-
MS16-083 - Critical: Security Update for Adobe Flash Player (3167685) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (June 16, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Adobe Flash Player when installed on all supported editions of Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows RT 8.1, and Windows 10...- News
- Thread
- adobe flash bug fixes critical cve extended security updates flash player june ms16-083 patch performance revision note security bulletin software update support update vulnerability windows 10 windows 8.1 windows rt windows server
- Replies: 0
- Forum: Security Alerts
-
MS15-077 - Important: Vulnerability in ATM Font Driver Could Allow Elevation of Privilege...
Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a target system and runs a specially crafted...- News
- Thread
- 2015 arbitrary code attack bulletin control cve elevation of privilege extended security updates important microsoft ms15-077 patch programs revision note software system user account vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
March 2015 Updates
Today, as part of Update Tuesday, we released 14 security bulletins to address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Exchange, and Internet Explorer. We encourage customers to apply all of these updates. For more information about this month’s security updates...- News
- Thread
- bulletin cve exploitability internet explorer march 2015 microsoft microsoft office msrc network security patch management security security advisory security features software update tech news update update tuesday vulnerability
- Replies: 0
- Forum: Security Alerts
-
February 2015 Updates
Today, as part of Update Tuesday, we released nine security bulletins – three rated Critical and six rated Important in severity, to address 56 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Microsoft Office, Internet Explorer, and Microsoft Server software. We...- News
- Thread
- 2015 advisory bulletin change critical cve exploitability important internet explorer microsoft microsoft office msrc re-release remote code execution response center security ssl update vulnerability windows server
- Replies: 0
- Forum: Security Alerts
-
TA14-323A: Microsoft Windows Kerberos KDC Remote Privilege Escalation Vulnerability
Original release date: November 19, 2014 Systems Affected Microsoft Windows Vista, 7, 8, and 8.1 Microsoft Server 2003, Server 2008, Server 2008 R2, Server 2012, and Server 2012 R2 Overview A remote escalation of privilege vulnerability exists in implementations of Kerberos Key Distribution...- News
- Thread
- administrator attack bulletin cve defense domain controller domain user escalation impact kerberos microsoft privilege escalation remote access research security service tickets systems affected update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
November 2014 Updates
Today, as part of Update Tuesday, we released 14 security updates – four rated Critical, nine rated Important, and two rated Moderate, to address 33 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office, .NET Framework, Internet Information Services...- News
- Thread
- ad fs critical cve deployment encryption exploit index iis important internet explorer microsoft moderate net framework november 2014 office rdp security security advisory update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS14-059 - Important: Vulnerability in ASP.NET MVC Could Allow Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (October 14, 2014): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET MVC. The vulnerability could allow security feature bypass if an attacker convinces a user to click a specially crafted link...- News
- Thread
- asp.net browser compromised websites content exploit cve cybersecurity email threats feature bypass internet safety link exploitation malware microsoft patch security security flaw update user awareness user interaction vulnerability web attack
- Replies: 0
- Forum: Security Alerts
-
The September 2014 Security Updates
Today, as a part of our regular Update Tuesday process, we released four security bulletins – one rated Critical and three rated Important in severity – to address 42 Common Vulnerabilities & Exposures (CVEs) in Microsoft Windows, Internet Explorer, .NET Framework, and Lync Server. We encourage...- News
- Thread
- activex controls advisory credential protection critical update cve deployment exploit index group policy important updates internet explorer microsoft remote code execution security bulletin security updates september 2014 trustworthy computing update tuesday webcast windows 7 windows server
- Replies: 0
- Forum: Security Alerts
-
MS14-043 - Critical: Vulnerability in Windows Media Center Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that...- News
- Thread
- critical cve exploitation extended security updates media center microsoft office patch remote code execution threats vulnerability
- Replies: 0
- Forum: Security Alerts
-
July 2014 Security Bulletin Release
Many around the globe have been following the 2014 FIFA World Cup Brazil™ closely. Regardless of which country you are supporting, many folks have been impressed by the defensive display put on by keeper Tim Howard in a loss against Belgium. It was a great performance highlighting a strong...- News
- Thread
- adobe flash browser upgrade bulletin credential theft critical cve enterprise security important internet explorer moderate protected mode remote code execution security server security smartscreen update vulnerability webcast windows windows journal
- Replies: 0
- Forum: Security Alerts
-
Theoretical Thinking and the June 2014 Bulletin Release
As security professionals, we are trained to think in worst-case scenarios. We run through the land of the theoretical, chasing “what if” scenarios as though they are lightning bugs to be gathered and stashed in a glass jar. Most of time, this type of thinking is absolutely the correct thing...- News
- Thread
- best practices bulletin critical update customer impact cve cybersecurity flash player internet explorer legacy support microsoft protected mode remote code execution research risk assessment security smartscreen theoretical thinking update vulnerability web standards
- Replies: 0
- Forum: Security Alerts
-
The April 2014 Security Updates
T. S. Elliot once said, “What we call the beginning is often the end. And to make an end is to make a beginning. The end is where we start from.” So as we put one season to bed, let’s start another by looking at the April security updates. Today, we release four bulletins to address 11 CVEs in...- News
- Thread
- adobe flash april 2014 bulletin cumulative update cve end of support exploit index guidance internet explorer knowledge base microsoft office microsoft word office 2003 remote code execution security security advisory update vulnerability webcast windows xp
- Replies: 0
- Forum: Security Alerts
-
The March 2014 Security Updates
This month we release five bulletins to address 23 unique CVEs in Microsoft Windows, Internet Explorer and Silverlight. If you need to prioritize, the update for Internet Explorer addresses the issue first described in Security Advisory 2934088, so it should be at the top of your list. While...- News
- Thread
- adobe flash aslr bulletin critical update customer security cve deployment exploit internet explorer malware mitigation ms14-012 ms14-014 remote code execution response communications security silverlight update vulnerability webcast
- Replies: 0
- Forum: Security Alerts
-
Safer Internet Day 2014 and Our February 2014 Security Updates
In addition to today being the security update release, February 11 is officially Link Removed for 2014. This year, we’re asking folks to Do 1 Thing to stay safer online. While you may expect my “Do 1 Thing” recommendation would be to apply security updates, I’m guessing that for readers of this...- News
- Thread
- critical update cve cybersecurity deployment digital safety direct2d emet forefront protection important updates internet explorer malware prevention microsoft remote code execution safer internet day security updates techsoup vbscript web security windows windows defender
- Replies: 0
- Forum: Security Alerts
-
A Look Into the Future and the January 2014 Bulletin Release
In January, there are those who like to make predictions about the upcoming year. I am not one of those people. Instead, I like to quote Niels Bohr who said, “Prediction is very difficult, especially if it’s about the future.” However, I can say without a doubt that change is afoot in 2014. In...- News
- Thread
- 2014 adobe flash application authentication bulletin cve developers kernel md5 microsoft privilege security server software support technology update vulnerability webcast windows xp
- Replies: 0
- Forum: Security Alerts
-
Authenticity and the November 2013 Security Updates
If you haven't had a chance to see the movie Gravity, I highly recommend you take the time to check it out. The plot moves a bit slowly at times, but director Alfonso Cuaron's work portrayal of zero gravity is worth the ticket price alone. Add in stellar acting and you end up with an epic movie...- News
- Thread
- activex authenticity certificate cryptography cumulative cve deployment digital signature directaccess emet internet explorer microsoft rc4 remote code execution security sha-2 sha1 update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Omphaloskepsis and the December 2013 Security Update Release
There are times when we get too close to a topic. We familiarize ourselves with every aspect and nuance, but fail to recognize not everyone else has done the same. Whether you consider this myopia, navel-gazing, or human nature, the effect is the same. I recognized this during the recent webcast...- News
- Thread
- advisory asp.net authenticode bulletin cumulative update cve december 2013 deployment execution extended security updates internet explorer microsoft mitigation patch management remote code execution staff update tuesday vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-098: Vulnerability in Windows could allow remote code execution: December 10, 2013
Continue reading...- News
- Thread
- cve exploit microsoft ms13-098 patch remote code execution security update vulnerability windows
- Replies: 0
- Forum: Knowledge Base (KB)
-
Authenticity and the November 2013 Security Updates
If you haven't had a chance to see the movie Gravity, I highly recommend you take the time to check it out. The plot moves a bit slowly at times, but director Alfonso Cuaron's work portrayal of zero gravity is worth the ticket price alone. Add in stellar acting and you end up with an epic movie...- News
- Thread
- activex authenticity certificate cryptography cve deployment digital signature directaccess emet internet explorer microsoft patch management remote code execution security sha-2 sha1 update vulnerability windows 8.1 x.509
- Replies: 0
- Forum: Security Alerts
-
The October 2013 security updates
This month we release eight bulletins – four Critical and four Important - which address 26 unique CVEs in Microsoft Windows, Internet Explorer, SharePoint, .NET Framework, Office, and Silverlight. For those who need to prioritize their deployment planning, we recommend focusing on MS13-080...- News
- Thread
- advisory bulletin cve deployment exploitability internet explorer md5 microsoft net framework october office remote code execution security sharepoint ssl trustworthy computing update vulnerability webcast windows
- Replies: 0
- Forum: Security Alerts