Severity Rating:
Revision Note: V1.1 (June 13, 2012): Advisory revised to notify customers that Windows Mobile 6.x, Windows Phone 7, and Windows Phone 7.5 devices are not affected by the issue.
Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived...
access denied
activeattacks
browser security
certificate
cybersecurity
digital certificates
extended security updates
internet explorer
man-in-the-middle
microsoft
phishing
revision note
security
security advisory
spoofing
vulnerability
web security
windows phone
Hi everyone -
We've updated Microsoft Security AdvisoryLink Removed due to 404 Error to include a step in the workaround requiring the blocking of requests that specify the application error path on the querystring. This can be done using URLScan, a free tool for Internet Information Services...
activeattacks
advisory
block requests
email alerts
iis
microsoft
monitoring
msrc blog
network security
request filtering
scott guthrie
security
server 2008
trustworthy computing
update
urlscan
vulnerability
windows 7
windows vista
workaround
Revision Note: V1.2 (September 24, 2010): Added an entry to the FAQ to announce a revision to the workaround, "Enable a UrlScan or Request Filtering rule, enable ASP.NET custom errors, and map all error codes to the same error page." Customers who have already applied the workaround should...
activeattacks
advisory
asp.net
customerrors
encryption
errorpage
faq
information
information disclosure
microsoft
request filtering
security
security breach
server issues
tampering
urlscan
viewstate
vulnerability
web.config
workaround
Revision Note: V1.1 (September 20, 2010): Revised Executive Summary to communicate that Microsoft is aware of limited, active attacks. Also added additional entries to the Frequently Asked Questions section and additional clarification to the workaround. Advisory Summary:Microsoft is...