Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-14-2006, 09:05 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Microsoft Patch Day for November

Microsoft Patch Day for November
<p>Microsoft released six security bulletins this morning, covering a total of 11 distinct security vulnerabilities. In rough order of most urgent to least, here we go:</p>

<p>Topping the list in raw urgency is MS06-066 (BID <a href="http://www.securityfocus.com/bid/21023">21023</a> and BID <a href="http://www.securityfocus.com/bid/20984">20984</a>, CVE-2006-4688 and CVE-2006-4689). This affects everything from Win2K SP0 to XP SP2, provided that the systems have the Client Service for Netware enabled. This obviously reduces the population of vulnerable systems, but for those systems this is where you want to start. This addresses two vulnerabilities, the more severe of which is the Microsoft Windows Client Service For Netware Remote Code Execution Vulnerability. If your computers match that description, you are wide open to remote attackers, who have the opportunity to run code of their choice on your machines – until you apply the patch, of course. The vulnerable service is not installed by default, but if it has been installed and is not needed it can (and should) be removed. BID 21023 allows full compromise and working exploit code has been published, so if your network is affected this should be a priority for you.</p>

<p>Next up is MS06-067, a cumulative update that addresses three vulnerabilities in IE 5 and 6 (BID <a href="http://www.securityfocus.com/bid/19738">19738</a>/ CVE-2006-4446, BID <a href="http://www.securityfocus.com/bid/20047">20047</a>/CVE-2006-4777, and BID <a href="http://www.securityfocus.com/bid/21020">21020</a> / CVE-2006-4687). The most urgent of these issues is the Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability (BID 20047). This is a previously known issue disclosed in September, and allows malicious Web site operators or defacers to run code using the browser’s improper handling of malformed parameters to the KeyFrame method of the DirectAnimation.PathControl object. Limited exploitation of this issue has been seen in the wild. Exploits for two of the three resolved issue are known to exist. There are multiple workarounds described in the MS Bulletin that should be followed immediately if patching is not an option right away. </p>

<p>MS06-071 (BID <a href="http://www.securityfocus.com/bid/20915">20915</a> / CVE-2006-5745), the Microsoft XML Core Service XMLHTTP ActiveX Control Remote Code Execution Vulnerability, addresses an issue in the XML core service of Windows 2000, 2003 and XP. Like the others, this can also allow attackers to run code of their choice on the affected system. This was first publicly mentioned earlier in November when exploitation of this issue was discovered in the wild by ISS xForce. Needless to say, multiple exploits for this vulnerability are now available for download. The vector of attack is the XMLHTTP ActiveX control. In the event that patching is not possible, the control can be disabled via the kill bit – see the bulletin for complete details.</p>

<p>MS06-070 (BID <a href="http://www.securityfocus.com/bid/20985">20985</a> / CVE-2006-4691), the Microsoft Windows Workstation Service NetpManageIPCConnect Remote Code Execution Vulnerability, had the potential to be the most severe issue this month (initially). Longer-than-expected hostnames sent in RPC transactions to W2K and XP targets could result in the execution of attacker-supplied code at the SYSTEM privilege level, making this a prime candidate for automated and self-replicating exploitation. However, (thankfully) it can only be exploited by users already possessing Administrator rights on XP. Windows 2000 machines can be compromised by anonymous attackers however, so this is still a serious threat on that platform. Exploits are not known to exist publicly at this time.</p>

<p>MS06-068 (BID <a href="http://www.securityfocus.com/bid/21034">21034</a> / CVE-2006-3445) was published to address a vulnerability in the Microsoft Agent ActiveX control. This vulnerability could allow arbitrary code to be run at the privilege level of the browser via a malicious ACF file. Exploits for this issue are not known to exist, and the usual ActiveX workarounds apply.</p>

<p>And finally, we have MS06-069 (BID <a href="http://www.securityfocus.com/bid/19980">19980</a> / CVE-2006-3311, CVE-2006-3587, CVE-2006-3588, CVE-2006-4640; BID <a href="http://www.securityfocus.com/bid/18894">18894</a> / CVE-2006-3587, CVE-2006-3588), which details several issues in the Adobe Flash Player included in Windows XP.</p>

<p>All of the bulletins released today can be found at: <a href="http://www.microsoft.com/athome/security/update/bulletins/200611.mspx">http://www.microsoft.com/athome/security/update/bulletins/200611.mspx</a></p>
http://www.symantec.com/enterprise/security_response/weblog/2006/11/microsoft_patch_day_for_novemb.html
http://www.symantec.com/enterprise/security_response/weblog/2006/11/microsoft_patch_day_for_novemb.html
Tue, 14 Nov 2006 16:50:00 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 09:25 AM.


    Firefox 2