Microsoft Patch Day: Critical Bulletins Expected - Security:: PAST 7 DAYS. 1 - Microsoft Patch Tuesday Targets 26 Application Flaws (10005) 2 - Is There Also A Russian Cyber War Against Georgia (7228) http://www.eweek.com/c/a/Security/Microsoft-Patch-Day-Critical-Bulletins-ExpectedHOME | Microsoft's Tuesday released a batch of seven security patches, including two for "critical" vulnerabilities found in the Windows Task Scheduler and HTML Help features.
As part of its monthly patch release cycle, the software giant warned that the Task Scheduler contains a buffer overflow that puts users at risk of computer takeover.
"If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges," the company warned in an advisory. iTWire - Firefox 2 turns 13:: Patch frenzy erupts after August Patch Tuesday August 14, 2008 (All Day) Latest Job Alerts - Subscribe to our Email Jobs Alerts and get emailed when a http://www.itwire.com/content/view/17323/53HOME |
Affected products include Windows 2000 and Windows XP. The Windows NT Workstation and Windows NT Server operating systems are not affected by default. However, if Internet Explorer 6.0 Service Pack 1 has been installed on those systems, the vulnerable component exists, Microsoft said.
Microsoft issued a separate alert for a vulnerability in HTML Help that could also lead to code execution attacks. The flaw, rated "critical," affects Windows 98, Windows Millennium Edition (Me), Windows 2000, Windows XP and Windows Server 2003.
According to the alert, the HTML Help hole could allow an attacker to "take complete control of an affected system." iTWire - Microsofts Mega Patch Tuesday:: Apples day in the sun as most valuable Silicon Valley company. Three important issues - and once again, Vista features in the critical patch list. http://www.itwire.com/content/view/14011/53HOME |
A successful attacker could commandeer machines to install programs; view, change, or delete data; or create new accounts with full user privileges. "Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges."
The July batch of advisories includes four patches rated "important" and one with a "moderate" rating.
A patch was released for a remote code execution vulnerability in the way that the Windows Shell launches applications. This flaw could also leave systems at risk of system takeover. Microsoft said significant user interaction is required to exploit this vulnerability, noting that users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges. SecurityForumX - Computer Network Virus Security :: View topic - MS :: Critical (2), Important (4), Moderate (1) Cumulative Security Update for Outlook Express our configuration aside from the application of the MS patches. http://www.infosyssec.com/forum/viewtopic.php?t=1593HOME | Microsoft Patch Day: 1 Critical Bulletin on Tap - Security:: 2 - Cyber-attacks Gaining Acceptance as Another Weapon in War (3369) 3 - Security Firms Warn of Hackers Spoofing CNN, MSNBC News Alerts (3271) http://www.eweek.com/c/a/Security/Microsoft-Patch-Day-1-Critical-Bulletin-on-TapHOME |
An "important" privilege elevation vulnerability was also patched to correct way that Utility Manager launches applications. According to the alert, a logged-on user could force Utility Manager to start an application with system privileges and could take complete control of the system. "An attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts that have full privileges," the company warned.
The company also plugged a privilege elevation hole in the POSIX operating system component (subsystem) that could be exploited to allow an attacker to take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts that have full privileges.
A separate patch with an "important" rating was also released for a bug found in IIS 4.0.
Microsoft also issued a cumulative update to plug a denial-of-service hole in Outlook Express.
Where's The Advantage In Windows Genuine Advantage?
Stocks Bounce After S&P Joins Bear Market
|