How McAfee work with Operation Aurora
How are McAfee customers protected from this attack?
McAfee DAT files (antivirus): Coverage will be www.mcafee.com/activate download provided for associated malware (as in the 5862 DATs, releasing January 15. Partial www.mcafee/activate coverage is provided in the current (5861) DATs for some components as Generic.dx!kwv, Generic Spy.e, Spy-Agent.ey, and Exploit-Comele.McAfee VirusScan Enterprise Buffer Overflow Protection: Generic Buffer Overflow www.mcafee.com/activate product key Protection is expected to cover some www.mcafee.com/activate, but not all, exploits mcafee.com/activate product key.
How were systems compromised?
When a user manually loaded/navigated www.mcafee/activate to a malicious web page from a vulnerable mcafee.com/activate product key Microsoft Windows www.mcafee.com/activate system, JavaScript code exploited a zero-day www.mcafee.com/activate download vulnerability www.mcafee.com/activate product key in Internet Explorer;Â
What was the payload of the exploit?
Once a system was www.mcafee.com/activate download successfully compromised, the exploit mcafee.com/activate product key was designed to download and run an executable from www.mcafee.com/activate product key a site, which has since been www.mcafee/activate taken offline. That executable installed a remote access www.mcafee.com/activate Trojan to load at startup. This Trojan also contacted a remote server. This allowed remote attackers to view, create, and modify information on the compromised system.
How wide-spread is this attack?
Aurora appears to have been a very www.mcafee/activate concentrated attack on specific targets. It is not believed www.mcafee.com/activate product key to be widespread www.mcafee.com/activate at this time.
How serious is this vulnerability?
The Microsoft Internet Explorer vulnerability mcafee.com/activate product key leveraged in this attack allows for remote www.mcafee.com/activate download code execution, but does require user intervention www.mcafee/activate (such as following a hyperlink to a website, or www.mcafee.com/activate opening an email attachment, etc). Furthermore, the single exploit known to exist can be thwarted by Data Execution Prevention (DEP), enabled by default in Internet www.mcafee.com/activate download Explorer 8 and optionally mcafee.com/activate product key in Internet Explorer 7.  Microsoft lists the following combinations www.mcafee/activate to be vulnerable: Internet Explorer 6 Service www.mcafee.com/activate product key Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet Explorer 7 and Internet Explorer www.mcafee.com/activate 8 on supported editions www.mcafee.com/activate download of Windows XP,
Comments
Post a Comment