Endpoint Protection

 View Only

Java 0-Day Coverage 

Aug 30, 2012 01:44 PM

Greetings everyone.

We are still getting a lot of questions about Symantec's coverage of the most recent Java 0-Day. I thought I would take a moment to jot down a list of our current coverage for this event, and hopefully save everyone some time and hassle.

Current Coverage:

Not-Coverage

  • 25431 -  Web Attack: Malicious JAR File Download 6
    Although this signature was updated recently, it does not provide additional protection specific to this vulnerability.
    This was reported incorrectly for a short time in the Security Response blog, but has since been corrected.

2nd 0-day??

There has been some mention of a second Java 0-day but this seems to be a matter of semantics. The exploit requires both to actually function, so most researchers are considering them a single vulnerabilty. This may change, but its where wer are currently at.

That said, all the coverage information above, still holds true.

http://threatpost.com/en_us/blogs/researchers-identify-second-new-java-bug-082812
http://www.informationweek.com/security/vulnerabilities/java-zero-day-attack-second-bug-found/240006431

Security Response Blogs:

New Java Zero-Day Vulnerability (CVE-2012-4681)
Java Zero-Day Used in Targeted Attack Campaign

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Sep 13, 2012 03:29 AM

Thank you for the clarification Brandon !

Sep 10, 2012 10:26 AM

@ John

Proactive Threat Protection or PTP updates on a non-standard schedule.

You can find the current definitions date for all the technologies here:
http://www.symantec.com/security_response/definitions.jsp

This is a good one to bookmark!

Also, please note we had a few issues with the site not reflecting the accurate date for PTP defs last week. You can see my responses to the following post for more info on that:
PTP not updating all other definitions are uptodate

Sep 06, 2012 08:26 PM

Ah ok, yes it seems that I have IPS enabled on all of my SEP clients as at below.

but my servers only got the Virus and Spyware protection :-|

Sep 06, 2012 09:29 AM

Update [August 30, 2012] -

Java Zero-Day Used in Targeted Attack Campaign

ALSO

Oracle has issued a patch: Java SE 7 Update 7 for CVE-2012-4186.
Users are advised to download the latest update.

Sep 06, 2012 09:25 AM

@Srikanth

Pathing the vulnerable application is ALWAYS to be preffered.

 

@John

In my post you will find the links to the IPS signatures. Those are deployed through IPS in SEP 12.1. So, yes, you are protected as lonag as you have the IPS component installed.

If not, then why not? :)

Sep 03, 2012 08:14 PM

Hm... Does SEP v 12.1 can prevent this issue ?

Sep 01, 2012 04:20 AM

Hi,

As per this post as of now it is not recommended to download and install java?

Related Entries and Links

No Related Resource entered.