Wednesday, April 13, 2011

Microsoft Issues Huge Patch for Update Windows, IE


Microsoft today released a batch of 17 security updates for Patch Tuesday to cover 64 vulnerabilities in Microsoft Windows, Office, Internet Explorer, Visual Studio,. NET Framework and GDI +.
New bugs are rated critical, while eight are important. An "important" bulletins includes 30 vulnerabilities in a bug, MS11-034, and they all share the same couple of cases, Microsoft said.
Microsoft identified three vulnerabilities that its priority bulletins for the month: MS11-020, which fixes a problem with Windows that could allow remote code execution if an attacker creates a specially crafted SMB packet and send the package on a affected system, MS11-019, another bug in Windows that could allow remote code execution if an attacker sent a specially crafted SMB response to a request from the client on the initiative of the SMB, and MS11-018, which could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer.
Also today, Microsoft introduced a Rootkit Evasion Prevention Tool and the Office File Validation, while announced in December 2010 but is now available for Office 2003 and 2007.
Office File Validation ", which is included in Word, Excel, PowerPoint and Publisher ... validate the file structure as it is opened by the user, "said Modesto Estrada, director of the Office program. "The validation will check the file to ensure it complies with specifications should Office. If this process fails, the user will be informed of potential problems."
The tool rookie, meanwhile, "will expose a rootkit installed and give your anti-malware's ability to detect and remove the rootkit," said Dustin Childs, senior security program, FRSC. "For a rootkit to succeed, it must remain persistent and hidden on a system. One way we saw hiding rootkits on 64-bit, without going through the driver signing checks made by winload.exe."

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home