US-CERT Technical Cyber Security Alerts: US-CERT Technical Cyber Security Alerts provide timely
information about current security issues, vulnerabilities, and
exploits.
Microsoft Updates for Multiple Vulnerabilities
Malicious Activity Associated with "Aurora" Internet Explorer Exploit
Microsoft Updates for Multiple Vulnerabilities
Microsoft Internet Explorer Vulnerabilities
Adobe Reader and Acrobat Vulnerabilities
Microsoft Windows EOT Font and Adobe Flash Player 6 Vulnerabilities
Oracle Updates for Multiple Vulnerabilities
Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR
Microsoft Updates for Multiple Vulnerabilities
Microsoft Updates for Multiple Vulnerabilities
Microsoft Security Bulletins: Microsoft Security Bulletins
Bulletin Severity Rating:Important – This security update resolves seven privately reported vulnerabilities in Microsoft Office Excel. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Bulletin Severity Rating:Important – This security update addresses a privately reported vulnerability in Windows Movie Maker and Microsoft Producer 2003. Windows Live Movie Maker, which is available for Windows Vista and Windows 7, is not affected by this vulnerability. The vulnerability could allow remote code execution if an attacker sent a specially crafted Movie Maker or Microsoft Producer project file and persuaded the user to open the specially crafted file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Bulletin Severity Rating:Important – This security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on to the system and then ran a specially crafted application. To exploit either vulnerability, an attacker must have valid logon credentials and be able to log on locally. The vulnerabilities could not be exploited remotely or by anonymous users.
Bulletin Severity Rating:Important – This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a specially crafted ticket renewal request is sent to the Windows Kerberos domain from an authenticated user on a trusted non-Windows Kerberos realm. The denial of service could persist until the domain controller is restarted.
Bulletin Severity Rating:Critical – This security update resolves a privately reported vulnerability in Microsoft DirectShow. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Bulletin Severity Rating:Important – This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.
Bulletin Severity Rating:Important – This security update resolves a privately reported vulnerability in Microsoft Windows Client/Server Run-time Subsystem (CSRSS). The vulnerability could allow elevation of privilege if an attacker logs on to the system and starts a specially crafted application designed to continue running after the attacker logs out. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.
Bulletin Severity Rating:Important – This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.
Bulletin Severity Rating:Critical – This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.
Bulletin Severity Rating:Critical – This security update addresses a privately reported vulnerability for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000 and Windows XP, Important for all supported editions of Windows Vista and Windows 7, Moderate for all supported editions of Windows Server 2003, and Low for all supported editions of Windows Server 2008 and Windows Server 2008 R2.
All Virus Alerts:
Kaspersky Lab has detected that multiple variants of Kido, a polymorphic worm, are currently spreading widely.
Kaspersky Lab has detected a new version of the ‘malicious blackmailer’ Gpcode – Virus.Win32.Gpcode.ak.
Kaspersky Lab has detected mass mailings of a new variant of Warezov, Email-Worm.Win32.Warezov.nf.
New Warezov variant mass mailed
A new variant of Warezov has been mass mailed, and is spreading rapidly
Multiple variants spreading
New variant of Zhelatin spreading rapidly
Sharp increase in the volume of Email-Worm.Win32.Zhelatin.r
Kaspersky Lab has detected a mass mailing of Email-Worm.Win32.Zhelatin.o, which is spreading as an attachment to infected emails.
Multiple new variants spreading
Security News (from SecurityFocus.com):
If your in IT you know coffee is almost as important as the air we breath. Show your support and add to the coffee fund. SHOW YOUR SUPPORT... Add to the coffee fundVN:F [1.6.9_936]
Rating: 0.0/5 (0 votes cast)
Popularity: 1% [?]