WatchGuard Protects Customers from ``Critical'' Microsoft Exchange Flaw that Leaves E-mail Servers Open to Attack; Company's Intelligent Layered Security keeps customers safe without relying on signatures.SEATTLE -- WatchGuard Technologies, Inc. (Nasdaq: WGRD) has announced that its Firebox X security appliances provide protection against the latest Microsoft Exchange Messaging and groupware software for Windows from Microsoft. Exchange Server is an Internet-compliant e-mail system that runs under Windows NT/2000 and Windows Server 2003. It can be accessed by Web browsers, the Exchange client, versions of Outlook and the earlier Windows Inbox. vulnerability disclosed today. This vulnerability is the result of a critical buffer overflow A common cause of malfunctioning software. If the amount of data written into a buffer exceeds the size of the buffer, the additional data will be written into adjacent areas, which could be buffers, constants, flags or variables. flaw affecting Microsoft Exchange Server Microsoft Exchange Server is a messaging and collaborative software product developed by Microsoft. It is part of the Microsoft Servers line of server products and is widely used by enterprises using Microsoft infrastructure solutions. 2000 and 2003, which results from the way Exchange handles one of Microsoft's enhanced SMTP (Simple Mail Transfer Protocol) The standard e-mail protocol on the Internet and part of the TCP/IP protocol suite, as defined by IETF RFC 2821. SMTP defines the message format and the message transfer agent (MTA), which stores and forwards the mail. verbs, potentially leaving e-mail servers open to attack. WatchGuard's Intelligent Layered Security Layered security is a new term used by information protection and online security vendors that describes the practice of leveraging several different point security solutions to protect the digital identities and information of consumer, enterprise or government environments. (ILS ILS In currencies, this is the abbreviation for the Israeli Shekel. Notes: The currency market, also known as the Foreign Exchange market, is the largest financial market in the world, with a daily average volume of over US $1 trillion. ), standard on the Firebox X500-X2500, prevents remote attackers from exploiting this flaw. "Many network security appliances on the market rely on signature updates to keep up to date with the latest threats. This leaves networks vulnerable to attack during that window of time before signatures are available and before patches for known flaws are deployed," said Mark Stevens, WatchGuard chief strategy officer. "Our Firebox X appliances provide stronger security for our customers. In the case of the new Microsoft Exchange flaw, this means protecting our customers' e-mail servers from potential attackers." "This vulnerability relies on injecting malicious SMTP commands directly into the Exchange server protocol processor," said David Piscitello, an internationally recognized leader in networking technology and president of Core Competence Core competence Primary area of expertise. Narrowly defined fields or tasks at which a company or business excels. Primary areas of specialty. , a network and security research consultancy. "This is exactly the kind of attack SMTP proxies thwart. It's nice that Microsoft recommends 'SMTP protocol inspection to filter out SMTP protocol extensions' as a workaround (jargon, programming) workaround - A temporary kluge used to bypass, mask or otherwise avoid a bug or misfeature in some system. Customers often find themselves living with workarounds for long periods of time rather than getting a bug fix. , but it's a simple fact that if you use an SMTP proxy in a firewall like WatchGuard's, you would not fall prey to this kind of attack at all." About WatchGuard Technologies, Inc. WatchGuard is a leading provider of network security solutions for small- to mid-sized enterprises worldwide, delivering integrated products and services that are robust as well as easy to buy, deploy and manage. The company's Firebox X line of expandable integrated security appliances is designed to be fully upgradeable as an organization grows and to deliver the industry's best combination of security, performance, intuitive interface and value. WatchGuard Intelligent Layered Security architecture protects against emerging threats effectively and efficiently and provides the flexibility to integrate additional security functionality and services offered through WatchGuard. Every WatchGuard product comes with an initial LiveSecurity Service subscription to help customers stay on top of the security landscape with vulnerability alerts, software updates, expert security instruction and superior customer care. For more information, please visit www.watchguard.com. WatchGuard, LiveSecurity and Firebox are either registered trademarks or trademarks of WatchGuard Technologies, Inc. in the United States United States, officially United States of America, republic (2005 est. pop. 295,734,000), 3,539,227 sq mi (9,166,598 sq km), North America. The United States is the world's third largest country in population and the fourth largest country in area. and/or other countries. All other trademarks are the property of their respective owners. |
|
||||||||||||||||

Printer friendly
Cite/link
Email
Feedback
Reader Opinion