Endpoint Protection

 View Only
  • 1.  New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 28, 2014 04:39 AM

    Symantec is aware of reports of a zero-day vulnerability (CVE-2014-1776) that affects all versions of Internet Explorer.  Security Response have posted a blog about this new vulnerability:

    Zero-Day Internet Explorer Vulnerability Let Loose in the Wild
    https://www-secure.symantec.com/connect/blogs/zero-day-internet-vulnerability-let-loose-wild

    Protection is available with the latest updates. Symantec protects customers against this attack with the following detections:

    • Bloodhound.Exploit.552
    • Web Attack: MSIE Use After Free CVE-2014-1776


  • 2.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Broadcom Employee
    Posted Apr 28, 2014 09:48 AM

    Thanks for the update, Mick!



  • 3.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 28, 2014 11:13 AM

    Do you know if SEP 11 also protects against this. 



  • 4.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 28, 2014 11:17 AM

    Yes, same definitions for both 11 and 12.



  • 5.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 28, 2014 03:00 PM

    Thanks!!! :)

     



  • 6.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 29, 2014 02:34 AM

    Any idea when this signatures are to be released?

    Vendor Detection

    • Symantec SEP/AV
    • Bloodhound.Exploit.552
    • Symantec SEP/IPS
    • Web Attack: MSIE Use After Free CVE-2014-1776


  • 7.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Broadcom Employee
    Posted Apr 29, 2014 03:25 AM

    Bloodhound.Exploit.552 and IPS definitions are already released.

     



  • 8.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 29, 2014 05:08 AM

    Many thanks, Pete!  You are correct.  These protections have been available for SEP 11 and SEP 12.1 via LiveUpdate for a couple days now.

     



  • 9.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 30, 2014 02:48 AM

    Just saw it now.IPS is included.



  • 10.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Broadcom Employee
    Posted Apr 30, 2014 02:49 AM

    whats the IPS definition you have on server. if it's updated with April 29 r12, it will have IPS signature.

    open SEPM console for IPS policy and search for id 27546. 



  • 11.  RE: New Security Response Blog Post about IE Zero Day Vulnerability CVE-2014-1776

    Posted Apr 30, 2014 02:59 AM

    Thanks. Got it.