-
November 2014 Updates
Today, as part of Update Tuesday, we released 14 security updates – four rated Critical, nine rated Important, and two rated Moderate, to address 33 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office, .NET Framework, Internet Information Services...- News
- Thread
- ad fs critical cve deployment encryption exploit index iis important internet explorer microsoft moderate net framework november 2014 office rdp security security advisory update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS14-059 - Important: Vulnerability in ASP.NET MVC Could Allow Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (October 14, 2014): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET MVC. The vulnerability could allow security feature bypass if an attacker convinces a user to click a specially crafted link...- News
- Thread
- asp.net browser compromised websites content exploit cve cybersecurity email threats feature bypass internet safety link exploitation malware microsoft patch security security flaw update user awareness user interaction vulnerability web attack
- Replies: 0
- Forum: Security Alerts
-
The September 2014 Security Updates
Today, as a part of our regular Update Tuesday process, we released four security bulletins – one rated Critical and three rated Important in severity – to address 42 Common Vulnerabilities & Exposures (CVEs) in Microsoft Windows, Internet Explorer, .NET Framework, and Lync Server. We encourage...- News
- Thread
- activex controls advisories credential protection critical update cve deployment exploit index group policy important updates internet explorer microsoft remote code execution security bulletin security updates september 2014 trustworthy computing update tuesday webcast windows 7 windows server
- Replies: 0
- Forum: Security Alerts
-
MS14-043 - Critical: Vulnerability in Windows Media Center Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that...- News
- Thread
- critical cve exploitation extended security updates media center microsoft office patch remote code execution threats vulnerability
- Replies: 0
- Forum: Security Alerts
-
July 2014 Security Bulletin Release
Many around the globe have been following the 2014 FIFA World Cup Brazil™ closely. Regardless of which country you are supporting, many folks have been impressed by the defensive display put on by keeper Tim Howard in a loss against Belgium. It was a great performance highlighting a strong...- News
- Thread
- adobe flash browser upgrade bulletin credential theft critical cve enterprise security important internet explorer moderate protected mode remote code execution security server security smartscreen update vulnerabilities webcast windows windows journal
- Replies: 0
- Forum: Security Alerts
-
Theoretical Thinking and the June 2014 Bulletin Release
As security professionals, we are trained to think in worst-case scenarios. We run through the land of the theoretical, chasing “what if” scenarios as though they are lightning bugs to be gathered and stashed in a glass jar. Most of time, this type of thinking is absolutely the correct thing...- News
- Thread
- best practices bulletin critical update customer impact cve cybersecurity flash player internet explorer legacy support microsoft protected mode remote code execution research risk assessment security smartscreen theoretical thinking update vulnerabilities web standards
- Replies: 0
- Forum: Security Alerts
-
The April 2014 Security Updates
T. S. Elliot once said, “What we call the beginning is often the end. And to make an end is to make a beginning. The end is where we start from.” So as we put one season to bed, let’s start another by looking at the April security updates. Today, we release four bulletins to address 11 CVEs in...- News
- Thread
- adobe flash april 2014 bulletin cumulative update cve end of support exploit index guidance internet explorer knowledge base microsoft office microsoft word office 2003 remote code execution security security advisory update vulnerabilities webcast windows xp
- Replies: 0
- Forum: Security Alerts
-
The March 2014 Security Updates
This month we release five bulletins to address 23 unique CVEs in Microsoft Windows, Internet Explorer and Silverlight. If you need to prioritize, the update for Internet Explorer addresses the issue first described in Security Advisory 2934088, so it should be at the top of your list. While...- News
- Thread
- adobe flash aslr bulletin critical update customer security cve deployment exploit internet explorer malware mitigation ms14-012 ms14-014 remote code execution response communications security silverlight update vulnerabilities webcast
- Replies: 0
- Forum: Security Alerts
-
Safer Internet Day 2014 and Our February 2014 Security Updates
In addition to today being the security update release, February 11 is officially Link Removed for 2014. This year, we’re asking folks to Do 1 Thing to stay safer online. While you may expect my “Do 1 Thing” recommendation would be to apply security updates, I’m guessing that for readers of this...- News
- Thread
- critical update cve cybersecurity deployment digital safety direct2d emet forefront protection important updates internet explorer malware prevention microsoft remote code execution safer internet day security updates techsoup vbscript web security windows windows defender
- Replies: 0
- Forum: Security Alerts
-
A Look Into the Future and the January 2014 Bulletin Release
In January, there are those who like to make predictions about the upcoming year. I am not one of those people. Instead, I like to quote Niels Bohr who said, “Prediction is very difficult, especially if it’s about the future.” However, I can say without a doubt that change is afoot in 2014. In...- News
- Thread
- 2014 adobe flash application authentication bulletin cve developers kernel md5 microsoft privilege security server software support technology update vulnerabilities webcast windows xp
- Replies: 0
- Forum: Security Alerts
-
Authenticity and the November 2013 Security Updates
If you haven't had a chance to see the movie Gravity, I highly recommend you take the time to check it out. The plot moves a bit slowly at times, but director Alfonso Cuaron's work portrayal of zero gravity is worth the ticket price alone. Add in stellar acting and you end up with an epic movie...- News
- Thread
- activex authenticity certificate cryptography cumulative cve deployment digital signature directaccess emet internet explorer microsoft rc4 remote code execution security sha-2 sha1 update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
Omphaloskepsis and the December 2013 Security Update Release
There are times when we get too close to a topic. We familiarize ourselves with every aspect and nuance, but fail to recognize not everyone else has done the same. Whether you consider this myopia, navel-gazing, or human nature, the effect is the same. I recognized this during the recent webcast...- News
- Thread
- advisory asp.net authenticode bulletin cumulative update cve december 2013 deployment execution extended security updates internet explorer microsoft mitigation patch management remote code execution staff update tuesday vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-098: Vulnerability in Windows could allow remote code execution: December 10, 2013
Continue reading...- News
- Thread
- cve exploit microsoft ms13-098 patch remote code execution security update vulnerability windows
- Replies: 0
- Forum: Knowledge Base (KB)
-
Authenticity and the November 2013 Security Updates
If you haven't had a chance to see the movie Gravity, I highly recommend you take the time to check it out. The plot moves a bit slowly at times, but director Alfonso Cuaron's work portrayal of zero gravity is worth the ticket price alone. Add in stellar acting and you end up with an epic movie...- News
- Thread
- activex authenticity certificate cryptography cve deployment digital signature directaccess emet internet explorer microsoft patch management remote code execution security sha-2 sha1 update vulnerabilities windows 8.1 x.509
- Replies: 0
- Forum: Security Alerts
-
The October 2013 security updates
This month we release eight bulletins – four Critical and four Important - which address 26 unique CVEs in Microsoft Windows, Internet Explorer, SharePoint, .NET Framework, Office, and Silverlight. For those who need to prioritize their deployment planning, we recommend focusing on MS13-080...- News
- Thread
- advisory bulletin cve deployment exploitability internet explorer md5 microsoft net framework october office remote code execution security sharepoint ssl trustworthy computing update vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (977377): Vulnerability in TLS/SSL Could Allow Spoofing - Version:...
Revision Note: V2.0 (August 10, 2010): Advisory updated to reflect publication of security bulletin. Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-049 to address this issue. For more information about this issue, including...- News
- Thread
- advisory cve knowledge base microsoft security spoofing ssl tls update vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA13-010A: Oracle Java 7 Security Manager Bypass Vulnerability
Original release date: January 10, 2013 | Last revised: February 06, 2013 Systems Affected Any system using Oracle Java 7 (1.7, 1.7.0) including Java Platform Standard Edition 7 (Java SE 7) Java SE Development Kit (JDK 7) Java SE Runtime Environment (JRE 7) OpenJDK 7 and 7u IcedTea...- News
- Thread
- applet attack browser cve disable java drive-by download exploitation impact java jdk jre malicious software openjdk oracle security security settings solutions update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS13-017 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2799494
Severity Rating: Important Revision Note: V1.0 (February 12, 2013) Bulletin published. Summary: This security update resolves three privately reported vulnerabilities in all supported releases of Microsoft Windows. The vulnerabilities could allow elevation of privilege if...- News
- Thread
- cve exposure kernel microsoft patch privilege security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Advance Notification Service for November 2012 Security Bulletin Release
Today, we’re providing advance notification for six bulletins to help protect customers against 19 CVEs. The four Critical-rated updates will address 13 vulnerabilities in Microsoft Windows, Internet Explorer and the .NET Framework. One bulletin rated Important will address four...- News
- Thread
- advance notification bulletin critical cve deployment important internet explorer microsoft moderate msrc net framework november office patch management security testing trustworthy computing update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS12-042: Description of the security update for Windows 7 and Windows Server 2008 R2: June 12, 2012
Resolves vulnerabilities in Microsoft Windows that could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application that exploits the vulnerability. An attacker must have valid logon credentials... More...- News
- Thread
- cve june 2012 microsoft patch management privilege escalation security server 2008 update vulnerabilities windows 7
- Replies: 0
- Forum: Knowledge Base (KB)