About this tag
The tag 'arbitrary' is used in the context of security vulnerabilities that could allow arbitrary code execution. Discussions cover Microsoft Office, Microsoft Malware Protection Engine, Oracle Java, Windows Sidebar and Gadgets, Microsoft Office IME, TrueType font parsing, Windows Autorun, and the Graphics Rendering Engine. These threads focus on updates and advisories that address vulnerabilities where an attacker could run arbitrary code, potentially leading to system compromise. The content is relevant for users seeking information about security patches and risks associated with arbitrary code execution in various Microsoft and third-party software.
-
Microsoft Security Advisory (2846338): Vulnerability in Microsoft Malware Protection Engine Could Al
Revision Note: V1.0 (May 14, 2013): Advisory published. Summary: Microsoft is releasing this security advisory to help ensure customers are aware that an update to the Microsoft Malware Protection Engine also addresses a security vulnerability reported to Microsoft. The update...- News
- Thread
- advisory arbitrary attack code context control customers engine execution exploit information local system malware microsoft protection remote security system update vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA13-064A: Oracle Java Contains Multiple Vulnerabilities
Original release date: March 05, 2013 Systems Affected Any system using Oracle Java 7, 6, 5 (1.7, 1.6, 1.5) including Java Platform Standard Edition 7 (Java SE 7) Java Platform Standard Edition 6 (Java SE 6) Java Platform Standard Edition 6 (Java SE 5) Java SE Development Kit (JDK...- News
- Thread
- applet arbitrary attack browser browser security drive-by download execution exploitation java java control panel jdk jre malicious software memory oracle plugins security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation
Revision Note: V1.0 (November 3, 2011): Advisory published. Summary: Microsoft is investigating a vulnerability in a Microsoft Windows component, the Win32k TrueType font parsing engine. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode...- News
- Thread
- advisory arbitrary attack code customer service data elevation exploitation fonts impact kernel malware microsoft revision security target truetype vulnerability win32k windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (967940): Update for Windows Autorun - 2/8/2011
Revision Note: V2.0 (February 8, 2011): Summary and update FAQ revised to notify users that the 971029 update to Autorun that restricts AutoPlay functionality to CD and DVD media will be offered via automatic updating. Advisory Summary:Microsoft is announcing the availability of updates to the...- News
- Thread
- advisory arbitrary attack autoplay autorun code functionality media microsoft network protection revision security server update usb windows windows vista
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2490606): Vulnerability in Graphics Rendering Engine Could Allow Remote
Revision Note: V1.1 (January 5, 2011): Added a link to the automated Microsoft Fix it solution for the Modify the Access Control List (ACL) on shimgvw.dll workaround.Summary: Microsoft is investigating new public reports of a vulnerability in the Windows Graphics Rendering Engine. An attacker...- News
- Thread
- access advisory arbitrary control data engine exploit fix graphics microsoft programs remote rendering rights security user account users vulnerability workaround
- Replies: 0
- Forum: Security Alerts
-
MS10-058 - Important: Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886)
Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege due to an error in the processing of a specific input buffer. An attacker who is able to log...- News
- Thread
- arbitrary elevation exploitation microsoft privilege security tcp/ip update vulnerability windows
- Replies: 0
- Forum: Security Alerts