"The encoding and encryption elements within pcAnywhere are vulnerable," Symantec acknowledged in a detailed report published this week (download PDF). "It is possible that successful man-in-the-middle attacks may occur depending on the configuration and use of the product. If a man-in-the-middle attack should occur, the malicious user could steal session data or credentials."
Attackers who obtain the software's cryptographic key can also launch unauthorized remote control sessions on pcAnywhere-equipped PCs, the company added. If successful, such attacks would give hackers free rein of the machine and possibly other systems on a network.
"My gut feel is that there was a hard-coded encryption key used to protect the data in transit and that key was exposed in the source code," said Moore after reviewing the Symantec information. "[So] this vulnerability allows anyone who can sniff the pcAnywhere traffic to decode authentication information, which in turn exposes the device to unauthorized access."
Symantec said a hacker could sniff out pcAnywhere traffic by planting a bot Trojan on a vulnerable PC.
The company has spelled out ways individuals and businesses can disable or uninstall pcAnywhere, as well as advice on how to secure Windows PCs if users simply must run the remote access software.
Symantec is also patching pcAnywhere.
The company has already updated pcAnywhere 12.5 to patch two vulnerabilities. And on Tuesday it promised to ship other fixes until it was satisfied that the software was safe to use.
It was unclear if the two patches issued this week were related to the source code theft -- Symantec did not mention that either were -- but Moore suspected that one of the pair stemmed from the leak.
On Wednesday, a Symantec spokesman said that the company couldn't predict when it would finish fixing pcAnywhere, citing the unpredictability of its investigation and patch development.
Because pcAnywhere is also bundled with three other titles -- Altiris Client Management Suite, Altiris IT Management Suite 7.0 or later, and Altiris Deployment Solution with Remote 7.1 -- IT administrators responsible for those enterprise management tools should also take steps, Symantec said.
"It's rather disappointing that they just hadn't fixed the bugs on their own without having events force them to," said Storms.
Symantec isn't the only security firm to see secrets seep onto the Internet or suffer a network breach. Last year, security company HB Gary's servers were compromised and its corporate emails published on the Web. A month later, RSA Security was hacked and information about its widely-used SecurID two-factor authentication technology was filched.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, or subscribe to Gregg's RSS feed. His email address is firstname.lastname@example.org.
Read more about Security in Computerworld's Security Topic Center.