Security Bulletin MS10-018 Released

SGT Oddball

Active member
Pro User
Local time
6:59 AM
Messages
647
Location
Lost in France
Hi everyone,

Today we released MS10-018 out-of-band due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in Security Advisory 981374. I want to reiterate that Internet Explorer 8 is not affected by this issue so customers using this version are not affected by these attacks and we continue to encourage customers to upgrade to the newer version because it provides more security and protection.

MS10-018 is a typical cumulative update for Internet Explorer and was originally going to be released during the normal update cycle on the 13th of April. The Internet Explorer team accelerated testing of this update due to the growing attacks against the publicly disclosed vulnerability (CVE-2010-0806), and the update has reached the appropriate quality bar for distribution to customers. Releasing the update early provides Internet Explorer 6 and 7 customers protection against the active attacks and provides users of all versions of Internet Explorer protection against nine other vulnerabilities. I clarify this in the following video:



Here is a simplified view of the ten vulnerabilities and their aggregate severity on Internet Explorer 6, 7, and 8:

* Vulnerability under active attack.

This table demonstrates what we have been saying about the improved security and protection offered in Internet Explorer 8 and why we continue to encourage customers to upgrade.

Since we announced yesterday that we would be releasing this bulletin out-of-band, we have been asked if it addresses the vulnerability that was used in the “pwn2own” contest at the CanSecWest security conference last week. We are still investigating that issue at this time so we do not have an update available. In accordance with the contest rules, the vulnerabilities used are responsibly disclosed so that the respective vendors can produce updates to protect their customers before the vulnerabilities can be used by criminals. Microsoft continues to encourage responsible disclosure and we are a sponsor of the CanSecWest conference because we believe in working closely with security researchers to protect customers and the entire computing ecosystem.

If you can, please join Adrian Stone and I today for a live webcast where we will cover the details of this bulletin and take customer questions live. Here is the registration information:

Date: Tuesday March 30, 2010
Time: 1:00 p.m. PST (UTC -8)
Registration: https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112

Jerry Bryant
Group Manager – Response Communications

*This posting is provided "AS IS" with no warranties, and confers no rights*

aggbug.aspx

More...
 

My Computer

OS
NT4
CPU
Cyrix 233
Motherboard
Jetway
Memory
8 Meg
Graphics Card(s)
Voodoo
Sound Card
SB16
Monitor(s) Displays
14" CRT
Screen Resolution
800x600
Hard Drives
40meg
Keyboard
Yes
Mouse
Yes
Internet Speed
56k
Hmmm...maybe I missed something from this statement....

I want to reiterate that Internet Explorer 8 is not affected by this issue so customers using this version are not affected by these attacks

because I just got notified by Windows Update that there is a 14.6MB!!! IE 8 Cumulative Security Update for Internet Explorer 8 (KB980182)

IE Update0182.JPG

Clicking the "More Information" links to this page - Microsoft Security Bulletin MS10-018 - Critical: Cumulative Security Update for Internet Explorer (980182)

Not an issue though.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built by me.
OS
Windows 10 Pro
CPU
Intel Core i7-4770K (3.5Ghz)
Motherboard
Gigabyte G1 Sniper 5 (F10 Bios)
Memory
32 gig Corsair Dominator Platinum (4x8Gig)
Graphics Card(s)
Sapphire Tri-X R9 Fury
Sound Card
Soundblaster ZXR
Monitor(s) Displays
NEC PA242W 24" LCD Monitor
Screen Resolution
1920 x 1200
Hard Drives
Primary - Samsung 850 Pro (512gig), Samsung 840 Pro (256gig), 2TB WD Caviar Black.
PSU
EVGA Supernova 1000 G2
Case
Cooler Master HAF X
Cooling
Corsair H100i with Corsair Air Series SP120 Quiet Fans
Keyboard
Logitech Wireless Wave
Mouse
Logitech Performance MX
Internet Speed
High Speed Cable
Antivirus
Norton Security
Browser
IE11
Other Info
Memory Timings - 1866MHz @ 9-9-9-27-1T @ 1.5 volts
I smell a rat!! And its coming from M$
 

My Computer

Computer Manufacturer/Model Number
The HAFmeister (Custom)
OS
Windows 7 Ultimate x64 RTM + SP1
CPU
Intel Core i7 950 3.06GHZ (OC'd to 3.99Ghz)
Motherboard
Asus Rampage III Extreme x58 SATA 6GB & USB 3.0
Memory
6GB OCZ Reaper HPC Edition PC3-16000 (set 1606Mhz 8-8-8-26)
Graphics Card(s)
EVGA Nvidia Geforce GTX 570
Sound Card
Creative SB X-Fi Titanium Fatal1ty Professional Series
Monitor(s) Displays
Samsung SM2433BW 24" Widescreen Monitor
Screen Resolution
1920x1200
Hard Drives
Western Digital Caviar Black 500GB 32Mb Buffer SATA II
Western Digital Caviar Black 750GB 32Mb Buffer SATA II
Western Digital Caviar Blue 500GB 16Mb Buffer SATA II
Western Digital My Book Essential Edition 750GB USB
Samsung Spinpoint 2TB SATA II
PSU
Thermaltake Toughpower 1200w (Modular)
Case
CoolerMaster HAF-932
Cooling
Zalman Reserator XT and ZM-WB5 Plus - GPU uses Stock coolers
Keyboard
Logitech G510
Mouse
Logitech G9 Gaming Mouse
Internet Speed
3MB Profile - 350-400kbs (Real-Speed)
Other Info
IcyBox Hot-Swap Bay,
Logitech G27 Steering Wheel,
Xbox 360 Wirless Elite Controller with Microsoft Reciever and
Play & Charge Kit,
Belkin USB Wireless Adaptor,
GAME Generic Controller (Playstation Looky-Likey),
Epson SX125 All-in-One.
Back
Top