-
MS14-043 - Critical: Vulnerability in Windows Media Center Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that...- News
- Thread
- critical cve exploitation extended security updates media center microsoft office patch remote code execution threats vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS14-048 - Important: Vulnerability in OneNote Could Allow Remote Code Execution (2977201) -...
Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft OneNote. The vulnerability could allow remote code execution if a specially crafted file is opened in an affected version...- News
- Thread
- bulletin exploitation microsoft onenote remote code execution revision security update user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS14-050 - Important: Vulnerability in Microsoft SharePoint Server Could Allow Elevation of...
Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft SharePoint Server. An authenticated attacker who successfully exploited this vulnerability could use a specially crafted...- News
- Thread
- attack authenticated exploitation javascript microsoft security sharepoint update vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA14-013A: NTP Amplification Attacks Using CVE-2013-5211
Original release date: January 13, 2014 | Last revised: February 05, 2014 Systems Affected NTP servers Overview A Network Time Protocol (NTP) Amplification attack is an emerging form of Distributed Denial of Service (DDoS) that relies on the use of publically accessible NTP servers to...- News
- Thread
- amplification attack configuration cve-2013-5211 ddos exploitation linux monitoring network ntp recommendations response restrict security server system udp unix upgrade vulnerability
- Replies: 0
- Forum: Security Alerts
-
Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution - Version: 2.0
Severity Rating: Critical Revision Note: V2.0 (January 14, 2014): Rereleased bulletin to announce the reoffering of the 2862330 update to systems running Windows 7 or Windows Server 2008 R2. See the Update FAQ for details. Summary: This security update resolves seven privately reported...- News
- Thread
- 2014 bulletin control critical drivers execution exploitation font files kernel microsoft patch re-release remote security server 2008 update update faq vulnerabilities windows windows 7
- Replies: 0
- Forum: Security Alerts
-
MS13-102 - Important : Vulnerability in LRPC Client Could Allow Elevation of Privilege...
Severity Rating: Important Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted LPC port message to any LPC...- News
- Thread
- administrator attack bulletin consumer credentials elevation exploitation important lpc ms13-102 patch privately privilege report revision security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel Could Allow...
Revision Note: V1.0 (November 27, 2013): Advisory published. Summary: Microsoft is investigating new reports of a vulnerability in a kernel component of Windows XP and Windows Server 2003. We are aware of limited, targeted attacks that attempt to exploit this vulnerability. Continue reading...- News
- Thread
- advisory cybersecurity exploitation kernel microsoft patch security vulnerability windows server windows xp
- Replies: 0
- Forum: Security Alerts
-
MS13-060 - Critical : Vulnerability in Unicode Scripts Processor Could Allow Remote Code...
Severity Rating: Critical Revision Note: V1.0 (August 13, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Unicode Scripts Processor included in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed a...- News
- Thread
- admin rights application attack critical documents execution exploitation extended security updates microsoft ms13-060 opentype privately reported remote code execution system impact unicode user account user rights vulnerability webpage
- Replies: 0
- Forum: Security Alerts
-
MS13-053 - Critical : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Executi
Severity Rating: Critical Revision Note: V1.0 (July 9, 2013): Bulletin published. Summary: This security update resolves two publicly disclosed and six privately reported vulnerabilities in Microsoft Windows. The most severe vulnerability could allow remote code execution...- News
- Thread
- critical drivers exploitation extended security updates kernel-mode ms13-053 remote code execution truetype fonts vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS13-048 - Important : Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229)
Severity Rating: Important Revision Note: V1.2 (June 18, 2013): Bulletin revised to announce a detection change in the security update for 2839229 to address the known issue documented in Microsoft Knowledge Base Article 2839229. This is a detection change only. Customers who have...- News
- Thread
- exploitation information disclosure kernel local access microsoft patch security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
TA13-169A: Oracle Releases Updates for Javadoc and Other Java SE Vulnerabilities
Original release date: June 18, 2013 | Last revised: June 19, 2013 Systems Affected Any system using Oracle Java including JDK and JRE 7 Update 21 and earlier JDK and JRE 6 Update 45 and earlier JDK and JRE 5.0 Update 45 and earlier JavaFX 2.2.21 and earlier Website owners that host...- News
- Thread
- api browser critical documentation exploitation impact injection java javadoc oracle patch phishing remediation security subfolders the frame tools update vulnerabilities web
- Replies: 0
- Forum: Security Alerts
-
MS13-048 - Important : Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229)
Severity Rating: Important Revision Note: V1.1 (June 12, 2013): Updated the Known Issues entry in the Knowledge Base Article section from "None" to "Yes". Summary: This security update resolves one privately reported vulnerability in Windows Kernel. The vulnerability could...- News
- Thread
- credentials exploitation information information disclosure kernel patch security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-048 - Important : Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229)
Severity Rating: Important Revision Note: V1.0 (June 11, 2013): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Windows Kernel. The vulnerability could allow information disclosure if an attacker logs on to a system and...- News
- Thread
- attack credentials exploitation extended security updates important information disclosure local account microsoft vulnerability windows kernel
- Replies: 0
- Forum: Security Alerts
-
MS13-042 - Important : Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (283
Severity Rating: Important Revision Note: V1.0 (May 14, 2013): Bulletin published. Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user open a specially crafted...- News
- Thread
- attack exploitation extended security updates microsoft office publisher remote code execution revision note user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS13-045 - Important : Vulnerability in Windows Essentials Could Allow Information Disclosure (28137
Severity Rating: Important Revision Note: V1.0 (May 14, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows Writer. The vulnerability could allow information disclosure if a user opens Writer using a specially...- News
- Thread
- exploitation information disclosure microsoft patch security update vulnerability web attack windows essentials windows writer
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2847140): Vulnerability in Internet Explorer Could Allow Remote Code Ex
Revision Note: V1.0 (May 3, 2013): Advisory published. Summary: Microsoft is investigating public reports of a vulnerability in Internet Explorer 8. Microsoft is aware of attacks that attempt to exploit this vulnerability. More...- News
- Thread
- advisory cybersecurity exploitation internet explorer malware microsoft remote code execution security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Evolving Response and the March 2013 Bulletin Release
As my career in security response has grown over the years, I am often reminded of the words of Italian author Giuseppe Tomasi Di Lampedusa, who stated, “If we want everything to remain as it is, it will be necessary for everything to change.” There are some things that we wish to...- News
- Thread
- advisory bulletin deployment exploitation guidance internet explorer kernel drivers march 2013 microsoft microsoft store physical access privacy protection remote code execution security silverlight threats trustworthy computing update vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Windows 8 Chrome Vulnerability Exploited: How Hackers Gained Control Over Windows Systems
Chrome was hacked and used to take over windows....here's the whole story. http://news.cnet.com/8301-1009_3-57573064-83/researchers-win-$100000-for-chrome-hack-that-leaves-windows-vulnerable/- Jimbo22
- Thread
- breach chrome cybersecurity exploitation hacked hackers internet malware news protection research risk security software technology threats update vulnerability windows
- Replies: 2
- Forum: Windows Help and Support
-
TA13-064A: Oracle Java Contains Multiple Vulnerabilities
Original release date: March 05, 2013 Systems Affected Any system using Oracle Java 7, 6, 5 (1.7, 1.6, 1.5) including Java Platform Standard Edition 7 (Java SE 7) Java Platform Standard Edition 6 (Java SE 6) Java Platform Standard Edition 6 (Java SE 5) Java SE Development Kit (JDK...- News
- Thread
- applet arbitrary attack browser browser security drive-by download execution exploitation java java control panel jdk jre malicious software memory oracle plugins security update vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
TA13-010A: Oracle Java 7 Security Manager Bypass Vulnerability
Original release date: January 10, 2013 | Last revised: February 06, 2013 Systems Affected Any system using Oracle Java 7 (1.7, 1.7.0) including Java Platform Standard Edition 7 (Java SE 7) Java SE Development Kit (JDK 7) Java SE Runtime Environment (JRE 7) OpenJDK 7 and 7u IcedTea...- News
- Thread
- applet attack browser cve disable java drive-by download exploitation impact java jdk jre malicious software openjdk oracle security security settings solutions update vulnerability
- Replies: 0
- Forum: Security Alerts