exploitation

  1. Microsoft Security Advisory (2488013): Vulnerability in Internet Explorer Could Allow Remote Code Ex

    Revision Note: V1.2 (January 11, 2011): Added the workaround, Prevent the recursive loading of CSS style sheets in Internet Explorer, and revised Executive Summary to reflect investigation of limited attacks. Summary: Microsoft is investigating new, public reports of targeted attacks attempting...
  2. MS11-002 - Critical: Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Exe

    Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in Microsoft Data Access Components. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page. An attacker who successfully exploited this...
  3. MS10-098 - Important: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privil

    Severity Rating: Important - Revision Note: V1.0 (December 14, 2010): Bulletin publishedSummary: This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an...
  4. MS10-103 - Important: Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292

    Severity Rating: Important - Revision Note: V1.0 (December 14, 2010): Bulletin published.Summary: This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker...
  5. MS10-103 - Important: Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292

    Bulletin Severity Rating:Important - This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could...
  6. MS10-075 - Critical: Vulnerability in Media Player Network Sharing Service Could Allow Remote Code E

    Severity Rating: Critical - Revision Note: V1.0 (October 12, 2010): Bulletin published.Summary: This security update resolves a privately reported vulnerability in the Microsoft Windows Media Player Network Sharing Service. The vulnerability could allow remote code execution if an attacker sent...
  7. MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194)

    Severity Rating: Important - Revision Note: V1.0 (October 12, 2010): Bulletin published.Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An...
  8. MS10-080 - Important: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211)

    Severity Rating: Important - Revision Note: V1.0 (October 12, 2010): Bulletin published.Summary: This security update resolves thirteen privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file or...
  9. Update to Security Advisory 2416728

    Hi everyone - We've just updated Link Removed due to 404 Error as we've begun to see limited attacks with the ASP.NET vulnerability. We have added questions and answers and encourage customers to review this information and evaluate it for their environment. We have also added additional...
  10. MS10-063 - Critical: Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2

    Severity Rating: Critical - Revision Note: V1.0 (September 14, 2010): Bulletin published.Summary: This security update resolves a privately reported vulnerability in the Unicode Scripts Processor. The vulnerability could allow remote code execution if a user viewed a specially crafted document...
  11. MS10-062 - Critical: Vulnerability in MPEG-4 Codec Could Allow Remote Code Execution (975558)

    Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in MPEG-4 codec. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any...
  12. MS10-048 - Important: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privil

    Severity Rating: Important - Revision Note: V1.0 (August 10, 2010): Bulletin published.Summary: This security update resolves one publicly disclosed and four privately reported vulnerabilities in the Windows kernel-mode drivers. The most severe of these vulnerabilities could allow elevation of...
  13. MS10-055 - Critical: Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665) - Ver

    Severity Rating: Critical - Revision Note: V1.0 (August 10, 2010): Bulletin published.Summary: This security update resolves a privately reported vulnerability in Cinepak Codec. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives...
  14. MS10-055 - Critical: Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)

    Bulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in Cinepak Codec. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any...
  15. MS10-058 - Important: Vulnerabilities in TCP/IP Could Allow Elevation of Privilege (978886)

    Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege due to an error in the processing of a specific input buffer. An attacker who is able to log...
  16. MS10-046 - Critical: Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198) - Ve

    Severity Rating: Critical - Revision Note: V1.0 (August 2, 2010): Bulletin published.Summary: This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An...
  17. Microsoft Security Bulletin Advance Notification for August 2010

    Revision Note: Advance Notification published.Summary: This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on August 2, 2010. The bulletin addresses a security vulnerability in all supported editions of Windows XP, Windows Server 2003...
  18. Microsoft Security Advisory (2286198): Vulnerability in Windows Shell Could Allow Remote Code Execut

    Revision Note: V1.2 (July 20, 2010): Clarified the vulnerability exploit description and updated the workarounds. Advisory Summary:Microsoft is investigating reports of limited, targeted attacks exploiting a vulnerability in Windows Shell, a component of Microsoft Windows. This advisory contains...
  19. Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Exe

    Revision Note: V2.0 (March 30, 2010): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-018 to address this issue. For more information about this issue, including...
  20. Microsoft Security Advisory (2219475): Vulnerability in Windows Help and Support Center Could Allow

    Revision Note: V1.2 (June 15, 2010): Revised Executive Summary to reflect awareness of limited, targeted active attacks that use published proof-of-concept exploit code. Advisory Summary:Microsoft has completed the investigation into a public report of this vulnerability. We have issued M10-042...