirus software to see which one is best
Bitdefender and Norton logo split a computer screen
I put Bitdefender vs Norton antivirus through a 7-round face-off — here's the winner
Norton 360 Standard (for Mac)
Norton 360 Deluxe is 75% off in this Black Friday deal — protect 5 PCs, Macs tablets or phones for just $30
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now