Check Point® Software Technologies Ltd. (Nasdaq:CHKP), the worldwide
leader in securing the Internet, today announced through Check Point
SmartDefense® Services, users of VPN-1® R65, R62, and VSX NGX R65 are
protected from an unpatched, publically available Microsoft Internet
Explorer 7 vulnerability. SmartDefense Services subscribers gain
immediate protection against the threat, which if exploited allows an
attacker to execute arbitrary commands and access information residing
on a targeted machine.
Made public a few days ago on Chinese online forums, the Internet
Explorer 7 browser flaw affects users running Windows XP Service Packs 2
and 3, Windows Vista, Windows Vista Service Pack 1, Windows Server 2003
Service Packs 1 and 2, and Windows Server 2008. The attack is a typical
drive-by download, where hackers infect existing Web sites - or set-up
their own rogue Web sites - and then redirect or trick users into going
to them. The moment the victim lands on the site, hackers slip malicious
software quietly onto the victim’s computer through a flaw in the
browser or a browser plug-in. The malicious software is often used to
silently steal sensitive data by secretly logging everything the victim
types. SmartDefense protection refutes this attack by preventing the
exploitation of the underlying browser's flaw.
"With no patch and the exploit code publically available for hackers to
use, businesses are left quite exposed,” said Oded Gonda, vice president
of network security products at Check Point. "Rather than rely on
employees to implement complicated workarounds locally, Check Point
SmartDefense Services provide enterprises immediate protection to the
latest threats.”
Check Point SmartDefense provides intrusion prevention capabilities that
are integrated into Check Point gateways. SmartDefense is updated by
SmartDefense Services, which provide ongoing and real-time updates and
configuration advisories for defenses and security policies.
SmartDefense protections are developed and distributed by SmartDefense
Research and Response Centers located around the globe.
More information about the vulnerability and the SmartDefense protection
can be found at Check Point's Security Research and Response website: www.checkpoint.com/defense/advisories/public/index.html.
In a related alert, Check Point also announced ZoneAlarm ForceField
browser security product protects consumers against the same
vulnerability. By placing a two-way "bubble of security" around the
browser, ZoneAlarm ForceField prevents drive-by downloads, unwanted
malware and other Web threats from damaging users' PCs or from stealing
users' private information.
About Check Point Software Technologies Ltd.
Check Point Software Technologies Ltd. (www.checkpoint.com)
is the leader in securing the Internet. Check Point offers total
security solutions featuring a unified gateway, single endpoint agent
and single management architecture, customized to fit customers’ dynamic
business needs. This combination is unique and is a result of our
leadership and innovation in the enterprise firewall, personal
firewall/endpoint, data security and VPN markets.
Check Point’s pure focus is on information security. Through its NGX
platform, Check Point delivers a unified security architecture to
protect business communications and resources, including corporate
networks and applications, remote employees, branch offices and partner
extranets. The company also offers market-leading endpoint and data
security solutions with Check Point Endpoint Security products,
protecting and encrypting sensitive corporate information stored on PCs
and other mobile computing devices. Check Point's award-winning
ZoneAlarm solutions protect millions of consumer PCs from hackers,
spyware and identity theft. Check Point solutions are sold, integrated
and serviced by a network of Check Point partners around the world and
its customers include 100 percent of Fortune 100 companies and tens of
thousands of businesses and organizations of all sizes.
©2003–2008 Check Point Software Technologies Ltd. All rights reserved.