26 Eylül 2012 Çarşamba

Security Bulletin Advance Notice for September 2012

To contact us Click HERE
Tweet This

Security Bulletin
On Tuesday, September 11, 2012, Microsoft is planning to release two (2) bulletins, of which both bulletins are identified Important.  The bulletins are related to Elevation of Privilege.  Although they do not require a restart, it is advised to restart the computer after installing the updates.


==================================NEW BULLETIN SUMMARY==================================Bulletin ID: Bulletin 1Maximum Severity Rating: ImportantVulnerability Impact: Elevation of Privilege RestartRequirement: No restart required Affected Software: Microsoft Visual StudioTeam Foundation Server 2010----------------------------Bulletin ID: Bulletin 2Maximum Severity Rating: ImportantVulnerability Impact: Elevation of Privilege RestartRequirement: No restart required Affected Software: Microsoft SystemsManagement Server 2003 and Microsoft System Center Configuration Manager 2007.----------------------------

As happens each month, Microsoft will also release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

IT Administrators are advised to pay particular attention to the information in the MSRC Blog regarding Security Advisory 2661254 (Update For Minimum Certificate Key Length).

References

  • MSRC Blog:  September ANS and an important heads-up concerning certificates
  • TechNet: Microsoft Security Bulletin Advance Notification for September 2012


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Microsoft Security Bulletin Release for September 2012

To contact us Click HERE
Tweet This


Microsoft released two (2) bulletins, of which both bulletins are identified Important.  The bulletins are related to Elevation of Privilege, although neither is known to be under active exploit in the wild.

The bulletins address twenty-six vulnerabilities in Microsoft Windows, Internet Explorer, Exchange Server, SQL Server, Server Software, Developer Tools, and Office.  Although they do not require a restart, it is advised to restart the computer after installing the updates.
  • MS12-061 (Visual Studio Team Foundation Server) This security update resolves a privately reported vulnerability in Visual Studio Team Foundation Server. This bulletin is rated Important for Microsoft Visual Studio Team Foundation Server 2010 Service Pack 1.
  • MS12-062 (System Center Configuration Manager) This security update resolves a privately reported vulnerability in Microsoft System Center Configuration Manager. The bulletin is rated Important for Microsoft Systems Management Server 2003 Service Pack 3 and Microsoft System Center Configuration Manager 2007 Service Pack 2.


Support

The following additional information is provided in the Security Bulletin:
  • The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
  • Security solutions for IT professionals: TechNet Security Troubleshooting and Support
  • Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
  • Local support according to your country: International Support

References

  • MSRC: Update Tuesday overview for September 2012
  • TechNet: Microsoft Security Bulletin Summary for September 2012
  • Security and Safety Center:  Microsoft security updates for Spetember 2012 




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Microsoft Security Advisory 2757760

To contact us Click HERE
Tweet This

Security Advisory
Microsoft released Security Advisory 2757760 to address an issue that affects all versions of Internet Explorer except IE10.

Current exploits of this vulnerability occur with Internet Explorer using third-party software, most particularly Oracle’s Java, when visiting a website hosting malicious code.

Update:  It was reported at the MSRC Blog that a Microsoft Fix it solution will be issued within the next few days.  In the interim, it was also stated that this vulnerability is currently not widespread.  See the update at Additional information about Internet Explorer and Security Advisory 2757760.

Recommendations:

Uninstall Java -- Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

  • Playing on-line games generally requires Java.
  • With OpenOffice, Java is needed for the items listed  here. 
  • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
  • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.

Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations such as DEP to configured applications.

The simple steps needed to add iexplore.exe to EMET and other actions are provided in the "Suggested Actions" section of the Security Advisory.  When checking EMET, I was pleased to see that I had already added iexplore.exe. 


References:

  • MSRC: Microsoft Releases Security Advisory 2757760
  • Tech Net Advisory: Microsoft Security Advisory (2757760) Vulnerability in Internet Explorer Could Allow Remote Code Execution
  • Download:  EMET (Enhanced Mitigation Toolkit v3.0)



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Out of Band Internet Explorer Security Update

To contact us Click HERE
Tweet This

Security Bulletin
On Friday, September 21, 2012, Microsoft  will release MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update will require a restart.

Microsoft Fix it

In addition, a Microsoft Fix it solution is available now for applying ahead of the update to protect your computer.

Fix it
EnableDisable
Fix this problem
Microsoft Fix it 50939
Fix this problem
      Microsoft Fix it 50938

(HT:  ky331)

References

  • MSRC Blog:  Internet Explorer Fix it available now; Security Update scheduled for Friday
  • TechNet: Microsoft Security Bulletin Advance Notification for September 2012 
  • Microsoft Security Advisory: Vulnerability in Internet Explorer could allow remote code execution




    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Microsoft MS12-063 – Critical Cumulative Security Update for Internet Explorer

    To contact us Click HERE
    Tweet This


    Microsoft released MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update requires a restart.
      The Bulletin addresses the following issues from the Common Vulnerabilities and Exposures (CVE) list:
      • OnMove Use After Free Vulnerability - CVE-2012-1529.
      • Event Listener Use After Free Vulnerability - CVE-2012-2546.
      • Layout Use After Free Vulnerability - CVE-2012-2548.
      • cloneNode Use After Free Vulnerability - CVE-2012-2557.
      • execCommand Use After Free Vulnerability - CVE-2012-4969.
      Internet Explorer 10 on Windows 8 and Windows Server 2012 is not affected.  All other versions of Internet Explorer are affected

      Support

      The following additional information is provided in the Security Bulletin:
      • The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
      • Security solutions for IT professionals: TechNet Security Troubleshooting and Support
      • Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
      • Local support according to your country: International Support

      References

      • MSRC: Microsoft releases MS12-063 – Cumulative Security Update for Internet Explorer
      • TechNet: Microsoft Security Bulletin MS12-063 - Critical




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      25 Eylül 2012 Salı

      Volkswagen Beetle Computer Case Gadget

      To contact us Click HERE
      Get A Free IPhone, XBox, Ps3, Wii, Pc, Laptop, Etc.. Easy!





      Technology is still continue growing so as to computer world. Personal Computer has this latest design the Volkswagen Beetle Computer Case. It was built and managed to squeeze the whole PC inside the body of the car. It just like a furniture display in your house.

      The front bumper is the home of the CD ROM which slides out when needed. The rear bumper houses various other ports that include USB as well as audio/video type stuff.

      The creator of the case maybe a fan of Volkswagen cars or just his interest to do unique things.


      Pet's Eye View Camera: Latest Pet Gadget

      To contact us Click HERE
      Get A Free IPhone, XBox, Ps3, Wii, Pc, Laptop, Etc.. Easy!




      Pet's Eye View camera is the latest gadget camera for pet. Here you can see what your furry little friend gets up to while you're at work or not in your house. Small and light enough for most cats and dogs.

      To install; just clip the lightweight digital camera to your pet's collar and you'll be able to take up to 40 photos to document their shenanigans. The camera has an auto interval mode that can be set to snap pictures at 1, 5 or 15 minute intervals. At 640 x 480 resolution the quality isn't too shabby either. All that's left for you to do is hook up the camera to your PC or Mac and check out what sort of mischief Rover and Tiddles have been getting up to in your absence.

      Features:

      * A mini digital camera that can be attached to your pet's collar.
      * Take up to 40 pictures of your pet's secret life.
      * Use only with flat nylon webbing or flat leather belt collars of at least 9.5mm wide (not included).
      * TO AVOID CHOKING HAZARD DO NOT USE WITH CHAIN OR ROLLED COLLARS.
      * Auto Interval setting allows you to set the camera to take shots at 1, 5 or 15 minute intervals. To conserve battery the camera will go into sleep mode between shots.
      * The camera takes 4" by 6" shots in 640 x 480 resolution.
      * The camera recharges via USB.
      * Requires Microsoft 2000 or higher/Mac OSX and above.
      * Includes Lithium Ion rechargeable battery.
      * Suitable for pets, though may be best if it is put on said pet by a human, aged 8 years+.
      * Size: 10 x 5 x 4cm.

      Pet's Eye View Camera lets you explore the secret life of your pet.