Saturday, March 8, 2008
After spending time auditing open source kernels and finding some interesting bugs, I wondered whether I could find a bug in a Microsoft Windows driver. There are lots of third-party drivers available for Windows, so choosing just a few to explore wasn’t easy. I finally chose some antivirus products, since they’re usually promising targets for bug hunting. I visited VirusTotal and chose the first antivirus product that I recognized on its list: avast! from ALWIL Software. That turned out to be a serendipitous decision.
On June 1, 2010, ALWIL Software was renamed AVAST Software.
I used the following steps to find the vulnerability: ...