The second Tuesday of a month is Microsoft’s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code [...]
- Author: Martin Brinkmann
- Comments: 1
No Patches For Internet Explorer Vulnerabilities This Month
Microsoft will be releasing two security bulletins on this January’s patch day leaving two security vulnerabilities affecting Internet Explorer and one issue affecting the Windows graphics rendering engine unaddressed. The first vulnerability affects Internet Explorer 6 to Internet Explorer 8 on all versions of the Windows operating system starting with Windows XP and ending at [...]
- Author: Martin Brinkmann
- Comments: None
Collection of Recent Microsoft Security News
Yesterday was one of the largest patch days in Windows history, with 16 security bulletins and way of 40 different vulnerabilities patched. If you have not updated your version of Windows yet you should consider doing so immediately to protect it from exploits that target these new vulnerabilities. But that was not the only good [...]
- Author: Martin Brinkmann
- Comments: 3
Microsoft Security Bulletins October 2010
Every second Tuesday in a month is patch day over at Microsoft. What does it mean? Microsoft pushes out all security patches of a month on that day to all users of their Windows operating systems and other applications like Microsoft Office. Only highly critical vulnerabilities receive out of band security patches. This month’s patch [...]
- Author: Martin Brinkmann
- Comments: None
Microsoft Releases Out Of Band Security Patch
Microsoft today released a new out of band security bulletin addressing a vulnerability in ASP.NET that affects all versions of the Microsoft .Net Framework when used on Windows Server operating systems, or on client systems that run a web server from their computer. While that excludes the majority of desktop users, it may still affect [...]
- Author: Martin Brinkmann
- Comments: 6
Microsoft Releases September Security Patches
Microsoft has released this month’s security patches for their operating systems and applications. The patches and updates are already available via Windows Update and Microsoft Download, and it is recommended to update the operating system as soon as possible to protect it from exploits targeting those vulnerabilities. A total of nine bulletins has been released [...]
- Author: Martin Brinkmann
- Comments: 5
Windows DLL Hijack Vulnerability Affects Exe Files As Well
The recently discovered DLL hijack vulnerability in Windows appears to be more critical than thought. Up until now it was confirmed that Windows would load dlls from the current working directory if they cannot be found in directories with a higher search priority. This in turn meant that attackers had to use a dll unknown [...]
- Author: Martin Brinkmann
- Comments: 1
DLLHijackAuditor, Check Programs For DLL Hijack Vulnerability
A new Windows vulnerability was made public in the end of August, which could allow remote code execution on a computer system. The issue is caused by programs and applications that use insecure programming practices. According to various researchers at least 40 popular applications are affected by the vulnerability. New users who want to read [...]
- Author: Martin Brinkmann
- Comments: 3
Microsoft Offers Workaround For Remote DLL Vulnerability
A vulnerability was recently discovered in Microsoft Windows operating systems that exploits the default dll loading behavior. A Microsoft Security Advisory explains that the “issue is caused by specific insecure programming practices that allow so-called binary planting or DLL preloading attacks”. In simple terms: Applications that do not use qualified paths for external dynamic link [...]
