March 2010 - posts - Ruud de Jonge

Ruud de Jonge

over Microsoft Platform en Security ontwikkelingen

March 2010 - posts

Alert - Critical Product Vulnerability - March 30, 2010 (Out-of-Band) Microsoft Security Bulletin Release

This alert is to provide you with an overview of the new security bulletin being released (out-of-band) on March 30, 2010.

New Security Bulletin

Microsoft is releasing one new security bulletin (out-of-band) for newly discovered vulnerabilities:

Bulletin ID

Bulletin Title

Maximum Severity Rating

Vulnerability Impact

Restart Requirement

Affected Software

MS10-018

Cumulative Security Update for Internet Explorer (980182)

Critical

Remote Code Execution

Requires a restart

All supported versions of Internet Explorer on supported versions of Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008*, Windows 7, and Windows Server 2008 R2.*

* Where indicated in the Affected Software table on the bulletin Web page, the vulnerabilities addressed by this update do not affect supported editions of Windows Server 2008 or Windows Server 2008 R2, when installed using the Server Core installation option. Affected software listed above is an abstract. Please see the bulletin at the link in the left column for complete details.

 

Public Bulletin Webcast

Microsoft will host a webcast to address customer questions on this bulletin:

Title: Information About Microsoft's March 2010 Out-of-Band Security Bulletin Release

Date: Tuesday, March 30, 2010, at 1:00 P.M. Pacific Time (U.S. & Canada).

URL: https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&EventID=1032448112

 

Public Resources related to this alert

·         Security Advisory 981374 – Vulnerability in Internet Explorer Could Allow Remote Code Execution:  http://www.microsoft.com/technet/security/advisory/981374.mspx   

·         Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/

·         Microsoft Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/

·         Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/

·         Microsoft Security Development Lifecycle (SDL) Blog: http://blogs.msdn.com/sdl/

New Security Bulletin Technical Details

In the following tables of affected and non-affected software, software editions that are not listed are past their support lifecycle. To determine the support lifecycle for your product and edition, visit the Microsoft Support Lifecycle Web site at http://support.microsoft.com/lifecycle/.

 

Bulletin Identifier

Microsoft Security Bulletin MS10-018

Bulletin Title

Cumulative Security Update for Internet Explorer (980182)

Executive Summary

This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.

 

The security update addresses these vulnerabilities by modifying the way that Internet Explorer handles objects in memory, validates input parameters, and filters HTML attributes.

 

This security update also addresses the vulnerability first described in Microsoft Security Advisory 981374.

Affected Software

All supported versions of Internet Explorer on supported versions of Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2*.


* Where indicated in the Affected Software table on the bulletin Web page, the vulnerabilities addressed by this update do not affect supported editions of Windows Server 2008 or Windows Server 2008 R2, when installed using the Server Core installation option. Please see the bulletin Web page at the link below for more details.

CVE, Exploitability Index Rating

·         CVE-2010-0267: Uninitialized Memory Corruption Vulnerability (EI = 3)

·         CVE-2010-0488: Post Encoding Information Disclosure Vulnerability (EI = 3)

·         CVE-2010-0489: Race Condition Memory Corruption Vulnerability (EI = 2)

·         CVE-2010-0490: Uninitialized Memory Corruption Vulnerability (EI = 3)

·         CVE-2010-0491: HTML Object Memory Corruption Vulnerability (EI = 1)

·         CVE-2010-0492: HTML Object Memory Corruption Vulnerability (EI = 1)

·         CVE-2010-0494: HTML Element Cross-Domain Vulnerability (EI = 1)

·         CVE-2010-0805: Memory Corruption Vulnerability (EI = 2)

·         CVE-2010-0806: Uninitialized Memory Corruption Vulnerability (EI = 1)

·         CVE-2010-0807: HTML Rendering Memory Corruption Vulnerability (EI = 1)

 

Note: Please see the Exploitability Index table on the bulletin summary page for more details: http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx

Attack Vectors

·         A maliciously crafted Web page

·         A maliciously crafted HTML e-mail

Mitigating Factors

·         Users would have to be persuaded to visit a malicious Web site.

·         Exploitation only gains the same user rights as the logged-on account.

·         By default, Outlook, Outlook Express, and Windows Mail open HTML e-mail messages in the Restricted Sites zone.

·         By default, IE on Windows 2003 and Windows Server 2008 runs in a restricted mode.

·         IE 5.01 SP4 and IE 8 are not affected by this vulnerability.

Restart Requirement

The update will require a restart.

Bulletins Replaced by This Update

MS10-002

Publicly Disclosed?
Exploited?

CVE-2010-0806 has been publicly disclosed prior to release.

CVE-2010-0806 has been exploited in the wild at release.

Full Details

http://www.microsoft.com/technet/security/bulletin/MS10-018.mspx

 

Regarding Information Consistency

 

We strive to provide you with accurate information in static (this mail) and dynamic (Web-based) content. Microsoft’s security content posted to the Web is occasionally updated to reflect late-breaking information. If this results in an inconsistency between the information here and the information in Microsoft’s Web-based security content, the information in Microsoft’s Web-based security content is authoritative.

 

If you have any questions regarding this alert please contact your Technical Account Manager or Application Development Consultant.

 

Thank you,

 

Microsoft CSS Security Team

 

 

Ruud de Jonge

Director Developer & Platform Evangelism of Microsoft in the Netherlands | Voice: +31-20-5001242

Messenger: ruud_de_jonge@hotmail.com | Blog: http://www.enthusiasm.nl | Visit: Evert van de Beekstraat 354, 1118 CZ Schiphol, NL 

clip_image001 

 

 

Posted: Mar 30 2010, 10:11 PM door Ruud de Jonge | met 1 comment(s)
Opgeslagen onder: ,
Alert for Users of Internet Explorer 6 and 7 : ADVANCE NOTIFICATION - March 30, 2010 (OOB) Microsoft Security Bulletin Release

What is the purpose of this alert?

This is an advance notification of an out-of-band security bulletin that Microsoft is intending to release on March 30, 2010. The bulletin is being released to address attacks against customers of Internet Explorer 6 and Internet Explorer 7. Users of Internet Explorer 8 and Windows 7 are not vulnerable to these attacks.

The vulnerability used in these attacks, along with workarounds, is described in Microsoft Security Advisory 981374.

The out-of-band security bulletin is a cumulative security update for Internet Explorer and will also contain fixes for privately reported vulnerabilities rated Critical on all versions of Internet Explorer that are not related to this attack.

Microsoft continues to encourage customers to follow the Protect Your Computer guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. Additional information can be found at www.microsoft.com/protect.

New Bulletin Summary

 

Bulletin Identifier

Internet Explorer

Maximum Severity Rating

Critical

Impact of Vulnerability

Remote Code Execution

Restart Requirement

The update will require a restart.

Affected Software

All supported versions of Internet Explorer on supported versions of Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

Note: information on affected software listed above is an abstract. Please see the Advance Notification Web page at the link below for complete details.

Although we do not anticipate any changes, the information provided in this summary is  subject to change until the release.

The full version of the Microsoft Security Bulletin Advance Notification for this (OOB) release can be found at http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx.

Public Bulletin Webcast

 

Microsoft will host a public webcast to address customer questions on these bulletins:

Title: Information about Microsoft March (OOB) Security Bulletin (Level 200)

Date: Tuesday, March 30, 2010, at 1:00 PM Pacific Time (U.S. & Canada).

URL: http://www.microsoft.com/technet/security/bulletin/summary.mspx

 

At this time no additional information on this bulletin, such as details regarding severity or details regarding the vulnerability will be made available until the bulletin is published.

Resources related to this alert

·         Security Advisory 981374 – Vulnerability in Internet Explorer Could Allow Remote Code Execution: http://www.microsoft.com/technet/security/advisory/981374.mspx 

·         Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/

·         Microsoft Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/

·         Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/

·         Microsoft Security Development Lifecycle (SDL) Blog: http://blogs.msdn.com/sdl/

 

Posted: Mar 29 2010, 09:22 PM door Ruud de Jonge | met no comments
Opgeslagen onder: , ,
.Net Magazine site nu live

Vandaag live gegaan. Alle content uit het .Net Magazine nu live en nog veel meer ! Communities, communities en communities !!!

http://www.dotnetmag.nl/Home

Ik ga naar de DevDays :-)

image

Ook dit jaar ben ik weer bij de DevDays en als ik zo om mij heen kijk is Arie druk bezig met het organiseren van de laatste sessies. Qua programma wordt het meer, meer en oh ja … meer. En natuurlijk zullen wij als eerste in NL aandacht besteden aan development voor Windows Phone 7 gebaseerd op S… en X… (Is nog geheim tot as maandag :-)). En de Geek Night wil je als technologie stuiterbal al helemaal niet missen !

Zie ik je ook in Den Haag op 30 en 31 Maart  ?

http://www.devdays.nl/

Posted: Mar 11 2010, 10:11 AM door Ruud de Jonge | met no comments
Opgeslagen onder: , , ,
Internet Explorer 8 biedt beste bescherming

Internet Explorer 8 biedt de beste bescherming tegen social engineering malware, terwijl andere browsers hopeloos falen. NSS Labs controleerde voor de derde keer hoe goed de vijf populairste browsers van het moment omgaan met kwaadaardige websites die malware aanbieden. Het gaat hier niet om drive-by download exploits, maar om screensavers, codecs en andere applicaties die veilig lijken, maar in werkelijkheid malware bevatten.

NSS Labs performs recurring, standardized testing of web browser security. This includes rating protection against socially-engineered malware and phishing attacks.

Originele artikel : http://nsslabs.com/browser-security

NEW! Q1 2010 Web Browser Comparative Test: Socially-Engineered Malware

This report followed the same Live Testing methodology as the two previous tests conducted in 2009. This report contains empirically-validated evidence gathered during 18 days of 24 x 7 testing, performed every six hours, over 74 discrete test runs, each one adding fresh new malware URLs. Each product was updated to the most current version available at the time testing began, and allowed access to the live Internet.

Tested products include:

  • Apple Safari 4
  • Google Chrome 4
  • Microsoft Internet Explorer 8
  • Mozilla Firefox 3.5
  • Opera 10

Read the Executive Summary.

Read the Full Report.

Met dank aan Security.nl

Posted: Mar 07 2010, 10:18 PM door Ruud de Jonge | met 1 comment(s)
Opgeslagen onder: