Site Archives Microsoft

March Microsoft Patch Tuesday

Posted on March 9th, 2010

Microsoft has announced two new patches today to fix vulnerabilities that could allow remote code execution.  Both patches are rated Important by Microsoft and affect Microsoft Windows and Microsoft Office.  Gladiator recommends that users immediately apply the Microsoft Office Excel patch. Detailed information for the patches can be found in Microsoft’s March Security Bulletin

New Internet Explorer Remote Code Execution Vulnerability

Posted on March 2nd, 2010

GSA Reference Number: AD100302-01

Simply Put: A new Internet Explorer remote code execution exploit has been released.  This vulnerability affects Internet Explorer 6, 7, and 8 running on Windows 2000, Windows XP, and Windows Server 2003.  This vulnerability uses VBScript and Windows Help files to force a victim machine to run remote code.  In order to trigger this vulnerability, a user would have to hit the F1 key while visiting a malicious website.

February Microsoft Patch Announcement

Posted on February 10th, 2010

Microsoft has announced 13 new patches for its February release. One vulnerability causing an elevation of privileges, fixed by MS10-015 and rated Important by Microsoft, already has exploit code available.  Five patches are rated Critical, seven are rated Important, and one is rated ModerateGladiator recommends that users immediately apply all critical updates. Detailed information for these patches can be found in Microsoft’s February Security Bulletin

Internet Explorer Information Disclosure Vulnerability

Posted on February 4th, 2010

GSA Reference Number: AD100203-01

Simply Put: A new Internet Explorer (IE) information disclosure vulnerability has been announced by Microsoft.  This vulnerability could allow an attacker to access files in known locations on the victim’s system. For now, no widespread worms or exploit packs are currently using this vulnerability, and Microsoft has stated that they do not know of any attacks currently taking advantage of this vulnerability.  This vulnerability does not affect Internet Explorer running in Protected Mode, which is the default setting on Windows Vista, Windows Server 2008, or Windows 7.  This mode is not available in Windows XP.  A patch has not yet been released by Microsoft.

Internet Explorer Out-of-Band Patch Released

Posted on January 21st, 2010

GSA Reference Number: AD100121-01

Previous GSA Reference Number: AD100119-01

Simply Put: Microsoft has released an out-of-band patch for the Internet Explorer remote code execution exploit referenced above as well as for other security vulnerabilities.  There is evidence that this exploit is being used in limited, targeted attacks on the Internet.  For now, no widespread worms or exploit packs are currently using this vulnerability.  The Microsoft bulletin can be found here, and the update can be downloaded through Windows Update.

Internet Explorer Remote Code Execution Exploit Released

Posted on January 19th, 2010

GSA Reference Number: AD100119-01

Simply Put: A new Internet Explorer remote code execution exploit has been released.  There is evidence that this exploit is being used in limited, targeted attacks on the Internet.  For now, no widespread worms or exploit packs are currently using this vulnerability.  Microsoft has not released a patch, but is currently researching the issue and hopefully will release one soon.  Reports have been published linking this exploit to the Google hacking incident.  According to this Microsoft article, an out-of-band patch will be released for this vulnerability.

January Microsoft Patch Tueday

Posted on January 12th, 2010

Microsoft has announced one new patch today regarding a flaw that could allow remote code execution.  The patch is rated Critical for Windows 2000 servers and Low for devices using other Windows Operating Systems.  Gladiator recommends that users immediately apply this update. Detailed information for the patch can be found in Microsoft’s January Security Bulletin.  Summary information is included below: