Internet Explorer Remote Code Execution Exploit Released
GSA Reference Number: AD100119-01
Simply Put: A new Internet Explorer remote code execution exploit has been released. There is evidence that this exploit is being used in limited, targeted attacks on the Internet. For now, no widespread worms or exploit packs are currently using this vulnerability. Microsoft has not released a patch, but is currently researching the issue and hopefully will release one soon. Reports have been published linking this exploit to the Google hacking incident. According to this Microsoft article, an out-of-band patch will be released for this vulnerability.
Adobe Releases Patch for Critical Vulnerability
GSA Reference Number: AD100114-01
Previous GSA Reference Number: AD091215-01
Simply Put: Adobe has released a patch for the previously announced critical remote code execution vulnerability in the Adobe Reader and Acrobat products. Adobe Reader and Acrobat 9.2 and earlier versions are confirmed as vulnerable. This vulnerability has become a target of malware authors, and should be patched as quickly as possible.
January Microsoft Patch Tueday
Microsoft has announced one new patch today regarding a flaw that could allow remote code execution. The patch is rated Critical for Windows 2000 servers and Low for devices using other Windows Operating Systems. Gladiator recommends that users immediately apply this update. Detailed information for the patch can be found in Microsoft’s January Security Bulletin. Summary information is included below:
Previous Articles
Gladiator Research and Security
This site is here to provide security related information and articles to better protect your financial institutions. We'll be posting advisories, blog entries and trends often so be sure to check back weekly.