<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avira - TechBlog &#187; Vulnerability warning</title>
	<atom:link href="http://techblog.avira.com/tag/vulnerability-warning/en/feed/en/" rel="self" type="application/rss+xml" />
	<link>http://techblog.avira.com</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 06:38:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Safari fixes and SMB vulnerability (Update)</title>
		<link>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/</link>
		<comments>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 06:54:26 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1395</guid>
		<description><![CDATA[Apple just released their web browser Safari in version 4.0.4 &#8211; both for Mac OS X and for Windows. Previous versions have some serious security vulnerabilities which can lead to remote code execution, crashes or to information disclosure, for example. More details can be found in Apples security advisory.
Just after the November patchday this week [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-404 alignleft" title="apple_1" src="http://techblog.avira.com/wp-content/uploads/2008/12/apple_1.png" alt="apple_1" width="45" height="50" />Apple just released their web browser Safari in version 4.0.4 &#8211; both for Mac OS X and for Windows. Previous versions have some serious security vulnerabilities which can lead to remote code execution, crashes or to information disclosure, for example. More details can be found in Apples <a title="About the security content of Safari 4.0.4" href="http://support.apple.com/kb/HT3949" target="_blank">security advisory</a>.</p>
<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />Just after the November patchday this week new reports about an issue with Microsofts SMB implementation in Windows 7 and Windows Server 2008 popped up. Rob VandenBrink of the <a title="Windows 7 / Windows Server 2008 R2 Remote SMB Exploit" href="http://isc.sans.org/diary.html?storyid=7573" target="_blank">Internet Storm Center</a> took the publicly available exploit code, fixed a line of code &#8211; et voilà, a machine with Windows 7 or Server 2008 connecting to this faked server instantly freezes. There are no reports yet about Microsoft investigating this issue.</p>
<p><strong>Update</strong>: Microsoft has released a <a title="Vulnerability in SMB Could Allow Denial of Service" href="http://www.microsoft.com/technet/security/advisory/977544.mspx" target="_blank">security advisory</a> this weekend where the company explains that it investigates the reports and is preparing a patch.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/13/safari-fixes-and-smb-vulnerability/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft fixes several critical flaws</title>
		<link>http://techblog.avira.com/2009/11/11/microsoft-fixes-several-critical-flaws/en/</link>
		<comments>http://techblog.avira.com/2009/11/11/microsoft-fixes-several-critical-flaws/en/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 06:20:25 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsoft Patchday]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1385</guid>
		<description><![CDATA[The Redmond company released 6 security bulletins with according patch-sets for this November Black Tuesday. These patches close security holes mainly in Microsoft Office and in the Windows Kernel which allow for example for drive-by-downloads, privilege escalation and remote code injection and execution.
Affected are all Microsoft operating systems (including Server 2008 core installations) and nearly [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />The Redmond company released 6 security bulletins with according patch-sets for <a title="Microsoft Security Bulletin Summary for November 2009" href="https://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_blank">this November</a> Black Tuesday. These patches close security holes mainly in Microsoft Office and in the Windows Kernel which allow for example for drive-by-downloads, privilege escalation and remote code injection and execution.</p>
<p>Affected are all Microsoft operating systems (including Server 2008 core installations) and nearly all Office versions &#8211; as well as the office viewers. Installing the updates fast is recommended as according to Microsofts threat matrix it is very likely that exploits for these vulnerabilities will appear very soon on the Internet.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/11/microsoft-fixes-several-critical-flaws/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November Patchday: Apple starts first</title>
		<link>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/</link>
		<comments>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 06:54:02 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Patchday]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1379</guid>
		<description><![CDATA[Just a few hours before Microsoft will release Updates for its software, Apple released version 10.6.2 of Mac OS X and Security Update 2009-006, respectively. This Update fixes numerous of security issues within the Mac operating system.
You can download the Update from Apples web site or just use the updater of Mac OS X. As [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-404" title="apple_1" src="http://techblog.avira.com/wp-content/uploads/2008/12/apple_1.png" alt="apple_1" width="45" height="50" />Just a few hours before Microsoft will release Updates for its software, Apple released version 10.6.2 of Mac OS X and Security Update 2009-006, respectively. This Update <a title="About Security Update 2009-006 / Mac OS X v10.6.2" href="http://support.apple.com/kb/HT3937" target="_blank">fixes numerous</a> of security issues within the Mac operating system.</p>
<p>You can download the Update from Apples <a title="Apple Support Downloads" href="http://support.apple.com/downloads/" target="_blank">web site</a> or just use the updater of Mac OS X. As some of the vulnerabilities allow for remote code injection and execution, the Update is recommended.</p>
<p>The Apple platforms will soon be targeted with more energy by cyber criminals: Just recently hackers attacked for example Apples iPhones which are jailbreak&#8217;ed &#8211; they broke into the phone through the standard password for the SSH installation. So at least change the default passwords if you used jailbreak.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/10/november-patchday-apple-starts/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Further critical Updates</title>
		<link>http://techblog.avira.com/2009/11/06/further-critical-updates/en/</link>
		<comments>http://techblog.avira.com/2009/11/06/further-critical-updates/en/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 06:48:32 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe Shockwave Player]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1367</guid>
		<description><![CDATA[Already last week Opera released version 10.01 of its Web Browser. It closes some security holes. At least one of them can lead to code injection (for example to infect the computer with a Trojan). Users are advised to install the new version fast.
Meanwhile, the Mozilla Foundation has updated Firefox to version 3.5.5. The developers [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-946" title="opera_logo" src="http://techblog.avira.com/wp-content/uploads/2009/06/opera_logo.gif" alt="opera_logo" width="50" height="40" />Already last week Opera released version 10.01 of its Web Browser. It closes <a title="Changelog for Opera 10.01" href="http://www.opera.com/docs/changelogs/windows/1001/" target="_blank">some</a> security holes. At least one of them can lead to code injection (for example to infect the computer with a Trojan). Users are advised to install the new version fast.</p>
<p><img class="alignleft size-full wp-image-255" title="ff_3" src="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png" alt="ff_3" width="50" height="40" />Meanwhile, the Mozilla Foundation has updated Firefox to <a title="Changelog for Firefox 3.5.5" href="http://www.mozilla-europe.org/en/firefox/3.5.5/releasenotes/" target="_blank">version 3.5.5</a>. The developers only mention stability fixes, this release doesn&#8217;t seem to fix security issues. Anyhow it is a good idea to install the update.</p>
<p><img class="alignleft size-full wp-image-1369" title="java_logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/java_logo.jpg" alt="java_logo" width="50" height="50" />There was another security Update for Sun Java. Version <a title="Java download" href="http://java.sun.com/javase/downloads/index.jsp" target="_blank">6 Update 17</a> fixes a lot of security vulnerabilities. Those flaws may lead to remote code execution, thus updating immediately is recommended.</p>
<p><img class="alignleft size-full wp-image-1372" title="adobe_shockwave_logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/adobe_shockwave_logo.png" alt="adobe_shockwave_logo" width="50" height="40" />What else? Adobe has released Shockwave Player 11.5.1.602 which also closes <a title="Adobe Security Bulletin" href="http://www.adobe.com/support/security/bulletins/apsb09-16.html" target="_blank">security holes</a> in the software which allow for remote malware injection. Users of the Shockwave Player (which is different from Adobe Flash Player) should also <a title="Adobe Shockwave Player Download" href="http://get.adobe.com/shockwave/" target="_blank">update</a> their software immediately.</p>
<p><img class="alignleft size-full wp-image-1377" title="chrome-logo" src="http://techblog.avira.com/wp-content/uploads/2009/11/chrome-logo.png" alt="chrome-logo" width="50" height="50" />Today also Google released an update for its <a title="Google Chrome Website" href="http://www.google.com/chrome" target="_blank">Chrome</a> browser. It fixes 2 security problems which put users at risk.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/06/further-critical-updates/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft plans 6 security bulletins</title>
		<link>http://techblog.avira.com/2009/11/06/microsoft-plans-6-security-bulletins/en/</link>
		<comments>http://techblog.avira.com/2009/11/06/microsoft-plans-6-security-bulletins/en/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 06:22:06 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Microsoft Patchday]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1365</guid>
		<description><![CDATA[For the upcoming Patch Tuesday next week, Microsoft plans to release 6 security bulletins. 3 of them handle critical rated security issues, the other 3 are rated important.
Affected are Windows Operating Systems starting from Windows 2000 up to Windows Server 2008. The &#8220;important&#8221; fixes are for Microsoft Office (also for Mac) and the Office Viewers.
Prepare [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1130" title="microsoft_logo" src="http://techblog.avira.com/wp-content/uploads/2009/09/microsoft_logo.jpg" alt="microsoft_logo" width="100" height="17" />For the upcoming Patch Tuesday next week, Microsoft <a title="Microsoft Security Bulletin Advance Notification for November 2009" href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_blank">plans</a> to release 6 security bulletins. 3 of them handle critical rated security issues, the other 3 are rated important.</p>
<p>Affected are Windows Operating Systems starting from Windows 2000 up to Windows Server 2008. The &#8220;important&#8221; fixes are for Microsoft Office (also for Mac) and the Office Viewers.</p>
<p>Prepare to install the patches as soon as possible as usually exploits for these security vulnerabilities are released very soon after Microsoft ships the patches.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/11/06/microsoft-plans-6-security-bulletins/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 3.5.4 closes 11 security holes</title>
		<link>http://techblog.avira.com/2009/10/28/firefox-3-5-4-closes-11-security-holes/en/</link>
		<comments>http://techblog.avira.com/2009/10/28/firefox-3-5-4-closes-11-security-holes/en/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 06:43:18 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1348</guid>
		<description><![CDATA[The Mozilla Foundation just released Firefox 3.5.4 &#8211; the new version closes 11 security holes of which 6 are considered critical from the Mozilla developers. Those vulnerabilities can be abused by cybercriminals to inject malicious code like a Trojan into the computer. The release also fixes a few non-security related issues.
Some of the bugs also [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png"><img class="alignleft size-full wp-image-255" title="ff_3" src="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png" alt="ff_3" width="50" height="40" /></a>The Mozilla Foundation just released Firefox 3.5.4 &#8211; the new version closes <a title="Changelog: Fixed in Firefox 3.5.4" href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4" target="_blank">11 security holes</a> of which 6 are considered critical from the Mozilla developers. Those vulnerabilities can be abused by cybercriminals to inject malicious code like a Trojan into the computer. The release also fixes a few non-security related issues.</p>
<p>Some of the bugs also affect earlier versions of the Mozilla browsers and get fixed within Firefox 3.0.15 (though it is recommended to update to Firefox 3.5) and in SeaMonkey 2.0. Thunderbird doesn&#8217;t get mentioned in the security advisories.</p>
<p>As some of the vulnerabilities are quite serious security issues, users should update the software as soon as possible. The easiest way is to go to the &#8220;Help&#8221; menu and choose &#8220;Check for Updates&#8221;.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/28/firefox-3-5-4-closes-11-security-holes/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe fixes Reader and Acrobat</title>
		<link>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/</link>
		<comments>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 06:21:45 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1307</guid>
		<description><![CDATA[Not only Microsoft released a bunch of patches to close security holes in their products, but also Adobe now ships updated software to fix several vulnerabilities in Adobe Reader and Acrobat which already get attacked with specially prepared PDF documents to take over control of vulnerable computers &#8211; Avira AntiVir protects its users and detects [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-870" title="acrobat_logo" src="http://techblog.avira.com/wp-content/uploads/2009/05/acrobat_logo.png" alt="acrobat_logo" width="31" height="33" />Not only Microsoft released a <a title="TechBlog: Microsoft closes 34 Security Holes" href="http://techblog.avira.com/2009/10/14/microsoft-closes-34-security-holes/en/" target="_self">bunch of patches</a> to close security holes in their products, but also Adobe now ships updated software to fix several vulnerabilities in Adobe Reader and Acrobat which already <a title="Avira issues a warning on harmful PDF files" href="http://www.avira.com/en/security_news/harmful_pdf_files.html" target="_blank">get attacked</a> with specially prepared PDF documents to take over control of vulnerable computers &#8211; Avira AntiVir protects its users and detects the currently circulating exploit PDF as Exp/Pidief.xam.</p>
<p>Users of Adobe Reader and Acrobat with earlier versions than the new 9.2 are advised to install the updated software immediately to protect themselves from the attacks; Adobe rates the vulnerabilities as critical. New versions of Reader are available for <a title="Adobe Reader Update for Windows" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Windows" target="_blank">Windows</a>, <a title="Adobe Reader Update for Mac" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Macintosh" target="_blank">Mac</a> and <a title="Adobe Reader Update for Unix" href="http://www.adobe.com/support/downloads/product.jsp?product=10&amp;platform=Unix" target="_blank">Unix</a>. Further links for updates for different Acrobat versions are listed in Adobes <a title="Security Advisory for Adobe Reader and Acrobat" href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">security advisory</a>.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/10/14/adobe-fixes-reader-and-acrobat/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit for SMBv2 hole in Vista publicly available</title>
		<link>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/</link>
		<comments>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 17:01:32 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[SMBv2]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1237</guid>
		<description><![CDATA[10 days ago first exploit code for the security vulnerability in the SMBv2 protocol appeared in the underground. Today working exploit code for the open source penetration testing framework Metasploit was released. Therewith it is possible for the cybercriminals to produce malware which infects vulnerable systems &#8211; Windows Vista, Windows Server 2008 and Windows 7 [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" /><a title="TechBlog: SMBv2 Exploit Code released" href="http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/" target="_self">10 days</a> ago first exploit code for the security vulnerability in the SMBv2 protocol appeared in the underground. Today working exploit code for the open source penetration testing framework Metasploit was released. Therewith it is possible for the cybercriminals to produce malware which infects vulnerable systems &#8211; Windows Vista, Windows Server 2008 and Windows 7 up to Release Candidate 1.</p>
<p>Now administrators should take countermeasures if they haven&#8217;t done so yet. Microsoft doesn&#8217;t provide a patch to solve the issue, but offers a &#8220;<a title="Microsoft Knowledgebase Article with Fix-it-for-me-tool" href="http://support.microsoft.com/kb/975497" target="_blank">1-click-tool</a>&#8221; which disables SMBv2 services on the affected systems. This can have a small performance impact. Another suggested solution by Microsoft is to block traffic to the TCP Ports 139 and 445 &#8211; which would disable Windows Network Sharing altogether.</p>
<p>We&#8217;re constantly monitoring the malware scene &#8211; if malware using this attack vector appears we can protect our customers very fast. Anyhow it is a good idea to implement the workaround with the Fix-it-for-me-tool.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/28/exploit-for-smbv2-hole-in-vista-publicly-available/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMBv2 Exploit Code released</title>
		<link>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/</link>
		<comments>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 04:31:56 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[SMBv2]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1168</guid>
		<description><![CDATA[Microsoft acknowledged a security hole in its SMBv2 implementation in Windows Vista, Server 2008 and Windows 7 up to the Release Candidate. With injecting specially prepared network packets attackers obviously are able to take complete control over affected computers.
Now a security company released an exploit for this vulnerability for their exploit framework for penetration testing. [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1088" title="win_logo" src="http://techblog.avira.com/wp-content/uploads/2009/08/win_logo.png" alt="win_logo" width="80" height="23" />Microsoft acknowledged a <a title="Microsoft Security Advisory (975497): Vulnerabilities in SMB Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/advisory/975497.mspx" target="_blank">security hole</a> in its SMBv2 implementation in Windows Vista, Server 2008 and Windows 7 <a title="Tweet from Jonathan Ness" href="http://twitter.com/jness/statuses/3856921104" target="_blank">up to</a> the Release Candidate. With injecting specially prepared network packets attackers obviously are able to take complete control over affected computers.</p>
<p>Now a security company released an exploit for this vulnerability for their exploit framework for penetration testing. It should work for Windows Vista and Server 2008. Also, the open source framework Metasploit is said to release a reliable exploit soon.</p>
<p>So it is just a matter of time until malware exploiting the SMBv2 vulnerability will appear in the wild. The security hole could be used by a worm for example. Microsoft has no patch ready, but advises to implement one of the following workarounds:</p>
<p>- Disable SMBv2 support. The Redmond company also provides a <a title="&quot;Fix-it-for-me&quot; tool for disabling/enabling SMBv2" href="http://support.microsoft.com/kb/975497" target="_blank">&#8220;Fix-it-for-me&#8221;</a> tool which will do this for the user. There is also a tool for enabling SMBv2 again.</p>
<p>- Block access to the TCP ports 139 and 445.</p>
<p>While the latter completely disables network shares for windows, the first solution should only have a small performance impact. Administrators might be advised best to disable the SMBv2 support in their LANs until Microsoft releases a patch so that no worm can spread through this security hole.</p>
<p>We&#8217;re monitoring the malware scene very closely so we can provide updated detections for appearing worms or similar malware for this vulnerability if necessary.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/18/smbv2-exploit-code-released/en/feed/en/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Firefox Update closes Drive-by-Download-Flaws</title>
		<link>http://techblog.avira.com/2009/09/10/firefox-update-closes-drive-by-download-flaws/en/</link>
		<comments>http://techblog.avira.com/2009/09/10/firefox-update-closes-drive-by-download-flaws/en/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 06:31:55 +0000</pubDate>
		<dc:creator>Dirk Knop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vulnerability warning]]></category>

		<guid isPermaLink="false">http://techblog.avira.com/?p=1149</guid>
		<description><![CDATA[The Mozilla developers released Firefox 3.5.3, which fixes overall 4 security holes in the Web browser. 3 of them are considered to be critical and allow for executing code within the browser with highest privileges and to compromise the computer. Attackers could abuse these vulnerabilities to inject for example Trojans and other malware onto the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-255" title="ff_3" src="http://techblog.avira.com/wp-content/uploads/2008/11/ff_3.png" alt="ff_3" width="50" height="43" />The Mozilla developers released Firefox 3.5.3, which fixes overall <a title="Security Advisories for Firefox 3.5" href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html" target="_blank">4 security holes</a> in the Web browser. 3 of them are considered to be critical and allow for executing code within the browser with highest privileges and to compromise the computer. Attackers could abuse these vulnerabilities to inject for example Trojans and other malware onto the victim&#8217;s computer &#8211; just with manipulated web pages.</p>
<p>With Firefox 3.5.3, the developers also added a nice new feature to the software: It&#8217;ll warn users if their Adobe Flash Player plug-in is outdated and must be updated. They&#8217;ll extend this feature for other plug-ins, according to the <a title="Mozilla Security Blog: Helping users keep plugins updated" href="http://blog.mozilla.com/security/2009/09/04/helping-users-keep-plugins-updated/" target="_blank">Mozilla Security Blog</a>.</p>
<p>Please install the update as soon as possible. The easiest way is to go to the Help menu and click on &#8220;Check for Updates&#8221;. You can also download the whole installation package on the <a title="Firefox Homepage" href="http://www.mozilla.org/firefox/" target="_blank">Firefox web site</a>.</p>
<p style="text-align: right;">Dirk Knop<br />
Technical Editor</p>
]]></content:encoded>
			<wfw:commentRss>http://techblog.avira.com/2009/09/10/firefox-update-closes-drive-by-download-flaws/en/feed/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
