Symantec.com > Enterprise > Security Response > Symantec ThreatCon

ThreatCon

The ThreatCon is currently at Level 1: Normal.

On January 10, 2012, Microsoft released its scheduled patch update for January 2012. This January's update covers vulnerabilities in the Microsoft Windows operating system, its components, as well as vulnerabilities in Windows Media Player, Windows Object Packager, and the Microsoft Anti-Cross Site Scripting Library. Seven security bulletins have been released to address these issues.

Exploitation of the patched vulnerability in Windows Media Player (BID 51292, CVE-2012-0003) is occurring in the wild on malicious websites for remote code execution. Attacks are currently not widespread.

Customers are advised to install all applicable updates as soon as possible.

Microsoft Security Bulletin Summary for January 2012
http://technet.microsoft.com/en-us/security/bulletin/ms12-jan

Malware Leveraging MIDI Remote Code Execution Vulnerability Found
http://blog.trendmicro.com/malware-leveraging-midi-remote-code-execution-vulnerability-found/

More Information on MS12-004
http://blogs.technet.com/b/srd/archive/2012/01/10/more-information-on-ms12-004.aspx

Microsoft Security Bulletin MS12-004 - Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)
http://technet.microsoft.com/en-us/security/bulletin/ms12-004

Advanced Exploitation of Internet Explorer Heap Overflow Vulnerabilities (MS12-004)
http://www.vupen.com/blog/20120117.Advanced_Exploitation_of_Windows_MS12-004_CVE-2012-0003.php

Microsoft Windows Media Player 'winmm.dll' MIDI File Parsing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/51292

Symantec ThreatCon Rating

The Symantec ThreatCon rating is a measurement of the global threat exposure, delivered as part of Symantec DeepSight Threat Management System.
ThreatCon Level 1
Low : Basic network posture
This condition applies when there is no discernible network incident activity and no malicious code activity with a moderate or severe risk rating. Under these conditions, only a routine security posture, designed to defeat normal network threats, is warranted. Automated systems and alerting mechanisms should be used.
View ThreatCon Definitions

Symantec DeepSight Threat Management System

Symantec DeepSight Threat Management System tracks security events on a global basis, providing early warning of active attacks. With personalized notification triggers and expert analysis, the system enables enterprises to prioritize IT resources in order to better protect critical information assets against a potential attack. To track security threats, it continuously correlates IDS and firewall attack data from the security systems of over 20,000 partners in over 180 countries, plus virus statistics from the Symantec Digital Immune System and many other human intelligence resources. Experts at Symantec analyze the information to identify active attacks and deliver advanced warning with actionable analyses and countermeasures.
Introducing Norton 2012
ThreatCon Widget