Antivirus SSDT hook bypass vulnerability Kommentar [0]
Recent reports have detailed a problem with many antivirus solutions that use so-called SSDT hooking to inspect programs for malicious content. Norman also uses this technology, and can at this time be bypassed this way.
The question remains, how big a problem is this for the users?
The effect of the vulnerability is that malicious software may be able to attack running antivirus solutions and aspects of their malware detection and self defense mechanisms. This is achieved by creating a so-called…



