Windows 7 Forums


Reply
Thread Tools

IT News Happening Now

 
 
Jeffreyobrien Jeffreyobrien is offline
Established Member
Jeffreyobrien's Avatar
Join Date: Feb 2010
Location: Sydney
Posts: 165
Thanked: 58
Send a message via Skype™ to Jeffreyobrien Jeffreyobrien's Twitter Pag
 
      04-24-2010
IT News Happening NowMicrosoft admits patch didn't fix vulnerability
Microsoft has yanked the security updates shipped in the MS10-025 bulletin after realizing the patch did not fix the underlying security vulnerability. by Ryan Naraine
READ FULL STORY
Microsoft has yanked the security updates shipped in the MS10-025 bulletin after realizing the patch did not fix the underlying security vulnerability.
The withdrawal of the bulletin means that affected Windows 2000 Server users should immediately consider applying mitigations and workarounds to avoid malicious hacker attacks.

The company did not explain why the bulletin was shipped with an inadequate patch. A brief blog post from Microsoft’s Jerry Bryant offered the following:
Today we pulled the update because we found it does not address the underlying issue effectively. We are not aware of any active attacks seeking to exploit this issue and are targeting a re-release of the update for next week.
The issue only affects Windows 2000 Server customers who have installed Windows Media Services (a non-default configuration).
Bryant urged affected users with internet facing systems with Windows Media Services installed to evaluate and use firewall best practices to limit their overall exposure.
The MS10-025 bulletin is rated “critical” because attackers could launchi remote code execution if an attacker sent a specially crafted transport information packet to a Microsoft Windows 2000 Server system running Windows Media Services.
Ryan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.

Email Ryan Naraine
For daily updates on Ryan's activities, follow him on Twitter.
Subscribe to Zero Day via Email alerts or RSS.

I hope everyone reads this and watch for the latest update for MS10-025 Microsoft have done this to further assist in protecting genuine microsoft user due to costs involved in security related issues.

Here’s the skinny from Microsoft’s advisory:
The vulnerability exists as an invalid pointer reference within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.
The flaw affects Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet Explorer 7 and Internet Explorer 8 on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are affected.
Here’s the danger:
To exploit, an attacker could host a specially crafted Web site, or take advantage of a compromised website, and then convince a user to view the Web site. In all cases, however, an attacker would have no way to force users to visit these malicious Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or in an Instant Messenger message, that directs users to the attacker’s Web site. It could also be possible to display specially crafted Web content using banner advertisements or other methods to deliver Web content to affected systems. The Microsoft investigation concluded that setting the Internet zone security setting to “high” will protect users from the vulnerability addressed in this advisory.
Microsoft is considering an out-of-band emergency IE patch to fix this vulnerability.

regards
jeffreyobrien

Last edited by Jeffreyobrien; 04-24-2010 at 06:33 AM.. Reason: Latest ZDNET update of the above security issue
 
Reply With Quote
 
 
 
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,507
Thanked: 511
 
      04-24-2010
Here we go again with this Remote Code Execution deal. A little over a month ago, Firefox users (prior to 3.6.2) were at risk. Now, it's IE across the board. When will this ever stop? The first incident of this (that I'm aware of) was in 2006. Look it up in Wikipedia, this is one of the most severe threats that there is on the internet. You're "lured" into clicking onto a site, and when you do, the damage can begin right then. It can actually take over your computer, making it into a zombie. Whatever you do, don't click onto anything that "pops up", or anything that you don't solicit. I'm glad that with FF, you have an ad blocker, and No Script to help you, to a degree. LOL, why must we go through this again?
 
Reply With Quote
 
Jeffreyobrien Jeffreyobrien is offline
Established Member
Jeffreyobrien's Avatar
Join Date: Feb 2010
Location: Sydney
Posts: 165
Thanked: 58
Send a message via Skype™ to Jeffreyobrien Jeffreyobrien's Twitter Pag
 
      04-24-2010
catilley,
spot on mate it was was in 2006 with IE 6 Zero day and its back right across the board,again how true how much more of this do we have to put up with as you said catilley this is the most severe threats out there on the internet. You're "lured" into clicking onto a site, and when you do, the damage can begin right then. It can actually take over your computer, making it into a zombie. Whatever you do, don't click onto anything that "pops up", or anything that you don't solicit by yourself.

Dont click on any email links you are not sure of they are sneaky enough as we all have seen this happen and I personally don't want to be going through it again I am keen to know if the new IE9 preview has the same problem.Catilley have you seen or read of anything in regards to IE 9.

Thanks for your input catilley its always right to the point.Microsoft have said that another patch is on its way I hope they are quick with releasing it asap.

regards
jeffreyobrien
 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,507
Thanked: 511
 
      04-24-2010
Actually, I've been so busy that I haven't given IE9 another thought. I recently upgraded my hard drive, the shortcut to IE9 is no longer there. I do need to redownload it. But with this IE scare, I won' use it.
 
Reply With Quote
 
Thrax Thrax is offline
Super Moderator
Thrax's Avatar
Join Date: Apr 2009
Location: Detroit Metro
Posts: 926
Thanked: 262
Send a message via ICQ to Thrax Send a message via AIM to Thrax Thrax's Twitter Pag
 
      04-24-2010
If you have NoScript installed, you're basically immune to remote code execution unless you download an infected file yourself, voluntarily.
 
Reply With Quote
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,851
Thanked: 1073
 
      04-24-2010
Do as Thrax recommends and there should be no problems.

I just still prefer Firefox! Used it for the past 5 years and love it.
 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,507
Thanked: 511
 
      04-24-2010
FF is the best! I do and have been using No Script and Adblock Plus for a while. But for the last couple of days, I've been using Pale Moon, an exact twin of FF. It even automatically installed my bookmarks and my browser add ons. It does appear to be slightly faster, but I haven't figured out the point in Mozilla having twins of the same browser on board. And I very seldom allow anything past No Script, but when making purchases, you're often required to temporary allow the site through to complete your transaction. Thanks for the info, Thrax!
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
bsod happening often lionel hunter Crashes, BSODs and Debugging 6 06-27-2010 02:16 AM
I've downloaded a folding client, nothing seems to be happening catilley1092 Off-Topic Discussion 13 05-09-2010 08:38 AM
Good News For A Change roban Installation, Setup and Updates 8 04-13-2010 10:16 PM
News Forum Ian Announcements, Suggestions and Feedback 6 10-14-2009 10:19 AM
No news ! Hope it dont last :( whoosh News 2 04-18-2009 02:58 PM


All times are GMT +1. The time now is 09:17 PM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33