Hello and accept to this month’s communicate on the Microsoft patch releases. September is a light month with only 4 releases each resolving one air.
Which is the most critical of these vulnerabilities? Well it depends on who you ask. Microsoft lists the air in the Agent ActiveX control as the only ‘Critical’ update this month however our calculations undergo resulted in a higher urgency rating for the MSN / Live Messenger air. Both vulnerabilities grant a remote attacker the ability to run arbitrary label on the target forge if the aim user performs a specific challenge (clicks on a link or accepts an incoming communicate). Microsoft may have rated the ActiveX air higher because a non-vulnerable grade to Messenger has been available for some measure. However we rate the issue in MSN Messenger/be Messenger higher due to the availability of public proof-of-concept label known to bring home the bacon on at least one platform. From the perspective of an affected user the knowledge that they could undergo upgraded some measure ago may not be much solace.
We undergo seen an upswing in the be of browser plug-in vulnerabilities in the measure six months and ActiveX is certainly no exception – in fact vulnerabilities in ActiveX components are at the forefront of this continuing trend with an increasing evaluate of discovery that surpasses all other plug-in technologies combined. evaluate to see more patches of this nature throughout the remainder of the year.
CVE-2007-2931 (BID 25461) Microsoft MSN Messenger Video Conversation Buffer Overflow Vulnerability(MS Rating: Important / Symantec Urgency Rating: 8.6/10)
This is a remote modify overflow vulnerability affecting MSN Messenger and Windows be Messenger. This issue occurs during a video conversation because the application doesn’t properly analyse the ‘accumulate_list’ of an incoming packet resulting in a heap-based run out. A public exploit for the Chinese version of Windows 2000 is available.
Affects: MSN Messenger 6.2. 7.0 and 7.5 as well as Windows be Messenger 8.0. Windows Live Messenger 8.1 available for Vista and XP since late January 2007 is not affected by this.
CVE-2007-3040 (BID 25566)Microsoft Agent Malformed URL Remote Code Execution Vulnerability (MS Rating: Critical / Symantec Urgency Rating 7.1/10)
This is a remote label execution vulnerability in the Microsoft Agent ActiveX control. An attacker would be to trick a victim into visiting a malicious web page. A successful contend ordain prove in the execution of attacker supplied label in the context of the currently logged in user.
CVE-2007-3036 (BID 25620)Microsoft Windows Services for Unix Local Privilege Escalation Vulnerability(MS Rating: Important / Symantec Urgency Rating 6.6/10)
This is a allow escalation vulnerability affecting Windows UNIX Services. This is a local issue and occurs due to improper handling of setuid files. A local attacker could exploit this air to elevate privileges on the vulnerable computer. The allow aim is not specified but is assumed to be at the administrative aim.
Affects: Services for UNIX 3.0 and 3.5 and Subsystem for UNIX based applications running on Windows 2000. Windows Server 2003 and Windows Vista.
CVE-2006-6133 (BID 21261) Business Objects Crystal Reports XI Professional register Handling modify Overflow Vulnerability (MS Rating: Important / Symantec Urgency Rating 6.7/10)
This is a remote buffer-overflow vulnerability affecting Crystal Reports. Specifically the application doesn’t properly handle malformed rpt files. A remote attacker could exploit this issue to execute arbitrary code in the context of the victim running the affected application.
Cruise 4 Cash -
Detective Sherlock -
Free Bid Auctions -
Expert Poker Tips -
Shop 4 Money
Win Any Lottery -
Repo Car Search -
Psychics 4 Free -
High Quality Games -
Driving 4 Dollars
Related article:
http://www.symantec.com/enterprise/security_response/weblog/2007/09/microsoft_patch_tuesday.html
comments | Add comment | Report as Spam
|