[ news_security_news ] WatchGuard Announces Protection Against Microsoft Exchange Vulnerability
SecurityProNews Staff Writer
2005-04-13
Insider Reports RSS Feed
WatchGuard Technologies has announced that its Firebox X security appliances provide protection against the latest Microsoft Exchange vulnerability disclosed today.
This vulnerability is the result of a critical buffer overflow flaw affecting Microsoft Exchange Server 2000 and 2003, which results from the way Exchange handles one of Microsoft's enhanced SMTP verbs, potentially leaving e-mail servers open to attack. WatchGuard's Intelligent Layered Security (ILS), standard on the Firebox X500-X2500, prevents remote attackers from exploiting this flaw.
"Many network security appliances on the market rely on signature updates to keep up to date with the latest threats. This leaves networks vulnerable to attack during that window of time before signatures are available and before patches for known flaws are deployed," said Mark Stevens, WatchGuard chief strategy officer. "Our Firebox X appliances provide stronger security for our customers. In the case of the new Microsoft Exchange flaw, this means protecting our customers' e-mail servers from potential attackers."
"This vulnerability relies on injecting malicious SMTP commands directly into the Exchange server protocol processor," said David Piscitello, an internationally recognized leader in networking technology and president of Core Competence, a network and security research consultancy. "This is exactly the kind of attack SMTP proxies thwart. It's nice that Microsoft recommends 'SMTP protocol inspection to filter out SMTP protocol extensions' as a workaround, but it's a simple fact that if you use an SMTP proxy in a firewall like WatchGuard's, you would not fall prey to this kind of attack at all."
About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.
More news_security_news Articles
Insider Reports RSS Feed
|
|