Showing posts with label Critical Patch Updates. Show all posts
Showing posts with label Critical Patch Updates. Show all posts

Friday, 13 November 2015

Microsoft Patches Update Outlook To Crash


Microsoft has released a new update for Windows 7, because the previous in some users Outlook to crash. Last Tuesday, Microsoft issued a critical security update (MS15-115) for multiple Windows computers leaks through which attackers could take over completely.

The 3097877 update caused some users of Outlook 2010 and 2013 ensure that the email program crashed when opening HTML emails, as evidenced by numerous complaints on the forum Microsoft and Reddit. The problems disappeared if the relevant update was removed. Microsoft allows now in the Security Bulletin MS15-115 know that the update has been re-released to fix the problem that caused crashes when viewing certain emails. Users also are advised to install the update again.

Wednesday, 11 November 2015

Microsoft Patches 53 Vulnerabilities In Windows, IE And Office


During the November Patch Tuesday, Microsoft has 53 vulnerabilities in Windows, Internet Explorer, Microsoft Edge, Office and several other products poem, including four zero-day vulnerabilities. The total contribution amounts to four twelve security updates, which are labeled as critical.

Critical updates address vulnerabilities that could allow an attacker to run arbitrary code on the computer can perform, without much user interaction. These four are updates for Internet Explorer, Edge and Microsoft Windows. There are also updates for Office, Lync, Skype for Business and .NET Framework appeared. Most leaks are fixed in Internet Explorer, namely 25.

In the case of the four zero-day vulnerabilities were those found in Windows and Office. It involved vulnerabilities that had already been announced for the release of the patches. According to Microsoft, there are no indications that the vulnerability for the appearance of the updates are attacked. An overview of all published Security Bulletins on this page to find. Updating via the Automatic Update feature, which is enabled on most Windows computers.

Monday, 2 November 2015

Forgotten Explorer Vulnerability In Windows 10 Still Patched


Microsoft has previously forgotten vulnerability in Internet Explorer for Windows 10 yet patched. On October 13 released Microsoft Security Bulletin MS15-106 for several critical vulnerabilities in Internet Explorer that could allow an attacker the underlying system could take over completely.

Several of the vulnerabilities were corrected by the Zero Day Initiative (ZDI) of security firm TippingPoint reported to Microsoft. Researchers can at ZDI sell vulnerabilities fee, and TippingPoint notifies the responsible supplier. Next, details of the vulnerability published as the supplier has solved the problem, or has not complied with the deadline of the ZDI.

In this case, made ​​after the publication of the TippingPoint Security Bulletin MS15-106 know that Microsoft is a critical vulnerability in Internet Explorer 11 for Windows 10 had composed, designated as CVE-2015-6045. The vulnerability, however, was not mentioned in the Microsoft Security Bulletin itself, what questions on Twitter made. TippingPoint then pulled the own publication about the vulnerability away.

It now appears that Microsoft had not patched the vulnerability. Thursday appeared namely a new version of the Microsoft Security Bulletin which announces that a new cumulative update was released CVE-2015-6045 in which it is resolved. The update is only for Windows 10, which also need to install the new update. On most systems, however, this happens automatically.

Tuesday, 27 October 2015

Criticism Joomla Leak Within Four Hours After Patch Attacked



A critical vulnerability in their content management system Joomla where last week a patch for appeared four hours after the release of the update has already attacked. The creators of Joomla administrators and webmasters had already in advance for the security warning.


The opinion stated that administrators had to be ready to roll out the update immediately. According to security firm Sucuri is very easy via the vulnerability to gain full administrator access. Sucuri says it saw direct attacks against two popular Joomla sites within four hours after the release of the update. By trying to steal the session logged managers Both websites were at the time of the attacks are not patched. And this probably applies to many more websites.

The update was in fact rolled out on Thursday afternoon, with many administrators probably were already free. Currently there are on the whole internet scans covering all kinds of random Joomla sites are scanned. In the case of scanned websites are vulnerable to the attack is carried out. Meanwhile says Sucuri have seen tens of thousands of attacks.According to the security company have the attacks show that webmasters and administrators have less than 24 hours to roll out an update to this type of serious problems.

Wednesday, 9 September 2015

Microsoft Office: Documents Install Backdoor Through Recent Office Leak



A recent vulnerability in Microsoft Office that in April was patched is already several weeks actively attacked and used to install a backdoor on Windows computers. A problem because many organizations install security updates for Microsoft Office or wait very long time here.

By opening a malicious document, an attacker could then install malware on the computer. A tactic that has been successfully applied. Last year made ​​the British anti-virus firm Sophos study (pdf) to the vulnerabilities that attackers use to this kind of attack. Two leaks, one from 2010 and one from 2012, was attacked by most of the malicious documents. Also from other surveys show that the vulnerability in 2012 the favorite target of attackers.

Although there is an update to the now attacked Office leak for about five months is available, the question is how many organizations have installed. Even before the patch Microsoft released the vulnerability was attacked. Early August saw Sophos, however, pass by a series of papers that try to take advantage of the leak. The documents have subjects like "WUPOS_update.doc", "ammendment.doc", "Information 2.doc" and "Anti-Money Laude Ring & Suspicious cases.doc".

In case the files are opened on an unpatched machine, the code in the document called Uwarrior install a backdoor on the computer. This allows the attackers full control over the machine. To prevent infection, managers and users are advised to patch Office and not to open unexpected or unsolicited documents. Last week warned IBM all e-mail attachments to make a comeback as an attack vector.

Tuesday, 25 August 2015

Manual Windows Updaters Warned Patch


Microsoft has warned users and administrators to manually update computers for an important security update that was re-released and needs to be reinstalled. On August 11, Microsoft wrote poetry different vulnerabilities in Windows, .NET Framework, Office, Lync and Silverlight.

Through the vulnerabilities could take over a computer attacker completely if the user opens a specially crafted document or visit untrustworthy sites with embedded TrueType or OpenType fonts. As a solution has published Microsoft Security Bulletin  MS15-080. This update is on most Windows computers automatically installed via Windows Update. However, it is also possible to download the update from the Microsoft Download Center.

The update for Vista SP2, Windows Server 2008 (R2) SP2 and Windows 7 SP1 via the Download Center offered is updated on August 18th. Microsoft recommends that Windows users who update for August 18 have been downloaded from the Download Center to download it again and install so that they are fully protected against the vulnerabilities listed in the bulletin. This only applies to people who have downloaded the update from the Download Center. Users who update from Windows Update, Windows Update Catalog and WSUS are deployed need to take any action.

Thursday, 11 June 2015

Microsoft Patches Critical Holes In IE And Windows Media Player



During the June Patch Tuesday, Microsoft has eight updates released that fix 45 vulnerabilities in total, including critical vulnerabilities in Internet Explorer and Windows Media Player. Through these vulnerabilities, an attacker in the worst case, the underlying system can take over completely.

The update for IE fixes a total of 24 vulnerabilities. Just visiting a malicious or hacked page would have been sufficient to allow an attacker to execute arbitrary code on the computer. Microsoft expects that cyber criminals have developed exploits within 30 days that will use these vulnerabilities to infect computers with malware.

In the case of Windows Media Player , an attacker remote computer completely take if malicious content opens in the media player. The impact of a strike may be limited, depending on the rights which the user is logged in. Despite the severity of the leak is not Microsoft expects cyber criminals are using the short-term.

The other six security updates that Microsoft released as "Important" labeled and repair vulnerabilities in the Windows kernel, Exchange Server, Active Directory Federation Services, Windows Kernel-Mode Drivers, Common Controls and Microsoft Office. Through the leak an attacker could increase his rights or run arbitrary code. Unlike the leaks in IE and Media Player would be here more interaction from the user is required, making Microsoft the impact is not as criticism but as judges important. All updates via Windows Update to download.

Thursday, 26 March 2015

Vulnerability Scanners F-Secure Patched


The Finnish anti-virus firm F-Secure warns of a leak in the virus scanners and security of the business which a remote attacker via a man-in-the-middle attack could attack the update channel. Then it would be possible to replace all the files on the computer.

The vulnerability, which was discovered by F-Secure itself has been assessed as "high". This is the next-to-highest rating.The problem is present in both the business and consumer software. For the affected software are now hotfixes. The warning for the leak was partly already published on 12 March, but is now updated with a description of the problem, vulnerable versions and the availability of the hotfix.

Monday, 23 March 2015

Emergency Patches Firefox Remedy Pwn2Own Leak


Mozilla has released in a short time two emergency patches for Firefox that fix critical vulnerabilities that an attacker in the worst case, the computer could take over completely. It involves two vulnerabilities that were demonstrated during the Pwn2Own contest in Vancouver.

During the event, researchers can win cash prizes by showing vulnerabilities in popular browsers and browser plug-ins. In Firefox three vulnerabilities were demonstrated, where it earned two responsible investigators $ 45,000 together. A day after the demonstration had already updated to Mozilla Firefox 36.0.3 done that fixed the first two leaks. A few hours later by Firefox 36.0.4 for the third vulnerability.

Updating to Firefox 36.0.4 possible via the automatic update feature of the browser or Mozilla.org . Besides Firefox succeeded researchers during the event also to Internet Explorer 11 , Safari and Google Chrome hack. In IE11 most vulnerabilities were discovered, namely four. On the same day as Mozilla also came with a Google update for Chrome, but the description is not mentioned in it or this version vulnerabilities have been patched.

Friday, 20 March 2015

Multiple Vulnerabilities In OpenSSL Patched


As mentioned earlier this week announced for updates today OpenSSL true that address multiple vulnerabilities. In total, it comes to 14 vulnerabilities, two of which are labeled as "high." This is the highest level for vulnerabilities that uses OpenSSL. The first high-leak is present only in version 1.0.2, and makes it possible to perform a Denial of Service against a server.

The second high-leak was originally labeled as "low", the lowest category that uses OpenSSL. One of the OpenSSL developers had previously indicated that only one high-leak would be, which was in version 1.0.2. Still, it was decided the low-leakage to label as high. It involves "FREAK leak" that previously was revealed by researchers. Through the leak, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

According to the OpenSSL developers was initially assumed that the problem would be small and it was not possible for many servers to downgrade to the weak encryption. Further investigation showed, however, that a significant number of servers supporting the weak encryption. The other vulnerabilities patched today were mainly possible to conduct denial of service attacks against servers. Administrators are advised, depending on which version is installed, upgrade to version 1.0.2a ,1.0.1m , 1.0.0r or 0.9.8zf .

Thursday, 29 January 2015

Experts: Linux system Reboot After Installation GHOST Patch


Tuesday released a patch for a critical vulnerability in Linux, but after installing the system must be restarted, as experts warn. Through the GHOST vulnerability an attacker can take over vulnerable systems in certain cases. Still, the leak can not be compared with other major vulnerabilities as Heartbleed and Shellshock.

Most systems are not vulnerable because, says security expert Robert Graham . Modern software would use a different function and even software that uses the function which the leak can be invoked does so in a way that can not be abused."Even if software will use the vulnerable function is not to say that it is also vulnerable," the expert notes. Also, most systems would not be attacked by the leak and many of the exploits used only locally. Graham says that users also do not have to panic.

He gets applause Jen Ellis security company Rapid7. "Unlike a leak as Heartbleed is not always exploit the problem. The general consensus is that the bug is not easy to abuse," Ellis says. Until now, there would be only one known case that is easy to abuse. Both experts suggest that users of their systems after installing the patch have to reboot. Without a reboot services that will use the vulnerable library not be restarted.

Thursday, 22 January 2015

Windows 10 Free For Users Of Windows 7 And 8.1


Windows 10, Microsoft will make available free of charge for users of Windows 7, Windows 8.1 and Windows Phone 8.1, so the software giant has tonight during a special event let you know. The upgrade to the operating system a year after launch free download. According to Microsoft, this involves more than a "one-time upgrade." Once a machine has been upgraded to Windows 10, Microsoft will continue to support operating system on the machine free of charge for the lifetime of the device.

Windows 10 will release the software giant new features sooner rather that it will wait for a new version of Windows. "We consider it as a Windows Service," said Microsoft's Terry Myerson. Therefore it would soon no longer make use of the device Windows, which would be good news for developers. Companies and business users, however, will have a choice whether they want to receive these consumer-oriented updates or important business rather shielding systems so that only receive critical patches and security updates.

One of the new additions to Windows 10 is an entirely new browser called "Project Spartan". The browser is specially designed for Windows 10 and should provide better interoperability, reliability and traceability. This would include reading articles should be improved and the voice assistant Cortana will be integrated into the browser, so users can find and do things faster. According to Microsoft's Jim alkove Spartan will be safer than ever.

Microsoft also showed tonight that already 1.7 million people in the pilot program of Windows 10 to participate and the software giant has already received 800,000 comments on the operating system. In addition, Windows 7 users were advised to install Internet Explorer 11 already, so they simply can upgrade to Windows 10 as the operating system is available.

Wednesday, 21 January 2015

Oracle Java SSL 3.0 Switches Off


To protect users from attack Java, Oracle SSL 3.0 disabled in the software. The measure is part of the security update that appeared Tuesday. "This Critical Patch Update disables the standard use of SSL 3.0. SSL 3.0 will be considered an obsolete protocol and this situation is exacerbated by the POODLE-leak. As a result, this protocol widely attacked by malicious hackers," says Eric Maurice Oracle.

The POODLE-vulnerability in SSL 3.0 ensures that an attacker who between a user and the Internet to know places, for example in an open Wi-Fi network, can steal information from encrypted connections, such as session cookies. Maurice gives organizations advised to discontinue use of all SSL versions, as it is no longer the safe communication between systems can be trusted.

Also Oracle customers have to change their code and switch to a more secure protocol such as TLS 1.2. Oracle employee further notes that Oracle in the future SSL in all Oracle software will turn off. Besides disabling SSL 3.0 update also fixes 19 vulnerabilities in Java, which in the worst case, an attacker can give full control over the system.