Assigned to the patch for IE security bulletin MS09-072 warns against four vulnerabilities in the browser. These errors have been reported there immediately Microsoft. According to the assessment team Security Team for all of these gaps will soon appear smooth exploits. Three of them also apply to Internet Explorer for Windows 7 and can cause serious problems - thanks to the harmful site is able to infect your computer. Particularly annoying is that once again has to be patched vulnerability that is associated with an error in the Active Template Library.
The Internet Authentication Service Microsoft (IAS) - by MS09-71 - were discovered two vulnerabilities. The problem is not limited in this version of the Server, because it seems that the client code to connect to authenticated using MS-CHAP2 is exposed to the existence of this vulnerability. Nevertheless, specialists of Redmond recognize that Windows itself does not execute the code on the client machines - or at least not in such a way that gave this vulnerability to exploit. Vulnerability becomes dangerous only in conjunction with other companies.
In turn, MS09-074 describes a third critical vulnerability in Microsoft Office Project, which can be exploited by a specially formed project file. The potential attacker can create a web page constructed in such a way that it will lead to a visit to open a malicious file by the application.
This above situation does not happen in the event of another failure, the document in Word 97 It consists in the fact that a properly crafted documents may provoke an error in Wordpad, and Office's converter. Here's consent is required to carry out the conversion and as a result of this vulnerability described in MS09-73 has received the highest degree of hazard classification. Despite this, it means the attacker can also take full control over your computer.
Two errors in Active Directory Federation Services (ADFS) are described in MS09-70 apply only to servers within the network. The last patch released with bulletin MS09-69 fixes a bug that leads to the fact that the attacker uses the IPSec service can fix the LSASS Windows server system.
Solution
Installation of the amendments prepared by the manufacturer eliminates the problems described.
Windows 7 bugs has been fixed
hbailla, Thursday, December 10, 2009from : it-chuiko.com
Labels:
windows 7
Subscribe to:
Post Comments (Atom)
Comments :
Post a Comment