SDA India is an online resource for Software, Development,IT, Architecture, Open Source, Mobile, Security, Databases, Delphi, C, OS, Asp, .Net, Php, Xml, Java

Information Security Enterprise IT Architecture Enterprise IT Architecture Wireless And Mobility Hardware & Networking Data & Storage
Average Rating Rate this article Poor Below Average Average Good Excellent
1 2 3 4 5
Microsoft’s Security Release Addresses Four Vulnerabilities



Microsoft, this week, has issued security bulletins and patches for four vulnerabilities. Three of the flaws, in Microsoft Word, Publisher and the Jet database engine, are critical in at least some configurations. The fourth details a moderate vulnerability in Microsoft's Malware Protection Engine, which powers products like Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security.

MS08-026 fixes two privately reported holes in Word that could have been allowed an attacker to take control of a victim's computer using a maliciously crafted Word file. The second bulletin, MS08-027, describes a flaw in Microsoft Publisher which sounds very similar to one of the Word vulnerabilities. It too is critical on Publisher 2000 and less so on other versions because of the Confirmation Tool.

MS08-028 repairs a publicly reported flaw in the Microsoft Jet Database Engine (4.0) in Windows. If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code, mitigated by the user's administrative rights.

Finally, security researchers had concerns regarding patches for two vulnerabilities in the Microsoft Malware Protection Engine. While the error was rated "moderate," an unpatched vulnerability provides a remote attacker the potential to compromise malware protection applications. By creating a malicious file, an individual could clog up the system with a denial of service attack, which could cause the Malware Protection Engine to stop scanning infected files.

Commenting on the release of these patches, Amol Sarwate, vulnerability lab manager at Qualys, said that though these bugs are considered to be only a moderate risk, system administrators should take them seriously.

He further added saying that, "If someone sends a malformed e-mail and that is processed by any of these antivirus and antispyware products, it would cause the product to crash. If you can crash security software that is supposed to protect you, then you are left with no protection at all.”



Post a Comment
Name
Title
Comment
From the News Desk
In a recent announcement Symantec said that it is expanding on …
According to Symantec’s MessageLabs, Web hosting service McColo was the host …
Intego, the Macintosh security specialist, has released the VirusBarrier X5 10.5.5, …
Articles

Records management has come a long way since its days of managing paper and file rooms only. Electronic records are the norm and to ensure that all electronic records are managed in accordance with policies and applicable regulations, legal and records management teams have had to overcome significant challenges. …

The last few years’ have witnessed alarming rates of employee churn and the modern world has termed this employee turnover as ‘Attrition’. The decision of ending association lies solely with employees but the organization plays a major role in decision making. Location preference, work environment, monetary dissatisfaction or personal priorities are …

Today we have easy access to software products in the market, with just a single degree of separation between the producer and the consumer. This has created new opportunities as well as problems, foremost among them being counterfeiting and piracy.Emerging and Existing Forms of PiracyIn 1929, Edwin Hubble, discovered …
Interviews

SOA is a principle of creating software functions as services, to enable alignment of business processes and related IT assets to meet change in business needs, leading to business agility, reduction in time to IT and cost to IT. SDA-India.com in conversation with Mr. K.R.Sanjiv on how does Service Oriented Architecture contribute to business …

Agile is a set of principles and practices for how to develop software and Scrum is a management methodology for implementing agile principles. SDA-India.com in conversation with Mr. John Scumniotales, VP of ALM Products, Serena Software. …

We are currently in the process of developing an Enterprise Information Management suite that would enable efficient management of both the structured and unstructured data of large organizations and provide a personalized digital dashboard to all the stakeholders to view critical reports and important documents. SDA-India.com in conversation with Mr Shastri, Chairman and Managing …
RSS
more »                                   
Menu
News Desk
Feature Stories
Articles
Interviews
Case Studies
White Paper
Analyst Corner
Planet SDA-India
SDA Events
INDIA IT Event Calender
IT Jobs
Advertise