Attackers are scanning ther internet for systems vulnerable to a flaw in SEMP

TECHi's Author Alfie Joshua
Opposing Author Zdnet Read Source Article
Last Updated
TECHi's Take
Alfie Joshua
Alfie Joshua
  • Words 69
  • Estimated Read 1 min

Symantec Endpoint Protection, developed by the US-based Symantec Corporation, was shipped without removing several critical security vulnerabilities. The vulnerabilities were discovered in a routine ’99er’ security crash test by experts of the SEC Consult Vulnerability Lab. The unremoved vulnerabilities enable state-sponsored or criminal hackers to take full control of the ‘Symantec Endpoint Protection Manager’ server. With the full control of the server the attackers could obliterate the endpoint protection.

Zdnet

Zdnet

  • Words 102
  • Estimated Read 1 min
Read Article

The Internet Storm Center (ISC) at the SANS Institute is reporting a burst of scanning on ports used by Symantec Endpoint Protection Manager (SEPM) versions 11.0 and 12.1. The scanning appears aimed at building a list of systems vulnerable to a recently-disclosed vulnerability in the product. Symantec disclosed the vulnerability on February 10 and released updates to SEPM (click here for instructions on how to apply updates). The fixed versions of the management console are 11.0 RU7 MP4a (11.0.7405.1424) or 12.1 RU4a (12.1.4023.4080). The vulnerability results from erroneous parsing of XML data sent to the console, causing the console to send unsanitized queries to an internal database. 

Source

NOTE: TECHi Two-Takes are the stories we have chosen from the web along with a little bit of our opinion in a paragraph. Please check the original story in the Source Button below.

Balanced Perspective

TECHi weighs both sides before reaching a conclusion.

TECHi’s editorial take above outlines the reasoning that supports this position.

More Two Takes from Zdnet

Microsoft won’t bring Android apps to Windows 10 after all
Microsoft won’t bring Android apps to Windows 10 after all

Things aren't looking good for Windows 10 Mobile, as Microsoft has cancelled Project Astoria, the initiative that was supposed to allow…

Huawei ended 2015 with more than 108 million smartphones shipped
Huawei ended 2015 with more than 108 million smartphones shipped

While Xiaomi was struggling just to meet the low-end of its sales goals for last year, Huawei was blowing past…

Microsoft has delayed its 84-inch tablet again
Microsoft has delayed its 84-inch tablet again

It was hard to believe the rumors that Microsoft is working on an 84-inch tablet at first, but when the…

It looks like even Windows 10 can’t save Microsoft’s mobile business
It looks like even Windows 10 can’t save Microsoft’s mobile business

Windows 10 was supposed to breathe new life into Microsoft's smartphone sales, but we haven't seen any evidence of that happening,…