-
Microsoft Security Advisory (2794220): Vulnerability in Internet Explorer Could Allow Remote Code Ex
Revision Note: V1.1 (December 31, 2012): Added link to Microsoft Fix it solution, "MSHTML Shim Workaround," that prevents exploitation of this issue. Summary: Microsoft is investigating public reports of a vulnerability in Internet Explorer 6, Internet Explorer 7, and Internet Explorer...- News
- Thread
- advisory attack exploitation fix internet explorer microsoft remote code execution security vulnerability workaround
- Replies: 0
- Forum: Security Alerts
-
MS13-007 - Important : Vulnerability in Open Data Protocol Could Allow Denial of Service (2769327) -
Severity Rating: Important Revision Note: V1.0 (January 8, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Open Data (OData) protocol. The vulnerability could allow denial of service if an unauthenticated attacker...- News
- Thread
- attack best practices denial of service firewall http open data protocol security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS13-006 - Important : Vulnerability in Microsoft Windows Could Allow Security Feature Bypass (27852
Severity Rating: Important Revision Note: V1.0 (January 8, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the implementation of SSL and TLS in Microsoft Windows. The vulnerability could allow security feature bypass...- News
- Thread
- attack bypass encryption microsoft security ssl tls update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Security Advisory 2798897 released, Certificate Trust List updated
Hello, Today we released Security Advisory 2798897 to notify customers that we are aware of active attacks using a fraudulent digital certificate issued by TURKTRUST Inc. To help protect customers, we have updated the Certificate Trust List (CTL) to remove the trust of the certificates causing...- News
- Thread
- advisory attack certificate communication customers digital fraud management protection security software trustlist trustworthy turktrust update windows server windows vista windows xp
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2798897): Fraudulent Digital Certificates Could Allow Spoofing - Versio
Revision Note: V1.0 (January 3, 2013): Advisory published. Summary: Microsoft is aware of active attacks using one fraudulent digital certificate issued by TURKTRUST Inc., which is a CA present in the Trusted Root Certification Authorities Store. This fraudulent certificate could be...- News
- Thread
- advisory attack certificate fraud man-in-the-middle microsoft phishing security spoofing turktrust windows
- Replies: 0
- Forum: Security Alerts
-
MS12-063 - Critical : Cumulative Security Update for Internet Explorer (2744842) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (September 21, 2012): Bulletin published. Summary: This security update resolves one publicly disclosed and four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code...- News
- Thread
- attack bulletin critical cumulative internet explorer ms12-063 remote code execution security update vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2757760): Vulnerability in Internet Explorer Could Allow Remote Code Ex
Revision Note: V1.0 (September 17, 2012): Advisory published. Summary: Microsoft is investigating public reports of a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9. Internet Explorer 10 is not affected. Microsoft is aware of...- News
- Thread
- advisory attack ie6 ie7 ie8 ie9 internet explorer microsoft remote code execution security vulnerability
- Replies: 1
- Forum: Security Alerts
-
Microsoft Security Advisory (2661254): Update For Minimum Certificate Key Length - Version: 1.2
Revision Note: V1.2 (September 11, 2012): Clarified that applications and services that use RSA keys for cryptography and call into the CertGetCertificateChain function could be impacted by this update. Examples of these applications and services include but are not limited to encrypted email...- News
- Thread
- advisory application attack certificate cryptography encryption fraud key length microsoft phishing pki security revision note rsa keys security services spoofing ssl tls update windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2661254): Update For Minimum Certificate Key Length - Version: 1.0
Revision Note: V1.0 (August 14, 2012): Advisory published. Summary: Microsoft is announcing the availability of an update to Windows that restricts the use of certificates with RSA keys less than 1024 bits in length. The private keys used in these certificates can be derived and could...- News
- Thread
- advisory attack certificate encryption key length microsoft phishing rsa security update
- Replies: 0
- Forum: Security Alerts
-
MS12-060 - Critical : Vulnerability in Windows Common Controls Could Allow Remote Code Execution (27
Severity Rating: Critical Revision Note: V1.0 (August 14, 2012): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows common controls. The vulnerability could allow remote code execution if a user visits a website...- News
- Thread
- attack common controls critical email threats extended security updates microsoft remote code execution vulnerability web attack windows
- Replies: 0
- Forum: Security Alerts
-
Blocking the SBP-2 driver and Thunderbolt controllers to reduce 1394 DMA and Thunderbolt DMA threats
Describes a scenario in which a BitLocker-protected computer may be vulnerable to Direct Memory Access (DMA) attacks. More...- News
- Thread
- attack bitlocker dma drivers encryption hardware protection security thunderbolt vulnerability
- Replies: 0
- Forum: Knowledge Base (KB)
-
MS12-048 - Important : Vulnerability in Windows Shell Could Allow Remote Code Execution (2691442) -
Severity Rating: Important Revision Note: V1.0 (July 10, 2012): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file or directory with...- News
- Thread
- admin rights attack important ms12-048 remote code execution security security bulletin update user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS12-049 - Important : Vulnerability in TLS Could Allow Information Disclosure (2655992) - Version:
Severity Rating: Important Revision Note: V1.0 (July 10, 2012): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in TLS. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served...- News
- Thread
- attack bulletin cbc cipher encryption important information information disclosure interception microsoft security tls traffic update vulnerability web
- Replies: 0
- Forum: Security Alerts
-
MS12-042 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2711167
Severity Rating: Important Revision Note: V1.0 (June 12, 2012): Bulletin published. Summary: This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of...- News
- Thread
- anonymous attack bulletin crafted application elevation exploitation important kernel local logon microsoft ms12-045 privately disclosed privilege remote attack report security update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
TA12-174A: Microsoft XML Core Services Attack Activity
Syndicated from the United States Security Readiness Team (US-CERT). Link Removed - Invalid URL- News
- Thread
- activity attack core services microsoft security us-cert xml
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2718704): Unauthorized Digital Certificates Could Allow Spoofing - Vers
Revision Note: V1.0 (June 3, 2012): Advisory published. Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...- News
- Thread
- advisory attack certificate digital certificates internet explorer microsoft phishing security spoofing windows
- Replies: 0
- Forum: Security Alerts
-
Security Advisory 2718704: Collision attack details, WU update rollout
Today, as a part of our continuing phased mitigation strategy recently discussed, we have initiated the additional hardening of Windows Update. We’ve also provided more information about the MD5 hash-collision attacks used by the Flame malware in the SRD blog. This information should help...- News
- Thread
- advisory attack automatic updates certificate code signing collision cryptography customer service hardening information integrity malware md5 mitigation phased strategy protection security trustworthy computing windows update windows vista
- Replies: 0
- Forum: Security Alerts
-
Security Advisory 2718704: Update to Phased Mitigation Strategy
Hello, At Microsoft, our commitment is to help ensure customer trust in their computing experience. That was the impetus for Trustworthy Computing, and central to that is the priority we place on taking the necessary actions to help protect our customers. Yesterday, we issued Security Advisory...- News
- Thread
- advisory attack certificate code signing collaboration collision cryptography customers defense deployment hardening malware microsoft mitigation phased protection security trustworthy update windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2718704): Unauthorized Digital Certificates Could Allow Spoofing - Vers
Revision Note: V1.0 (June 3, 2012): Advisory published. Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...- News
- Thread
- advisory attack digital certificates internet explorer microsoft phishing security spoofing windows
- Replies: 2
- Forum: Security Alerts
-
MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Si
Severity Rating: Critical Revision Note: V1.2 (May 22, 2012): Added an entry to the Frequently Asked Questions (FAQ) Related to This Security Update section to explain this revision. Summary: This security update resolves three publicly disclosed vulnerabilities and seven...- News
- Thread
- attack critical documents dotnet email execution faq framework malicious software microsoft office remote revision security silverlight truetype update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts