Resolves a vulnerability in the Windows kernel-mode drivers that could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files.
More...
Resolves a vulnerability in VBScript on Microsoft Windows that could allow remote code execution if a malicious Web site displayed a specially crafted dialog box on a Web page and a user pressed the F1 key.
Link Removed
Severity Rating: Critical
Revision Note: V1.0 (December 13, 2011): Bulletin published.
Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted...
2011
bulletin
critical
december
disclosure
drivers
execution
font files
kernel-mode
malicious
microsoft
patch
remote code
revision
security
truetype
update
vulnerability
web page
windows
Hi everyone,
This post is to notify customers that Microsoft will revoke trust in an Intermediate Certificate Authority, DigiCert Sdn. Bhd. (Digicert Malaysia) in an update to be released through Windows Update.
DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE...
Severity Rating: Critical
Revision Note: V1.0 (June 14, 2011): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code...
Dillon Beresford and Brian Meixell were planning to perform a demonstration of how to attack critical infrastructure at the TakeDown Conference but cancelled after they were "asked very nicely" to refrain from providing that information. Beresford, a security analyst at NSS Labs, told Link...
Revision Note: V1.0 (January 28, 2011): Advisory published. Advisory Summary:Microsoft is investigating new public reports of a vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to cause a victim to run malicious scripts when visiting various...
advisory
attack
disclosure
editions
exploitation
impact
information
malicious
microsoft
proof-of-concept
published
reports
revision
scripts
security
supported
vulnerability
websites
windows
xss
Overview
Today we released MicrosoftLink Removed due to 404 Error. This is different from other Microsoft Security Advisories because it's not talking about specific vulnerabilities in Microsoft products. Rather, this is our official guidance in response to security research that has outlined a...
advisory
applications
attacks
best practices
binary planting
defense
development
guidance
investigation
libraries
malicious
microsoft
network
protection
research
security
technical
threats
vulnerabilities
vulnerability research
Microsoft patching up Windows shortcut vulnerability today
Later today, at 10 AM PDT (5 PM UTC), Microsoft is set to release an out of band update that will address the Windows Shell bug that enables malicious code to be executed when a user clicks the displayed icon of a specially crafted...
bug fix
code execution
exploit
malicious
microsoft
out of band
patch
patching
security
server 2003
server 2008
shell
shortcut
testing
update
vulnerability
windows
windows 7
windows vista
windows xp
Link Removed - Invalid URL
Security researchers point out that spam containing links to abusive .cn domains is on the decline. This trend seems to be related to new domain registrationLink Removed requirements recently introduced by China's Internet Network Information Center (CNNIC).
On...
:cool:
Ok this is the disclamier section. All link and software related items found in this forum are subject to change. Links will come and go. DO NOT use the links in this forum for any malicious acts or behavior. They are simply here for you test your own software and systems as needed...