Anzeige
Mehr »
Login
Samstag, 20.04.2024 Börsentäglich über 12.000 News von 689 internationalen Medien
Goldaktie: Eine Erfolgsgeschichte, die seinesgleichen sucht, startet gerade richtig durch!
Anzeige

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
PR Newswire
177 Leser
Artikel bewerten:
(0)

Vulnerability Advisory: McAfee, Inc. Solutions Protect Against Eight Newly Disclosed Microsoft Windows Vulnerabilities


SANTA CLARA, Calif., April 10 /PRNewswire-FirstCall/ -- McAfee, Inc. , today announced that it provides coverage for the eight security vulnerabilities disclosed by Microsoft Corporation. These vulnerabilities have been reviewed by McAfee(R) Avert(R) Labs, and based on their findings, McAfee recommends that users confirm the Microsoft product versioning outlined in the bulletins and update as recommended by Microsoft and McAfee. This includes deploying solutions to ensure protection against the vulnerabilities outlined in this advisory.

"Of particular concern are CVE-2007-0938, the Microsoft Content Management Service Remote Code Execution Vulnerability of MS07-018 and MS07-021, and the MsgBox (CSRSS) Remote Code Execution Vulnerability," said David Marcus, security research and communications manager, McAfee Avert Labs. "Both of these can result in remote code execution on affected systems. Combined with the popularity of browser or Web-based attack vectors, these vulnerabilities can be particularly dangerous. Consumers and enterprises should take these vulnerabilities very seriously and employ a risk-based management approach to make sure they are properly protected."

Microsoft Vulnerability Overview: * MS07-018 - Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution * MS07-019 - Vulnerability in Universal Plug and Play Could Allow Remote Code Execution * MS07-020 - Vulnerability in Microsoft Agent Could Allow Remote Code Execution * MS07-021 - Vulnerability in CSRSS Could Allow Remote Code Execution * MS07-022 - Vulnerability in Windows Kernel Could Result in Elevation of Privilege Scope of Potential Compromise

Today's five security bulletins cover a total of eight vulnerabilities. Among the vulnerabilities, four are rated critical by Microsoft due to their potential for remote code execution.

For additional information on today's vulnerabilities as well as information on current threats, visit McAfee's Threat Center at http://www.mcafee.com/us/threat_center/default.asp where you will find blogs http://www.avertlabs.com/research/blog/ from McAfee Avert Labs researchers. More information on the vulnerabilities can also be found at http://www.microsoft.com/technet/security/current.aspx .

McAfee Solutions


With McAfee's Security Risk Management approach, customers can effectively address business priorities and security realities. McAfee's award-winning solutions identify and block known and unknown attacks before they can cause damage. McAfee will continue to update its coverage as needed as new exploit vectors are discovered and as new threats emerge.

Out of the box, Host IPS protects against many buffer overflow exploits. McAfee Host IPS v6.0 and McAfee Entercept(R) protect users against code execution that may result from common classes of exploits targeted at the buffer overflow/overrun vulnerabilities in Universal Plug and Play and Microsoft Agent. This "out of the box" protection is provided without the need for security content updates for either product.

The McAfee Vulnerability Shield package for McAfee Host IPS v6.0 customers provides specific protection against common classes of exploits targeted at the vulnerabilities in Microsoft Content Management Server, Universal Plug and Play and Microsoft Agent. The Vulnerability Shield package is deployed through McAfee ePolicy Orchestrator(R) to agents, protecting systems without a reboot.

McAfee VirusScan(R) Enterprise 8.0i and McAfee Managed VirusScan with AntiSpyware protect users against code execution that may result from common classes of exploits targeted at the buffer overflow/overrun vulnerabilities in Universal Plug and Play and Microsoft Agent.

McAfee IntruShield(R) provides coverage for Microsoft Content Management Server, Universal Plug and Play, and Microsoft Agent vulnerabilities through signature sets released today. McAfee IntruShield sensors deployed in in-line mode can be configured with a response action to drop such packets for preventing these attacks.

The McAfee System Compliance Profiler, a component of McAfee ePolicy Orchestrator, is being updated for today's newly disclosed vulnerabilities in Microsoft Content Management Server, Universal Plug and Play, Microsoft Agent, CSRSS, and Windows Kernel to quickly assess compliance levels of the security patches announced today.

The McAfee Foundstone(R) and McAfee Policy Enforcer checks are being created to detect the vulnerabilities announced today, and will be available in the packages released today and the day after tomorrow, respectively. These checks are expected to accurately identify if a system is vulnerable in many enterprise environments.

McAfee Hercules(R) Policy Auditor compliance checks and McAfee Hercules(R) Remediation Manager remediations are being created to identify unpatched systems and apply the necessary patches to affected systems for the vulnerabilities in Microsoft Content Management Server, Universal Plug and Play, Microsoft Agent, CSRSS, and Windows Kernel. Updates will be available in today's V-Flash package.

Avert DAT files have already been released to detect known exploits and new detection will be added as new exploits are discovered. DAT files are used by McAfee GroupShield(R), PortalShield(TM), Secure Internet Gateway appliances, Secure Messaging Gateway appliances, Secure Web Gateway appliances, Total Protection suites, VirusScan Enterprise, VirusScan Command Line, VirusScan Online and other McAfee scanners. McAfee users can refer to http://www.mcafee.com/us/threat_center/default.asp for information regarding any new threats attempting to exploit these vulnerabilities.

McAfee Avert Labs maintains one of the top-ranked security threat and research organizations in the world, employing researchers in 16 countries around the globe. The Labs combine world-class malicious code and anti-virus research with intrusion prevention and vulnerability research expertise. McAfee protects customers by providing deep analysis and core technologies that are developed through the combined efforts of its researchers. McAfee Avert Labs continually monitors the Internet for new threats and attack vectors on a daily basis. Whenever possible, we will update our security technologies and coverage as these new threats and vectors emerge.

About McAfee, Inc.

McAfee Inc., the leading dedicated security technology company, headquartered in Santa Clara, California, delivers proactive and proven solutions and services that secure systems and networks around the world. With its unmatched security expertise and commitment to innovation, McAfee empowers home users, businesses, the public sector, and service providers with the ability to block attacks, prevent disruptions, and continuously track and improve their security. http://www.mcafee.com/.

NOTE: McAfee, Avert, IntruShield, Entercept, Foundstone, ePolicy Orchestrator, VirusScan, GroupShield, PortalShield, and Hercules are registered trademarks or trademarks of McAfee, Inc. and/or its affiliates in the United States and/or other countries. McAfee Red in connection with security is distinctive of McAfee brand products. All other registered and unregistered trademarks herein are the sole property of their respective owners.
Großer Insider-Report 2024 von Dr. Dennis Riedl
Wenn Insider handeln, sollten Sie aufmerksam werden. In diesem kostenlosen Report erfahren Sie, welche Aktien Sie im Moment im Blick behalten und von welchen Sie lieber die Finger lassen sollten.
Hier klicken
© 2007 PR Newswire
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.