SDAC installer reading lsass.exe process memory

Discussion of open issues, suggestions and bugs regarding SDAC (SQL Server Data Access Components) for Delphi, C++Builder, Lazarus (and FPC)
Post Reply
carlmon
Posts: 7
Joined: Thu 16 Oct 2008 09:49

SDAC installer reading lsass.exe process memory

Post by carlmon » Wed 06 May 2020 14:02

Hi,

Our AV (Carbon Black) was triggered by the SDAC installer. It seems to be reading the lsass.exe process' memory where Windows credentials are kept. Is this intended and why is it needed?

Some screenshots for further detail:
Image
Image

Stellar
Devart Team
Posts: 359
Joined: Tue 03 Oct 2017 11:00

Re: SDAC installer reading lsass.exe process memory

Post by Stellar » Tue 12 May 2020 15:37

During SDAC installation, we don't read the lsass.exe process' memory. SDAC installer was developed using InnoSetup, which might use that process, though we're not sure as it's a third-party tool.
Our users haven't reported issues with antivirus alerts during the installation so far.

Post Reply