Posts Tagged ‘microsoft’

Windows 7 “XP Mode” Vulnerability

This past Thursday (3/18/10) Microsoft announced that it will be dropping the hardware acceleration requirement for using the “XP Mode” feature on Windows 7.  XP Mode allows a user to run software which is not Windows 7 compatible in a virtualized instance of Windows XP on the same box.  Previously, to use this feature in [...]

Vulnerability Roundup

Well, it isn’t Patch Tuesday yet, but that doesn’t mean there isn’t Microsoft news.  A new 0-day has been found which exploits the help system in IE and older versions of windows (2000, XP, 2003).  I’ve included a few links with information about the vulnerability and mitigation steps.  It appears a patch for this (and [...]

Vulnerability Roundup

Another week, another Adobe security problem, this time in Adobe’s Download Manager.  The Adobe Download Manager (DLM) used to download updates from Adobe’s site, but Aviv Raff discovered a vulnerability which would force the Download Manager to download a file of an attacker’s choosing.  DLM is supposed to remove itself from a system after a [...]

Vulnerability Roundup

While they were absent from last week’s roundup, Adobe has returned with advisories in 3 of their products, not surprisingly Flash and Reader, and also BlazeDS which is included in some of their server offerings.  The Flash and Reader vulnerabilities share a CVE (CVE-2010-0186) which can allow an attacker to subvert domain sandboxing.  The Reader [...]

Vulnerability Roundup

So last month’s Patch Tuesday was pretty quiet on the Microsoft front.  Not so lucky this month with a total of 13 bulletins, 5 critical, 7 important.  And one for MS Paint.  That’s right, Paint.  Looks like I’ll have to put down the little spray paint tool for a bit. The others include patches for [...]

Vulnerability Roundup

Well, it looks like all the big boys are here.  Microsoft, Google, Adobe, Cisco, and ISC’s BIND all make this week’s roundup.  As mentioned in last week’s roundup, Microsoft released an out-of-band update for vulnerabilities related to the attacks on Google, Adobe and others. Speaking of Google and Adobe, Chrome 4 Stable has been released, [...]

Vulnerability Roundup

Here are some of the more interesting vulnerabilities or patches from this week. As this is our first roundup, some of these are a little older than a week, but noteworthy nonetheless. This week we have a light Patch Tuesday from Microsoft, but Adobe picks up the slack with patches for a server product, Acrobat [...]