-
MS11-093 - Important : Vulnerability in OLE Could Allow Remote Code Execution (2624667) - Version: 1
Severity Rating: Important Revision Note: V1.0 (December 13, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all...- News
- Thread
- 2011 admin rights affected software attack bulletin execution exploit extended security updates important ms11-093 ole patch management privately reported remote code execution software security user account user rights vulnerability windows server windows xp
- Replies: 0
- Forum: Security Alerts
-
MS11-088 - Important : Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Priv
Severity Rating: Important Revision Note: V1.0 (December 13, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user...- News
- Thread
- 2010 administrative arbitrary attack chinese elevation ime kernel microsoft office privilege security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS11-097 - Important : Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevati
Severity Rating: Important Revision Note: V1.0 (December 13, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected...- News
- Thread
- attack bulletin credentials elevation microsoft privilege security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS11-098 - Important : Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)
Severity Rating: Important Revision Note: V1.0 (December 13, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected...- News
- Thread
- attack kernel microsoft patch privilege security technet update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation
Revision Note: V1.3 (November 8, 2011): Added link to MAPP Partners with Updated Protections in the Executive Summary. Revised impact statement for the workaround, Deny access to T2EMBED.DLL, to address a reoffer issue on Windows XP and Windows Server 2003. Also, revised the mitigating factors...- News
- Thread
- access advisory attack elevation exploitation fonts impact kernel malware mapp microsoft parsing programs protection security truetype vulnerability windows server windows xp workaround
- Replies: 0
- Forum: Security Alerts
-
MS11-037: Vulnerability in MHTML could allow information disclosure: June 14, 2011
Resolves a vulnerability in the MHTML protocol handler in Windows that could allow information disclosure if a user opens a specially crafted URL from an attacker's website. More...- News
- Thread
- attack browser information disclosure mhtml microsoft protocol security update vulnerability windows
- Replies: 0
- Forum: Knowledge Base (KB)
-
MS11-083 - Critical : Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516) - Version:
Severity Rating: Critical Revision Note: V1.0 (November 8, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow...- News
- Thread
- attack bulletin critical microsoft ms11-083 remote code execution security tcp/ip udp update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation
Revision Note: V1.0 (November 3, 2011): Advisory published. Summary: Microsoft is investigating a vulnerability in a Microsoft Windows component, the Win32k TrueType font parsing engine. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode...- News
- Thread
- advisory arbitrary attack code customer service data elevation exploitation fonts impact kernel malware microsoft revision security target truetype vulnerability win32k windows
- Replies: 0
- Forum: Security Alerts
-
MS11-051: Vulnerability in Active Directory Certificate Services Web Enrollment could allow elevatio
Resolves a vulnerability in Active Directory Certificate Services Web Enrollment that could allow elevation of privilege and enable an attacker to execute arbitrary commands on the site in the context of the target user. Link Removed- News
- Thread
- active directory arbitrary commands attack certificate services elevation ms11-051 privilege security vulnerability web enrollment
- Replies: 0
- Forum: Knowledge Base (KB)
-
MS11-080 - Important : Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege
Severity Rating: Important Revision Note: V1.0 (October 11, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if...- News
- Thread
- afd attack elevation microsoft ms11-080 privilege security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS11-075 - Important : Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execu
Severity Rating: Important Revision Note: V1.0 (October 11, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an...- News
- Thread
- accessibility attack bulletin dll extended security updates microsoft network security remote code execution vulnerability webdav
- Replies: 0
- Forum: Security Alerts
-
Microsoft releases Security Advisory 2588513
Hello. Today we released Security Advisory 2588513, addressing an information-disclosure issue in SSL (Secure Sockets Layer) 3.0 and TLS (Transport Layer Security) 1.0 to provide guidance for customers. This is an industry-wide issue with limited impact that affects the Internet ecosystem as a...- News
- Thread
- advisory attack bandwidth browser communication computing exploitation guidance https information internet mitigation protocol risk security ssl threats tls update vulnerability
- Replies: 0
- Forum: Security Alerts
-
St. Petersburg police accuse woman, 22, of 'vampire' attack on man
ST. PETERSBURG — The vampire attacked just before midnight on the porch of a vacant Hooters. Read Full Story: Link Removed due to 404 Error- reghakr
- Thread
- attack crime hooters incident news police porch st petersburg vacant vampire
- Replies: 0
- Forum: The Water Cooler
-
Microsoft Security Advisory (961509): Research proves feasibility of collision attacks against MD5
Revision Note: Advisory published Summary: Microsoft is aware that research was published at a security conference proving a successful attack against X.509 digital certificates signed using the MD5 hashing algorithm. This attack method would allow an attacker to generate additional...- News
- Thread
- advisory attack authentication certificate collision conference cryptography cybersecurity digital signature hashing md5 microsoft research security vulnerabilities x.509
- Replies: 0
- Forum: Security Alerts
-
MS11-070 - Important : Vulnerability in WINS Could Allow Elevation of Privilege (2571621) - Version:
Severity Rating: Important Revision Note: V1.0 (September 13, 2011): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow elevation of privilege if a user...- News
- Thread
- attack bulletin credentials elevation internet local access ms11-070 patch patch management privileged access revision risk security services update vulnerability windows wins
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (968272): Vulnerability in Microsoft Office Excel Could Allow Remote Cod
Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin. Summary: Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file...- News
- Thread
- advisory attack bulletin excel execution microsoft remote code execution security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (974926): Credential Relaying Attacks on Integrated Windows Authenticati
Revision Note: V1.0 (December 8, 2009): Advisory published. Summary: This advisory addresses the potential for attacks that affect the handling of credentials using Integrated Windows Authentication (IWA), and the mechanisms Microsoft has made available for customers to help protect...- News
- Thread
- advisory attack authentication credentials iwa mechanism microsoft protection security windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation Bypass
Revision Note: V1.0 (August 10, 2010): Advisory published. Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that...- News
- Thread
- advisory attack isolation microsoft privilege protection security tapi update windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Versio
Revision Note: V3.0 (September 6, 2011): Revised to announce the release of an update that addresses this issue. Summary: Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root...- News
- Thread
- advisory attack digital certificates fraud internet explorer microsoft phishing security spoofing windows
- Replies: 0
- Forum: Security Alerts
-
MS11-031 - Critical : Vulnerability in JScript and VBScript Scripting Engines Could Allow Remote Cod
Severity Rating: Critical Revision Note: V1.1 (April 20, 2011): Bulletin updated to clarify that the JScript 5.8 and VBScript 5.8 update (KB2510531) also replaces MS09-045, in addition to MS10-022, for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and...- News
- Thread
- attack bulletin critical email jscript kb2510531 malware messenger microsoft patch remote code execution security update vbscript vulnerability website windows server windows vista windows xp
- Replies: 0
- Forum: Security Alerts