Members
  • Total Members: 12816
  • Latest: t114563
Stats
  • Total Posts: 28524
  • Total Topics: 8240
  • Online Today: 815
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: Patch out now for Microsoft Security Advisory (2286198)  (Read 1555 times)

0 Members and 1 Guest are viewing this topic.

mercenary

  • SCF Member
  • **
  • Posts: 27
  • KARMA: 3
Patch out now for Microsoft Security Advisory (2286198)
« on: 02. August 2010., 18:50:31 »
General Information
Executive Summary
Microsoft is investigating reports of limited, targeted attacks exploiting a vulnerability in Windows Shell, a component of Microsoft Windows. This advisory contains information about which versions of Windows are vulnerable as well as workarounds and mitigations for this issue.

The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the icon of a specially crafted shortcut is displayed. This vulnerability can be exploited locally through a malicious USB drive, or remotely via network shares and WebDAV. An exploit can also be included in specific document types that support embedded shortcuts.

Microsoft is currently working to develop a security update for Windows to address this vulnerability.

We are actively working with partners in our Microsoft Active Protections Program (MAPP) to provide information that they can use to provide broader protections to customers.




The patch is out now...  That was quick!  thanks MS...

http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx

Samker's Computer Forum - SCforum.info

Patch out now for Microsoft Security Advisory (2286198)
« on: 02. August 2010., 18:50:31 »




Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: Patch out now for Microsoft Security Advisory (2286198)
« Reply #1 on: 02. August 2010., 21:05:26 »

Thanks for info's Mercenary.  :up:




Quote
News is related with:
   
"Microsoft warns of new 0-day exploit, involving the Windows Shell (.lnk)": http://scforum.info/index.php/topic,4366.0.html

and
   
"Microsoft offer temporary "Fixit" for critical Windows Shell vulnerability": http://scforum.info/index.php/topic,4376.0.html

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising