Security Advisories

Security Advisories

Microsoft Security Advisory (2588513): Vulnerability in SSL/TLS Could Allow Information Disclosure - Version: 1.0

Microsoft Security Advirsories - Mon, 09/26/2011 - 01:00
Revision Note: V1.0 (September 26, 2011): Advisory published.
Summary: Microsoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0 and TLS 1.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS traffic. This vulnerability primarily impacts HTTPS traffic, since the browser is the primary attack vector, and all web traffic served via HTTPS or mixed content HTTP/HTTPS is affected. We are not aware of a way to exploit this vulnerability in other protocols or components and we are not aware of attacks that try to use the reported vulnerability at this time. Considering the attack scenario, this vulnerability is not considered high risk to customers.
Categories: Security Advisories

Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0

Microsoft Security Advirsories - Mon, 09/19/2011 - 01:00
Revision Note: V5.0 (September 19, 2011): Revised to announce the rerelease of the KB2616676 update. See the Update FAQ in this advisory for more information.
Summary: Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root Certification Authorities Store. A fraudulent certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer. While this is not a vulnerability in a Microsoft product, this issue affects all supported releases of Microsoft Windows.
Categories: Security Advisories

Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution - Version: 10.0

Microsoft Security Advirsories - Tue, 09/13/2011 - 01:00
Revision Note: V10.0 (September 13, 2011): Added the following Microsoft Security Bulletins to the Updates relating to Insecure Library Loading section: MS11-071, "Vulnerability in Windows Components Could Allow Remote Code Execution;" and MS11-073, "Vulnerabilities in Microsoft Office Could Allow Remote Code Execution."
Summary: Microsoft is aware that research has been published detailing a remote attack vector for a class of vulnerabilities that affects how applications load external libraries.
Categories: Security Advisories

Microsoft Security Advisory (2562937): Update Rollup for ActiveX Kill Bits - Version: 1.0

Microsoft Security Advirsories - Tue, 08/09/2011 - 01:00
Revision Note: V1.0 (August 9, 2011): Advisory published.
Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.
Categories: Security Advisories

Microsoft Security Advisory (2524375): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0

Microsoft Security Advirsories - Wed, 07/06/2011 - 01:00
Revision Note: V5.0 (July 6, 2011): Announced the release of an update for Zune HD devices and moved Zune devices to the Non-Affected Devices table.
Summary: Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store, on all supported releases of Microsoft Windows, Windows Mobile 6.x, Windows Phone 7, Microsoft Kin, and Zune HD devices. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.
Categories: Security Advisories

Microsoft Security Advisory (2501584): Release of Microsoft Office File Validation for Microsoft Office - Version: 2.0

Microsoft Security Advirsories - Thu, 06/30/2011 - 01:00
Revision Note: V2.0 (June 30, 2011): Announced that the Office File Validation Add-in described in Microsoft Knowledge Base Article 2501584 is available through the Microsoft Update service.
Summary: Microsoft is announcing the availability of the Office File Validation feature for supported editions of Microsoft Office 2003 and Microsoft Office 2007. The feature, previously only available for supported editions of Microsoft Office 2010, is designed to make it easier for customers to protect themselves from Office files that may contain malformed data, such as unsolicited Office files received from unknown or known sources, by scanning and validating files before they are opened.
Categories: Security Advisories
Syndicate content