TechShoutAdd to My AOL, MyYahoo, Google, Bloglines



McAfee Provides Coverage for 18 Microsoft Vulnerabilities

          0 Votes
Friday, July 14th, 2006 | Related entries: Security, Software

McAfee VirusScan Logo Antivirus and computer security company, McAfee Inc. has announced that it now provides coverage for the 18 security vulnerabilities which were disclosed by Software giant, Microsoft on Tuesday.

The vulnerabilities disclosed by Microsoft were reviewed by McAfee Avert Labs. Based on their findings, McAfee advises users to confirm the Microsoft product versioning outlined in the bulletins and to update as recommended by Microsoft and Mcafee. Users are advised to use solutions so as to ensure protection against the vulnerabilities outlined in this advisory.

“Microsoft continues to provide numerous patches for critical vulnerabilities as seen today in the widely deployed Microsoft Office and Excel applications, which accounted for 70% of the patched vulnerabilities,” said Monty Ijzerman, senior manager of the Global Threat Group for McAfee Avert Labs. “McAfee sees this as part of the trend to attack and target applications as well as base operating systems. To date this year, 31 patches have been issued for applications in contrast to 41 for operating systems. For 2005 these numbers are 13 and 73, respectively.”

Microsoft released seven security bulletins, which cover a total of eighteen vulnerabilities. Out of these, fourteen are rated critical due to their potential for remote code execution. 13 pertain to Microsoft Excel and Microsoft out of the critical vulnerabilities.

MS06-035 Mailstop Heap Overflow is definitely a worm candidate because it is remotely exploitable, even without the need for user interaction on Windows 2000 SP4 and Windows XP SP1.

McAfee mentioned that its solutions have helped to identify and block known as well as unknown attacks before they can cause any damage. McAfee Host IPS v6.0 and McAfee Entercept protect users against code execution that may occur due to exploitation of the buffer overflow/overrun vulnerabilities in Microsoft Excel, Microsoft Office, Microsoft Internet Information Services and DCHP Client Service.

McAfee VirusScan Enterprise 8.0i and McAfee Managed VirusScvan with AntiSpyware protect against attacks targeting the buffer overflow vulnerabilities in Microsoft Excel, Microsoft Office, Microsoft Internet Information Services, DCGP Client Service and .NET vulnerabilities through signature sets 1.8.78, 1.9.61, 2.1.44, 3.1.17. McAfee IntruShield sensors deployed in in-line mode can be configured with a response action to drop such packets for preventing these attacks.

Related:


Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture.
Anti-Spam Image

 
Web TechShout.com