Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-29-2007, 10:21 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Microsoft's Patch Tuesday for November

Microsoft's Patch Tuesday for November
<p>Hello and welcome to this month’s blog on the Microsoft patch releases. November is a light month with only two releases, each addressing one vulnerability.</p>

<p>The first bulletin, rated as critical by Microsoft, addresses a vulnerability reported in October (<a href="http://www.securityfocus.com/bid/25945">BID 25945</a>). The problem stems around how Windows handles certain malformed URLs. This issue saw a fair amount of press over the last month including a <a href="http://www.microsoft.com/technet/security/advisory/943521.mspx">security advisory</a> released by Microsoft. </p>

<p>The second vulnerability, rated as important by Microsoft, involves the Microsoft DNS Server service. An attacker may be able to exploit this issue to corrupt the DNS cache and have DNS entries point to attacker-controlled IPs. <br />
This can then be further utilized to aid in phishing style attacks.</p>

<p>Microsoft’s summary of the November releases can be found here: <a href="http://www.microsoft.com/technet/security/bulletin/ms07-nov.mspx">http://www.microsoft.com/technet/security/bulletin/ms07-nov.mspx</a></p>

<p><strong>1. Vulnerability in Windows URL Handling Could Allow Remote Code Execution (KB943460)</strong></p>

<p>CVE-2007-3896 (<a href="http://www.securityfocus.com/bid/25945">BID 25945</a>) <br />
Windows URL Handling Vulnerability (MS Rating: Critical / Symantec Urgency Rating: 8.2/10)</p>

<p>This is an update to a previously disclosed vulnerability in Windows regarding URL handling. The issue is caused by how interactions are handled between Internet Explorer and Windows Shell. This issue was introduced in an updated component installed with Internet Explorer 7. Third-party applications that do not perform adequate input validation on URLs may serve as attack vectors for this vulnerability. Successfully exploiting this issue allows remote attackers to execute arbitrary commands in the context of users that follow malicious URLs.</p>

<p>Affects the following operating systems with Internet Explorer 7 installed: Windows XP Service Pack 2, Windows XP Professional x64 Edition, Windows XP Professional x64 Edition SP2, Windows Server 2003 SP1 & Sp2, Windows Server 2003 x64 Edition, Windows 2003 Server x64 Edition SP2, Windows Server 2003 Itanium SP1 & SP2</p>

<p>Note: This does not affect Windows Vista.</p>

<p><strong>2. Vulnerability in DNS Could Allow Spoofing (KB941672)</strong></p>

<p>CVE-2007-3898 (<a href="http://www.securityfocus.com/bid/25919">BID 25919</a>) <br />
DNS Spoofing Attack Vulnerability (MS Rating: Important / Symantec Urgency Rating: 7.1/10)</p>

<p>This is a remote vulnerability in Windows DNS Server service that may allow an attacker to spoof responses to DNS requests. The DNS protocol includes a transaction ID that is used to correlate requests. However, the Windows DNS Server service does not provide enough entropy in the randomization process when creating that ID for use in recursive DNS queries. This may allow an attacker to spoof legitimate responses, poisoning the DNS cache, and potentially redirecting traffic to attacker-controlled locations.</p>

<p>Affects: Windows 2000 Server SP4, Windows Server 2003 SP1 & SP2, Windows Server 2003 x64, Windows Server 2003 x64 SP2, Windows Server 2003 Itanium SP1 & SP2</p>

<p>More information on this and other vulnerabilities is available at Symantec’s free <a href="http://www.securityfocus.com/">SecurityFocus</a> portal and to our customers through the DeepSight Threat Management System.</p>
http://www.symantec.com/enterprise/security_response/weblog/2007/11/microsofts_patch_tuesday_for_n.html
http://www.symantec.com/enterprise/security_response/weblog/2007/11/microsofts_patch_tuesday_for_n.html
Tue, 13 Nov 2007 12:08:00 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 01:04 PM.


    Firefox 2