العودة   منتديات عشاق السودان > منتديات الكمبيوتر والإنترنت > منتدى الشبكات وأنظمة التشغيل
التسجيل مستضيف الصور التعليمـــات قائمة الأعضاء التقويم اجعل كافة المشاركات مقروءة

رد
 
LinkBack أدوات الموضوع طرق مشاهدة الموضوع
قديم 21-11-2006, 14:24   رقم المشاركة : 1 (permalink)
معلومات العضو
Temon
عضو مميز
 
الصورة الرمزية Temon
 

 

 
إحصائية العضو









Temon غير متواجد حالياً

 

إحصائية الترشيح

عدد النقاط : 30
Temon is on a distinguished road

 

 

Exclamation Microsoft users face two zero-day threats in a week

Takeaway: Microsoft has released two security advisories in the past week, confirming two separate ActiveX vulnerabilities. Exploit code is circulating for both threats, but Microsoft hasn't yet released patches. Get the details in this edition of the IT Locksmith, and learn about possible workarounds.

Two ActiveX threats have emerged for Microsoft users. Attack code is currently circulating, but workarounds are available.
Details

As confirmed in Microsoft Security Advisory 927709, "Vulnerability in Visual Studio 2005 Could Allow Remote Code Execution," a remote code execution threat has emerged in Visual Studio 2005 (CVE-2006-4704). Proof-of-concept code is currently circulating, and there have been reports of attacks exploiting this vulnerability.

The particular ActiveX control causing problems is the WMI Object Broker control. The vulnerability, linked to WmiScriptUtils.dll, doesn't affect users running Internet Explorer 7 with the default settings and those using Visual Studio 2005 on Windows Server 2003 with the default settings. The Microsoft security advisory lists possible workarounds, including directions for setting the kill bit to disable the vulnerability control.

In addition, Microsoft has released Security Advisory 927892, "Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution." The advisory details a separate XML Core Services threat linked to XMLHTTP 4.0.

US-CERT Vulnerability Note VU#585137 also addresses this threat. (US-CERT, the United States Computer Emergency Readiness Team, is the operational arm of the National Cyber Security Division of the Department of Homeland Security.)

While exploit code is available, the XMLHTTP ActiveX 4.0 control doesn't come installed with Windows XP by default. However, it's bundled with many applications, so this threat can affect Internet Explorer users. This vulnerability doesn't affect those running Windows Server 2003 in its default configuration (with the Enhanced Security Configuration).

Both the security advisory and the vulnerability note describe possible workarounds. In addition, there is a simple registry patch available.

You can set a kill bit to disable the specific ActiveX control in Internet Explorer. See Microsoft Knowledge Base article 240797 for details. You can also disable ActiveX entirely. For more information, see this US-CERT resource.

التوقيع


You will never walk aLone
Temon غير متواجد حالياً   رد مع اقتباس
رد


أدوات الموضوع
طرق مشاهدة الموضوع

تعليمات المشاركة
لا تستطيع كتابة مواضيع
لا تستطيع كتابة ردود
لا تستطيع إرفاق ملفات
لا تستطيع تعديل مشاركاتك

كود [IMG] متاحة
كود HTML معطلة
Trackbacks are متاحة
Pingbacks are متاحة
Refbacks are متاحة


الساعة الآن: 23:47


Powered by vBulletin® Version 3.6.8, Copyright ©2000 - 2008, Tranz By Almuhajir
جميع الآراء والتعليقات المطروحة تمثل وجهة نظر كاتبها وليس بالضرورة وجهة نظر الموقع
SudaBest.net SudaBest.net

Search Engine Optimization by vBSEO 3.2.0 RC5

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98