Showing posts with label Microsoft Patch Tuesday. Show all posts
Showing posts with label Microsoft Patch Tuesday. Show all posts

Wednesday, 10 February 2016

Major Updates For Windows, IE, Office And Edge


During the February Patch Tuesday, Microsoft released 13 security updates for critical vulnerabilities in Windows, Internet Explorer, Microsoft Edge Office, Microsoft Server Software, the .NET Framework and Adobe Flash Player. Six of the updates are rated as critical.

In this case, an attacker could execute arbitrary code on the computer with hardly any user interaction. It involves, for example just visiting a malicious or hacked website. The remaining updates are for vulnerabilities that an attacker who already had access to a system to increase its rights or cause a denial of service.

Two of the vulnerabilities in Microsoft SharePoint and Windows, were already known before Microsoft had released an update.These vulnerabilities would not be attacked active. Most problems have been resolved in Internet Explorer. It involves a total of 13 vulnerabilities. There are also two critical vulnerabilities in the built-in PDF reader in Windows 8.1 and later. Via a malicious PDF document, it was possible for an attacker to take over your computer. An overview of all updates on this page to find. Updating is done on most Windows computers automatically.

Friday, 13 November 2015

Microsoft Patches Update Outlook To Crash


Microsoft has released a new update for Windows 7, because the previous in some users Outlook to crash. Last Tuesday, Microsoft issued a critical security update (MS15-115) for multiple Windows computers leaks through which attackers could take over completely.

The 3097877 update caused some users of Outlook 2010 and 2013 ensure that the email program crashed when opening HTML emails, as evidenced by numerous complaints on the forum Microsoft and Reddit. The problems disappeared if the relevant update was removed. Microsoft allows now in the Security Bulletin MS15-115 know that the update has been re-released to fix the problem that caused crashes when viewing certain emails. Users also are advised to install the update again.

Wednesday, 11 November 2015

Microsoft Patches 53 Vulnerabilities In Windows, IE And Office


During the November Patch Tuesday, Microsoft has 53 vulnerabilities in Windows, Internet Explorer, Microsoft Edge, Office and several other products poem, including four zero-day vulnerabilities. The total contribution amounts to four twelve security updates, which are labeled as critical.

Critical updates address vulnerabilities that could allow an attacker to run arbitrary code on the computer can perform, without much user interaction. These four are updates for Internet Explorer, Edge and Microsoft Windows. There are also updates for Office, Lync, Skype for Business and .NET Framework appeared. Most leaks are fixed in Internet Explorer, namely 25.

In the case of the four zero-day vulnerabilities were those found in Windows and Office. It involved vulnerabilities that had already been announced for the release of the patches. According to Microsoft, there are no indications that the vulnerability for the appearance of the updates are attacked. An overview of all published Security Bulletins on this page to find. Updating via the Automatic Update feature, which is enabled on most Windows computers.

Wednesday, 22 July 2015

Criticism Windows Leak Was Already Known To Hacking Team


The critical flaw in Windows which Microsoft yesterday an emergency patch released was already known to the Italian Hacking Team, which previously had also developed an exploit, as reported anti-virus company Trend Micro. Through the vulnerability an attacker could completely take over Windows computers when the user opens a malicious document or visits a malicious or hacked website. There is no further interaction is required.

"Because of this vulnerability, attackers could use to infect the computer with system privileges by rootkits or boat kits without this was reported by any means," said analyst Li Moony. He argues that attackers can remotely control vulnerable computers over the leak. Trend Micro reported the problem to Microsoft. Something that also involved researchers from Google and the American security company FireEye.

According to Li contains the dataset by Hacking Team was looted exploit code to make use of the vulnerability, but no attacks are still found in the wild. However, this seems a matter of time. Earlier there were already vulnerabilities found in the stolen data of Hacking Team, which were then used by cyber criminals to infect computers with malware. Users also get the urgent advice to security MS15-078 to install. However, this will happen automatically on most computers.

An attacker recently managed to break into the Italian company and made it more than 400GB of data captured and then put the data online. The data have been found so far six so-called zero-day vulnerabilities. Vulnerabilities in which at the time of the discovery for no update was available yet. These are three vulnerabilities in Adobe Flash Player, two Windows and one in Internet Explorer.

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .

Wednesday, 15 July 2015

Microsoft Patches 59 Vulnerabilities, Of Which 7 Zero Days



Microsoft Patch Tuesday during the July 59 vulnerabilities in Windows, Internet Explorer, Office and SQL Server patched, 7 of zero days. It is in this case for vulnerabilities that were already known or were attacked before the relevant Microsoft security update was available.

Three of the zero-day vulnerabilities in Internet Explorer, Office and Windows were actively attacked, Microsoft said. Two of these vulnerabilities in IE and Windows, were coming from the Italian company hacked Hacking Team. This means that Hacking Team possessed far as is known about five zero-day vulnerabilities. In addition to IE and Windows, the company had also provided with three unknown vulnerabilities in Adobe Flash Player. The remaining four zero-day vulnerabilities that Microsoft patched this month found in IE and were already made ​​public, but according to the software giant does not actively attacked.

Updates

In total there are 14 security updates. Thus it belongs patch round both the number patches as corrected vulnerabilities into one of the toughest rounds patch from Microsoft ever. Four updates, MS15-065 , MS15-066 , MS15-067 and MS15-068 , have the highest priority and are labeled by Microsoft as critical. Through these vulnerabilities, an attacker can take over the underlying system. These include a vulnerability in the Remote Desktop Protocol (RDP). RDP is not enabled by default, but if that is the case an attacker by sending a few packets take over the system.

Three other updates are not labeled as critical, but let an attacker or run arbitrary code on a computer. It is MS15-058 for SQL Server MS15-069 for Windows and MS15-070 for Office. Microsoft regards this update as "important" because an attacker needs to do more effort before code execution is possible. The other security bulletins this month fix vulnerabilities that an attacker can increase his privileges on the computer. These include to the zero-day flaw in Windows which was discovered by Hacking Team. In these vulnerabilities, an attacker must already have access to the system before use can be made.

The updates can be downloaded via Windows Update and will be automatically installed on most computers. An overview of all bulletins on this page to find.

Thursday, 11 June 2015

Microsoft Patches Critical Holes In IE And Windows Media Player



During the June Patch Tuesday, Microsoft has eight updates released that fix 45 vulnerabilities in total, including critical vulnerabilities in Internet Explorer and Windows Media Player. Through these vulnerabilities, an attacker in the worst case, the underlying system can take over completely.

The update for IE fixes a total of 24 vulnerabilities. Just visiting a malicious or hacked page would have been sufficient to allow an attacker to execute arbitrary code on the computer. Microsoft expects that cyber criminals have developed exploits within 30 days that will use these vulnerabilities to infect computers with malware.

In the case of Windows Media Player , an attacker remote computer completely take if malicious content opens in the media player. The impact of a strike may be limited, depending on the rights which the user is logged in. Despite the severity of the leak is not Microsoft expects cyber criminals are using the short-term.

The other six security updates that Microsoft released as "Important" labeled and repair vulnerabilities in the Windows kernel, Exchange Server, Active Directory Federation Services, Windows Kernel-Mode Drivers, Common Controls and Microsoft Office. Through the leak an attacker could increase his rights or run arbitrary code. Unlike the leaks in IE and Media Player would be here more interaction from the user is required, making Microsoft the impact is not as criticism but as judges important. All updates via Windows Update to download.

Wednesday, 11 March 2015

Microsoft Patches 45 Vulnerabilities, Including Stuxnet And FREAK


Microsoft has during Patch Tuesday of March 14 released updates, which together 45 vulnerabilities in Windows, Office, Exchange and Internet Explorer fix, including the Stuxnet leak from 2010 and the recently discovered FREAK leak. Especially re-patching the Stuxnet leak creates experts in amazement.Through the vulnerability knew the Stuxnet worm and the Fanny-espionage worm to spread.

Only connect a USB stick that made ​​the leak abuse was sufficient to infect Windows, even stood Autorun and Autoplay disabled. It was in fact a whole new way to attack Windows computers. In 2010, Microsoft came up with an update for the leak, but this patch showed the vulnerable code is not corrected, allowing Windows computers all the time were vulnerable, so warn researchers from HP.

There is also an update to the " FREAK-leak "in SSL / TLS appeared. Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Other vulnerabilities

In addition to the update for the Stuxnet leak four other updates are labeled as critical. Through these updates fix vulnerabilities that an attacker in the worst case can take over the entire system. It comes to vulnerabilities in Internet Explorer, the VBScript Scripting Engine in Windows, Adobe Font Driver and Office. In the case of one of the IE-leakage was the vulnerability already publicly known before the patch appeared. Through other vulnerabilities that Microsoft patched attackers could increase their rights to systems retrieve information, cause a denial of service and bypass security measures.Can update via Windows Update .

Wednesday, 11 February 2015

Microsoft Patches 56 Vulnerabilities In Windows, IE and Office


During the Patch Tuesday in February, Microsoft has nine updates that released a total of 56 vulnerabilities in Windows, Office, Internet Explorer and Microsoft Server software fix. Three of the patches as critical, while the remaining six were labeled as important.

The three critical updates for Windows Kernel Mode Driver, Windows Group Policy and IE and give an attacker the ability to take the operating system in the worst case completely. Most leaks were this patch Tuesday patched in Internet Explorer.Security Bulletin MS15-009 namely fixes 41 vulnerabilities. Of these leaks, there was one already made ​​public before the update appeared. However, Microsoft has not observed attacks who abuse the leak.

This is different in the case of another leak that resolves MS15-009. This is a vulnerability to bypass ASLR protection of IP.An attacker would have to combine this vulnerability with another leak to perform an attack. In the case of Office are three vulnerabilities in the past. These vulnerabilities allowed an attacker to execute arbitrary code on the computer when a malicious Office file was opened. All nine security updates using Windows Update to download.