Calendar Of Updates: Worm Alert: Big Yellow - Calendar Of Updates

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Worm Alert: Big Yellow

#1 User is offline   Hardhead 

  • Calendar & Board Admin
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Board
  • Posts: 5,662
  • Joined: 30-March 04

Posted 16 December 2006 - 12:33 AM

Quote

Systems Affected:
Symantec AntiVirus 10.0.x for Windows (all versions)
Symantec AntiVirus 10.1.x for Windows (all versions)
Symantec Client Security 3.0.x for Windows (all versions)
Symantec Client Security 3.1.x for Windows (all versions)

Overview:
The eEye Research honeypot network has recently detected a new worm that is actively exploiting a remote Symantec vulnerability originally discovered by eEye Research on May 24, 2006 and patched by Symantec on June 12, 2006. This vulnerability has been publicly exploited as early as November 30, but this is the first example of a worm leveraging this vulnerability for self-propagation. Generally, patch processes are not in place for non-Microsoft applications such as Symantec AntiVirus/Client Security, so many Symantec users may be at risk for this vulnerability throughout their networks. All enterprises running such software should assess their posture against this worm as soon as possible by validating that they have the latest version of Symantec AntiVirus/Client Security as well as blocking port tcp/2967 at the gateway to minimize attackable surface area.
http://research.eeye...AL20061215.html


#2 User is offline   Hardhead 

  • Calendar & Board Admin
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Board
  • Posts: 5,662
  • Joined: 30-March 04

Posted 17 December 2006 - 04:31 AM

Quote

Symantec has also released virus definition pertaining to this worm:
Backdoor.Wualess.B
W32.Sagevo

http://isc.sans.org/...hp?storyid=1947


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic