WinXP and/or Win2003 hanged systems because of SC Forefront Endpoint Protection faulty update
by Manuel Humberto Santander Pelaez (Version: 1)
Reader Philipp reported today a bug affecting his remaining Windows XP machines and Windows 2003 servers. Seems to be that all Windows XP and Windows 2003 machines with SC Forefront Endpoint Protection definition update 1.171.1.0 and later are affected. You might want to test definition update 1.171.64.0, as we have received reports stating that it fixes the problem. However, we have not seen yet any official statement from Microsoft regarding this issue.
If you disable Forefront because it's not letting your machine work, please place other controls that minimize the associated risk. Otherwise, your computers could be so easily hacked.
We also receive questions on which AV is the best. Since the answer is it depends on the company and the information security assets, you might want to check the Magic Quadrant for Endpoint Protection from Gartner Group and try to find yourself what is the best answer for your company. If you want to read the entire file, you can have it from Mcafee or Computerlinks.
We will update this diary if more information becomes available.
More information available at:
- http://msmvps.com/blogs/kenlin/archive/2014/04/16/winxp-and-or-win2003-with-sc-forefront-endpoint-protection-installed-msmpeng-exe-crashes-after-definition-update.aspx
- http://social.technet.microsoft.com/Forums/forefront/en-US/08cdcadc-5d7c-48c5-95d5-6e47291ddef0/scep-2012-432150-with-sigs-117110-causes-xp-to-hang-until-msmpeng-finally-crashes?forum=FCSNext
Manuel Humberto Santander Pelaez
SANS Internet Storm Center - Handler
Twitter:@manuelsantander
Web:http://manuel.santander.name
e-mail: msantand at isc dot sans dot org
Comments
I think not. The Magic Quadrants tend to be biased towards the size and fandom within certain circles.. and speak little or nothing to the technical merits or cost effectiveness of those vendors' products.
I would be interested in more data-driven comparisons.
There are a lot of security products out there, end point protection products, etc with very high price tags.
Doubtful that many of them are worth it.
Particularly with the spikes in 0-day fresh malware that scanners cannot reasonably pick up.
Anonymous
Apr 17th 2014
1 decade ago