Business Intelligence |    Certification |    Cloud Computing |    Community Manager |    CRM/ERP/ETL |    Data Center |    Database |    Enterprise 2.0 |    Enterprise Applications |    Featured stories |    Free Trials |    Green Technology |    Guest Bloggers |    Identity |    Information Technology |    IT Compliance |    IT Decision-making |    Networking |    On-Demand |    Patch Tuesday |    Podcasts |    Programming |    Security |    Social Computing |    Social Media |    Software |    Storage |    Telecommunication |    Videos |    Virtualization |    Windows |    Wireless

Shavlik Statement on Emergency Out-of-Band Patch for IE Attack Code Used to Hack Google
by Jason Miller

Jason Miller

"Microsoft has gone out-of-band from their normal release cycle for a critical security bulletin release. The bulletin addresses the zero-day vulnerability described in Security Advisory KB979352.

The last time Microsoft went out-of-band for a security bulletin was in July 2009. That bulletin addressed a vulnerability in the ATL library. Unlike the July out-of-band release, this bulletin fixes a zero-day exploit that is currently being attacked.

This bulletin, MS10-002, applies to all supported versions of Internet Explorer on all supported operating systems.

Only 1 of the vulnerabilities has been publicly disclosed and is currently being used in targeted attacks. The other 7 vulnerabilities addressed by this bulletin are not publicly known and are not being used in attacks.

It is important to note that this is a cumulative update for Internet Explorer. Multiple vulnerabilities are addressed by this bulletin. With each patch, administrators should test the patch to ensure functionality is not broken in Internet Explorer by the fixes. In the case of this patch, Administrators should deploy this patch immediately to all servers and workstations as the exploit code has been published for the one known vulnerability.

Microsoft typically releases a cumulative Internet Explorer update every other month. February’s patch day would mark the usual schedule for another cumulative release. Microsoft rolled the fix for the publicly known exploit with this cumulative update. Microsoft has shown with this bulletin release that they are able to address critical vulnerabilities while still addressing other vulnerabilities that may or may not be publicly known."

  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The Top 10 Reports for Managing Vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Shavlik COMMENTS ON EMERGENCY OUT-OF-BAND PATCH FOR INTERNET EXPLORER ATTACK CODE USED TO HACK GOOGLE

————-

Shavlik NetChk Protect Leverages Single Agent to Both Detect and Block, As Well As Ensure All Systems Patched Against this Zero Day IE Flaw

St. Paul, MN (January 21, 2010) — Shavlik Technologies, the market leader in simplifying and automating critical-to-perform and manage IT operations, today commented on the latest Microsoft out-of-band patch that repairs a zero-day flaw in Internet Explorer. Shavlik is also offering a webinar to demonstrate how its single agent solution can do double duty by both applying the out-of-band patch and protecting systems by detecting and blocking the exploit code.

"Today Microsoft released a new out-of-band patch designed to address the serious undiscovered flaw in Internet Explorer that was used to launch a zero-day attack against Google users in China," said Jason Miller, data and security team leader, Shavlik Technologies. "The exploit allowed hackers to trick users into installing malware on targeted machines which could then be used to steal data.

"The attack looks like a message that’s sent from a trusted source via email or social media, so when the user clicks on a link or file, it triggers the hack. The exploit opens a back door which then compromises the machine of the target. This attack was designed to exploit PCs, netbooks and laptops using Internet Explorer version 6 running on Windows XP. By issuing this out-of-band patch now, Microsoft has cut the time hackers could use to exploit the vulnerability in advance of the February 9 Patch Tuesday bulletin releases."

Shavlik reports that users of Shavlik NetChk Protect and its Shavlik NetChk Agent are protected against this flaw. The Shavlik NetChk Agent, which integrates Sunbelt Software’s award-winning VIPRE antivirus + antispyware engine, detects the exploit code and blocks it from executing. IT administrators can use the Shavlik NetChk console to quickly and easily determine that VIPRE threat signature files and engines are up-to-date. Once the out-of-band patch is released, the Shavlik NetChk Agent will deploy the patch. The Shavlik NetChk Agent reduces agent bloat by using a single agent to provide patch management and antivirus + antispyware.

Shavlik NetChk Protect is consistently ranked the best solution available for simplifying and automating critical IT operations for Microsoft Windows environments. Shavlik reports that corporate computing users running Windows Vista or Windows 7 would be challenged to exploit the flaw effectively due to advanced security protections already built into these newer versions of the Windows OS.

"However, just because it’s more difficult to exploit this flaw doesn’t mean that Windows Vista and Windows 7 users shouldn’t apply this patch immediately," said Miller.

Tags: , , ,



Share
                                                 
sharebar end


This entry was posted on Thursday, January 21st, 2010 at 11:18 AM and is filed under Community Manager, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply
 

You must be logged in to post a comment.

 



 
Related Tweets




Syndicated Content
  Making The Buy For Trust Seal


VeriSign At SES


VeriSign Now a Symantec Company


  PayPal UK Launch Security Key - Guest Posting from PayPal
I am happy to say they are using VeriSign Identity Protection to deliver this, which means that PayPal Customers will be able to use their token at other sites who join the VIP network. PayPal are the first UK members of the network, but there are around 30 other members in different countries around the world so you can expect to see more places where you can use your token in the UK appearing shortly.

Facebook scam - Part 2
This just in from the BBC web site, Symantec have identified a virus that steals user names and passwords, nothing new there. But, if I understand this right, it is delivered through a Facebook invitation from someone you don't know and delivers malware which can then steal user names / passwords and also keylog credit card info.

Survey finds passwords are not secure - well d'uh!
I don't think the vendor community has been crying wolf about the problems that stronger authentication solves, more like highlighting that this problem is here and growing. Well the discussion I have had recently with many different organisations across many different industries are now resulting in more and more consumer projects in this area

  Cloud Identity, Trust and the Liability Elephant.
I have been involved with a couple similar initiatives around certification for identity and thought it would be interesting to explain the logic behind these efforts. The first initiative is led by the Open Identity Exchange and is based on...

Greek Heroes, Facebook and Trust
When Achilles was a baby, the oracle predicted that he would die in battle from an arrow. Thetis, Achilles' mother who did not want her son to die decided to dip Achilles' body into the water of a river that...

PCI for the Cloud
For most enterprise and security vendors, the cloud is fascinating both as a technology and a business disruptor. In fact, SAAS CEOs such as Successfactor, SalesForce and NetSuite are hot shots in Silicon Valley these days. Yet, most of us...

Search
 Whitepaper   Webcasts  Videos  All

     


Member Login
User Name  :    Password  : 

Register | Forgot Password

Featured blog

Favorites

Other Posts

Sponsors
        

Sign up to receive email notifications about our newest white papers
.........................................................................
           Full Name  : 
Email Addresss  : 
   Confirm Email  : 


Breaking News
 
Featured stories