Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,570 members, 7,809,081 topics. Date: Thursday, 25 April 2024 at 10:38 PM

Microsoft Fixes 29 Vulnerabilities - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Microsoft Fixes 29 Vulnerabilities (543 Views)

Microsoft Fixes Windows 10 Crash Bug Before Launch Date / Easy Fixes For Some Common Laptop Issues / Common Wi-fi Problem And Fast Fixes (2) (3) (4)

(1) (Reply)

Microsoft Fixes 29 Vulnerabilities by Fulaman198(m): 7:18pm On Jul 08, 2014
Microsoft today released six security bulletins and updates to address the vulnerabilities disclosed in them. The updates address a total of 29 vulnerabilities.

MS14-037: Cumulative Security Update for Internet Explorer (2975687) — This update fixes 24 vulnerabilities, all of them memory corruption vulnerabilities, in every supported version of Internet Explorer. Ironically, the only IE version for which there are no critical vulnerabilities in this update is IE6 on Windows Server 2003. None of the vulnerabilities had been publicly disclosed or exploited.
MS14-038: Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) — A user who opens a specially-crafted Journal file can be exploited in their user context. All versions of Windows since Vista are affected and the vulnerability is critical on all of them. Running as a standard user limits the potential damage.
MS14-039: Vulnerability in On-Screen Keyboard Could Allow Elevation of Privilege (2975685) — When the on-screen keyboard is triggered by a malicious low-integrity process, that process could load and execute programs with the privileges of the current user. This vulnerability is rated important.
MS14-040: Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) — An attacker who has rights to log on locally could run a malicious program that would elevate privileges to kernel mode. This vulnerability is rated important.
MS14-041: Vulnerability in DirectShow Could Allow Elevation of Privilege (2975681) — A user could elevate privilege by running a malicious program from a low-integrity process. Running IE in immersive mode with Enhanced Protected Mode helps to mitigate this problem. This vulnerability is rated important.
MS14-042: Vulnerability in Microsoft Service Bus Could Allow Denial of Service (2972621) — A remote authenticated attacker could create and run a program that sends a sequence of specially crafted Advanced Message Queuing Protocol (AMQP) messages to the target system, triggering a denial of service. This vulnerability is rated moderate.
The Microsoft Exploitability Index this month's updates says that successful exploit code for 28 of the 29 vulnerabilities is "likely." The 29th is not listed in the index. (This is likely an error. We have informed Microsoft and will update the story when they respond.)

As is usually the case, Microsoft will also release a new version of the Windows Malicious Software Removal Tool and a large collection of non-security updates to various Windows versions. The list of these updates and links to their knowledge base articles is below. Some of them are live as we publish this article, others will come online with a day.

Article and Source from: http://www.zdnet.com/microsoft-fixes-29-windows-vulnerabilities-7000031357/?s_cid=e589&ttag=e589&ftag=TREc64629f

(1) (Reply)

Is Anything Wrong With Glo Gbam? / Pls Help Me Out / Cctv Installations And Training In Port Harcourt...view Pics

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 9
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.