Feed aggregator

Fix it tool available to block Internet Explorer attacks leveraging CVE-2014-0322

Microsoft Security Center Center News - Wed, 02/19/2014 - 08:00
Today, we released Security Advisory 2934088 to provide guidance to customers concerned about a new vulnerability found in Internet Explorer versions 9 and 10. This vulnerability has been exploited in limited, targeted attacks against Internet Explorer 10 users browsing to www.vfw.org and www.gifas.asso.fr. We will cover the following topics in this blog post:
Categories: Microsoft

Microsoft Releases Security Advisory 2934088

Microsoft Security Center Center News - Wed, 02/19/2014 - 08:00
Today, we released Security Advisory 2934088 regarding an issue that impacts Internet Explorer 9 and 10. Internet Explorer 6, 7, 8 and 11 are not affected. At this time, we are only aware of limited, targeted attacks against Internet Explorer 10. This issue allows remote code execution if users browse to a malicious website with an affected browser.
Categories: Microsoft

February 2014 Security Bulletin Webcast and Q&A

Microsoft Security Center Center News - Fri, 02/14/2014 - 08:00
Today we published the February 2014 Security Bulletin Webcast Questions & Answers page. We answered seven questions on air, with the majority of questions focusing on the MSXML bulletin (MS14-005) and the revision to Security Advisory 2915720. One question that was not answered on air has been included on the Q&A page.
Categories: Microsoft

Assessing risk for the February 2014 security updates

Microsoft Security Center Center News - Tue, 02/11/2014 - 08:00
Today we released seven security bulletins addressing 31 unique CVE’s. Four bulletins have a maximum severity rating of Critical while the other three have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max Exploit-ability Likely first 30 days impact Platform mitigations and key notes MS14-010(Internet Explorer) Victim browses to a malicious webpage.
Categories: Microsoft

Safer Internet Day 2014 and Our February 2014 Security Updates

Microsoft Security Center Center News - Tue, 02/11/2014 - 08:00
In addition to today being the security update release, February 11 is officially Safer Internet Day for 2014. This year, we’re asking folks to Do 1 Thing to stay safer online. While you may expect my “Do 1 Thing” recommendation would be to apply security updates, I’m guessing that for readers of this blog, that request would be redundant.
Categories: Microsoft

Update (2/10) - Advance Notification Service for February 2014 Security Bulletin Release

Microsoft Security Center Center News - Mon, 02/10/2014 - 08:00
Update as of February 10, 2014 We are adding two updates to the February release. There will be Critical-rated updates for Internet Explorer and VBScript in addition to the previously announced updates scheduled for release on February 11, 2014. These updates have completed testing and will be included in tomorrow’s release.
Categories: Microsoft

Antimalware Support for Windows XP and the January 2014 Security Bulletin Webcast and Q&A

Microsoft Security Center Center News - Fri, 01/17/2014 - 08:00
Today we’re publishing the January 2014 Security Bulletin Webcast Questions & Answers page. We answered 16 questions in total, with the majority of questions focusing on the Dynamics AX bulletin (MS14-004), the update for Microsoft Word (MS14-001) and the re-release of the Windows 7 and Windows Server 2008 R2 updates provided through MS13-081.
Categories: Microsoft

A Look Into the Future and the January 2014 Bulletin Release

Microsoft Security Center Center News - Tue, 01/14/2014 - 08:00
In January, there are those who like to make predictions about the upcoming year. I am not one of those people. Instead, I like to quote Niels Bohr who said, “Prediction is very difficult, especially if it’s about the future.” However, I can say without a doubt that change is afoot in 2014.
Categories: Microsoft

Assessing risk for the January 2014 security updates

Microsoft Security Center Center News - Tue, 01/14/2014 - 08:00
Today we released four security bulletins addressing six CVE’s. All four bulletins have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max exploit-ability rating Likely first 30 days impact Platform mitigations and key notes MS14-002(NDProxy, a kernel-mode driver) Attacker able to run code at a low privilege level inside an application sandbox exploits this vulnerability to elevate privileges to SYSTEM.
Categories: Microsoft

Advance Notification Service for the January 2014 Security Bulletin Release

Microsoft Security Center Center News - Thu, 01/09/2014 - 08:00
Today we provide advance notification for the release of four bulletins for January 2014. All bulletins this month are rated Important in severity and address vulnerabilities in Microsoft Windows, Office, and Dynamics AX. The update provided in MS14-002 fully addresses the issue first described in Security Advisory 2914486. We have only seen this issue used in conjunction with a PDF exploit in targeted attacks and not on its own.
Categories: Microsoft

Predictions for 2014 and the December 2013 Security Bulletin Webcast, Q&A, and Slide Deck

Microsoft Security Center Center News - Mon, 12/16/2013 - 08:00
Today we’re publishing the December 2013 Security Bulletin Webcast Questions & Answers page. We answered 17 questions in total, with the majority of questions focusing on the Graphics Component bulletin (MS13-096), Security Advisory 2915720 and Security Advisory 2905247. We also wanted to note a new blog on the Microsoft Security Blog site on the top cyber threat predications for 2014.
Categories: Microsoft

Software defense: mitigating common exploitation techniques

Microsoft Security Center Center News - Wed, 12/11/2013 - 08:00
In our previous posts in this series, we described various mitigation improvements that attempt to prevent the exploitation of specific classes of memory safety vulnerabilities such as those that involve stack corruption, heap corruption, and unsafe list management and reference count mismanagement. These mitigations are typically associated with a specific developer mistake such as writing beyond the bounds of a stack or heap buffer, failing to correctly track reference counts, and so on.
Categories: Microsoft

Assessing risk for the December 2013 security updates

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
Today we released eleven security bulletins addressing 24 CVE’s. Five bulletins have a maximum severity rating of Critical while the other six have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max XI Likely first 30 days impact Platform mitigations and key notes MS13-096(GDI+ TIFF parsing) Victim opens malicious Office document.
Categories: Microsoft

MS13-098: Update to enhance the security of Authenticode

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
Today we released MS13-098, a security update that strengthens the Authenticode code-signing technology against attempts to modify a signed binary without invalidating the signature. This update addresses a specific instance of malicious binary modification that could allow a modified binary to pass the Authenticode signature check. More importantly, it also introduces further hardening to consider a binary “unsigned” if any modification has been made in a certain portion of the binary.
Categories: Microsoft

Omphaloskepsis and the December 2013 Security Update Release

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
There are times when we get too close to a topic. We familiarize ourselves with every aspect and nuance, but fail to recognize not everyone else has done the same. Whether you consider this myopia, navel-gazing, or human nature, the effect is the same. I recognized this during the recent webcast when someone asked the question – “What’s the difference between a security advisory and a security bulletin?
Categories: Microsoft

Pages

Subscribe to Geeksultant aggregator