You are here
Home › Bill Lindner › SupportSoft Tech Support Tools Leave PCs Vulnerable to Remote AttackSupportSoft Tech Support Tools Leave PCs Vulnerable to Remote Attack
The United States Emergency Readiness Team (US-CERT) has issued an advisory regarding remote tech support tools made by SupportSoft.
The affected software uses ActiveX controls contain multiple buffer overflow vulnerabilities which could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
The SupportSoft ActiveX controls are essentially small applications that can be run from Microsoft's Internet Explorer. The affected software is often used by Internet service providers, PC makers and other companies to provide support functions such as remote assistance.
SupportSoft is aware of a remote code execution vulnerability that exists in SmartIssue, RemoteAssist, and Probe controls on both the 5.6 Versions and Version 6.x versions of its software. This vulnerability has already been addressed in the latest versions of all SupportSoft software and patches have been delivered and installed by all SupportSoft corporate customers. Users can download the SupportSoft ActiveX Controls Update from the SupportSoft web site.
SupportSoft offers a step-by-step guide to fix the problem, beginning with searching a PC's hard drive for the vulnerable file (tgctlsi.dll) and applying a fix. The US-CERT recommends the SupportSoft fix, but has found eight additional files are vulnerable: tgctlins.dll; sdcnetcheck.dll; tgctlar.dll; tgctlch.dll; tgctlpr.dll; tgctlcm.dll; tglib.dll; and tgctlidx.dll. They also recommend searching a PC for files to determine if a system is vulnerable.
Note that since the vulnerable controls are commonly included with third-party software that is not explicitly packaged as "SupportSoft," searching for the above files is the most effective way to determine if a system is vulnerable.
US-CERT lists 37 companies and organizations that have shipped the affected software. Some have addressed the problem, while others are still listed as vulnerable or unknown. Some of the companies including IBM, BellSouth, Comcast and Time Warner have yet to fix the vulnerability.
Symantec includes the SupportSoft components in its consumer security products. Symantec has issued its own alert along with the fixes. The software affected by the flaws include:
- Symantec Automated Support Assistant
- Symantec Norton AntiVirus 2006
- Symantec Norton Internet Security 2006
- Symantec Norton System Works 2006
Symantec's corporate security products are not affected. The problem is listed as "high" risk, but is mitigated somewhat, because triggering the flaw would require some action on the part of the user.
The security company worked with SupportSoft on updates and has made those available via the LiveUpdate feature in its products, it said. Additionally, in November 2006, the flawed versions of the ActiveX controls were disabled through LiveUpdate, Symantec said.
Visit Bill's Links and More for more great tips, just like this one!
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.