Tuesday, November 08, 2011

Adobe Releases Critical Update for Shockwave Player


An update to Adobe Shockwave Player has been released to address critical vulnerabilities in version 11.6.1.629 and earlier version on both Windows and Macintosh systems. If successfully exploited, malicious code could be executed on the system.



Release date: November 8, 2011
Vulnerability identifier: APSB11-27
CVE number: CVE-2011-2446, CVE-2011-2447, CVE-2011-2448, CVE-2011-2449
Platform: Windows and Macintosh

Update Information


The newest version of Shockwave Player 11.6.3.633 is available here: http://get.adobe.com/shockwave/.

Please remember to uncheck any unwanted 3rd party toolbars/programs during installation. Also please do not confuse this with Adobe Flash Player which is a different program.

For how to disable the auto-update setting in Shockwave Player, see http://kb2.adobe.com/cps/166/tn_16683.html (This must be set every time Shockwave Player is updated if you do not want auto-updating.)



Reference

Adobe - Security Bulletins: APSB11-27 - Security update available for Adobe Shockwave Player


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Friday, November 04, 2011

Microsoft Fix it for Duqu Malware, Security Advisory 2639658


Microsoft released Security Advisory 2639658 which relates to a Windows kernel issue related to the Duqu malware, a trojan that injects malicious code into other processes.

As illustrated in the image below of the Duqu infection schematics, provided by Symantec in Duqu: Status Updates Including Installer with Zero-Day Exploit Found,  once infected, the trojan can then install programs; view, change, or delete data; or create new accounts with full user rights.



Microsoft is aware of targeted attacks that try to use the reported vulnerability and reports that at this time they see "low customer impact". Work continues to provide a security update for the vulnerability, either via an out-of-band update or during the regular monthly release process.  An update is not expected to be ready for delivery with the scheduled November update.


Microsoft Fix it

As an interim work-around, Microsoft has provided a Microsoft Fix it solution to simplify the work-around for workaround to deny access to t2embed.dll. 

The Fix it solution is available from Microsoft KB Article 2639658, with direct links to the download files to enable and disable the solution below.

EnableDisable
Fix this problem
Microsoft Fix it 50792
Fix this problem
      Microsoft Fix it 50793

References





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, November 03, 2011

Security Bulletin Advance Notification for November, 2011


On Tuesday, November 8, 2011, Microsoft is planning to release four (4) Security Bulletins, addressing four (4) CVEs in Windows. One bulletin is identified as Critical, two as Important and one Moderate.

The bulletins address Remote Code Execution, Elevation of Privilege and Denial of Service, several requiring a restart. Whether required or not, it is advised to restart your computer after installing updates. 

References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...