NT Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Netflix outside the USA - in Linux & with Tunlr
· Enhanced Mitigation Experience Toolkit 4.0
· Intel Haswell HD Graphics 4600 vs. AMD Radeon Graphics On Linux
· DSA 2709-1: wireshark security update
· Simulator Provides Early Look at iOS 7 on the iPad
· AMD A10-6800K Cracks 8.00 GHz Mark and more
· Ubuntu 13.10 Release Schedule
· PHP 5.5.0 RC3 for Debian 7.0 Wheezy
· Windows 8.1 screenshots leaked, redesigns showcased
· DSA 2708-1: fail2ban security update

Upcoming News
· SanDisk Extreme II 240GB SSD Review
· Решебник 5 класс бесплатно
· ASUS Maximus VI Extreme Z87 motherboard review
· The SSD Review has Posted a New Article!
· News: AMD's A10-6800K and A10-6700 'Richland' APUs reviewed
· AllPuter.com product launch: 20X Super Long Range Telescope for Galaxy Note 2 Photography
· Intel DZ87KLT-75K "Kinsley Thunderbolt" Motherboard Review @ HiTech Legion
· Corsair Carbide Air 540 ATX Cube Chassis Review
· REVIEW: Diamond Radeon HD 7790 @ PureOverclock
· SanDisk Extreme II 240 GB SSD Review @ OCC

Windows Compatibility
· Norton Antivirus Corporate Server & Client v8.0
· Time Commando
· Delta Force 2
· Adobe Photodeluxe Home Edition 4.0
· Warcraft 3: Frozen Throne
· Borland C++ 4.51
· FaxTalk Messenger Pro V6.0 SP1
· Dragon's Lair 3D
· 3Com Etherlink XL 10/100 PCI NIC/3C905C
· Trident 4dWave DX

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2627 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3432 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93155 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 174 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6886 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Windows XP
· Microsoft
· Updates
· Interviews
· Windows Server 2003
· General
· Windows Vista
· Webcasts
· Windows Server 2008
· Windows Home Server
· Windows 7
· Windows 8
· Windows Phone 7

What's New
Login to see an overview of all news stories since your last visit.

Affiliates

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

NT Compatible » News » October 2010 » Microsoft Security Bulletin Updates 10/13/10

Microsoft Security Bulletin Updates 10/13/10

Posted by Philipp Esselbach on: 10/14/2010 08:26 AM [ Print | 0 comment(s) ]

Microsoft has updated the following security bulletins:

- MS10-082 - Important: Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) - Version:1.1
- MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.1
- MS10-077 - Critical: Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) - Version:1.1
- MS10-072 - Important: Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) - Version:1.1
- MS10-071 - Critical: Cumulative Security Update for Internet Explorer (2360131) - Version:1.1
- MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.1




MS10-082 - Important: Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Corrected the download link in the Affected Software table for Windows Media Player 11 on Windows XP Professional x64 Edition Service Pack 2.

Summary: This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Read more

MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Corrected the package name for the Microsoft Office Compatibility Pack (KB2345043) update. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action.

Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Read more

MS10-077 - Critical: Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) - Version:1.1
Severity Rating: Critical - Revision Note: V1.1 (October 13, 2010): Changed the vulnerability severity rating for Windows Server 2008 and Windows Server 2008 R2 to Important. Also added a link to Microsoft Knowledge Base Article 2160841 under Known Issues in the Executive Summary, and revised the vulnerability mitigations.

Summary: This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario.

Read more

MS10-072 - Important: Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (October 13, 2010): Added a link to Microsoft Knowledge Base Article 2412048 under Known Issues in the Executive Summary.

Summary: This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft SharePoint and Windows SharePoint Services. The vulnerabilities could allow information disclosure if an attacker submits specially crafted script to a target site using SafeHTML.

Read more

MS10-071 - Critical: Cumulative Security Update for Internet Explorer (2360131) - Version:1.1
Severity Rating: Critical - Revision Note: V1.1 (October 13, 2010): Corrected the update package names for Internet Explorer in the Windows Server 2008 deployment reference table. This is an informational change only. Customers who have already successfully updated their systems do not need to take any action.

Summary: This security update resolves seven privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Read more

MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.1
Severity Rating: Important - Revision Note: V2.1 (October 13, 2010): Added three update FAQs to clarify affected software.

Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET. The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.

Read more


Bookmark and Share

Related Threads

07/16/2010 11:12 AM: Microsoft Windows Network - invalid (deleted ) domain (0) by LuRs52
01/04/2011 02:24 AM: How flexible is Microsoft Security Essentials? (1) by MrJeebs
10/06/2009 10:44 AM: Microsoft windows network install (7) by danleff
11/16/2008 11:21 PM: Microsoft Xbox 360 Wireless Receiver for Windows (1) by Steiner
06/30/2008 12:27 AM: Microsoft Sidewinder FF Wheel (0) by DenMac70
07/09/2008 10:58 AM: New bigger hard drive - will Microsoft object? (4) by EASEUS Data Recovery
01/06/2008 01:00 PM: Microsoft.NET (4) by Cormac
07/26/2007 09:40 AM: Microsoft SideWinder Precision Wheel Sensitivity (1) by danleff
05/26/2007 05:28 PM: microsoft sidewinder ff wheel shaking non stop (0) by x-c33d
10/11/2009 04:16 AM: Microsoft Windows Network Lost (2) (2) by wlidster

« Arch Linux Review · ECS GeForce GTS 450 1GB Black Edition Video Card Review »

NT Compatible » News » October 2010 » Microsoft Security Bulletin Updates 10/13/10
All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition