SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, November 9, 2010

Security Bulletin Release for November, 2010

Posted on 11:07 AM by Unknown

Microsoft released three (3) bulletins addressing 11 vulnerabilities in Microsoft Office and Unified Access Gateway (UAG). One of the bulletins is rated Critical with the other two as Important. 

Following is the description from the MSRC Blog:
  • MS10-087 This bulletin resolves five issues affecting all currently supported Microsoft Office products. The bulletin is rated Critical for Office 2007 and Office 2010 due to a preview pane vector in Outlook that could trigger the vulnerability when a customer views a specially crafted malicious RTF (Rich Text Format) file. The update also addresses an Office vector for the vulnerability described in Security Advisory 2269637, which has been referred to as "DLL Preloading" and "Binary planting." MS10-087 is Microsoft's top priority bulletin for deployment in November and has an Exploitability Index rating of 1.
  • MS10-088 This bulletin resolves two cooperatively disclosed vulnerabilities in Microsoft PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. The overall severity rating is Important due to the user interaction required to open the malicious file and we give the bulletin a rating of 2 in our deployment priority assessment.
  • MS10-089 This bulletin resolves four cooperatively disclosed vulnerabilities in Unified Access Gateway (UAG), which is a component of Microsoft Forefront. The most significant of these could allow elevation of privilege if a user clicks on a malicious link on a website. This update is offered through the Microsoft Download Center and is not available through Microsoft Update at this time. With an overall severity rating of Important and user interaction required to exploit, we also give this a deployment priority of 2.
Microsoft is not aware of any active attacks seeking to exploit the vulnerabilities addressed in this month's release.

For complete details, see the references listed below.


References:
  • MSRC: November 2010 Security Bulletin Release
  • TechNet: Microsoft Security Bulletin Summary for November 2010
  • Security Research and Defense:  DEP, EMET protect against attacks on the latest Internet Explorer vulnerability

Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
v>
Email ThisBlogThis!Share to XShare to Facebook
Posted in Microsoft, Security, Updates, Vulnerabilities, Windows, Windows 7 | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Security Bulletin Advance Notice for August, 2013
    On Tuesday, August 13, 2013, Microsoft is planning to release eight (8) bulletins.  Three of the bulletins are identified as Critical with f...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...
  • Long Awaited Outlook.com Calendar Refresh Rollout
    The long-awaited Outlook.com calendar refresh has been released and is in the process of being rolled out. Because the servers are grouped i...
  • Microsoft Security Advisory 2269637 Released
    Microsoft released Security Advisory 2269637 which relates to a remote attack vector to a class of vulnerabilities affecting applications t...
  • Oracle Java Update
    Oracle released the Java SE 7u40 today.  In addition to bug fixes and enhancements, the update includes the following: advanced monitoring ...
  • Adobe Reader Security Updates
    Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.03) and earlier versions for Windows and Macintosh. Adobe identif...
  • Advance Notice: Security Updates for Java SE
    The Sun Security Blog published the following update announcement: "On November 3, 2009, Sun will release the following security update...
  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...
  • Waledac Botnet Takedown
    The Waledac botnet had the capability of sending 1.5 billion spam e-mails per day. During a three-week period in December, 2009, approximat...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ►  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ►  August (9)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ►  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ►  October (11)
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ►  June (12)
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ►  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ►  January (13)
  • ▼  2010 (146)
    • ►  December (10)
    • ▼  November (15)
      • Command Prompt Series, 7Tutorials
      • Online Shopping Safety Tips
      • Happy Thanksgiving (and Happy Birthday!)
      • How the TLD4 rootkit gets around driver signing po...
      • Accelerated Adobe Reader/Acrobat Security Update
      • Security alert: Active Links in Messenger 2009 Tem...
      • Advance Notice: Adobe Reader/Acrobat Out of Cycle ...
      • Lest We Forget
      • Hotmail Now Includes Full-Session HTTPS Encryption
      • Security Bulletin Release for November, 2010
      • WinPatrol 19.3 Issues and Solutions
      • Adobe Flash Player Critical Security Update
      • Security Bulletin Advance Notification for Novembe...
      • Microsoft Security Advisory 2458511 Released
      • The Office 2010 Beta Has Expired!
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ►  February (14)
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile