SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, January 9, 2011

Assessing the risk of public issues currently being tracked by the MSRC

Posted on 12:11 PM by Unknown
To help clear up confusion regarding public issues being tracked by the Microsoft Security Research & Defense team, the table below was published at the MSRC Blog. 

The risk to the vulnerabilities can be removed by applying the provided work-around.

Issue Status Mitigation
Internet Explorer 6/7/8 vulnerability in recursive style sheet importing. (CVE-2010-3971) Public, exploit code is available. We are seeing limited exploitation. As listed in Security Advisory #2488013, EMET is an effective mitigation tool. Anti-virus and IDS/IPS signatures developed by our MAPP partners for this issue have also been quite effective at detecting and blocking attacks.
Windows graphics rendering engine vulnerability in parsing BMP thumbnails embedded within an OLESS document container. (CVE-2010-3970) Public exploit code was posted this week. Proof-of-concept code we have seen so far requires a user to browse to an attacker-writable folder using Windows Explorer. If Explorer is set to display thumbnails or a preview of contained files (neither setting is the default), the chance of code execution exists. Current proof-of-concept code is not successful when Explorer is set to display files in the default List mode. As listed in Security Advisory #2490606, modify the Access Control List on shimgvw.dll. The advisory also lists a one-click FixIt to automate this configuration change.
IIS 7.0 and 7.5 FTP service vulnerability in encoding Telnet IAC (Interpret As Command) characters in the FTP response. (SRD blog post) As discussed in this SRD blog post, attempts to exploit this vulnerability would most likely result in a Denial-of-Service. We have not seen attempts to exploit this vulnerability for code execution. The FTP service is not installed by default with IIS 7 or IIS 7.5. And when it is installed, it is not enabled by default. If you have enabled IIS FTP service, consider disabling it, if possible, until a security update is available.
Internet Explorer fuzzer released publicly capable of hitting Internet Explorer crashes A fuzzer for various browsers was released, as well as information on a crash that shows a potentially exploitable condition. While the fuzzer is successful in encountering exploitable memory corruption issues in Internet Explorer, we have been unable so far to turn a crash into a stand-alone HTML page that could be used as a browse-and-own exploit. Encountering the issues appears dependent on first loading many previous iterations of HTML in the fuzzer, making the issues we have discovered so far less useful for the purpose of real-world attacks. We are still investigating this issue and will monitor for any developments that may change the current risk. Unable to make an assessment at this time without stand-alone PoC. However, we are working on a security update to address the issues found in fuzzing.
WMI Administrative Tools ActiveX control vulnerability. Only the very few customers who have installed the WMI Administrative Toolkit are vulnerable to this issue. This product has a small number of total downloads. The ActiveX control itself is not signed by Microsoft. This is not a case where an attacker can host a Microsoft-signed ActiveX control and entice the user to make one click to allow it to install. The real-world risk to most customers from this issue is expected to be quite low. This ActiveX control can be killbitted to protect any machines that have installed the WMI Administrative Toolkit. The affected ActiveX control was not intended to be instantiated within Internet Explorer so legitimate use of the WMI Administrative Toolkit should not be impacted by this configuration change. The attached .txt file, if renamed to .reg and opened, will apply the killbit to the affected clsid’s.


Source:  Assessing the risk of public issues currently being tracked by the MSRC


Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Advisory, Vulnerabilities, Information, How To,


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Email ThisBlogThis!Share to XShare to Facebook
Posted in Advisory, Microsoft, Security, Vulnerabilities, Windows, Windows 7 | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...
  • Critical Adobe Flash Player Update Released
    Adobe Flash Player was updated to address security vulnerabilities.  These updates address a vulnerability that could cause the application...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • How to use Hotmail Aliases
    Whether shopping online, joining an on-line tech forum, registering your account for on-line bill payment or some other service, a valid e-m...
  • Critical Adobe PDF Vulnerability: Disable JavaScript!
    No relief appears to be in sight as far as Adobe product vulnerabilities this year. Here is hope that 2010 proves better for Adobe secur...
  • Waledac Botnet Takedown
    The Waledac botnet had the capability of sending 1.5 billion spam e-mails per day. During a three-week period in December, 2009, approximat...
  • Critical Adobe and Adobe Acrobat Update
    Adobe has taken to using the same "patch Tuesday" as Microsoft. If you use Adobe Reader or Adobe Acrobat, it is strongly advise...
  • Adobe Flash Player Critical Security Updates
    Adobe Flash Player was updated to address critical security vulnerabilities.  These updates address a vulnerability that could cause the ap...
  • Important service change regarding Twitter with Widows Live‏
    Social Networking has become not only a popular way for friends to communicate. It is also a great means of sharing information. I have fo...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ►  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ►  August (9)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ►  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ►  October (11)
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ►  June (12)
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ▼  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ▼  January (13)
      • Microsoft Security Advisory 2501696 and Fix it
      • Data Privacy
      • Facebook Privacy "Instant Personalization"
      • Microsoft Fix It Available to Uninstall Office Suites
      • Leaked "Official" Windows 7 Service Pack 1
      • Microsoft Fix it Available for Security Advisory 2...
      • Security Bulletin Release for January, 2011
      • Assessing the risk of public issues currently bein...
      • Microsoft Fix it Available for Security Advisory 2...
      • Security Bulletin Advance Notification for January...
      • Microsoft Security Advisory 2490606
      • Facebook Page Created for Security Garden
      • Congratulations 2011 Microsoft MVP!‏
  • ►  2010 (146)
    • ►  December (10)
    • ►  November (15)
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ►  February (14)
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile