Feed aggregator

Antimalware Support for Windows XP and the January 2014 Security Bulletin Webcast and Q&A

Microsoft Security Center Center News - Fri, 01/17/2014 - 08:00
Today we’re publishing the January 2014 Security Bulletin Webcast Questions & Answers page. We answered 16 questions in total, with the majority of questions focusing on the Dynamics AX bulletin (MS14-004), the update for Microsoft Word (MS14-001) and the re-release of the Windows 7 and Windows Server 2008 R2 updates provided through MS13-081.
Categories: Microsoft

A Look Into the Future and the January 2014 Bulletin Release

Microsoft Security Center Center News - Tue, 01/14/2014 - 08:00
In January, there are those who like to make predictions about the upcoming year. I am not one of those people. Instead, I like to quote Niels Bohr who said, “Prediction is very difficult, especially if it’s about the future.” However, I can say without a doubt that change is afoot in 2014.
Categories: Microsoft

Assessing risk for the January 2014 security updates

Microsoft Security Center Center News - Tue, 01/14/2014 - 08:00
Today we released four security bulletins addressing six CVE’s. All four bulletins have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max exploit-ability rating Likely first 30 days impact Platform mitigations and key notes MS14-002(NDProxy, a kernel-mode driver) Attacker able to run code at a low privilege level inside an application sandbox exploits this vulnerability to elevate privileges to SYSTEM.
Categories: Microsoft

Advance Notification Service for the January 2014 Security Bulletin Release

Microsoft Security Center Center News - Thu, 01/09/2014 - 08:00
Today we provide advance notification for the release of four bulletins for January 2014. All bulletins this month are rated Important in severity and address vulnerabilities in Microsoft Windows, Office, and Dynamics AX. The update provided in MS14-002 fully addresses the issue first described in Security Advisory 2914486. We have only seen this issue used in conjunction with a PDF exploit in targeted attacks and not on its own.
Categories: Microsoft

Predictions for 2014 and the December 2013 Security Bulletin Webcast, Q&A, and Slide Deck

Microsoft Security Center Center News - Mon, 12/16/2013 - 08:00
Today we’re publishing the December 2013 Security Bulletin Webcast Questions & Answers page. We answered 17 questions in total, with the majority of questions focusing on the Graphics Component bulletin (MS13-096), Security Advisory 2915720 and Security Advisory 2905247. We also wanted to note a new blog on the Microsoft Security Blog site on the top cyber threat predications for 2014.
Categories: Microsoft

Software defense: mitigating common exploitation techniques

Microsoft Security Center Center News - Wed, 12/11/2013 - 08:00
In our previous posts in this series, we described various mitigation improvements that attempt to prevent the exploitation of specific classes of memory safety vulnerabilities such as those that involve stack corruption, heap corruption, and unsafe list management and reference count mismanagement. These mitigations are typically associated with a specific developer mistake such as writing beyond the bounds of a stack or heap buffer, failing to correctly track reference counts, and so on.
Categories: Microsoft

Assessing risk for the December 2013 security updates

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
Today we released eleven security bulletins addressing 24 CVE’s. Five bulletins have a maximum severity rating of Critical while the other six have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max XI Likely first 30 days impact Platform mitigations and key notes MS13-096(GDI+ TIFF parsing) Victim opens malicious Office document.
Categories: Microsoft

MS13-098: Update to enhance the security of Authenticode

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
Today we released MS13-098, a security update that strengthens the Authenticode code-signing technology against attempts to modify a signed binary without invalidating the signature. This update addresses a specific instance of malicious binary modification that could allow a modified binary to pass the Authenticode signature check. More importantly, it also introduces further hardening to consider a binary “unsigned” if any modification has been made in a certain portion of the binary.
Categories: Microsoft

Omphaloskepsis and the December 2013 Security Update Release

Microsoft Security Center Center News - Tue, 12/10/2013 - 08:00
There are times when we get too close to a topic. We familiarize ourselves with every aspect and nuance, but fail to recognize not everyone else has done the same. Whether you consider this myopia, navel-gazing, or human nature, the effect is the same. I recognized this during the recent webcast when someone asked the question – “What’s the difference between a security advisory and a security bulletin?
Categories: Microsoft

Pages

Subscribe to Geeksultant aggregator