-
TA14-017A: UDP-based Amplification Attacks
Original release date: January 17, 2014 | Last revised: February 09, 2014 Systems Affected Certain UDP protocols have been identified as potential attack vectors: DNS NTP SNMPv2 NetBIOS SSDP CharGEN QOTD BitTorrent Kad Quake Network Protocol Steam Protocol Overview A Distributed...- News
- Thread
- amplification amplification factor attack bandwidth best practices damage ddos detection drdos impact ingress filtering mitigation network prevention protocol security source ip traffic shaping udp vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2719662): Vulnerabilities in Gadgets Could Allow Remote Code...
Revision Note: V1.1 (July 3, 2013): Clarified that disabling Windows Sidebar and Gadgets can help protect customers from potential attacks that leverage Gadgets to execute arbitrary code. This is an informational change only. Summary: Microsoft is announcing the availability of an automated...- News
- Thread
- advisory arbitrary code attack automated fix gadgets informational microsoft protection remote code execution security update vulnerabilities windows 7 windows vista
- Replies: 0
- Forum: Security Alerts
-
MS14-002 - Important : Vulnerability in Windows Kernel Could Allow Elevation of Privilege...
Severity Rating: Important Revision Note: V1.0 (January 14, 2014): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially...- News
- Thread
- attack credentials elevation of privilege extended security updates important local logon microsoft ms14-002 vulnerability windows kernel
- Replies: 0
- Forum: Security Alerts
-
TA14-013A: NTP Amplification Attacks Using CVE-2013-5211
Original release date: January 13, 2014 | Last revised: January 14, 2014 Systems Affected NTP servers Overview A Network Time Protocol (NTP) Amplification attack is an emerging form of Distributed Denial of Service (DDoS) that relies on the use of publically accessible NTP servers to...- News
- Thread
- amplification attack configuration cve-2013-5211 ddos linux monitoring network ntp ntpd protocol recommendations security time udp unix vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS13-046 - Important : Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of...
Severity Rating: Important Revision Note: V1.1 (December 16, 2013): Revised bulletin to announce a detection change to correct an offering issue for Windows RT (2829361) and Windows RT (2830290). This is a detection change only. There were no changes to the update files. Customers who have...- News
- Thread
- attack detection change drivers elevation important kernel-mode local access microsoft ms13-046 patch privilege revision security update vulnerabilities windows windows rt
- Replies: 0
- Forum: Security Alerts
-
MS13-102 - Important : Vulnerability in LRPC Client Could Allow Elevation of Privilege...
Severity Rating: Important Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted LPC port message to any LPC...- News
- Thread
- administrator attack bulletin consumer credentials elevation exploitation important lpc ms13-102 patch privately privilege report revision security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Security and policy surrounding bring your own devices (BYOD)
As the proliferation of devices continues to capture the imagination of consumers, and has ignited what is referred to as bring your own device (BYOD) revolution, many IT departments across the globe are now facing increased security considerations. While organizations encourage BYOD for cost...- News
- Thread
- activesync attack authentication byod certificate cost savings cybersecurity device management encryption exchange it department malware policy productivity security security features third party trustworthy computing user education windows phone
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2880823): Deprecation of SHA-1 Hashing Algorithm for Microsoft...
Revision Note: V1.0 (November 12, 2013): Advisory published. Summary: Microsoft is announcing a policy change to the Microsoft Root Certificate Program. The new policy will no longer allow root certificate authorities to issue X.509 certificates using the SHA-1 hashing algorithm for the purposes...- News
- Thread
- advisory algorithms attack certificate code signing digital security hashing man-in-the-middle microsoft phishing policy change revision note root certificate security sha1 spoofing ssl v1.0 x.509
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2880823): Deprecation of SHA-1 Hashing Algorithm for Microsoft...
Revision Note: V1.0 (November 12, 2013): Advisory published. Summary: Microsoft is announcing a policy change to the Microsoft Root Certificate Program. The new policy will no longer allow root certificate authorities to issue X.509 certificates using the SHA-1 hashing algorithm for the purposes...- News
- Thread
- advisory attack certificate code signing cybersecurity digital certificates hashing man-in-the-middle microsoft phishing policy policy change root certificate security sha1 spoofing ssl vulnerability x.509
- Replies: 0
- Forum: Security Alerts
-
MS13-080 - Critical : Cumulative Security Update for Internet Explorer (2879017) - Version: 1.2
Severity Rating: Critical Revision Note: V1.2 (October 8, 2013): Bulletin revised to announce that the 2884101 update is available via Windows Update. Summary: This security update resolves one publicly disclosed vulnerability and nine privately reported vulnerabilities in Internet Explorer. The...- News
- Thread
- attack critical extended security updates internet explorer ms13-080 remote code execution revision note user rights vulnerability windows update
- Replies: 0
- Forum: Security Alerts
-
MS13-034 - Important : Vulnerability in Microsoft Antimalware Client Could Allow Elevation of...
Severity Rating: Important Revision Note: V1.2 (October 8, 2013): Bulletin revised to announce a detection change in the 2781197 package. This is a detection change only. Customers who have already successfully updated their systems do not need to take any action. Summary: This security update...- News
- Thread
- antimalware attack elevation microsoft privilege security system threats update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS13-087 - Important : Vulnerability in Silverlight Could Allow Information Disclosure...
Severity Rating: Important Revision Note: V1.0 (October 8, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Silverlight. The vulnerability could allow information disclosure if an attacker hosts a website that contains a specially...- News
- Thread
- attack bulletin extended security updates information disclosure microsoft security silverlight user awareness vulnerability web content
- Replies: 0
- Forum: Security Alerts
-
MS13-085 - Important : Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (October 8, 2013): Bulletin published. Summary: This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file with an...- News
- Thread
- attack bulletin excel extended security updates important microsoft office remote code execution user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS13-077 - Important : Vulnerability in Windows Service Control Manager Could Allow Elevation...
Severity Rating: Important Revision Note: V1.0 (September 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker convinces an authenticated user to execute...- News
- Thread
- attack authentication bulletin elevation microsoft privilege security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-065 - Important : Vulnerability in ICMPv6 could allow Denial of Service (2868623) -...
Severity Rating: Important Revision Note: V1.0 (August 13, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow a denial of service if the attacker sends a specially crafted ICMP packet to the...- News
- Thread
- attack bulletin denial of service icmpv6 ms13-065 security technet update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-060 - Critical : Vulnerability in Unicode Scripts Processor Could Allow Remote Code...
Severity Rating: Critical Revision Note: V1.0 (August 13, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Unicode Scripts Processor included in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed a...- News
- Thread
- admin rights application attack critical documents execution exploitation extended security updates microsoft ms13-060 opentype privately reported remote code execution system impact unicode user account user rights vulnerability webpage
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2862973): Update for Deprecation of MD5 Hashing Algorithm for...
Revision Note: V1.0 (August 13, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update for supported editions of Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 that restricts the use of certificates...- News
- Thread
- advisory attack certificate deprecation hashing information man-in-the-middle md5 microsoft phishing root certificate safety security technology update vulnerability windows 7 windows 8 windows server windows vista
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2862973): Update for Deprecation of MD5 Hashing Algorithm for...
Revision Note: V1.0 (August 13, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update for supported editions of Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 that restricts the use of certificates...- News
- Thread
- advisory attack certificate cybersecurity encryption hashing man-in-the-middle md5 microsoft phishing protocol root certificate security threats update vulnerability windows 7 windows 8 windows server windows vista
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation...
Revision Note: V1.0 (August 10, 2010): Advisory published. Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that can help...- News
- Thread
- advisory attack isolation microsoft privilege protection security tapi update windows
- Replies: 0
- Forum: Security Alerts
-
MS11-007 - Critical : Vulnerability in the OpenType Compact Font Format (CFF) Driver Could...
Severity Rating: Critical Revision Note: V2.1 (July 9, 2013): Bulletin revised to announce a detection change that excludes Windows 7 language packs from the 2485376 update for Windows XP Professional x64 Edition Service Pack 2. This is a detection change only. Customers who have already...- News
- Thread
- attack cff driver critical detection email execution fonts messenger ms11-007 opentype patch remote security update user action vulnerability web security windows 7 windows xp
- Replies: 0
- Forum: Security Alerts