CA Patches High Risk Anti-Virus Flaw

CA Patches High Risk Anti-Virus Flaw

Written By
Ryan Naraine
Ryan Naraine
May 24, 2005
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A high-risk buffer overflow vulnerability in Computer Associates International Inc.s eTrust Vet anti-virus engine could put users at risk of PC takeover attacks, the company warned in an advisory.

The Islandia, N.Y., software giant issued an alert for the flaw late Monday with a chilling warning that a successful attacker using a specially crafted Microsoft Office document could “gain full access to the computer without any user interaction.”

The issue affects several enterprise products that rely on the Vet anti-virus engine, including CA InoculateIT 6.0, eTrust Antivirus 6.0 through 7.1, eTrust Antivirus for the Gateway 7.0 and 7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, and BrightStor ARCserve Backup.

Users of the consumer-facing eTrust EZ Antivirus and eTrust EZ Armor suites are also at risk.

“All Computer Associates corporate products and some of our retail products that utilize the Vet Antivirus Engine have the ability to patch this vulnerability automatically. For these products, the patch for this vulnerability was already rolled out as part of the daily Vet Signature updates and no further action is required,” CA explained in an advisory.

The company said the Vet Antivirus Engine is included in drivers, system services to automatically scan any files that the computer may access. “In the worst scenario, an external attacker may present a carefully crafted Microsoft Office document to a vulnerable computer for virus scanning and gain control of the computer without any user interaction,” the alert read.

A knowledge document was also issued with detailed instructions on how to apply the required updates.

Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.