Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Read more »Vuln: Microsoft DirectX DirectShow Length Record Remote Code Execution Vulnerability
Vuln: Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnerability
Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnerability
Read more »Microsoft Fixes Nine Flaws in Monthly Patch Release
Microsoft patched nine vulnerabilities this month for Patch Tuesday. Among them are two critical flaws that have come under attack by hackers. - Microsoft released six security bulletins for this months Patch Tuesday, including fixes for vulnerabilities impacting DirectShow and the Video ActiveX Control that have been targeted by attackers.
The bulletins address a total of nine vulnerabilities. Three of the bulletins the ones affecting...
Vuln: Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerability
Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerability
Read more »Microsoft Patches Nine Security Flaws
Microsoft Corp. today issued software updates to plug at least nine different security holes in its various Windows operating systems and other software. Today's patch batch includes fixes for two very serious flaws that are actively being exploited by attackers to break into vulnerable PCs. Redmond issued patches to fix the vulnerability in itsVideo ActiveX Control for Internet Explorer, as well as the DirectShow flaw in Windows. Criminals currently are using both security holes to plant rogue software on PCs when users visit certain hacked or malicious Web sites. Contrary to what Microsoft itself said, the company did not release an official patch to plug the other ActiveX flaw hackers are actively exploiting -- which I first wrote about yesterday. Instead, it has released an interim workaround to blunt the threat from that weakness. Unfortunately, someone at Redmond seems to be a little confused about this point. In its advisory,
Microsoft repairs critical DirectShow, Video ActiveX vulnerabilities
The software giant issued six updates this week as part of its Patch Tuesday updates. Three bulletins were rated critical.
Read more »Bugtraq: ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability
ZDI-09-045: Microsoft DirectShow Quicktime Atom Parsing Memory Corruption Vulnerability
Read more »Vuln: Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability
Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability
Read more »Bugtraq: TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability
TPTI-09-05: Microsoft DirectShow QuickTime Atom Parsing Memory Corruption Vulnerability
Read more »Vuln: Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vulnerability
Read more »