Endpoint Protection

 View Only
Expand all | Collapse all

Attack: structured exception handler overwrite .. (And other error )

  • 1.  Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 15, 2019 01:24 PM

    After stop some useless windows services and block ip adress in policies firewall symantec , some symantec client crush  and others work perfect .

     

    ERROR MESSAGE : Attack: structured exception handler overwrite detect , symantec endpoint protection will end the application c:\Program files (x86)\symantec\symantec endpoint protection \14.2.1031.0100.105\bin\ccSvcHst.exe

     

    And other error Message .....

     

    PLEASE HELP ME TO KNOW IF THE PROBLEM IS A BUG OR IS UPDATE WINDOWS ... OR MY MODIFICATIONS 



  • 2.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 15, 2019 01:39 PM

    Likely known issue and being investigated by SYMC. See here:

    https://www.symantec.com/connect/forums/attack-structured-exception-handler-overwrite-detected-when-running-office-365-and-outlook

    https://www.symantec.com/connect/forums/anyone-having-any-issues-virus-defs-11419-rev21



  • 3.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 15, 2019 04:16 PM

    Just got off the phone with support.  As a temporary workaround they had me modify the Memory Exploit Mitigation policy and set the entry for ccSvcHst.exe to Log Only.



  • 4.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 04:53 AM

    Thanks to all who are following this thread.  Run LiveUpdate to obtain the latest IPS defintions in order to resolve this issue.  (IPS Signatures 201901150.64 and above.)



  • 5.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 06:44 AM
    I can't update automaticly because services symantec are stoped .. and i have a lot of remote clients


  • 6.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 10:46 AM

    I have the same problem today .

     

    structured exception handler overwrite detect , symantec endpoint protection will end the application c:\Program files (x86)\symantec\symantec endpoint protection \14.2.1031.0100.105\bin\ccSvcHst.exe



  • 7.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 11:28 AM

    Hi Olek,

    Can you let me know exactly what ISP definitions you have in place?  Are they the very latest?



  • 8.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 12:05 PM

    No I install the lates update and is good .I thought Russia attack my firewall .



  • 9.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 12:30 PM

    What is the best way to tell what version of IPS definitions are installed?  I have done the LiveUpdates this morning on a couple of PCs that had the issue.  Then a little while later we got the same message again.  I rebooted the PC after getting the alert again and haven't had it since.  So should one reboot there PC after running the LiveUpdate? 



  • 10.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 16, 2019 03:00 PM

    The solution I did is script on active directory to launch sep client in start-up, and let it be updated ... if you do not start it in start-up the SEP Service will stop  and sep client crush !



  • 11.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 18, 2019 11:09 AM

    Do you have any information about when a fix might be coming?



  • 12.  RE: Attack: structured exception handler overwrite .. (And other error )

    Posted Jan 21, 2019 03:16 AM

    The issue should be resolved with present definitions (20190115.64 or later) and, if the problem is still seen, reboot the computers.  If the issue can be reproduced after applying those definitions and rebooting, please get in touch with Tech Support and provide them with a procdump of ccsvchst.exe.