SDA India is an online resource for Software, Development,IT, Architecture, Open Source, Mobile, Security, Databases, Delphi, C, OS, Asp, .Net, Php, Xml, Java

Average Rating Rate this article Poor Below Average Average Good Excellent
1 2 3 4 5
Microsoft’s Security Release Addresses Four Vulnerabilities



Microsoft, this week, has issued security bulletins and patches for four vulnerabilities. Three of the flaws, in Microsoft Word, Publisher and the Jet database engine, are critical in at least some configurations. The fourth details a moderate vulnerability in Microsoft's Malware Protection Engine, which powers products like Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security.

MS08-026 fixes two privately reported holes in Word that could have been allowed an attacker to take control of a victim's computer using a maliciously crafted Word file. The second bulletin, MS08-027, describes a flaw in Microsoft Publisher which sounds very similar to one of the Word vulnerabilities. It too is critical on Publisher 2000 and less so on other versions because of the Confirmation Tool.

MS08-028 repairs a publicly reported flaw in the Microsoft Jet Database Engine (4.0) in Windows. If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code, mitigated by the user's administrative rights.

Finally, security researchers had concerns regarding patches for two vulnerabilities in the Microsoft Malware Protection Engine. While the error was rated "moderate," an unpatched vulnerability provides a remote attacker the potential to compromise malware protection applications. By creating a malicious file, an individual could clog up the system with a denial of service attack, which could cause the Malware Protection Engine to stop scanning infected files.

Commenting on the release of these patches, Amol Sarwate, vulnerability lab manager at Qualys, said that though these bugs are considered to be only a moderate risk, system administrators should take them seriously.

He further added saying that, "If someone sends a malformed e-mail and that is processed by any of these antivirus and antispyware products, it would cause the product to crash. If you can crash security software that is supposed to protect you, then you are left with no protection at all.”



Post a Comment
Name
Title
Comment
From the News Desk
Microsoft this week announced that it has sold 28 million units …
In a recent announcement LG Electronics said that it would launch …
AMD and HP have jointly announced the immediate addition of the …
Comodo, a provider of Identity and Trust Assurance Internet Services, has …
LG Electronics Asia has announced the appointment of marketing veterans Arthur …
Sun Microsystems India and Indian Institute of Technology (IIT) recently announced …
In a joint announcement Citigroup (Citi), the global financial services company, …
Articles

Enterprises today are heterogeneous in nature comprising of legacy and modern systems. To remain competitive integration of applications within a business or between different businesses must be done quickly and cost effectively. However it is a complex task requiring diverse, heterogeneous applications, developed in different architectures and programming languages …

Your proof of concept is complete. You’re confident a service-oriented architecture (SOA) approach will make your IT department more responsive to business needs and better able to deliver positive business outcomes. But how do you start?Because of the inherent complexity and broad impact of an SOA implementation, a centralized …

SOA is hot and being an expert in SOA can be a ramp up for a successful career in the international IT market. But what do companies expect from a SOA expert? Are special skills needed which differ from general IT skills? How important is process and industry experience to be …
Interviews

SOA is a principle of creating software functions as services, to enable alignment of business processes and related IT assets to meet change in business needs, leading to business agility, reduction in time to IT and cost to IT. SDA-India.com in conversation with Mr. K.R.Sanjiv on how does Service Oriented Architecture contribute to business …

Agile is a set of principles and practices for how to develop software and Scrum is a management methodology for implementing agile principles. SDA-India.com in conversation with Mr. John Scumniotales, VP of ALM Products, Serena Software. …

We are currently in the process of developing an Enterprise Information Management suite that would enable efficient management of both the structured and unstructured data of large organizations and provide a personalized digital dashboard to all the stakeholders to view critical reports and important documents. SDA-India.com in conversation with Mr Shastri, Chairman and Managing …
RSS
more »                                   
Menu
News Desk
Feature Stories
Articles
Interviews
Case Studies
White Paper
Analyst Corner
Planet SDA-India
SDA Events
INDIA IT Event Calender
IT Jobs
Advertise