SDA India is an online resource for Software, Development,IT, Architecture, Open Source, Mobile, Security, Databases, Delphi, C, OS, Asp, .Net, Php, Xml, Java

Average Rating Rate this article Poor Below Average Average Good Excellent
1 2 3 4 5
Microsoft’s Security Release Addresses Four Vulnerabilities



Microsoft, this week, has issued security bulletins and patches for four vulnerabilities. Three of the flaws, in Microsoft Word, Publisher and the Jet database engine, are critical in at least some configurations. The fourth details a moderate vulnerability in Microsoft's Malware Protection Engine, which powers products like Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security.

MS08-026 fixes two privately reported holes in Word that could have been allowed an attacker to take control of a victim's computer using a maliciously crafted Word file. The second bulletin, MS08-027, describes a flaw in Microsoft Publisher which sounds very similar to one of the Word vulnerabilities. It too is critical on Publisher 2000 and less so on other versions because of the Confirmation Tool.

MS08-028 repairs a publicly reported flaw in the Microsoft Jet Database Engine (4.0) in Windows. If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code, mitigated by the user's administrative rights.

Finally, security researchers had concerns regarding patches for two vulnerabilities in the Microsoft Malware Protection Engine. While the error was rated "moderate," an unpatched vulnerability provides a remote attacker the potential to compromise malware protection applications. By creating a malicious file, an individual could clog up the system with a denial of service attack, which could cause the Malware Protection Engine to stop scanning infected files.

Commenting on the release of these patches, Amol Sarwate, vulnerability lab manager at Qualys, said that though these bugs are considered to be only a moderate risk, system administrators should take them seriously.

He further added saying that, "If someone sends a malformed e-mail and that is processed by any of these antivirus and antispyware products, it would cause the product to crash. If you can crash security software that is supposed to protect you, then you are left with no protection at all.”



Post a Comment
Name
Title
Comment
From the News Desk
The Board of the Internet Corporation for Assigned Names and Numbers …
Fabien Potencier, before releasing Symfony 1.1, has given some information about …
Cloud computing management system provider RightScale has released a new utility …
ActiveState Software has announced the release of Version 4.4 of Komodo …
In a recent announcement, Nokia said it has acquired Symbian, the …
Quantcast, a provider of Open Internet Ratings, has introduced a new …
The Wall Street Journal recently reported that Mobile phones designed around …
Articles

Whether you are producing a product, an application, a system, or a service, requirements drive the development process. Industry studies show that poor requirements definition and requirements management practices are the largest contributor to project failures, but that …

Managing storage resources has never been more challenging or critical. According to analysts, storage is growing at an estimated 50 - 60 percent annually even as storage utilization rates remain at an alarmingly low 30 - 40 percent. At the same time, storage resources are often spread across multiple geographic sites …

MySQL databases increasingly power production applications, whether web based collaboration tools or CRM applications. It is critical for the DBAs managing these production MySQL databases to have a robust data protection solution. Their top priority is hot backup and recovery of their database to a point-in-time (or transaction) of …
Interviews

We are currently in the process of developing an Enterprise Information Management suite that would enable efficient management of both the structured and unstructured data of large organizations and provide a personalized digital dashboard to all the stakeholders to view critical reports and important documents. SDA-India.com in conversation with Mr Shastri, Chairman and Managing …

Microsoft Tech Day is an event of technology & only for technologists! Events like these add new dimensions to Sapient Technology Practice and solidify Sapient delivery capabilities in Microsoft Technology. SDA-India.com sits with Mr. Sandeep Dhar, Managing Director, Sapient, to know more about MS Tech days and how significant is the relationship between Sapient and Microsoft. …

Imagine data intensive enterprises like BFSI, IT and Telecom where huge amounts of data are churned everyday. In these enterprises, data changes often and the amount of stored data is large. In the event of lost data, damaged files, or extended downtime, this could lead to business getting affected. Mr. Basant Rajan, CTO India, Symantec Corporation, talks to SDA-India.com, enlightening our readership on the benefits of Back …
RSS
more »                                   
Menu
News Desk
Feature Stories
Articles
Interviews
Case Studies
White Paper
Analyst Corner
Planet SDA-India
SDA Events
INDIA IT Event Calender
IT Jobs
Advertise