What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In October 2020, CyberArk researcher Eran Shimony reported vulnerabilities involving products from 10 cybersecurity vendors. The findings described two local attack techniques—symlink attacks and DLL hijacking—that could, depending on the affected product and conditions, let a lower-privileged attacker reach privileged operations. They were separate flaws, not one vulnerability shared by every vendor. SecurityWeek reported that the vendors had released patches by October 7, 2020; that historical report does not establish the status of current products or versions.
Which vendors were named?
SecurityWeek’s October 7, 2020 account of Shimony’s research named these ten vendors:
- Kaspersky
- McAfee
- Symantec
- Fortinet
- Check Point
- Trend Micro
- Avira
- Microsoft
- Avast
- F-Secure
The report did not identify one shared CVE, a single affected-product list, or uniform version ranges for all ten vendors. It therefore should not be read as evidence that every product from each company was affected.
How did the reported attack techniques work?
Both techniques exploit a boundary between a less-privileged user’s control over files or paths and a later action by a more-privileged process. The report described distinct examples and did not provide a vendor-by-vendor exploit matrix.
#1 Best Overall
| Technique | Attacker-controlled element | Privileged action involved | Reported potential impact |
|---|---|---|---|
| Symlink attack | A symbolic link or directory that redirects a path | A privileged process later accesses or operates on the path | Privilege escalation or arbitrary file deletion in described cases |
| DLL hijacking | A malicious DLL placed in a location searched by an installer or application | The installer or application loads the attacker’s library instead of the intended one | Potential execution through a higher-privilege process |
Symlink attacks
A symbolic link makes one path point to another. If a lower-privileged user can arrange a link or directory and a privileged service later uses it without safely validating the target, the service may act on a file the user could not normally change. SecurityWeek’s account discussed illustrative symlink methods involving Avira and McAfee products; those examples should not be generalized to all named vendors.
DLL hijacking
Applications search specific locations when loading libraries. If an attacker can place a malicious DLL in a searched location ahead of the legitimate library, an installer or application may load it. Shimony’s report emphasized installer behavior and noted the relevance of user-accessible locations such as Downloads: a high-privilege installation path can be exposed if it loads attacker-controlled files from such a location.
Why can a flaw in security software have serious consequences?
Antivirus and other defensive products may run processes with elevated privileges so they can inspect files, enforce policy, or manage system components. A path-handling or library-loading error in such a process can give a local attacker a route to operations beyond their normal permissions. Shimony told SecurityWeek that the implications were often full local-system privilege escalation and warned that malware could use such a foothold to persist and cause further damage. This was his assessment of the risk, not a quantified measure of how often the flaws were exploitable.
Shimony described the work as an examination of common security-product bug classes that could let a standard user escalate privileges. The practical lesson is about secure handling of filesystem paths and library loading at privilege boundaries—not that antivirus protection as a category is ineffective.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
What did the 2020 report say about patches?
SecurityWeek reported on October 7, 2020 that the vendors had released patches after disclosure. That statement is a contemporaneous summary, not a current patch-status check. The sources do not establish which product builds were affected or fixed, whether older products remain supported, or the present state of each vendor’s advisories. For a particular installation, check the relevant vendor’s official security advisories and confirm that the installed product and version are covered.
Kaspersky’s vulnerability advisory index is one official starting point for that vendor; it does not verify the status of the other nine companies or resolve the affected-version details of this report.

