Explaining about the flaw in his advisory, he stated that the flaw enabled a potential attacker to execute code. Ironically, exploiting this vulnerability could, therefore, permit running malware.
Trend Micro Anti-Threat Toolkit (ATTK) will load and execute arbitrary .EXE files if a malware author happens to use the vulnerable naming convention of "cmd.exe" or "regedit.exe" and the malware can be placed in the vicinity of the ATTK when a scan is launched by the end-user. Since the ATTK is signed by verified publisher and therefore assumed trusted any MOTW security warnings are bypassed if the malware was internet downloadedThe vulnerability could serve as a persistent vector for running the malware and could execute the code each time ATTK would run.
In addition to the advisory, the researcher has also shared a PoC video for the exploit.
The flaw affected ATTK versions 1.62.0.1218 and below for Windows. Following his report, Trend Micro has recently released an updated version of the ATTK that patches the bug. Users should ensure updating their systems to ATTK version 1.62.0.1223 to prevent potential exploit.
In other news, Avast has recently suffered a security breach. They endured an attack on their systems that aimed at infecting their CCleaner app.
Let us know your thoughts in the comments.