Archive for July 10th, 2011

Safety notice: MS11-006; Knowledge base Numbers: KB2483185; Levels: critical

Description: this patch to repair the Office 2010 Windows shell image processing components of a has been publicly disclosed when there is a security hole, the vulnerability of the users browse the attacker carefully constructed thumbnail, may cause the attacker malicious code enforced, install malicious programs or steal, distort the user privacy data.

Influence operating system: Windows XP / 2003 / Vista / 2008

4, Microsoft Internet information services (IIS) remote FTP server code execution holes

Safety notice: MS11-004; Knowledge base Numbers: KB2489256; Levels: critical

Description: this patch repair Microsoft Office 2007 Internet information services (IIS) FTP server to exist in a place of components has been publicly disclosed when there is a security hole, the vulnerability of the IIS FTP server received an attacker carefully constructed FTP command, and will lead to attack the malicious code on the server are implemented, install malicious programs or steal, tamper with the user data.

Influence operating system: Microsoft Office 2007 Windows Vista / 2008 / Windows 7

5, Microsoft active directory remote denial of service holes

Safety notice: MS11-005; Knowledge base Numbers: KB2478953; Levels: important

Description: this patch repair Microsoft active directory exists in the one place has been publicly disclosed security hole, the attacker may be sent through special packet to the existence of loopholes of the server, lead to the server refused to service.

 

According to Microsoft practice, its official website in the release of the initial patch, will first report to the vulnerability of the Office 2007 public institutions or individuals thanks to them. So far, 360 security center is domestic only won the honor of the personal computer security vendors. In previous July 2009, 360 for independent found "DirectShow video setups" loophole obtain Microsoft vote of thanks.

Add: Microsoft patch information in February 2011

1, Windows kernel permissions ascension holes (Windows "elders" holes)

Safety notice: MS11-011; Knowledge base Numbers: KB2393802; Levels: important

Description: this patch to repair the Microsoft Office 2007 Windows kernel a point has been publicly disclosed security hole and a secret report security flaws have invaded the attacker may use system these bugs, further improve access control over the system.

Influence operating system: Windows XP / 2003 / Vista / 2008 / Windows 7

2, IE browser cumulative security update (IE "Christmas" holes)

Safety notice: MS11-003; Knowledge base Numbers: KB2482017; Levels: critical

Description: this patch to repair IE browser the existence of two place has been publicly disclosed in two security vulnerabilities and Office 2010 secret report security hole, when the vulnerability of the existing users browse the attacker carefully construction site, may cause the attacker malicious code enforced, install malicious programs or steal, distort the user privacy data.

Operating system and software version influence: Windows XP / 2003 / Vista / 2008 / Windows 7 IE6 / IE7 / IE8