Andrew Berges

Configuration Manager, Security, and other musings from a self-confessed IT geek.

Am I the only one that finds this a bit comical?

As reported on Donna's SecurityFlash weblog, Agnitum (maker of Outpost Firewall) is rather critical of the firewall included with Windows Vista.

Donna already makes mention in her post of the still-unpatched vulnerabilities in Agnitum's own firewall offerings, but then today I read this on the Virus Bulletin RSS feed:

'Security researchers at Matousec, known to VB readers from their firewall leak tests, have released details of an exploit taking advantage of a weakness in Agnitum's Outpost firewall product.

The attack exploits a weakness in the self-protection system used by Outpost to prevent tampering with its own files. Full details of the exploit are available online for malicious use, and no patch has yet been made available, as the vendor was informed of the problem at the same time as the public disclosure.

It is believed the flaw affects various versions between 3.0.5 and 4.0.1, and can only be exploited from the local system. The release from Matousec is here, with an alert from heise security here'

Comments

No Comments