There is a report out of Kaspersky Labs that there's a new form of "drive by" malware that exploits a known Java vulnerability, (CVE-2011-354) to inject an encrypted dll from the web directly into the memory of the javaw.exe process. To qote the article in The Register, "That mode of operation means Windows and MacOS are both affected by the exploit, which is hard for many antivirus programs to spot given it runs within a trusted process."
The article is here:
http://www.theregister.co.uk/2012/03/18/fileless_malware_found/
It would be nice to know if Webroot can detect this type of exploit.
Reply
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.