Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Chicks just love a Geek in Uniform.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. Smart Defrag
2. GS Auto Clicker
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. Visual C++ Redistributable Runtimes AIO Repack
7. K-Lite Mega Codec Pack
8. ImgBurn
9. Unlocker
10. Format Factory
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » April 2013 » Microsoft Expected to Patch Pwn2Own IE Vulnerabilities

Microsoft Expected to Patch Pwn2Own IE Vulnerabilities


Contributed by: Email on 04/04/2013 03:17 PM [ comments Comments ]


Appropriately enough for the start of the baseball season, Microsoft is going to go 4-for-4 and release another set of critical Internet Explorer patches on Tuesday, the fourth consecutive month in which serious vulnerabilities in the browser are being addressed in Microsoft’s Patch Tuesday monthly security updates.

The browser patches are expected to address vulnerabilities first brought to light and exploited last month during the Pwn2Own contest at the CanSecWest Conference. All three major browsers—IE, Mozilla Firefox and Google Chrome—were taken down with zero-day exploits during the contest. Mozilla and Google issued patches for the vulnerabilities within 24 hours. IE users have been exposed since the March 7 contest, however details on the IE bugs have not been publicly disclosed.

“Even with their new, more aggressive IE patch cadence they’re still behind other browsers that don’t stick to a monthly patch schedule,” said Andrew Storms, director of security operations at security company nCircle. “This probably isn’t a huge problem for enterprise security teams because the bug hasn’t been publicly released.”

IE has been a vehicle for many noteworthy attacks this year, including a series of watering hole attacks against human rights and political organizations that exploited zero-day vulnerabilities in IE. Those vulnerabilities were patched in an out-of-band security update.

Next week’s patches address remote code execution vulnerabilities rated critical in IE 10 on Windows 8 systems, IE 8 and 9 on Windows 7, IE 7 and 8 for Vista and IE 6, 7 and 8 on Windows XP.

The out-of-band patch fixed memory corruption vulnerabilities in the browser that were exploited in watering hole attacks against the Council of Foreign Relations website, as well as number of manufacturing and human rights sites. The emergency repair was necessitated when hackers were able to bypass a Fix It mitigation provided by Microsoft.

Shortly thereafter in February’s security update release, additional IE vulnerabilities in versions 6-10 were patched, including one being exploited in the wild.

Last month, Microsoft released a cumulative update for the browser, and came a few days after IE 10 running on a Windows 8 machine was compromised at Pwn2Own. The IE patches repaired nine use-after free vulnerabilities, one of which was being exploited in targeted attacks.

The IE update is one of two critical bulletins expected next week. The second addresses remote code execution vulnerabilities in Windows.

Seven other bulletins are expected next week, all of them rated important, including an information disclosure flaw in Microsoft Office and Microsoft SharePoint Server 2013, the company said.

The remaining important bulletins are privilege escalation vulnerabilities in Windows, Microsoft Office Web Apps 2010 Service Pack 1, Microsoft SharePoint Server 2010 Service Pack 1, Microsoft Groove Server 2010 Service Pack 1 and Windows Defender for Windows 8 and Windows RT.

“The number of bulletins isn’t the only factor IT security teams consider when they review a patch so, even though the overall patch count is a little higher than average this month and only two of the bulletins merit a critical rating, it’s too early to assume it’s going to be an easy month,” Storms said.






« Skype, Dropbox Patch Critical Facebook Authentication Bugs · Microsoft Expected to Patch Pwn2Own IE Vulnerabilities · Diamond Multimedia VideoStream - WPCTVPRO @ Bjorn3D »




Comments
comments powered by Disqus

MajorGeeks.Com » News » April 2013 » Microsoft Expected to Patch Pwn2Own IE Vulnerabilities

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition