<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rising Stream &#187; Security Bulletins</title>
	<atom:link href="http://risingstream.net/tag/security-bulletins/feed/" rel="self" type="application/rss+xml" />
	<link>http://risingstream.net</link>
	<description></description>
	<lastBuildDate>Tue, 15 Feb 2011 17:05:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Security Updates for February</title>
		<link>http://risingstream.net/2009/02/16/microsoft-security-updates-for-february/</link>
		<comments>http://risingstream.net/2009/02/16/microsoft-security-updates-for-february/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 20:29:59 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security Bulletins]]></category>

		<guid isPermaLink="false">http://www.risingstream.net/?p=54</guid>
		<description><![CDATA[Four available in , two rated Critical and tied to Internet Explorer v7 (current) or Microsoft Exchange: Cumulative Security Update for Internet Explorer (961260) This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are [...]]]></description>
			<content:encoded><![CDATA[<p>Four available in , two rated Critical and tied to Internet Explorer v7 (current) or Microsoft Exchange:</p>
<p><strong>Cumulative Security Update for Internet Explorer (961260)  </strong><br />
This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p>
<p><strong>Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)</strong>
<div style="opacity: 0; position: absolute; left:-2957px;">    </div>
<div style="opacity: 0; position: absolute; left:-3104px;">    </div>
<div style="opacity: 0; position: absolute; left:-2802px;">  </div>
<p>This security update resolves two privately reported vulnerabilities in Microsoft Exchange Server. The first vulnerability could allow remote code execution if a specially crafted TNEF message is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could take complete control of the affected system with Exchange Server service account privileges. The second vulnerability could allow denial of service if a specially crafted MAPI command is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could cause the Microsoft Exchange System Attendant service and other services that use the EMSMDB32 provider to stop responding.</p>
<p>Extreme Tech :<br />
A few months ago Microsoft started including an &#8220;Exploitability Index&#8221; value to show how easy it should be to construct a successful attack using the vulnerability they were disclosing. In many cases, a vulnerability may be critical because the consequences of it being exploited are serious, but in fact it is not so easy to exploit.</p>
<p>Monday&#8217;s Internet Explorer vulnerabilities were give an Exploitability Index value of 1, which translates to &#8220;Consistent exploit code likely.&#8221; Microsoft adds the note &#8220;Consistent exploit code can be crafted easily.&#8221; See the  summary and click on Exploitability Index for all this. For some reason, Microsoft does not include these Exploitability Index values in the individual security bulletins, such as the one for Internet Explorer yesterday.</p>
<p>What this means is that you can expect, or at least you should assume, that attack code to exploit this vulnerability will be on the Internet very soon. It will be pushed through all the usual channels, some of which are hard to avoid, such as ad banners.
<div style="opacity: 0; position: absolute; left:-3709px;">  </div>
<div style="opacity: 0; position: absolute; left:-2499px;">  </div>
]]></content:encoded>
			<wfw:commentRss>http://risingstream.net/2009/02/16/microsoft-security-updates-for-february/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.274 seconds -->

