logo

New Vulnerability Uses Antivirus Software to Inject Malware

ID: b227b5f4-0583-578a-9f7a-eedbbebd819d

STIX ID: report--b227b5f4-0583-578a-9f7a-eedbbebd819d

Feed Name: Binary Defense Blog

Threat Score
50/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

AVGator is a vulnerability in multiple antivirus products where the "restore from quarantine" feature can be exploited to move quarantined malware into privileged directories (e.g., C:\Program Files or C:\Windows) using NTFS junction points and DLL search-order abuse, allowing the malware to run with full privileges; a researcher demonstrated this via a phishing infection during a penetration test. Vendors including Emsisoft, Ikarus, Kaspersky, Malwarebytes, Trend Micro, and ZoneAlarm were notified and have released updates; the technique requires physical/local access, making shared-computer environments most at risk. Analysts recommend keeping antivirus software updated and disabling restore-from-quarantine functionality.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.