-
MS15-122 - Important: Security Update for Kerberos to Address Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (November 10, 2015): Bulletin published. Summary: This security update resolves a security feature bypass in Microsoft Windows. An attacker could bypass Kerberos authentication on a target machine and decrypt drives protected by BitLocker. The...- News
- Thread
- 2015 authentication bitlocker bypass cybersecurity drive exploitation important kerberos ms15-122 patch protection security system update v1.0 vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
3108638 - Update for Windows Hyper-V to Address CPU Weakness - Version: 1.0
Revision Note: V1.0 (November 10, 2015): Advisory published. Summary: Microsoft is announcing the availability of a security update for Windows Hyper-V to protect against a denial of service condition that can be triggered with certain central processing unit (CPU) chipsets. Although the...- News
- Thread
- 2015 advisory chipset cpu denial of service exploitation hyper-v kernel-mode microsoft patch security system update technology update version 1.0 virtualization weakness windows
- Replies: 0
- Forum: Security Alerts
-
MS15-099 - Critical: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (September 8, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file...- News
- Thread
- 2015 critical cybersecurity exploitation malware microsoft office patch remote code execution revision note risk security update user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS15-093 - Critical: Security Update for Internet Explorer (3088903) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (August 18, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker...- News
- Thread
- 2015 admin rights browser updates critical cybersecurity exploitation extended security updates internet explorer malware prevention ms15-093 network security patch protection remote code execution security technet threats update user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS15-082 - Important: Vulnerabilities in RDP Could Allow Remote Code Execution (3080348) -...
Severity Rating: Important Revision Note: V1.0 (August 11, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a specially crafted sequence of packets to a targeted system...- News
- Thread
- 2015 bulletin cybersecurity exploitation extended security updates important ms15-082 network patch rdp remote access remote code execution system risk update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-079 - Critical: Cumulative Security Update for Internet Explorer (3082442) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (August 11, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- 2015 administrative critical cumulative exploitation extended security updates internet explorer microsoft ms15-079 patch remote code execution revision note risk security software support update user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
MS15-088 - Important: Unsafe Command Line Parameter Passing Could Allow Information...
Severity Rating: Important Revision Note: V1.0 (August 11, 2015): Bulletin published. Summary: This security update helps to resolve an information disclosure vulnerability in Microsoft Windows, Internet Explorer, and Microsoft Office. To exploit the vulnerability an attacker would first have to...- News
- Thread
- bug fixes command line exploitation information disclosure internet explorer microsoft office ms15-088 notepad office updates patch powerpoint revision note risk mitigation security software security technical bulletin update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-069 - Important: Vulnerabilities in Windows Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow Remote Code Execution if an attacker first places a specially crafted dynamic link library (DLL) file...- News
- Thread
- attacker control cybersecurity dll exploitation malware microsoft ms15-069 patch remote code execution revision note rtf file security system protection update user rights vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS15-069 - Important: Vulnerabilities in Windows Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow Remote Code Execution if an attacker first places a specially crafted dynamic link library (DLL) file...- News
- Thread
- attack control cybersecurity dll exploitation important malware microsoft ms15-069 patch protection remote code execution revision note rtf security update user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-065 - Critical: Security Update for Internet Explorer (3076321) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (July 14, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- 2015 administrative browser security bulletin critical exploitation extended security updates internet explorer ms15-065 patch remote code execution security security bulletin software update technet update user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
MS15-037 - Important: Vulnerability in Windows Task Scheduler Could Allow Elevation of...
Severity Rating: Important Revision Note: V1.0 (April 14, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. An attacker who successfully exploited the vulnerability could leverage a known invalid task to cause Task Scheduler to run a...- News
- Thread
- 2015 administrator bulletin cybersecurity data security elevation exploitation microsoft revision note security security advisory software system account task scheduler update user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
TA15-103A: DNS Zone Transfer AXFR Requests May Leak Domain Information
Original release date: April 13, 2015 Systems Affected Misconfigured Domain Name System (DNS) servers that respond to global Asynchronous Transfer Full Range (AXFR) requests. Overview A remote unauthenticated user may request a DNS zone transfer from a public-facing DNS server. If...- News
- Thread
- axfr bindings configuration dns domain exploitation guidelines impact internet misconfiguration network protection remote access risk scan scripting security unauthenticated access vulnerability zone transfer
- Replies: 0
- Forum: Security Alerts
-
MS15-022 - Critical: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (March 10, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An...- News
- Thread
- admin rights arbitrary code critical update exploitation extended security updates microsoft office remote code execution user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS15-011 - Critical: Vulnerability in Group Policy Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (February 10, 2015): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. A remote code execution vulnerability exists in how group policy receives and applies connection data when a...- News
- Thread
- critical domain controller exploitation group policy microsoft remote code execution security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS14-073 - Important: Vulnerability in Microsoft SharePoint Foundation Could Allow Elevation...
Severity Rating: Important Revision Note: V1.0 (November 11, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft SharePoint Server. An authenticated attacker who successfully exploited this vulnerability could run arbitrary script in...- News
- Thread
- attack authenticated exploitation microsoft scripting security sharepoint update vulnerability web-based
- Replies: 0
- Forum: Security Alerts
-
MS14-076 - Important: Vulnerability in Internet Information Services (IIS) Could Allow...
Severity Rating: Important Revision Note: V1.0 (November 11, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Internet Microsoft Information Services (IIS) that could lead to a bypass of the "IP and domain restrictions" security feature...- News
- Thread
- bulletin domain restrictions exploitation iis internet information services ip rights microsoft security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA14-300A: Phishing Campaign Linked with “Dyre” Banking Malware
Original release date: October 27, 2014 Systems Affected Microsoft Windows Overview Since mid-October 2014, a phishing campaign has targeted a wide variety of recipients while employing the Dyre/Dyreza banking malware. Elements of this phishing campaign vary from target to target including...- News
- Thread
- adobe reader antivirus banking campaign credentials dyre email exploitation infection malware patch phishing protection scam security update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
TA14-290A: SSL 3.0 Protocol Vulnerability and POODLE Attack
Original release date: October 17, 2014 Systems Affected All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this...- News
- Thread
- browser cipher ciphertext data breach downgrade attack encryption exploitation legacy systems mitm network security openssl poodle protocol risk assessment security sensitive data ssl 3.0 tls transport layer security vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS14-061 - Important: Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote...
Severity Rating: Important Revision Note: V1.0 (October 14, 2014): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if an attacker convinces a user to open a specially crafted...- News
- Thread
- administrative exploitation microsoft office remote code execution security update user rights vulnerability word
- Replies: 0
- Forum: Security Alerts
-
MS14-046 - Important: Vulnerability in .NET Framework Could Allow Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow security feature bypass if a user visits a specially crafted website. In a...- News
- Thread
- aslr bypass exploitation microsoft net framework patch security update vulnerability web attack
- Replies: 0
- Forum: Security Alerts