isn
[Top] [All Lists]

[ISN] Microsoft issues emergency patch for 10 IE holes

To: isn@infosecnews.org
Subject: [ISN] Microsoft issues emergency patch for 10 IE holes
From: InfoSec News <alerts@infosecnews.org>
Date: Wed, 31 Mar 2010 00:00:23 -0600 (CST)
Delivered-to: isn@infosecnews.org
List-archive: <http://www.infosecnews.org/pipermail/isn>
List-help: <mailto:isn-request@infosecnews.org?subject=help>
List-id: InfoSec News <isn.infosecnews.org>
List-post: <mailto:isn@infosecnews.org>
List-subscribe: <http://www.infosecnews.org/mailman/listinfo/isn>, <mailto:isn-request@infosecnews.org?subject=subscribe>
List-unsubscribe: <http://www.infosecnews.org/mailman/listinfo/isn>, <mailto:isn-request@infosecnews.org?subject=unsubscribe>
Organization: InfoSec News - http://www.infosecnews.org/
http://news.cnet.com/8301-27080_3-20001428-245.html

By Elinor Mills
InSecurity Complex
CNet News
March 30, 2010

Microsoft issued an emergency security update on Tuesday to plug 10 
holes in Internet Explorer, including a critical vulnerability that has 
been exploited in attacks in the wild.

The cumulative update, which Microsoft announced on Monday, resolves 
nine privately reported flaws and one that was publicly disclosed. The 
most severe vulnerabilities could lead to remote code execution and a 
complete takeover of the computer if a user were to view a malicious Web 
site using IE, Microsoft said in the bulletin summary.

Users of IE8 and Windows 7 are not vulnerable to the flaw being used in 
specific attacks, according to Microsoft. However, software affected by 
the cumulative update addressing all the IE vulnerabilities includes 
Windows 2000, Windows XP, Windows Server 2003 and Server 2008, Vista, 
and Windows 7.

The security bulletin also includes two other bulletins rated 
"important" that patch a vulnerability in Windows Movie Maker and 
Microsoft Producer 2003, and seven vulnerabilities in Office Excel.

[...]



<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Microsoft issues emergency patch for 10 IE holes, InfoSec News <=