Symantec confirms vulnerability in antivirus software
Symantec confirmed Friday afternoon a vulnerability in its Antivirus Corporate Edition software that had been discovered by security firm Eeye. According to the company, a successful exploit of the flaw could "potentially cause a system crash, or allow a remote or local attacker to execute arbitrary code with System level rights on the affected system."
At this time, Symantec has only issued IDS signatures that will be able to detect attempts to exploit the vulnerability. Network Security Appliance 7100 signatures (SU 46), Gateway Security 3.0 signatures (SU 19) and Client Security 2.0 and 3.0 signatures (SU 22) have been made available via the software’s live update feature.
The company recommends that customers adjust their software policies as long as the flaw is exposed to a potential exploit. Specifically, the firm said that companies should restrict access to administration or management systems to privileged users only, keep all operating systems and applications updated with the latest vendor patches and "run both firewall and antivirus applications, at a minimum to provide multiple points of detection and protection to both inbound and outbound threats."
Symantec also said that users should "be cautious visiting unknown or untrusted websites or following unknown URL links" and should not "open attachments or executables from unknown sources."
Related article :
Symantec’s antivirus software vulnerable to worms - security firm
- Office 2007 downloads top 200,000
- Adobe discloses some Apollo details
- Microsoft plans first major overhaul of Xbox Live
- Gaming heaven for Southern California residents - Howie's Game Shack
- Kingston to unveil new USB flash disk lineup and high-density memory cards at Computex 2006
- LED backlighting for TVs coming faster than anticipated
- Osram: Efficiency of LED-BLUs to approach that of CCFL starting in 2007
- HP to ship 12 million notebooks in 2006
- Intel to drop rebates for large orders of desktop CPUs
- New Orleans residents to get free Wi-Fi network
- Intel to launch next-gen desktop processor Conroe on 23 July
- USPTO invalidates some of Forgent Networks' JPEG patent claims
- Is Physics The Third Wheel In Gaming?
- Intel to launch dual-core Itanium 2 at Computex
- More than 10% of LCD TVs to use 40- and 42" panels in 2006
- Samsung SDI aims to retake PDP crown in 2007
- Demand for monitor panels to pick up in H2
- Start-up promises search for IM




