![]() |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| »Top Protections Microsoft SMB Client Vulnerabilities ( MS10-020) Several critical vulnerabilities have been identified in Microsoft Server Message Block (SMB), a network file sharing protocol. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. One, CVE-2009-3676, has been public for five months and was the first confirmed zero-day vulnerability in Windows 7. See Microsoft Security Advisory 977544. Check Point has provided immediate protection for this vulnerability since November 17, 2009 and provides immediate protection against exploits that use these vulnerabilities through its integrated IPS offerings. More information. (Internet Explorer MS10-018, Firefox Security Advisories, Safari CVE-2009-3271) Exploitation of browser vulnerabilities is a favorite attack vector and browser vendors have been trying to keep up with security updates. On March 30th Microsoft released an out-of-band security update for Internet Explorer that fixed 10 Critical vulnerabilities. Check Point provided protections for all 10. In addition Check Point IPS-1 provides protections against 7 Firefox exploits, 3 that were Critical, and an immediate protection against an up-patched Safari exploit. More information. Blocking Null Prefix in DNS MX Records (MS10-024, CVE-2010-0024) A denial of service vulnerability has been reported in the way that Microsoft Windows Simple Mail Transfer Protocol (SMTP) component handles specially crafted DNS Mail Exchanger (MX) resource records. A remote attacker may trigger this vulnerability via a specially crafted DNS request with a null prefix in the MX record. Successful exploitation of this issue could cause the affected system to stop accepting requests. Check Point provides immediate protection against this exploit through its integrated IPS offerings; SmartDefense and the IPS Software Blade. More information. |
April 13, 2010
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
» Highlighted Protections This table lists Check Point protections for recently disclosed threats. In some cases, Check Point protections against such threats or threat types have been available for some time, and the date listed is the date when the protection became available.
More Updates > |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Read Check Point's Privacy Policy ©2003-2010 Check Point Software Technologies Ltd. (Nasdaq: CHKP) All rights reserved. 800 Bridge Parkway, Redwood City, CA USA 94065 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||