Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

Just when you thought things couldn't get Geekier - MajorGeeks.Com.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. Mozilla Firefox
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » April 2013 » Microsoft Expected to Patch Pwn2Own IE Vulnerabilities

Microsoft Expected to Patch Pwn2Own IE Vulnerabilities


Contributed by: Email on 04/04/2013 03:17 PM [ comments Comments ]


Appropriately enough for the start of the baseball season, Microsoft is going to go 4-for-4 and release another set of critical Internet Explorer patches on Tuesday, the fourth consecutive month in which serious vulnerabilities in the browser are being addressed in Microsoft’s Patch Tuesday monthly security updates.

The browser patches are expected to address vulnerabilities first brought to light and exploited last month during the Pwn2Own contest at the CanSecWest Conference. All three major browsers—IE, Mozilla Firefox and Google Chrome—were taken down with zero-day exploits during the contest. Mozilla and Google issued patches for the vulnerabilities within 24 hours. IE users have been exposed since the March 7 contest, however details on the IE bugs have not been publicly disclosed.

“Even with their new, more aggressive IE patch cadence they’re still behind other browsers that don’t stick to a monthly patch schedule,” said Andrew Storms, director of security operations at security company nCircle. “This probably isn’t a huge problem for enterprise security teams because the bug hasn’t been publicly released.”

IE has been a vehicle for many noteworthy attacks this year, including a series of watering hole attacks against human rights and political organizations that exploited zero-day vulnerabilities in IE. Those vulnerabilities were patched in an out-of-band security update.

Next week’s patches address remote code execution vulnerabilities rated critical in IE 10 on Windows 8 systems, IE 8 and 9 on Windows 7, IE 7 and 8 for Vista and IE 6, 7 and 8 on Windows XP.

The out-of-band patch fixed memory corruption vulnerabilities in the browser that were exploited in watering hole attacks against the Council of Foreign Relations website, as well as number of manufacturing and human rights sites. The emergency repair was necessitated when hackers were able to bypass a Fix It mitigation provided by Microsoft.

Shortly thereafter in February’s security update release, additional IE vulnerabilities in versions 6-10 were patched, including one being exploited in the wild.

Last month, Microsoft released a cumulative update for the browser, and came a few days after IE 10 running on a Windows 8 machine was compromised at Pwn2Own. The IE patches repaired nine use-after free vulnerabilities, one of which was being exploited in targeted attacks.

The IE update is one of two critical bulletins expected next week. The second addresses remote code execution vulnerabilities in Windows.

Seven other bulletins are expected next week, all of them rated important, including an information disclosure flaw in Microsoft Office and Microsoft SharePoint Server 2013, the company said.

The remaining important bulletins are privilege escalation vulnerabilities in Windows, Microsoft Office Web Apps 2010 Service Pack 1, Microsoft SharePoint Server 2010 Service Pack 1, Microsoft Groove Server 2010 Service Pack 1 and Windows Defender for Windows 8 and Windows RT.

“The number of bulletins isn’t the only factor IT security teams consider when they review a patch so, even though the overall patch count is a little higher than average this month and only two of the bulletins merit a critical rating, it’s too early to assume it’s going to be an easy month,” Storms said.






« Skype, Dropbox Patch Critical Facebook Authentication Bugs · Microsoft Expected to Patch Pwn2Own IE Vulnerabilities · Diamond Multimedia VideoStream - WPCTVPRO @ Bjorn3D »




Comments
comments powered by Disqus

MajorGeeks.Com » News » April 2013 » Microsoft Expected to Patch Pwn2Own IE Vulnerabilities

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition