Skip the navigation
News Analysis

Faulty McAfee update burns IT execs

The security firm moves quickly to placate companies crippled by its flawed antivirus software.

By Gregg Keizer and Robert McMillan
May 10, 2010 06:00 AM ET

Computerworld - McAfee Inc. moved swiftly to make amends to corporate and individual customers whose PCs were crippled late last month by a faulty antivirus update that it distributed.

Less than a week after the security vendor had pushed the flawed update to users, it offered affected business customers a free one-year subscription to its automated security assessment service, and reimbursement to consumers for any "reasonable expenses" related to the incident.

The faulty update, released on April 21, had corporate IT administrators scrambling when the new signatures quarantined a critical Windows system file, causing some computers running Windows XP Service Pack 3 to crash and reboot repeatedly.

McAfee said later that a small fraction of its corporate customers -- less than 0.5% -- were affected by the glitch. But those that were faced a time-consuming repair process. Virtually all of the affected PCs were unable to connect to a network, so corporate support personnel had to manually fix each machine impaired by the faulty update.

An Intel Corp. spokesman said an unknown number of the chip maker's systems were knocked offline by the bad update. He said the resulting problems had a "significant" impact on the company.

"There were quite a few clients, laptops and PCs [affected]," the spokesman said. "We were able to get it stopped fairly early on, but clearly not soon enough."

About 40% of machines used by the government of Washington's Snohomish County were affected by the problem, according to John Storbeck, the county's engineering services supervisor. In an e-mail, he called the incident "a nightmare."

In Iowa, a disaster response exercise was disrupted when the update caused 9-1-1 computer systems to crash, said Deb Hale, a security administrator at Long Lines, an Internet service provider in Sioux City. "Thanks to McAfee, we were forced to test our response to a disaster while in the midst of a real 'disaster,' " she wrote in a blog post on the SANS Institute's Internet Storm Center site.

"This is the worst glitch that I've ever had to deal with," said Ken Whittaker, a desktop support technician at a Michigan university where some 10,000 desktops were affected by the defect. He asked that the school not be identified.

It's not unheard of for antivirus vendors to mistakenly impair software with their updates. Criminals have become so good at switching up their code that companies like McAfee must now churn out millions of signatures in a cat-and-mouse game to identify malware that is in circulation. That leads to errors.

Still, the fact that McAfee allowed a major Windows component to be misidentified demonstrates "a failure in their quality control process," said Amrit Williams, chief technology officer at systems management software vendor BigFix Inc.

"You're not talking about some obscure file from a random third party; you're talking about a critical Windows file," said Williams, a former director of engineering at McAfee. "The fact that it wasn't found is extremely troubling."

McMillan is a reporter for the IDG News Service.

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs