CRITICAL: This X-Press Update™ product enhancement (XPU) 24.4, featuring Virtual Patch ™ technology, includes 30 new events including added coverage for detection of spyware applications, and vulnerabilities in the SOAP protocol. Also in this XPU are 12 security content updates. Blocking for 27 existing events has been enabled including critical issues with Microsoft Exchange server and the NT TCP/IP stack. Please see the X-Force Advisories http://xforce.iss.net/xforce/alerts/id/192 and http://xforce.iss.net/xforce/alerts/id/193 for additional information.



Checks:

RiskVulnIDCheck NameCategory
High14411Spyware_PH_MarketScoreSuspicious Activity
High15650MSRPC_Svcctl_Remote_ControlUnauthorized Access Attempt
High15650MSRPC_Svcctl_Remote_QueryUnauthorized Access Attempt
Medium18576HTTP_Media_Player_setItemInfo_CodeExecUnauthorized Access Attempt
High18912HTTP_AWStats_PluginMode_ExecUnauthorized Access Attempt
High19058HTTP_AWStats_ConfigDir_ExecUnauthorized Access Attempt
Medium19060HTTP_Squid_Cache_PoisoningUnauthorized Access Attempt
Low19062DNS_DNSSEC_Type_MismatchDenial of Service
Medium19236HTML_URL_HomographUnauthorized Access Attempt
High19339HTTP_AWStats_LoadPluginUnauthorized Access Attempt
Medium19386ICMP_PingTunnel_DetectedSuspicious Activity
High19704ICMPv6_Malformed_Option_SegmentUnauthorized Access Attempt
High19705PlugAndPlay_BOUnauthorized Access Attempt
High19705PlugAndPlay_DoSUnauthorized Access Attempt
Low19731SIP_Large_Content_LengthSuspicious Activity
Low19732SIP_Long_Header_ValueSuspicious Activity
Low19733SIP_Long_Request_URISuspicious Activity
Low19734SIP_Long_Header_NameSuspicious Activity
Low19767SIP_Content_Length_MismatchSuspicious Activity
Low19768SIP_Blank_Header_ValueSuspicious Activity
Low19770SIP_Large_Max_ForwardsSuspicious Activity
Medium19812HTML_Element_Filename_TraversalUnauthorized Access Attempt
High19829MSRPC_MSMQ_OverflowUnauthorized Access Attempt
High19835Content_RAR_Missing_ExtensionUnauthorized Access Attempt
High19835Content_Incorrect_ExtensionUnauthorized Access Attempt
High19841HTML_Hostname_OverflowUnauthorized Access Attempt
Medium19944SOAP_AccessDeniedUnauthorized Access Attempt
Low19963SOAP_Envelope_OverflowDenial of Service
Low19986SOAP_Message_BodyProtocol Signature
Low19992InstallShield_Silent_InstallerUnauthorized Access Attempt

If you are an existing customer or partner, and you wish to download X-Press Updates from our download center, click here.