Monthly Archives: December 2008

1 Hotmail hoax

Sophos daily Top hoax:
1 Hotmail hoax
More information at Sophos.com

Posted in Sophos Security | Leave a comment

Troj/Invo-Zip

The top malware seen by Sophos in the last month
1 New Troj/Invo-Zip 12%
Go to more information at Sophos.com

Posted in Sophos Security | Leave a comment

Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution - 12/22/2008

Revision Note: Advisory published Advisory Summary:Microsoft is investigating new public reports of a vulnerability that could allow remote code execution on systems with supported editions of Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2000 Desktop Engine (WMSDE), [...]

Posted in MS Security | Leave a comment

Microsoft Security Advisory (961051): Vulnerability in Internet Explorer Could Allow Remote Code Execution - 12/17/2008

Revision Note: December 17, 2008: Advisory updated to reflect publication of security bulletin. Advisory Summary:Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS08-078 to address this issue. For more information about this issue, including download links for an available security update, please review MS08-078. The vulnerability addressed is [...]

Posted in MS Security | Leave a comment

MS08-078 - Critical: Security Update for Internet Explorer (960714)

Bulletin Severity Rating:Critical - This security update resolves a publicly disclosed vulnerability. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user [...]

Posted in MS Security | Leave a comment

MS08-077 - Important: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)

Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability. The vulnerability could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack leading to elevation of privilege could result in denial of service or information disclosure.

Posted in MS Security | Leave a comment

MS08-076 – Important: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807)

Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in the following Windows Media components: Windows Media Player, Windows Media Format Runtime, and Windows Media Services. The most severe vulnerability could allow remote code execution. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability [...]

Posted in MS Security | Leave a comment

MS08-075 – Critical: Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349)

Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in Windows Search. These vulnerabilities could allow remote code execution if a user opens and saves a specially crafted saved-search file within Windows Explorer or if a user clicks a specially crafted search URL. An attacker who successfully exploited these vulnerabilities could take [...]

Posted in MS Security | Leave a comment

Now available: Microsoft Security Intelligence Report Volume 5 (January through June 2008)

Volume 5 of the Microsoft Security Intelligence Report offers Microsofts unique perspective on the threat ecosystem using data provided from hundreds of millions of computers around the world and some of the busiest services on the Internet.
Go to full Article at Microsoft.com

Posted in MS Security | Leave a comment

Download Microsoft Identity Lifecycle Manager 2 Release Candidate

The newly released Identity Lifecycle Manager (ILM) 2 RC dramatically changes the identity management landscape by delivering powerful self-service capabilities for Office end users, rich administrative tools and enhanced automation for IT professionals, and .NET and WS-* based extensibility for developers.
Go full Article at Microsoft.com

Posted in MS Security | Leave a comment