Showing posts with label Advisory. Show all posts
Showing posts with label Advisory. Show all posts

Friday, January 17, 2020

Microsoft Security Advisory for Remote Code Execution Vulnerability in IE

Security Advisory

Microsoft released Security Advisory ADV200001 for a remote code execution vulnerability with limited active attacks in Internet Explorer.  The issue is described as the way that the scripting engine handles objects in memory in Internet Explorer. As described in the advisory:
"The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
In the event you use Internet Explorer, it is strongly advised that you follow the instructions at the bottom of the Advisory to restrict access to JScript.dll as a workaround.

References


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...





Thursday, March 05, 2015

Microsoft Security Advisory 3046015 (FREAK)

Security Advisory
Microsoft released Security Advisory 3046015 which relates to the SSL/TLS issue referred being referred to as “FREAK” (Factoring attack on RSA-EXPORT Keys).

Most of the publicity surrounding FREAK has been addressing the vulnerability in the Safari, Chrome and Android browsers with OS X, iOS and Android.  However, the flaw also affects many popular websites.  As described in the Security Advisory:
"The vulnerability could allow a man-in-the-middle (MiTM) attacker to force the downgrading of the cipher used in an SSL/TLS connection on a Windows client system to weaker individual ciphers that are disabled but part of a cipher suite that is enabled."
The problem is that it isn't only the browser that is vulnerable but websites as well.  Are you or the sites you frequent vulnerable?  To find out, do the following:
To learn more about FREAK, see Time to FREAK out? How to tell if you're vulnerable | Computerworld by Gregg Keizer.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 21, 2014

Microsoft Security Advisory 3010060 with Fixit Solution

Security Advisory
Microsoft released Security Advisory 3010060 which relates to a vulnerability affecting all supported releases of Microsoft Windows, excluding Windows Server 2003.

The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that contains an OLE object. Microsoft is aware of limited, targeted attacks. 

Recommendations

Microsoft has made available a Fix it solution "OLE packager shim workaround" which prevents execution of the vulnerability.  Below are direct links to both enable and disable the Fix it solution.



NoteThe Fix it solution is not at this time for 64-bit editions of PowerPoint on x64-based editions of Windows 8 and Windows 8.1. 
 
Enable Fix itDisable Fix it


Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 14, 2014

Microsoft Security Bulletin Release for October 2014


Microsoft released eight (8) bulletins.  Three (3) bulletins are identified as Critical and five (5) as Important.

The updates address 24 Common Vulnerabilities & Exposures (CVEs) in Windows, Office, .NET Framework, .ASP.NET, and Internet Explorer (IE). Reminder to those who have problems with .NET updates to install separately with a restart between other updates.

Critical:

  • MS14-056 -- Cumulative Security Update for Internet Explorer (2987107)  
  • MS14-057 -- Vulnerabilities in .NET Framework Could Allow Remote Code Execution (3000414) 
  • MS14-058 -- Vulnerability in Kernel-Mode Driver Could Allow Remote Code Execution (3000061) 

Important:
  • MS14-059 -- Vulnerability in ASP.NET MVC Could Allow Security Feature Bypass (2990942) 
  • MS14-060 -- Vulnerability in Windows OLE Could Allow Remote Code Execution (3000869)
  • MS14-061 -- Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434) 
  • MS14-062 -- Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) 
  • MS14-063 -- Vulnerability in FAT32 Disk Partition Driver Could Allow Elevation of Privilege (2998579)   
Information on non-security update information can be found in KB 894199.

Security Advisories


The following security advisories were released:
Revised advisories:

Notes



The following additional information is provided in the Security Bulletin:

References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...



    Tuesday, June 17, 2014

    Microsoft Security Advisory 2974294, Malware Protection Engine

    Security Advisory
    Microsoft released Security Advisory 2974294 which relates to a vulnerability which could allow denial of service if the Microsoft Malware Protection Engine scans a specially crafted file.

    Microsoft is not aware of code existing for the vulnerability.

    The vulnerability affects the following software:
    • Microsoft Forefront Client Security
    • Microsoft Forefront Endpoint Protection 2010
    • Microsoft Forefront Security for SharePoint Service Pack 3
    • Microsoft System Center 2012 Endpoint Protection
    • Microsoft System Center 2012 Endpoint Protection Service Pack 1
    • Microsoft Malicious Software Removal Tool (May 2014 or earlier)
    • Microsoft Security Essentials
    • Microsoft Security Essentials Prerelease
    • Windows Defender for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2
    • Windows Defender for Windows RT and Windows RT 8.1
    • Windows Defender for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
    • Windows Defender Offline
    • Windows Intune Endpoint Protection 
    Microsoft Forefront Server Security Management Console and Microsoft Internet Security and Acceleration (ISA) Server are not affected because they do not use the Malware Protection Engine.

    Recommendations 

    Due to update mechanism, an updated Malware Protection Engine will be applied within 48 hours of release, the timing dependent upon location and Internet connection.  Thus, action on your part is not required.

    To update Microsoft Security Essentials now, merely launch MSE and check for updates.  The updated Engine Version is 1.1.10701.0 or higher.  To check, click the arrow next to Help and click About.

    Microsoft Security Essentials



    References:


    Remember - "A day without laughter is a day wasted." May the wind sing to you and the sun rise in your heart...

    Sunday, April 27, 2014

    Security Advisory 2963983, IE Zero-Day Vulnerability

    Security Advisory
    Microsoft released Security Advisory 2963983 which relates to a vulnerability in Internet Explorer.

    With the vulnerability, an attacker could cause remote code execution if someone visited a malicious website with an affected browser. Generally, this would occur by an attacker convincing someone to click a link in an email or instant message.

    Although the vulnerability affects all versions of IE, at this time, Microsoft is aware of limited, targeted attacks, in which the exploit observed appears to target IE9, IE10 and IE11.


    Additional details about the exploit are available from the FireEye Blog, New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks.

    Recommendations 

    As illustrated in the "Security Research and Defense Blog" reference below, users of IE 10 and 11 should ensure they haven't disabled Enhanced Protection Mode. 

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET).  The recommended setting for EMET 4.1, available from KB Article 2458544, is automatically configured to help protect Internet Explorer. No additional steps are required.

    See the Tech Net Advisory for instructions on changing the following settings to help protect against exploitation of this vulnerability:
    • Change your settings for the Internet security zone to high to block ActiveX controls and Active Scripting
    • Change your settings to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. 

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Monday, March 24, 2014

    Security Advisory 2953095 for Microsoft Word 2010

    Security Advisory
    Microsoft released Security Advisory 2953095 which relates to a vulnerability in Microsoft Word. At this time, Microsoft is aware of limited, targeted attacks directed at Microsoft Word 2010.

    With the vulnerability, an attacker could cause remote code execution if someone was convinced to open a specially crafted Rich Text Format (RTF) file or a specially crafted mail in Microsoft Outlook while using Microsoft Word as the email viewer.

    Recommendations 

    Users of Microsoft Word 2010 are encouraged to apply the Microsoft Fix it solution.  If you use Outlook, follow the Office help instructions to Read email messages in plain text.

     
    Enable Fix itDisable Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), with instructions provided in the Security Research and Defense Blog article referenced below.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Wednesday, February 19, 2014

    Microsoft Security Advisory 2934088

    Security Advisory
    Microsoft released Security Advisory 2934088 which impacts Internet Explorer 9 and 10. Internet Explorer 6, 7, 8 and 11 are not affected.

    Although Internet Explorer 9 is vulnerable, at this time, Microsoft is only aware of limited, targeted attacks against Internet Explorer 10. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message.

    Recommendations

    Users of Internet Explorer 10 should update to IE11, available here.

    If you use Internet Explorer 9 or 10 and are unable to update to Internet Explorer 11, it the below-linked Fix it solution is strongly advised.
     
    Enable Fix itDisable Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory as well as the Security Research and Defense Blog article.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, November 05, 2013

    Microsoft Security Advisory 2896666 with Fix it

    Security Advisory
    Microsoft released Security Advisory 2896666 which relates to a vulnerability in the Microsoft Graphics component that affects Microsoft Windows Vista and Windows Server 2008, Microsoft Office 2003 through 2010, and all supported versions of Microsoft Lync.

    Microsoft is aware of targeted attacks primarily in the Middle East and South Asia that attempt to exploit this vulnerability in Microsoft Office products.  

    The vulnerability is a remote code execution vulnerability that exists in the way affected components handle specially crafted TIFF images.  The vulnerability is exploited either through previewing or opening a specially crafted email message or file.  It is also exploited by browsing similarly web content.  The attacker could gain the same user rights as the current user.

    Recommendations

    Microsoft has made available a Fix it solution which will disable the TIFF codec. Below are the links to both enable and disable the Fix it solution. 
     
    Enable Fix itDisable Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, September 17, 2013

    Security Advisory 2887505 and Microsoft Fix it

    Security Advisory
    Microsoft released Security Advisory 2887505 which relates to an issue with Internet Explorer.

    It is important to note that there are a limited number of targeted attacks which are specifically directed at Internet Explorer 8 and 9. The issue, however, could potentially affect all supported versions of IE.

    As described by Dustin Childs in the below-referenced MSRC Blog post,
    "This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. This would typically occur when an attacker compromises the security of trusted websites regularly frequented, or convinces someone to click on a link in an email or instant message."

    Mitigations

    Microsoft has made available a Fix it solution for users of Internet Explorer.  Additional mitigations include the following advice, also from the MSRC Blog post:

    • Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
      This will help prevent exploitation but may affect usability; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones
      This will help prevent exploitation but can affect usability, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    Below are the links to both apply and uninstall the Fix it solution.  Note:  The Fix it solution applies only 32-bit versions of Internet Explorer.
     
    Apply Fix itUninstall Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Wednesday, May 08, 2013

    Microsoft FixIt for Security Advisory 2847140

    Security Advisory
    Microsoft released a Microsoft Fix it solution for Security Advisory 2847140, which relates to a vulnerability for IE8.

    Although it is anticipated that there will be an update included with next week's security updates, anyone with IE8 installed is advised to install the Fix it solution.  The Fix it uses the Windows application compatibility toolkit to make a small change at runtime to mshtml.dll every time IE is loaded. 

    Below are the links to both apply and uninstall the Fix it solution: 
     
    Apply Fix itUninstall Fix it

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:



    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Thursday, February 14, 2013

    Critical Security Advisory for Adobe Reader and Acrobat (APSA13-02)

    Adobe
     Adobe released Security Advisory (APSA13-02) related to critical security vulnerabilities in Adobe Reader and Acrobat XI (11.0.01 and earlier), X (10.1.5 and earlier) and 9.5.3 and earlier for Windows and Macintosh.


    Release date: February 13, 2012
    Last updated: February 14, 2012
    Vulnerability identifier: APSA13-02
    CVE number: CVE-2013-0640, CVE-2013-0641
    Platform: All Platforms


    Adobe reported that the vulnerabilities are being exploited in the wild in targeted attacks designed to trick Windows users into clicking on a malicious PDF file delivered in an email message.  These vulnerabilities could cause the application to crash and potentially allow an attacker to take control of the affected system.

    Both Windows and Macintosh operating systems are vulnerable, however mitigation is only provided for users of Adobe Reader XI and Acrobat XI for Windows.  

    Enable "Protected View"

    In order to minimize vulnerability it is recommended Windows users of Adobe Reader and Acrobat ensure that Protected View is enabled.  Unfortunately, neither the Protected Mode or Protected View option is available for Macintosh users.

    To enable this setting, do the following:
    • Click Edit > Preferences > Security (Enhanced) menu. 
    • Change the "Off" setting to "All Files".
    • Ensure the "Enable Enhanced Security" box is checked. 

    Adobe Protected View
    Image via Sophos Naked Security Blog
    If you haven't updated to the latest version of Adobe Reader it is strongly advised that you do so and enable the settings as illustrated above.  On other hand, if you are looking for a replacement for Adobe Reader, consider Replacing Adobe Reader with Sumatra PDF.

    References




    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Sunday, January 13, 2013

    Advance Notification for Update to Address Security Advisory 2794220

    Security Bulletin
    On Monday, January 14, 2013, Microsoft is planning to release an out-of-band critical security update for the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected. 

    Although Microsoft has seen only a limited number of customers affected by the issue, the potential exists that more could be affected.  Thus, it is advised that the update be installed as soon as possible. 

    Even with the update, if your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    If you applied the Fix it released in Security Advisory 2794220, it will not need to be uninstalled before applying the security update.

    References



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Thursday, January 03, 2013

    Security Advisory 2798897 Released, Certificate Trust List Updated

    Security Advisory
    Microsoft released Security Advisory 2798897 to provide notification regarding a a fraudulent digital certificate issued by TURKTRUST Inc.

    TURKTRUST Inc. incorrectly created two subsidiary Certificate Authorities: (*.EGO.GOV.TR and e-islem.kktcmerkezbankasi.org). The *.EGO.GOV.TR subsidiary CA was used to issue a fraudulent digital certificate to *.google.com.

    Actions:

    Windows Vista and newer:

    With up-to-date security updates, your computer was protected with the installation of Microsoft Knowledge Base Article 2677070, released on June 12, 2012.

    The update provides an automatic updater feature which includes a mechanism that allows Windows to specifically flag certificates as untrusted. With this feature, Windows checks daily for updated information about certificates that are no longer trustworthy.  In the past, movement of certificates to the untrusted store required a manual update.

    If you have not installed KB 2677070, it is strongly advised that you do so as soon as possible.

    Windows XP and Windows Server 2003

    Because the automatic updater feature is not applicable to Windows XP and Windows Server 2003, it is necessary for users of these systems to manually check for updates.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Saturday, December 29, 2012

    Microsoft Security Advisory 2794220

    Security Advisory
    Microsoft released Security Advisory 2794220 to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.

    At this time, Microsoft is aware of a very small number of targeted attacks.  This issue allows remote code execution if users browse to a malicious website with an affected browser.  Generally, this is a result of an attacker convincing someone to click a link in an email or instant message.

    Recommendations:

    Microsoft is actively working to develop a security update to address the issue.  In the meantime, please consider the following suggestions:

    1.  Update Internet Explorer -- If your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    2.  Update or Uninstall Java -- Current exploits of this type of vulnerability in Internet Explorer use third-party software, including Oracle’s Java, to help obtain reliable exploitation.

    Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

    • Playing on-line games generally requires Java.
    • With OpenOffice, Java is needed for the items listed here
    • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
    • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
    If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.  The current version of Java is Version 7 Update 10.
     

    3.  Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations to help protect against this and other issues and should not affect usability of websites.

    An easy guide for EMET installation and configuration is available in KB2458544.  Additional information about configuring EMET is available in the EMET User's Guide, in the following locations:
    • 32-bit systems -- C:\Program Files\EMET\EMET User's Guide.pdf
    • 64-bit systems -- C:\Program Files (x86)\EMET\EMET User's Guide.pdf
    Additional suggestions are available in the MSRC Blog post and the Security Advisory, referenced below.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, September 18, 2012

    Microsoft Security Advisory 2757760

    Security Advisory
    Microsoft released Security Advisory 2757760 to address an issue that affects all versions of Internet Explorer except IE10.

    Current exploits of this vulnerability occur with Internet Explorer using third-party software, most particularly Oracle’s Java, when visiting a website hosting malicious code.

    Update:  It was reported at the MSRC Blog that a Microsoft Fix it solution will be issued within the next few days.  In the interim, it was also stated that this vulnerability is currently not widespread.  See the update at Additional information about Internet Explorer and Security Advisory 2757760.

    Recommendations:

    Uninstall Java -- Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

    • Playing on-line games generally requires Java.
    • With OpenOffice, Java is needed for the items listed  here
    • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
    • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
    If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.

    Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations such as DEP to configured applications.

    The simple steps needed to add iexplore.exe to EMET and other actions are provided in the "Suggested Actions" section of the Security Advisory.  When checking EMET, I was pleased to see that I had already added iexplore.exe. 


    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, July 10, 2012

    Microsoft Security Advisory 2719662, Gadget Vulnerability

    Security Advisory
    Microsoft released KB Article 2719662 which relates to the Windows Sidebar and Gadgets on supported versions of Windows Vista and Windows 7.  Microsoft has discovered that some Windows Vista and Windows 7 gadgets do not adhere to secure coding practices and should be regarded as causing risk to the systems on which they’re run. 

    Insecure Gadgets or Gadgets installed from untrusted sources can harm your computer and can access your computer's files, show you objectionable content, or change their behavior at any time. 

    As described in the Security Advisory:
    "An attacker who successfully exploited a Gadget vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

    Microsoft Fix it

    As a work-around, particularly for IT Administrators, Microsoft has provided a Microsoft Fix it solution that blocks the attack vector for this vulnerability.

    The Fix it solution is available from Microsoft KB Article 2719662, with direct links to the download files to enable and disable the solution below.  I suggest that you save both files so that you can disable the solution prior to installing the update when it is released.

    Edit Note:  Report from http://www.dslreports.com/forum/r27320136-Microsoft-Security-Advisory-2719662 (H/T: Siljaline).
    "FYI: Microsoft has switched the Enable and Disable Fix-Its. 50906 enables the Fix It. 50907 disables the Fix It."



    EnableDisable
    Fix this problem
    Microsoft Fix it 50907
    Fix this problem
          Microsoft Fix it 50906

    References


    HatTip:  ky331


    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, June 12, 2012

    Microsoft Security Advisory 2719615 + Fix it Solution


    Microsoft released Security Advisory 2719615 which relates to a Remote Code Execution issue involving MSXML Core Services 3.0, 4.0, 5.0, and 6.0. The vulnerability affects all supported releases of Microsoft Windows, and all supported editions of Microsoft Office 2003 and Microsoft Office 2007.

    As described in the Security Advisory:
    "The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website."


    Microsoft Fix it

    As an interim work-around, Microsoft has provided a Microsoft Fix it solution that blocks the attack vector for this vulnerability.

    The Fix it solution is available from Microsoft KB Article 2719615, with direct links to the download files to enable and disable the solution below.  I suggest that you save both files so that you can disable the solution prior to installing the update when it is released.


    EnableDisable
    Fix this problem
    Microsoft Fix it 50897
    Fix this problem
          Microsoft Fix it 50898

    References


    HatTip:  ky331


    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...