Symantec Evaluates MS Agent ActiveX And MS CSRSS
By:
Shabana
| Apr 11, 2007
Microsoft has issued information on five new security bulletins, in addition to the out-of-cycle zero-day vulnerability affecting Windows Animated Cursor remote code execution.
Symantec evaluates two of the most critical issues:
Symantec Security Response rates the Microsoft Agent ActiveX vulnerability to be the most critical of the security bulletins since a successful exploit could allow an attacker to install malicious code of his/her choice and potentially allow the attacker to gain complete control of the affected system in the worst case scenario.
Microsoft also issued a patch for the vulnerability in Microsoft Client/ Server Runtime Server Subsystem (CSRSS). This remote code execution vulnerability is critical since it affects various versions of Microsoft Windows, including Windows 2000, Windows XP, Windows Server 2003, and Windows Vista. This vulnerable component of Microsoft Windows is downloaded by default and if successfully exploited, the attacker could completely compromise the computer.
Symantec recommends the following actions for IT administrators:
- Evaluate the possible impact of these vulnerabilities to critical systems.
- Plan for required responses including patch deployment and implementation of security best practices using the appropriate security and availability solutions.
- Take proactive steps to protect the integrity of networks and information.
Symantec recommends the following actions for consumers:
- Regularly run Windows Update and install the latest security patches to keep software up to date.
- Avoid opening unknown or unexpected e-mail attachments or Web links from unknown or unverified sources.
Symantec evaluates two of the most critical issues:
Symantec Security Response rates the Microsoft Agent ActiveX vulnerability to be the most critical of the security bulletins since a successful exploit could allow an attacker to install malicious code of his/her choice and potentially allow the attacker to gain complete control of the affected system in the worst case scenario.
Microsoft also issued a patch for the vulnerability in Microsoft Client/ Server Runtime Server Subsystem (CSRSS). This remote code execution vulnerability is critical since it affects various versions of Microsoft Windows, including Windows 2000, Windows XP, Windows Server 2003, and Windows Vista. This vulnerable component of Microsoft Windows is downloaded by default and if successfully exploited, the attacker could completely compromise the computer.
Symantec recommends the following actions for IT administrators:
- Evaluate the possible impact of these vulnerabilities to critical systems.
- Plan for required responses including patch deployment and implementation of security best practices using the appropriate security and availability solutions.
- Take proactive steps to protect the integrity of networks and information.
Symantec recommends the following actions for consumers:
- Regularly run Windows Update and install the latest security patches to keep software up to date.
- Avoid opening unknown or unexpected e-mail attachments or Web links from unknown or unverified sources.
| Ads by Google | ||
Post a Comment on “Symantec Evaluates MS Agent ActiveX And MS CSRSS”
LATEST NEWS
- Focus Softnet Launches ERP Soln Bundled With BI Tools
- Sunil Jose To Head Sybase India As Managing Director
- Smarter Technology Use Could Reduce Global Emissions By 15%
- CRA To Web Enable New Pension Scheme
- HP Enhances SOA Governance Software
- CSC Roll Out Completed In Jharkhand And Haryana
- Organisations Should Focus On IT Modernisation: Gartner
- Core Software Releases Transcription Manager 2.0
- Attunity Delivers Oracle, Teradata Connectors For MS SQL Server 2008
- Motorola Launches New In-Vehicle Mobile Computer
| Ads by Google | ||
RELATED
| Ads by Google | ||
Hot Searches & Keywords :
AMD
APAC
Acquisition
Asia Pacific
Asian Paints
BFSI
BI
BPO
BSNL
Bangalore
Bharti Airtel
Blackberry
Broadband
Business Objects
Business intelligence
CA
CIO
CRM
Cisco
Cisco Systems
Compliance
Data
Data Centre
Datacentre
Dell
EMC
ERP
Frost & Sullivan
Gartner
Google
Growth
HDFC Bank
HP
IBM
IDC
IPTV
IT
India
Innovation
Intel
Internet
Linux
Manish Choksi
McAfee
Microsoft
Mobile
Nasscom
NetApp
Network
Networking
Novell
Open Source
Oracle
PLM
ROI
Red Hat
Retail
SAP
SMB
SMBs
SME
SOA
SaaS
Security
Servers
Software
Storage
Sun Microsystems
Symantec
TCS
Unified Communications
VMware
Virtualisation
VoIP
Web
Web 2.0
Websense
WiMax
Wipro
e-governance
healthcare
outsourcing
partnership
telecom
|
|
||
| Ads by Google |
Sections
Applications |
Audits&surveys |
Bfsi |
Bookreviews |
Businessintelligence |
Businessprocesses |
Ciscosmenews |
Ciscowhitepapers |
Computing |
Contactcenters |
Contributedvideos |
Crm |
Ctoprofiles |
Datasecurity |
Databases |
Datacenters |
Education |
Energy |
Erp |
Focusspecials |
Government |
Guruspeak |
Hardwaresecurity |
Indialogue |
Innovation&leadership |
Innovators |
Intrusiondetection |
Intrusionprevention |
Ites |
Knowledgeprocess |
Lenovo |
Linux |
Managedservices |
Manufacturing |
Media |
Mobile |
Mobility |
Movement |
Networking |
Oncuewithitleaders |
Peoplemanagement |
Pharma |
Platforms |
Policies&compliance |
Recruitment |
Retail |
Saas |
Scm |
Securitymanagement |
Servers |
Services |
Softwaresecurity |
Softwareservices |
Specialreports |
Storage |
Storagesolution(apps) |
Techaction |
Telecom |
Telecommunications |
Theinsider |
Trendwatch |
Web |
Webisodescisco |
Weeklywrapup |
About Us | Copyright © 2006, Biztech2.com India - A Network18 Venture

