The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin Summary for January 2012
Time: 07:34 EST/12:34 GMT | News Source: ActiveWin.com | Posted By: Robert Stein
  • Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.
  • Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. All supported editions of Windows 7 and Windows Server 2008 R2 are not affected by this vulnerability. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.
  • Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.
  • Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.
Write Comment
Return to News

  Displaying 576 through 581 of 581
Prev | First
  The time now is 10:54:42 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/27/2025 6:59:57 PM
https://moanio.com/video.php?id=3414
https://moanio.com/video.php?id=2448
https://moanio.com/video.php?id=5658
https://moanio.com/video.php?id=165
https://moanio.com/video.php?id=2665
https://moanio.com/video.php?id=570
https://moanio.com/video.php?id=5579
https://moanio.com/video.php?id=1288
https://moanio.com/video.php?id=1402
https://moanio.com/video.php?id=4226

#577 By 4240821 (82.115.4.230) at 7/29/2025 7:13:20 AM
https://justpaste.me/eYIS4
https://justpaste.me/ZpUn
https://justpaste.me/Z5dd2
https://justpaste.me/bqOv2
https://justpaste.me/cdI71
https://justpaste.me/diwh2
https://justpaste.me/dMDD3
https://justpaste.me/edia3
https://justpaste.me/bZbg5
https://justpaste.me/Yilu1

#578 By 4240821 (82.115.4.230) at 7/30/2025 8:35:11 AM
https://justpaste.me/aYCF3
https://justpaste.me/de2R
https://justpaste.me/cdTp2
https://justpaste.me/d3j2
https://justpaste.me/aegI2
https://justpaste.me/eGjM
https://justpaste.me/cHmo5
https://justpaste.me/cx1N
https://justpaste.me/ZqUb5
https://justpaste.me/ZO4J

#579 By 4240821 (82.115.4.230) at 7/31/2025 6:09:56 PM
https://justpaste.me/cKZC3
https://justpaste.me/azLB
https://justpaste.me/dAQc2
https://justpaste.me/c69p1
https://justpaste.me/boh6
https://justpaste.me/bNsc
https://justpaste.me/cQL91
https://justpaste.me/fmpb
https://justpaste.me/fwQ32
https://justpaste.me/fRsQ4

#580 By 4240821 (82.115.4.230) at 8/1/2025 11:23:19 AM
https://justpaste.me/ezQ41
https://justpaste.me/f2s5
https://justpaste.me/esjt1
https://justpaste.me/aCEt2
https://justpaste.me/eqmU4
https://justpaste.me/ZV45
https://justpaste.me/aTcj1
https://justpaste.me/aYyE2
https://justpaste.me/dA43
https://justpaste.me/Z0GD

#581 By 4240821 (82.115.4.230) at 8/1/2025 9:34:09 PM
https://justpaste.me/Z8y82
https://justpaste.me/bY432
https://justpaste.me/em0H1
https://justpaste.me/fBll3
https://justpaste.me/c69p1
https://justpaste.me/fiPx1
https://justpaste.me/e42R
https://justpaste.me/fRsQ4
https://justpaste.me/adWT1
https://justpaste.me/eJGU3

Write Comment
Return to News
  Displaying 576 through 581 of 581
Prev | First
  The time now is 10:54:42 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *