<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://myitforum.com/cs2/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results matching tags 'Internet Explorer' and 'Enterprise Applications'</title><link>http://myitforum.com/cs2/search/SearchResults.aspx?q=&amp;tag=Internet+Explorer%2CEnterprise+Applications&amp;orTags=0&amp;o=DateDescending</link><description>Search results matching tags 'Internet Explorer' and 'Enterprise Applications'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007.1 SP2 (Build: 31113.47)</generator><item><title>Microsoft Security Bulletin Advance Notification for January 2010 - Issued: January 20, 2010</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/microsoft-security-bulletin-advance-notification-for-january-2010-issued-january-20-2010.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144449</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Microsoft Security Bulletin Advance Notification for January 2010&lt;/p&gt;  &lt;p&gt;Issued: January 20, 2010&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010.&lt;/p&gt;  &lt;p&gt;The full version of the Microsoft Security Bulletin Advance Notification for January 2010 can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;This bulletin advance notification will be replaced with the January bulletin summary on January 21, 2010. The revised bulletin summary will include the out-of-band security bulletin, as well as the security bulletins already released on January 12, 2010.&lt;/p&gt;  &lt;p&gt;For more information about the bulletin advance notification service, see &lt;a href="http://www.microsoft.com/technet/security/Bulletin/advance.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/advance.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on &lt;a href="http://www.microsoft.com/technet/security/bulletin/notify.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/notify.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Microsoft will host a webcast to address customer questions on the out-of-band bulletin on January 21, 2010, at 1:00 PM Pacific Time (US &amp;amp; Canada). Register for the Security Bulletin Webcast at &lt;a href="http://www.microsoft.com/technet/security/bulletin/summary.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/summary.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.&lt;/p&gt;  &lt;p&gt;This advance notification provides a number as the bulletin identifier, because the official Microsoft Security Bulletin numbers are not issued until release. The bulletin summary that replaces this advance notification will have the proper Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the bulletin identifier. The security bulletins for this month are as follows, in order of severity:&lt;/p&gt;  &lt;p&gt;Critical Security Bulletins&lt;/p&gt;  &lt;p&gt;===========================&lt;/p&gt;  &lt;p&gt;IE Bulletin&lt;/p&gt;  &lt;p&gt;- Affected Software:&lt;/p&gt;  &lt;p&gt;- Internet Explorer 5.01 Service Pack 4 when installed on &lt;/p&gt;  &lt;p&gt;Microsoft Windows 2000 Service Pack 4&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 Service Pack 1 when installed on &lt;/p&gt;  &lt;p&gt;Microsoft Windows 2000 Service Pack 4&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 with SP2 for Itanium-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 with SP2 for Itanium-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Vista, &lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition,&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Vista,&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition,&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows 7 for 32-bit Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows 7 for x64-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 R2 for x64-based Systems &lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 R2 for Itanium-based Systems &lt;/p&gt;  &lt;p&gt;- Impact: Remote Code Execution&lt;/p&gt;  &lt;p&gt;- Version Number: 1.0&lt;/p&gt;</description></item><item><title>Microsoft Announces Out-of-Band Security Bulletin for the IE Vulnerability – SANS Internet Storm Center</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/microsoft-announces-out-of-band-security-bulletin-for-the-ie-vulnerability-sans-internet-storm-center.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144452</guid><dc:creator>cmosby</dc:creator><description>&lt;div class="headline"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8041"&gt;Microsoft Announces Out-of-Band Security Bulletin for the IE Vulnerability&lt;/a&gt; &lt;/div&gt;  &lt;div class="digg"&gt;   &lt;div class="addthis_toolbox addthis_default_style"&gt;&lt;a class="addthis_button_compact at300m" href="http://www.addthis.com/bookmark.php?v=250&amp;amp;username=jullrich"&gt;&lt;span class="at300bs at15t_compact"&gt;&lt;/span&gt;Share&lt;/a&gt; &lt;span class="addthis_separator"&gt;|&lt;/span&gt; &lt;a class="addthis_button_facebook at300b" title="Send to Facebook" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=facebook&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_facebook"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_myspace at300b" title="Send to MySpace" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=myspace&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_myspace"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_google at300b" title="Send to Google" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=google&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_google"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_twitter at300b" title="Tweet This" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=twitter&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_twitter"&gt;&lt;/span&gt;&lt;/a&gt;      &lt;div class="atclear"&gt;&lt;/div&gt;   &lt;/div&gt;   &lt;/div&gt;  &lt;div class="diaryheader"&gt;Published: 2010-01-20,   &lt;br /&gt;Last Updated: 2010-01-20 22:03:06 UTC    &lt;br /&gt;by Lenny Zeltser (Version: 2) &lt;/div&gt; &lt;a href="http://isc.sans.org/diary.html?storyid=8041#comment"&gt;0 comment(s)&lt;/a&gt;   &lt;div class="diarybody"&gt;   &lt;p&gt;Microsoft posted &amp;quot;an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.&amp;quot;&lt;/p&gt;    &lt;p&gt;For details, see:&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;Microsoft also posted a comprehensive overview of the exploits that target this vulnerability. See:&lt;/p&gt;    &lt;p&gt;&lt;a href="http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx"&gt;http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx&lt;/a&gt;&lt;/p&gt;    &lt;p&gt; -- Lenny&lt;/p&gt;    &lt;p&gt;Lenny Zeltser - Security Consulting&lt;/p&gt; &lt;/div&gt;</description></item><item><title>Reports of DEP being bypassed – Microsoft Security Research &amp;amp; Defense</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/reports-of-dep-being-bypassed-microsoft-security-research-amp-defense.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144454</guid><dc:creator>cmosby</dc:creator><description>&lt;h2&gt;Reports of DEP being bypassed&lt;/h2&gt;  &lt;p&gt;Yesterday we heard reports of a commercially available exploit that bypasses DEP. This exploit was made available to a limited number of major security vendors (Antivirus, IDS, and IPS vendors) and government CERT agencies. We wanted to use this opportunity to give an overview of current customer risk related to this DEP bypass.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Real-world attacks so far still only effective against Internet Explorer 6&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We have seen an increase in attacks attempting to exploit the vulnerability detailed in &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;Security Advisory 979352&lt;/a&gt;. However, all attacks we have seen so far still target Internet Explorer 6 - this is also confirmed by the attack samples our Microsoft Active Protections Program (MAPP) &lt;a href="http://www.microsoft.com/security/msrc/collaboration/mapppartners.aspx"&gt;partners&lt;/a&gt; have sent in.&lt;/p&gt;  &lt;p&gt;While we have not seen real-world attacks for any other platform, we have seen researchers poking at other platforms and have seen the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Private proof-of-concept code exploiting IE7 on Windows XP for arbitrary code execution&lt;/li&gt;    &lt;li&gt;Private proof-of-concept code exploiting IE7 on Windows Vista without DEP enabled for code execution within the Protected Mode sandbox. We are not aware of any proof-of-concept code exploiting Windows Vista with DEP enabled.&lt;/li&gt;    &lt;li&gt;Commercial, limited distribution proof-of-concept code exploiting IE8 on Windows XP with DEP enabled for arbitrary code execution. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;State-of-the-art of attacker research on various platforms&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Here’s the current state-of-the-art on each platform:&lt;/p&gt;  &lt;table&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;&amp;#160;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows XP&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows Vista&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows 7&lt;/b&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 6&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;Public exploit code consistently reliable for arbitrary code execution&lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 7&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;Private proof-of-concept is likely consistently reliable for arbitrary code execution&lt;/td&gt;        &lt;td&gt;Private proof-of-concept is likely consistently reliable for limited code execution within the Protected Mode sandbox. &lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 8&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;In our testing, the commercially-available, limited distribution exploit results in code execution about one in three attempts. For two in three attempts, it results in an Internet Explorer crash.&lt;/td&gt;        &lt;td&gt;No known proof-of-concept code. Current exploits modified for use on Windows Vista would likely be effective for limited code execution within the Protected Mode sandbox on less than 1% (1/256 + 1/255 + 1/254) of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows Vista.&lt;/td&gt;        &lt;td&gt;No known proof-of-concept code. Current exploits modified for use on Windows 7 would likely be effectively for limited code execution within the Protected Mode sandbox on less than 1% (1/256 + 1/255 + 1/254) of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows 7.&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;b&gt;Other mitigations (besides DEP)&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We have discussed DEP at length in this blog. As you can see in the table above, two other mitigations help prevent or limit the impact of attacks on later platforms. &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Internet Explorer Protected Mode&lt;/b&gt; limits the impact of Windows Vista and Windows 7 exploits. Attackers who are able to successfully exploit Internet Explorer on those platforms are stuck in a “sandbox”, potentially able to read data but unable to install programs or change system configuration.&lt;/li&gt;    &lt;li&gt;&lt;b&gt;Address Space Layout Randomization (ASLR)&lt;/b&gt; makes exploiting vulnerabilities more difficult by relocating normally-predictable code locations pseudo-randomly in memory. ASLR re-bases DLL’s to random locations in memory, making ret2libc type attacks unreliable. Due to ASLR we believe exploits for Internet Explorer 8 on Windows Vista or Windows 7 could result in limited code execution for less than 1% of attempts.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;Out-of-band update coming tomorrow&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We’ll be releasing a comprehensive, well-tested security update tomorrow morning PST to address this vulnerability. In the meantime, we hope this information helps you assess risk and protect your environment. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Acknowledgements&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Thanks Matt Miller and John Lambert for help with the ASLR arithmetic and other feedback.&amp;#160; &lt;/p&gt;  &lt;p&gt;- Jonathan Ness, MSRC Engineering&lt;/p&gt;  &lt;p&gt;*Posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights.*&lt;/p&gt;</description></item><item><title>Reports of DEP being bypassed – Microsoft Security Research &amp;amp; Defense</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/reports-of-dep-being-bypassed-microsoft-security-research-amp-defense.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144454</guid><dc:creator>cmosby</dc:creator><description>&lt;h2&gt;Reports of DEP being bypassed&lt;/h2&gt;  &lt;p&gt;Yesterday we heard reports of a commercially available exploit that bypasses DEP. This exploit was made available to a limited number of major security vendors (Antivirus, IDS, and IPS vendors) and government CERT agencies. We wanted to use this opportunity to give an overview of current customer risk related to this DEP bypass.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Real-world attacks so far still only effective against Internet Explorer 6&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We have seen an increase in attacks attempting to exploit the vulnerability detailed in &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;Security Advisory 979352&lt;/a&gt;. However, all attacks we have seen so far still target Internet Explorer 6 - this is also confirmed by the attack samples our Microsoft Active Protections Program (MAPP) &lt;a href="http://www.microsoft.com/security/msrc/collaboration/mapppartners.aspx"&gt;partners&lt;/a&gt; have sent in.&lt;/p&gt;  &lt;p&gt;While we have not seen real-world attacks for any other platform, we have seen researchers poking at other platforms and have seen the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Private proof-of-concept code exploiting IE7 on Windows XP for arbitrary code execution&lt;/li&gt;    &lt;li&gt;Private proof-of-concept code exploiting IE7 on Windows Vista without DEP enabled for code execution within the Protected Mode sandbox. We are not aware of any proof-of-concept code exploiting Windows Vista with DEP enabled.&lt;/li&gt;    &lt;li&gt;Commercial, limited distribution proof-of-concept code exploiting IE8 on Windows XP with DEP enabled for arbitrary code execution. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;State-of-the-art of attacker research on various platforms&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Here’s the current state-of-the-art on each platform:&lt;/p&gt;  &lt;table&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td&gt;&amp;#160;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows XP&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows Vista&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;&lt;b&gt;Windows 7&lt;/b&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 6&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;Public exploit code consistently reliable for arbitrary code execution&lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 7&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;Private proof-of-concept is likely consistently reliable for arbitrary code execution&lt;/td&gt;        &lt;td&gt;Private proof-of-concept is likely consistently reliable for limited code execution within the Protected Mode sandbox. &lt;/td&gt;        &lt;td&gt;N/A&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td&gt;&lt;b&gt;IE 8&lt;/b&gt;&lt;/td&gt;        &lt;td&gt;In our testing, the commercially-available, limited distribution exploit results in code execution about one in three attempts. For two in three attempts, it results in an Internet Explorer crash.&lt;/td&gt;        &lt;td&gt;No known proof-of-concept code. Current exploits modified for use on Windows Vista would likely be effective for limited code execution within the Protected Mode sandbox on less than 1% (1/256 + 1/255 + 1/254) of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows Vista.&lt;/td&gt;        &lt;td&gt;No known proof-of-concept code. Current exploits modified for use on Windows 7 would likely be effectively for limited code execution within the Protected Mode sandbox on less than 1% (1/256 + 1/255 + 1/254) of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows 7.&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;b&gt;Other mitigations (besides DEP)&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We have discussed DEP at length in this blog. As you can see in the table above, two other mitigations help prevent or limit the impact of attacks on later platforms. &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Internet Explorer Protected Mode&lt;/b&gt; limits the impact of Windows Vista and Windows 7 exploits. Attackers who are able to successfully exploit Internet Explorer on those platforms are stuck in a “sandbox”, potentially able to read data but unable to install programs or change system configuration.&lt;/li&gt;    &lt;li&gt;&lt;b&gt;Address Space Layout Randomization (ASLR)&lt;/b&gt; makes exploiting vulnerabilities more difficult by relocating normally-predictable code locations pseudo-randomly in memory. ASLR re-bases DLL’s to random locations in memory, making ret2libc type attacks unreliable. Due to ASLR we believe exploits for Internet Explorer 8 on Windows Vista or Windows 7 could result in limited code execution for less than 1% of attempts.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;Out-of-band update coming tomorrow&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We’ll be releasing a comprehensive, well-tested security update tomorrow morning PST to address this vulnerability. In the meantime, we hope this information helps you assess risk and protect your environment. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Acknowledgements&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Thanks Matt Miller and John Lambert for help with the ASLR arithmetic and other feedback.&amp;#160; &lt;/p&gt;  &lt;p&gt;- Jonathan Ness, MSRC Engineering&lt;/p&gt;  &lt;p&gt;*Posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights.*&lt;/p&gt;</description></item><item><title>Microsoft Announces Out-of-Band Security Bulletin for the IE Vulnerability – SANS Internet Storm Center</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/microsoft-announces-out-of-band-security-bulletin-for-the-ie-vulnerability-sans-internet-storm-center.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144452</guid><dc:creator>cmosby</dc:creator><description>&lt;div class="headline"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=8041"&gt;Microsoft Announces Out-of-Band Security Bulletin for the IE Vulnerability&lt;/a&gt; &lt;/div&gt;  &lt;div class="digg"&gt;   &lt;div class="addthis_toolbox addthis_default_style"&gt;&lt;a class="addthis_button_compact at300m" href="http://www.addthis.com/bookmark.php?v=250&amp;amp;username=jullrich"&gt;&lt;span class="at300bs at15t_compact"&gt;&lt;/span&gt;Share&lt;/a&gt; &lt;span class="addthis_separator"&gt;|&lt;/span&gt; &lt;a class="addthis_button_facebook at300b" title="Send to Facebook" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=facebook&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_facebook"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_myspace at300b" title="Send to MySpace" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=myspace&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_myspace"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_google at300b" title="Send to Google" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=google&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_google"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="addthis_button_twitter at300b" title="Tweet This" href="http://www.addthis.com/bookmark.php?pub=jullrich&amp;amp;v=250&amp;amp;source=tbx-250&amp;amp;tt=0&amp;amp;s=twitter&amp;amp;url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D8041&amp;amp;title=Microsoft%20Announces%20Out-of-Band%20Security%20Bulletin%20for%20the%20IE%20Vulnerability&amp;amp;content=&amp;amp;lng=en" target="_blank"&gt;&lt;span class="at300bs at15t_twitter"&gt;&lt;/span&gt;&lt;/a&gt;      &lt;div class="atclear"&gt;&lt;/div&gt;   &lt;/div&gt;   &lt;/div&gt;  &lt;div class="diaryheader"&gt;Published: 2010-01-20,   &lt;br /&gt;Last Updated: 2010-01-20 22:03:06 UTC    &lt;br /&gt;by Lenny Zeltser (Version: 2) &lt;/div&gt; &lt;a href="http://isc.sans.org/diary.html?storyid=8041#comment"&gt;0 comment(s)&lt;/a&gt;   &lt;div class="diarybody"&gt;   &lt;p&gt;Microsoft posted &amp;quot;an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.&amp;quot;&lt;/p&gt;    &lt;p&gt;For details, see:&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;Microsoft also posted a comprehensive overview of the exploits that target this vulnerability. See:&lt;/p&gt;    &lt;p&gt;&lt;a href="http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx"&gt;http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx&lt;/a&gt;&lt;/p&gt;    &lt;p&gt; -- Lenny&lt;/p&gt;    &lt;p&gt;Lenny Zeltser - Security Consulting&lt;/p&gt; &lt;/div&gt;</description></item><item><title>Microsoft Security Bulletin Advance Notification for January 2010 - Issued: January 20, 2010</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/20/microsoft-security-bulletin-advance-notification-for-january-2010-issued-january-20-2010.aspx</link><pubDate>Wed, 20 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144449</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Microsoft Security Bulletin Advance Notification for January 2010&lt;/p&gt;  &lt;p&gt;Issued: January 20, 2010&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010.&lt;/p&gt;  &lt;p&gt;The full version of the Microsoft Security Bulletin Advance Notification for January 2010 can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;This bulletin advance notification will be replaced with the January bulletin summary on January 21, 2010. The revised bulletin summary will include the out-of-band security bulletin, as well as the security bulletins already released on January 12, 2010.&lt;/p&gt;  &lt;p&gt;For more information about the bulletin advance notification service, see &lt;a href="http://www.microsoft.com/technet/security/Bulletin/advance.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/advance.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on &lt;a href="http://www.microsoft.com/technet/security/bulletin/notify.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/notify.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Microsoft will host a webcast to address customer questions on the out-of-band bulletin on January 21, 2010, at 1:00 PM Pacific Time (US &amp;amp; Canada). Register for the Security Bulletin Webcast at &lt;a href="http://www.microsoft.com/technet/security/bulletin/summary.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/summary.mspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.&lt;/p&gt;  &lt;p&gt;This advance notification provides a number as the bulletin identifier, because the official Microsoft Security Bulletin numbers are not issued until release. The bulletin summary that replaces this advance notification will have the proper Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the bulletin identifier. The security bulletins for this month are as follows, in order of severity:&lt;/p&gt;  &lt;p&gt;Critical Security Bulletins&lt;/p&gt;  &lt;p&gt;===========================&lt;/p&gt;  &lt;p&gt;IE Bulletin&lt;/p&gt;  &lt;p&gt;- Affected Software:&lt;/p&gt;  &lt;p&gt;- Internet Explorer 5.01 Service Pack 4 when installed on &lt;/p&gt;  &lt;p&gt;Microsoft Windows 2000 Service Pack 4&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 Service Pack 1 when installed on &lt;/p&gt;  &lt;p&gt;Microsoft Windows 2000 Service Pack 4&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 6 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 with SP2 for Itanium-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 with SP2 for Itanium-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Vista, &lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition,&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 7 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 2 and &lt;/p&gt;  &lt;p&gt;Windows XP Service Pack 3&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows XP Professional x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 for &lt;/p&gt;  &lt;p&gt;Windows Server 2003 x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Vista,&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition,&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 1, and&lt;/p&gt;  &lt;p&gt;Windows Vista x64 Edition Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for 32-bit Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for x64-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems and&lt;/p&gt;  &lt;p&gt;Windows Server 2008 for Itanium-based Systems Service Pack 2&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows 7 for 32-bit Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows 7 for x64-based Systems&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 R2 for x64-based Systems &lt;/p&gt;  &lt;p&gt;(Windows Server 2008 Server Core installation not affected)&lt;/p&gt;  &lt;p&gt;- Internet Explorer 8 in &lt;/p&gt;  &lt;p&gt;Windows Server 2008 R2 for Itanium-based Systems &lt;/p&gt;  &lt;p&gt;- Impact: Remote Code Execution&lt;/p&gt;  &lt;p&gt;- Version Number: 1.0&lt;/p&gt;</description></item><item><title>Microsoft Security Advisory Notification - Issued: January 14, 2010</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/15/microsoft-security-advisory-notification-issued-january-14-2010.aspx</link><pubDate>Fri, 15 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144343</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Title: Microsoft Security Advisory Notification&lt;/p&gt;  &lt;p&gt;Issued: January 14, 2010&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Security Advisory Released Today&lt;/p&gt;  &lt;p&gt;==============================================&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (979352)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Internet Explorer Could&lt;/p&gt;  &lt;p&gt;Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;http://www.microsoft.com/technet/security/advisory/979352.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: Advisory published.&lt;/p&gt;</description></item><item><title>0-day vulnerability in Internet Explorer 6, 7 and 8  - SANS Internet Storm Center</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/15/0-day-vulnerability-in-internet-explorer-6-7-and-8-sans-internet-storm-center.aspx</link><pubDate>Fri, 15 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144344</guid><dc:creator>cmosby</dc:creator><description>&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7993"&gt;&lt;font color="#0000ff" face="Calibri"&gt;0-day vulnerability in Internet Explorer 6, 7 and 8&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri"&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Published: 2010-01-14,     &lt;br /&gt;Last Updated: 2010-01-14 22:19:56 UTC      &lt;br /&gt;by Bojan Zdrnja (Version: 1)       &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7993#comment"&gt;&lt;font color="#0000ff" face="Calibri"&gt;1 comment(s)&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri"&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;span&gt;Microsoft just published an &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;&lt;font color="#0000ff"&gt;advisory&lt;/font&gt;&lt;/a&gt; about a critical security vulnerability in all versions of Internet Explorer (apart from 5 – but no one has that around anymore, right?).      &lt;br /&gt;      &lt;br /&gt;While all versions of Internet Explorer are affected, the risk for everyone running Internet Explorer 8 is lower since it has DEP (Data Execution Prevention) enabled by default. DEP makes exploitation of this vulnerability more difficult so as a temporary workaround you might want to enable it for older IEs (keep in mind that it might break some add-ons).      &lt;br /&gt;      &lt;br /&gt;Microsoft says that so far they only saw exploits against Internet Explorer 6. In a related post (&lt;a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/"&gt;&lt;font color="#0000ff"&gt;here&lt;/font&gt;&lt;/a&gt;) McAfee said that this vulnerability was (one of those) used to compromise Google. So, it appears that it was maybe even a cocktail of 0-day exploits used (IE + Adobe).      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;</description></item><item><title>0-day vulnerability in Internet Explorer 6, 7 and 8  - SANS Internet Storm Center</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/15/0-day-vulnerability-in-internet-explorer-6-7-and-8-sans-internet-storm-center.aspx</link><pubDate>Fri, 15 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144344</guid><dc:creator>cmosby</dc:creator><description>&lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7993"&gt;&lt;font color="#0000ff" face="Calibri"&gt;0-day vulnerability in Internet Explorer 6, 7 and 8&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri"&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Published: 2010-01-14,     &lt;br /&gt;Last Updated: 2010-01-14 22:19:56 UTC      &lt;br /&gt;by Bojan Zdrnja (Version: 1)       &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin:0in 0in 0pt;" class="MsoNormal"&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7993#comment"&gt;&lt;font color="#0000ff" face="Calibri"&gt;1 comment(s)&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri"&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;span&gt;Microsoft just published an &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;&lt;font color="#0000ff"&gt;advisory&lt;/font&gt;&lt;/a&gt; about a critical security vulnerability in all versions of Internet Explorer (apart from 5 – but no one has that around anymore, right?).      &lt;br /&gt;      &lt;br /&gt;While all versions of Internet Explorer are affected, the risk for everyone running Internet Explorer 8 is lower since it has DEP (Data Execution Prevention) enabled by default. DEP makes exploitation of this vulnerability more difficult so as a temporary workaround you might want to enable it for older IEs (keep in mind that it might break some add-ons).      &lt;br /&gt;      &lt;br /&gt;Microsoft says that so far they only saw exploits against Internet Explorer 6. In a related post (&lt;a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/"&gt;&lt;font color="#0000ff"&gt;here&lt;/font&gt;&lt;/a&gt;) McAfee said that this vulnerability was (one of those) used to compromise Google. So, it appears that it was maybe even a cocktail of 0-day exploits used (IE + Adobe).      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;</description></item><item><title>Microsoft Security Advisory Notification - Issued: January 14, 2010</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2010/01/15/microsoft-security-advisory-notification-issued-january-14-2010.aspx</link><pubDate>Fri, 15 Jan 2010 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:144343</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Title: Microsoft Security Advisory Notification&lt;/p&gt;  &lt;p&gt;Issued: January 14, 2010&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Security Advisory Released Today&lt;/p&gt;  &lt;p&gt;==============================================&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (979352)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Internet Explorer Could&lt;/p&gt;  &lt;p&gt;Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;http://www.microsoft.com/technet/security/advisory/979352.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: Advisory published.&lt;/p&gt;</description></item></channel></rss>