You are here: silicon.com > Software > Security Strategy

Security Strategy

Security warning over tech support tools

Multiple flaws found...

Tags: tech support, security flaws, flaws

By Joris Evers

Published: 27 February 2007 08:55 GMT

Multiple flaws in commonly used technical support tools can open Windows PCs to cyber attack, security experts have warned.

The vulnerable tools are often used by ISPs, PC makers and others to provide support functions such as remote assistance, the US Computer Emergency Readiness Team (US-Cert) said in an alert. The tools, provided by SupportSoft, contain multiple vulnerabilities, it warned.

US-Cert lists nearly 40 companies and other organisations that have shipped the affected software. Some have addressed the problem, while others are still listed as vulnerable or unknown. Those that have yet to fix the SupportSoft issue include IBM and internet access providers BellSouth, Comcast and Time Warner, it said.

Symantec includes the SupportSoft components in its consumer security products. The company released its own alert last week, along with fixes. The problem is "high" risk but is mitigated somewhat, because triggering the flaw would require some action on the part of the user, Symantec noted.

It said: "If successfully exploited, this vulnerability could potentially compromise a user's system, possibly allowing execution of arbitrary code or unauthorised access."

The SupportSoft ActiveX controls are essentially small applications that can be run from Microsoft's Internet Explorer. Symantec shipped the vulnerable controls with Norton AntiVirus 2006, Norton Internet Security 2006 and Norton System Works 2006, it said. Symantec's corporate security products are not affected.

The security company worked with SupportSoft on updates and has made those available via the LiveUpdate feature in its products, it said. Additionally, in November 2006, the flawed versions of the ActiveX controls were disabled through LiveUpdate, Symantec said.

SupportSoft has published its own advisory on the issue. The company offers a step-by-step guide to fix the problem, beginning with searching a PC's hard drive for the vulnerable file (tgctlsi.dll) and applying a fix.

The US-Cert recommends the SupportSoft fix but has found eight additional files are vulnerable and lists those as: tgctlins.dll; sdcnetcheck.dll; tgctlar.dll; tgctlch.dll; tgctlpr.dll; tgctlcm.dll; tglib.dll; tgctlidx.dll.

Searching a PC for all the files is the most effective way to determine if a system is vulnerable, the group said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
FIX CONNECTIVITY SPECIALIST - Hedge Fund

FIX CONNECTIVITY SPECIALIST - Hedge Fund FIX CONNECTIVITY SPECIALIST - Hedge Fund A leading Hedge Fund requires a FIX connectivity specialist / ...

Campaign/Marketing Analyst

Experience of processing cold lists ? You will be required to undertake data support activities for the marketing team with respect to the planning, ...

Electronic Engineer

The successful candidates will have detailed knowledge of the application of microelectronics to signal processing, data acquisition, and motion ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: