Cyber-attack: Enable automatic updates on anti-virus products to prevent vulnerabilities, says NCC

Date:

By Abubakar Yunusa Abuja

The Nigerian Communications Commission (NCC) says enabling automatic update features for AVAST and AVG anti-virus applications could prevent cyber vulnerabilities.

The commission’s computer security incident response team (CSIRT) said this on Sunday in a statement signed by Ikechukwu Adinde, NCC’s director of public affairs.

NCC said the vulnerabilities in AVAST and AVG anti-virus apps can lead to millions of devices being attacked.

The commission, however, advised consumers to always enable automatic update features to stay safe.

NCC has been vocal about the increasing rate of cyber-attacks in recent times.

It said the latest advisory is part of efforts to keep Nigerians safe on the internet.

READ MORE  Power: AEDC/AQUIVIS deploy Smart High-Tension Fault Detector

“The AVAST and AVG Antiviruses can lead to attacks on millions of devices with high impact in terms of consequences to the ICT user,” the statement reads.

“The threat types as a result of this vulnerability are bypass authentication, remote code execution and unauthorised access while consequences range from privilege escalation, bypass security products, overwrite system components and corrupting the operating system.

“According to CSIRT, researchers at SentinelOne security firm have discovered two potentially damaging vulnerabilities in AVAST and AVG antivirus products that allow attackers to escalate privileges enabling them to disable security products, overwrite system components, corrupt the operating system, or perform malicious operations unimpeded.

READ MORE  AEDC announces power interruption in parts of Abuja

“Two vulnerabilities identified as CVE-2022-26522 and CVE-2022-26523 targeted the “anti rootkit” driver of Avast antivirus (also used by AVG) allowing an attacker with limited privileges on the targeted system to execute code in system mode (kernel mode) and take complete control of the device. Moreover, the vulnerabilities allow complete take-over of a device, even without privileges, due to the ability to execute code in kernel mode.

“However, the cybersecurity centre has offered tripartite measures that should be taken by Internet/ICT users to prevent being vulnerable to cyber threats. They include enabling automatic update features for AVAST and AVG antiviruses, upgrading AVAST and AVG antiviruses to version 22.1.2504, as well as carrying out regular patch management.”

READ MORE  Risk Managers set for Annual Conference

Never miss a moment! Get the stories shaping Nigeria, delivered straight to your phone. Follow Peoplesdaily Newspaper on WhatsApp for breaking news, exclusive reports, and the headlines everyone will be talking about, before anyone else.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

Popular

More like this
Related

2027: Kano ADC Guber Candidate, Ibrahim Little Unveils Running Mate

By Mustapha Adamu, Kano The African Democratic Congress (ADC) governorship...

FG seeks $50 billion for recharging of shrinking Lake Chad

By Ochiaka Ugwu Nigerian government has called for raising of...

Mass Wedding: Gov. Yusuf Provides Food Support for 1,500 Couples

From Mustapha Adamu, Kano Kano State Governor, Abba Kabir Yusuf,...

IsDB, SOZEA Intensify Islamic Social Finance Drive, Train Sokoto Staff on Zakkat, Waqf

IsDB, SOZEA Intensify Islamic Social Finance Drive, Train Sokoto...