Microsoft today issued three "critical" security bulletins as part of its monthly Patch Tuesday program. Together with nine other alerts, which the company rated as "important," the bulletins address 22 vulnerabilities spanning Microsoft products from Windows and Internet Explorer to Office and Internet Information Services.
On the top of the list is MS11-003, which is a cumulative update for Internet Explorer that resolves four vulnerabilities. Included is a fix for the nasty CSS bug outlined in Security Advisory 2488013, a bug that could give attackers control of people's computers.
In a podcast about the patches, Jerry Bryant, the group manager of response communications for Microsoft's Trustworthy Computing Group, downplayed the scope of the CSS issue, saying that the company had seen only limited, targeted attacks focused on this vulnerability. To drive that point home, the company has released telemetry of how that vulnerability stacks up against an already-patched vulnerability in the Windows Shell, to explain why a fix was not made available outside the company's normal release cycle.
"While our first priority is to protect customers from issues like these, we also look to minimize disruption that issues like out-of-band releases can bring," Bryant said.
The second critical item included in the list of patches is the thumbnail image attack vulnerability, which is being addressed in MS11-006. This fixes the security hole in Microsoft's Windows Graphics Rendering Engine that could let attackers gain control of users' computers by having them load a specially formatted image. The problem affects Windows XP, Server 2003, Windows Vista, and Windows Server 2008, but not Windows 7 or Windows Server 2008 R2, the company said.
"We have not seen any attacks against this vulnerability, but proof of concept code is available to attackers, so we recommend customers put this at the top of their priority list," Bryant said.
The third critical item that's being patched is the OpenType Compact Font exploit as part of MS11-007. That particular vulnerability requires end users to load what Microsoft classifies as a "maliciously crafted" font. Bryant explained that the issue had privately been disclosed to the company, and that it was rated a 2 in the Exploitability Index, since Microsoft does not believe a reliable exploit code will show up within the next 30 days.
One tier Lower on the company's deployment priority index (which is how Microsoft dictates to customers the order in which to deploy patches to machines) is the fix to the zero-day vulnerability with the FTP services in IIS 7.0 and 7.5. It too has a rating of 2 in the Exploitability Index, and it makes up part of MS11-004.
Along with those critical and important updates, Microsoft is changing its Autorun functionality when users plug in USB thumb drives. The company is disabling Autorun from USB thumb drives in versions of Windows that are older than Windows 7, which already has such a security feature. That's going out to users as an AutoUpdate in Windows Update.
As mentioned in previous coverage about this month's batch of updates, Microsoft has not offered up more details on long-term fixes for the MHTML vulnerability that cropped up last month and affects Internet Explorer. But according to Jim Walter, the manager of McAfee Threat Intelligence Service, the MHTML problem is smaller than most.
"The scope and impact of the MHTML vulnerability is relatively limited compared to other recent zero-day code execution vulnerabilities," Walter said in a statement. "Based on the information that is currently available, we are aware that successful exploitation could lead to the running of arbitrary scripts, as well as the disclosure of sensitive information."
More details about the list of fixes, and ways to deploy them, can be found in Microsoft's Security Response Center blog.
View the original article here
The website aims at providing Internet users the latest virus, spyware, malware, and other wares that compromises the users privacy.
Friday, February 11, 2011
Friday, February 4, 2011
How To Remove Spyware Intervalhehehe
How to prevent and remove Spyware Intervalhehehe effectively?
Do you want to prevent and remove Spyware Intervalhehehe easily from your computer? If you have ever typed this into a search engine, I believe you will get thousands of recommendations. But which one is the best way to prevent and remove Spyware Pop-Ups? In this article, we will discuss what Spyware Intervalhehehe is and how to prevent/remove it effectively so as to secure your computer and personal information.First, let's have a look at what Spyware Intervalhehehe really is.
Spyware Intervalhehehe will secretly install on users' computer without letting them know or installation requirements. Once it installs on the computer, some ruinous problems will come on the neck of others such as:
1. The computer runs slower than ever before or takes forever to start up/ shut down or run large programs.
2. You browser or other account settings have been modified without your permission even though you have changed it back several times.
3. Your programs don't work properly for Spyware Intervalhehehe will attack the programs installed on the computer which resulting in missing/corrupt items. These items will stop you from successfully running the program that you exactly want.
So how does Spyware Intervalhehehe get on the computer?
After chatting with one of my friends who dedicates on computer technology, I know that Spyware Intervalhehehe always gets on users' computer through the below channels.
1. Bundled with other programs downloads. This is the most common ways for Spyware Intervalhehehe to get on the computer.
2. Spyware Intervalhehehe will slow com onto your computer when you are browsing unsafe websites. These websites will be plated with some malicious codes. When the PC users visit the website, it will make use of the vulnerabilities in your browser to infect the computer without permission.
3. Most of the time, Spyware Intervalhehehe will disguise themselves as an useful utility and user will sometimes download and install them directly on the computer without realizing them it will do harm to the computer.
4. Spyware Intervalhehehe is also contained in email attachments. Please note it is very easy to fake email address. Even though the email address is not faked, your friends, co-workers, or other members will also unsuspectingly send you an infected file which contains Spyware Pop-Ups. So it if highly recommended that you should first scan the received email attachments before opening them.
From the above discussion, we know that it is very easy for Spyware Intervalheheh eto get onto your computer from aspects which has no way of guarding against that manually. But with powerful anti-spyware software installed on your computer, you can protect your computer against Spyware Intervalheheheeffectively. Anti-spyware software is designed to easily/thoroughly scan and remove spyware/ kinds of PC threats from the computer.
To sum, Spyware Intervalhehehe can access into your computer from different ways, which cannot be prevented manually. To protect your computer and your personal information, do remember to install and run an Instant Spyware Removal frequently so as to prevent or remove potential Spyware Intervalheheheat any time!
Article Source: http://www.articlesbase.com/security-articles/how-to-prevent-and-remove-spyware-intervalhehehe-effectively-3196894.html
Subscribe to:
Posts (Atom)