Welcome to Smokey's Security Forums.
Guests have only limited access to the board and it's features, please consider registering to gain full access!
Registration is free and it only takes a few moments to complete.

Smokey's Security Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

Guests now allowed to post for Malware Removal help.

There are a few rules governing this, so please check the link below for more information:

   Guests allowed to post for Malware Removal help

OTL Log Analysis and Malware Removal - Qualified PC Disinfection & Cleaning - Microsoft Security Info & Alert Center - Official Jetico Inc. Support Forums

Share this topic on FacebookShare this topic on MySpaceShare this topic on Del.icio.usShare this topic on DiggShare this topic on RedditShare this topic on StumbleUponShare this topic on TwitterAuthorTopic: Advisory 979352 Update for Monday January 18  (Read 111 times)

0 Members and 1 Guest are viewing this topic.

GilbertTopic starter

  • Updates Moderator
  • *
  • Offline Offline
  • location: Arctic
  • Posts: 5886
Advisory 979352 Update for Monday January 18
« Reply #1 on: January 19, 2010, 05:01:24 AM »
Advisory 979352 Update for Monday January 18
19 January 2010, 2:55 am

For today’s update we want to share some insight on the current threat landscape for Security Advisory 979352, some new resources we have published and the current status on producing a security update.

As we’ve previously reported, attacks remain targeted to a very limited number of corporations and are only effective against Internet Explorer 6.

We have not seen successful attacks on Internet Explorer 8. We continue to recommend customers upgrade to Internet Explorer 8 to benefit from the improved security protection it offers.

Additionally at this time, we have not seen any successful attacks against Internet Explorer 7. However, earlier today, we were made aware of reports that researchers have developed Proof-of-Concept (PoC) code that exploits this vulnerability on Internet Explorer 7 on Windows XP and Windows Vista. We are actively investigating, but cannot confirm, these claims.

Today we also published a guidance page, including an online video, for home users who may be confused, or concerned, about this security vulnerability and want to know what they should do to protect themselves from the known attacks. This page is located here.

         More listening and viewing options:          

Windows Media Video (WMV)             Windows Media Audio (WMA)             iPod Video (MP4)             MP3 Audio             High Quality WMV (2.5 Mbps)             Zune Video (WMV)                           Jonathan Ness from our Security Research & Defense team has also provided a video explaining Data Execution Prevention (DEP). While this technology offers a key mitigation against known attacks, how it works is somewhat complicated, so this video is to help people unfamiliar with DEP, better understand it.

         More listening and viewing options:          

Windows Media Video (WMV)             Windows Media Audio (WMA)             iPod Video (MP4)             MP3 Audio             High Quality WMV (2.5 Mbps)             Zune Video (WMV)                           Customers have been asking us when we will have an update available for this issue and if we will release the update out-of-band. We want to let customers know that we will release this security update as soon as the appropriate amount of testing has been completed. While we cannot yet give a date of when that will be we will keep customers update.

We will continue to monitor the threat landscape, and we will provide daily updates as things develop.

Thanks!

Jerry Bryant

*This posting is provided "AS IS" with no warranties, and confers no rights



Source: The Microsoft Security Response Center (MSRC)

>> To obtain the full Microsoft Security Center - MSRC article, click the link in the first post line <<
 

* Permissions
You can't post new topics.
You can't post replies.
You can't post attachments.
You can't modify your posts.
BBCode Enabled
Smilies Enabled
[img] Enabled
HTML Disabled


Except where otherwise stated, all content Copyright © 2006 - 2010 Smokey Services™ -- All rights reserved

Surf Smokey's with confidence: all external links in posts are checked and rated by WOT - Web of Trust
Security Knowledge-, Alert- & News Center and Comprehensive Microsoft Windows Information & Download Center
Board- and databases search functions and the download of post attachments are only available to registered board members

    


==>Think your PC is infected? Click here for OTL Log Analysis and Malware Removal Assistance<==


Smokey's Security Forums provide full qualified OTL Log Analysis & Cleaning Services
OTL (formerly OTListIt2) by OldTimer is a sophisticated, comprehensive log analysis tool to clean PCs with malicious content

Microsoft Security Info & Alert Center - most recent, real-time released Microsoft Security Bulletins, Alerts, Advisories and Vulnerabilities:
<div style="background-color: none transparent;"><a href="http://www.rsspump.com/?web_widget/rss_widget" title="rss widget">Rss widget</a></div>