YOUR FEEDBACK
Ubuntu Here We Come! - Java Finally To Become 100% Open Source
Reader wrote: Since November 206, wow! that is a long process.
SOA World Conference
Virtualization Conference
$200 Savings Expire May 16, 2008... – Register Today!


2007 West
GOLD SPONSORS:
Active Endpoints
Your SOA Needs BPEL for Orchestration
BEA
Virtualized SOA: Adaptive Infrastructure for Demanding Applications
Nexaweb
Overcoming Bandwidth Challenges with Nexaweb
TIBCO
What is Service Virtualization?
SILVER SPONSORS:
WSO2
Using Web Services Technologies and FOSS Solutions
Click For 2007 East
Event Webcasts

2008 East
PLATINUM SPONSORS:
Appcelerator
Think Fast: Accelerate AJAX Development with Appcelerator
GOLD SPONSORS:
DreamFace Interactive
The Ultimate Framework for Creating Personalized Web 2.0 Mashups
ICEsoft
AJAX and Social Computing for the Enterprise
Kaazing
Enterprise Comet: Real–Time, Real–Time, or Real–Time Web 2.0?
Nexaweb
Now Playing: Desktop Apps in the Browser!
Sun
jMaki as an AJAX Mashup Framework
POWER PANELS:
The Business Value
of RIAs
What Lies Beyond AJAX?
KEYNOTES:
Douglas Crockford
Can We Fix the Web?
Anthony Franco
2008: The Year of the RIA
Click For 2007 Event Webcasts
SYS-CON.TV
TOP LINKS YOU MUST CLICK ON


eEye Releases Temporary Software Patch to Protect Against Zero-Day Flaw
eEye Security Protects Users From Critical Vulnerabilities Without Need for Software Patches

Digg This!

ALISO VIEJO, CA -- (MARKET WIRE) -- 03/30/07 -- eEye Digital Security®, the leading developer of system security software and the foremost contributor to security research and innovation, today released a custom form of protection to immediately address a critical exploit circulating via a flaw in Microsoft's Windows Operating System (OS). The flaw would allow a remote attacker to take complete control of an infected system. Additionally, eEye confirmed that Blink®, the award-winning Internet client security solution, provides proactive protection against this flaw.

To proactively protect Windows users around the world, eEye has released a temporary patch that prevents the flaw from being exploited. For individuals and organizations interested in receiving eEye's temporary zero-day patch, a copy can be downloaded at http://research.eeye.com/html/alerts/zeroday/20070328.html.

"Almost a year ago to the day, we released one of the first third-party patches, proactively providing Windows users temporary protection against a serious zero-day vulnerability; we are doing it yet again," said Marc Maiffret, eEye's co-founder and chief hacking officer. "Unlike last year's JScript Vulnerability, there are no immediately effective means of mitigation for this zero-day vulnerability. As a result, we encourage all Windows users to take advantage of our free patch until other means of protection become available."

Alternatively, users may install Blink Personal Internet security or Blink Professional Unified Client Security, which also provide protection without the need for security patches. http://www.eeye.com/html/products/blink/personal/

This unspecified vulnerability exists within multiple versions of Microsoft Windows operating systems and allows for a remote attacker to execute arbitrary code under the context of the logged-in user. This vulnerability can be exploited by visiting a malicious web site or opening a malformed Microsoft Office document.

This zero-day vulnerability has a very high impact since the source of the malicious payload can be any site on the Internet. An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials. The impact of this exploit can vary from the reported Trojan installation to full system compromise by coupling this attack with a privilege escalation vulnerability to acquire SYSTEM access, which would provide the attacker complete control over the compromised host.

The most potent attack method used by this vulnerability is conducted by embedding a malicious .ANI file within an HTML web page. Doing so allows the vulnerability to be exploited with minimal user interaction by simply coaxing a user to follow a hyperlink and visit a malicious web site. Other exploit vectors exist including Microsoft Office applications since they also rely on the same .ANI processing code, making email delivery also a potent threat by using Microsoft Office attachments.

About eEye Digital Security®

eEye Digital Security is a leading developer of system security software, and the foremost contributor to security research and innovation. eEye enables secure computing through world-renowned research and innovative technology, supplying some of the world's largest businesses with an integrated and research-driven vulnerability assessment, intrusion prevention, and client security solution. eEye's customers represent the largest deployments of vulnerability assessment and prevention technology in the private and public sectors. eEye protects the networks and digital assets of a growing network of more than 9,000 corporate and government deployments worldwide. Founded in 1998, eEye Digital Security is headquartered in Orange County, California. For more information, please visit www.eeye.com.

All trademarks contained within this press release are the sole property of their respective owners and are hereby acknowledged.

Add to DiggBookmark with del.icio.usAdd to Newsvine

Contacts:

Agency:
Victor Cruz
MediaPR
1.508.655.4397
email: Email Contact

Corporate, North America:
Stacy Newman
1.949.900.4131
email: Email Contact

About Marketwire .
Copyright © 2007 Marketwire. All rights reserved. All the news releases provided by Market Wire are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.

LATEST ECLIPSE STORIES . . .
Borland Finally Dumps CodeGear Tools Division
It's only taken Borland two years but it's finally dumped its CodeGear tools division, responsible for Borland's hereditary JBuilder, Delphi and C++ Builder lines as well as its new web ventures into PHP and Ruby, said to be used by 7.5 million developers. Embarcadero Technologies is b
AJAX World - Skyway Software Announces RIA Developer Contest
According to Sean Walsh, President and CEO of Skyway Software, 'Our Skyway Community is thriving and our members are very talented. We truly look forward to their RIAs submittals and Skyway Builder extensions and are excited that all of the contributions will benefit the entire Skyway
Skyway Software Releases Eclipse Plug-In at JavaOne
Skyway Software announced a strategic partnership with SpringSource. In this technology partnership, Skyway Software becomes an application-delivery ISV certified by SpringSource and integrates Spring into Skyway Visual Perspectives, its end-to-end application development and delivery
Virtualization Conference Keynote Webcast Live on SYS-CON.TV
Brian Stevens, the Chief Technology Officer and Vice President of Engineering of Red Hat, delivered his Virtualization Keynote 'The Future of the Virtual Enterprise' at SYS-CON's Virtualization Conference & Expo 2007 West in San Francisco. 'Virtualization is the hottest subject today,
3rd International Virtualization Conference & Expo: Themes & Topics
From Application Virtualization to Xen, a round-up of the virtualization themes & topics being discussed in NYC June 23-24, 2008 by the world-class speaker faculty at the 3rd International Virtualization Conference & Expo being held by SYS-CON Events in The Roosevelt Hotel, in midtown
Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
Red Hat is a trusted open source provider. Red Hat offers enterprise customers a long-term plan for building infrastructures on the quality and innovation of open source. Combining open source operating system platform, Red Hat Enterprise Linux, together with applications, management
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE