Security Advisory 979352 Released

SGT Oddball

New member
Pro User
Local time
6:22 AM
Messages
647
Location
Lost in France
Based upon our investigations, we have determined that Internet Explorer was one of the vectors used in targeted and sophisticated attacks against Google and possibly other corporate networks. Today, Microsoft issued guidance to help customers mitigate a Remote Code Execution (RCE) vulnerability in Internet Explorer. Additionally, we are cooperating with Google and other companies, as well as authorities and other industry partners.

Microsoft remains committed to taking the appropriate action to help protect our customers. We released Security Advisory 979352 to provide customers with actionable guidance and tools to help with protections against exploit of this vulnerability. Microsoft has not seen widespread customer impact, rather only targeted and limited attacks exploiting IE 6 at this time. Our teams are currently working to develop an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out of band.

It is important to note that complex attacks targeting specific corporate networks are becoming more prevalent in the threat landscape, therefore organizations should follow defense-in-depth best practices, and deploy multiple layers of protection to improve their security posture. In addition, Protected Mode in IE 7 on Windows Vista and later significantly reduces the ability of an attacker to impact data on a user’s machine. Customers should also enable Data Execution Prevention (DEP) which helps mitigate online attacks. DEP is enabled by default in IE 8 but must be manually enabled in prior versions.

Customers can also set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting in these zones or configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. You can find details on implementing these settings in the advisory.

Anyone believed to have been affected can visit: http://www.microsoft.com/protect/support/default.mspx and should contact the national law enforcement agency in their country. Those in the United States can contact Customer Service and Support at no charge using the PC Safety hotline at 1-866-727-2338 (PCSAFETY). Additionally, customers in the United States should contact their local FBI office or report their situation at: www.ic3.gov. Customers should follow the guidance in the advisory and our Protect Your PC guidance of enabling a firewall, getting software updates, and installing antivirus software (learn more by visiting the Protect Your PC web site). International customers can find their Regional Customer Service Representative http://support.microsoft.com/common/international.aspx.

We are also working with our Microsoft Active Protections Program (MAPP), the Microsoft Security Response Alliance (MSRA), authorities and other industry partners to help provide broader protections for customers. Together with our partners, we will continue to monitor the threat landscape and will take action against any web sites that seek to exploit this vulnerability.

The Security Advisory will be updated with any new developments so if you are not already subscribed to our comprehensive alerts, please do so in order to be alerted by email when new information is added.

-Mike Reavey

*This posting is provided "AS IS" with no warranties, and confers no rights.*

aggbug.aspx

More...
 

My Computer

OS
NT4
CPU
Cyrix 233
Motherboard
Jetway
Memory
8 Meg
Graphics Card(s)
Voodoo
Sound Card
SB16
Monitor(s) Displays
14" CRT
Screen Resolution
800x600
Hard Drives
40meg
Keyboard
Yes
Mouse
Yes
Internet Speed
56k
Thanks for the information.
 

My Computer

Computer Manufacturer/Model Number
Self Build 64bit
OS
Vista Ult64, Win7600
CPU
Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS
Motherboard
Asus P5E3 Deluxe WiFi @p 64 bit OS
Memory
4096 MB DDR3-SDRAM
Graphics Card(s)
ATI Radeon HD 3870 Series x2 Crossfired
Sound Card
Realtek on board
Monitor(s) Displays
Samsung SyncMaster - 23 inches
Screen Resolution
1680x1050 pixels at 60 Hz in True Colors
Hard Drives
Hitachi (250 GB)/Samsung 750 GB. /Barracuda 160 GB.
My Book 1 TB external..
PSU
Cooler Master 1000w
Case
Cooler Master Cosmos 1000.
Cooling
Fans and fresh air,
Keyboard
Wireless
Mouse
Wireless
Internet Speed
Never fast enough
Other Info
I use a Magnum.
Thanks Sarge.
 

My Computer

Computer Manufacturer/Model Number
Dell XPS420
OS
Vista Ult 64 bit Seven Ult RTM x64
CPU
Intel Core2 Quad Q6600 2.40 gigahertz
Memory
Crucial Ballistix 4x2GB PC2 6400
Graphics Card(s)
NVIDIA GeForce 8600 GTS 256 MB
Sound Card
Creative SB X-Fi audio
Monitor(s) Displays
HP w2207 + HPvs15
Screen Resolution
1680x1050 + 1024x768
Hard Drives
2-WD5000AAKS-500 GB
WD5000AAV-500 GB external
Keyboard
Microsoft Comfort Curve
Mouse
MX Revolution
Other Info
Wacom Intuos 2 Graphics Tablet
Experience Index=5.5
Back
Top