Showing posts with label Microsoft Security Bulletin. Show all posts
Showing posts with label Microsoft Security Bulletin. Show all posts

Thursday, 12 November 2015

Windows BitLocker Decryption Leak Made Possible


A vulnerability in Windows that Microsoft patched this month made it possible in certain circumstances for attackers to hard disks that were encrypted with BitLocker to decrypt. BitLocker encryption software from Microsoft which is present on certain versions of Windows.

To gain access to encrypted hard drives, there are several options, such as using a PIN, USB key, or Trusted Platform Module (TPM). On Windows, however, found himself a vulnerability through which an attacker could bypass Kerberos authentication and attacked computers could decrypt hard disks encrypted with BitLocker.

In the case of the now-remedied vulnerabilities an attacker could abuse it here only if the attacked system without BitLocker PIN or USB key used, the computer was located and the attacker had physical access to the machine in a domain. According to Microsoft, there are no known cases in which the vulnerability is actually attacked. In order to solve the problem is Microsoft Security Bulletin MS15-122 appeared.

Tuesday, 25 August 2015

Manual Windows Updaters Warned Patch


Microsoft has warned users and administrators to manually update computers for an important security update that was re-released and needs to be reinstalled. On August 11, Microsoft wrote poetry different vulnerabilities in Windows, .NET Framework, Office, Lync and Silverlight.

Through the vulnerabilities could take over a computer attacker completely if the user opens a specially crafted document or visit untrustworthy sites with embedded TrueType or OpenType fonts. As a solution has published Microsoft Security Bulletin  MS15-080. This update is on most Windows computers automatically installed via Windows Update. However, it is also possible to download the update from the Microsoft Download Center.

The update for Vista SP2, Windows Server 2008 (R2) SP2 and Windows 7 SP1 via the Download Center offered is updated on August 18th. Microsoft recommends that Windows users who update for August 18 have been downloaded from the Download Center to download it again and install so that they are fully protected against the vulnerabilities listed in the bulletin. This only applies to people who have downloaded the update from the Download Center. Users who update from Windows Update, Windows Update Catalog and WSUS are deployed need to take any action.

Wednesday, 18 March 2015

Problems Solved Updates For Windows Server 2003


Microsoft has problems with two security updates for Windows Server 2003 last week appeared resolved.It is Microsoft Security Bulletin MS15-025 , which fixes multiple vulnerabilities in the Windows kernel. Due to an error, Microsoft continued to offer the update to users, even though they had already installed the patch.

There is now a new version of the update appeared. Both users that the first version of the update had not yet installed, and administrators who had done so, need to install the new version. According to Microsoft, this is necessary to avoid future problems with detection updates.

The second problem arose in Microsoft Security Bulletin MS15-027 , which fixes a vulnerability in NETLOGON. After installing the update could be "connectivity issues" arise. Also in this case there is a new version of the update appeared that administrators need to install Server 2003, regardless of whether they had or not installed the first version of the update.