iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > WatchGuard Announces Protection Against Microsoft Exchange Vulnerability
Search:
[ news_security_news ]

WatchGuard Announces Protection Against Microsoft Exchange Vulnerability



SecurityProNews
Staff Writer
2005-04-13

SecurityProNews: Insider Reports Insider Reports RSS Feed


WatchGuard Technologies has announced that its Firebox X security appliances provide protection against the latest Microsoft Exchange vulnerability disclosed today.

This vulnerability is the result of a critical buffer overflow flaw affecting Microsoft Exchange Server 2000 and 2003, which results from the way Exchange handles one of Microsoft's enhanced SMTP verbs, potentially leaving e-mail servers open to attack. WatchGuard's Intelligent Layered Security (ILS), standard on the Firebox X500-X2500, prevents remote attackers from exploiting this flaw.

"Many network security appliances on the market rely on signature updates to keep up to date with the latest threats. This leaves networks vulnerable to attack during that window of time before signatures are available and before patches for known flaws are deployed," said Mark Stevens, WatchGuard chief strategy officer. "Our Firebox X appliances provide stronger security for our customers. In the case of the new Microsoft Exchange flaw, this means protecting our customers' e-mail servers from potential attackers."

"This vulnerability relies on injecting malicious SMTP commands directly into the Exchange server protocol processor," said David Piscitello, an internationally recognized leader in networking technology and president of Core Competence, a network and security research consultancy. "This is exactly the kind of attack SMTP proxies thwart. It's nice that Microsoft recommends 'SMTP protocol inspection to filter out SMTP protocol extensions' as a workaround, but it's a simple fact that if you use an SMTP proxy in a firewall like WatchGuard's, you would not fall prey to this kind of attack at all."







About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds