Energizer software found to open backdoor

An application that allows users to view the battery charging status of the Energizer DUO USB charger contains a vulnerability that could enable an attacker to install malware on Windows machines.

The flaw, disclosed Friday by US-CERT in a note, involves Arucer.dll, a backdoor trojan that permits unauthorized remote system access through TCP port 7777.

The trojan runs each time the computer starts and listens for commands over the port, according to a Symantec blog post on Friday.

"An attacker is able to remotely control a system, including the ability to list directories, send and receive files and execute programs," the note said. "The backdoor operates with the privileges of a logged-on user."

A VirusTotal report from early Monday showed that less than 25 percent of anti-virus solutions were detecting the backdoor.

Energizer is aware of the problem and is trying to learn how the software was tampered with, according to a news release.

"Energizer has discontinued sale of this product and has removed the site to download the software," the company said. "In addition, the company is directing consumers that downloaded the Windows version of the software to uninstall or otherwise remove the software from your computer. This will eliminate the vulnerability.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.