MCSE Forum - German Windows 2000/XP/2003/2008/Windows Vista und Windows 7 - IT Community Board
Werbung
Zurück   MCSE Forum - German Windows 2000/XP/2003/2008/Windows Vista und Windows 7 - IT Community Board > Internet, Netzwerk & Co > Firewalling | Security | Netzwerk allg. > Securitymeldungen
Seite neu laden Alert - Microsoft Security Advisory 960906 Released
Spenden

Login
Benutzername:
Kennwort:


Werbung


Statistik
Themen: 26020
Beiträge: 43231
Benutzer: 3,521
Produkte: 1
Links: 1
Wir begrüßen unseren neuesten Benutzer: darkarchon
Mit 901 Benutzern waren die meisten Benutzer gleichzeitig online (05.04.2008 um 14:21).
Neue Benutzer:
01.08.2011
- darkarchon
27.07.2011
- kirvad
26.07.2011
- Mama1970
21.06.2011
- quam2000
21.06.2011
- amandany67...

hawaiihabi (45), Roteiro-Ball (44), antixp (42), Wasi (42), Puppet675 (33), werty (33), AchGehZu (29)

Antwort
 
LinkBack Themen-Optionen Ansicht
  (#1 (permalink)) Alt
Administrator
 
Benutzerbild von Jochen
 
Beiträge: 4,146
Registriert seit: 18.06.2003
Ort: Essen
Standard Alert - Microsoft Security Advisory 960906 Released - 18.12.2008, 11:15

Microsoft untersucht derzeit neue Berichte über eine mögliche Sicherheitsanfälligkeit im WordPad Text Converter für Word 97.
Weitere Infos findet Ihr in der Mail unten (engl.) oder in den nächsten Tagen auf http://www.microsoft.com/germany/tec...n/default.mspx (dt).

_________________________________

What is the purpose of this alert?
This alert is to notify you that Microsoft has released Security Advisory 960906 - Vulnerability in WordPad Text Converter Could Allow Remote Code Execution - on December 9, 2008.

Summary

Microsoft is investigating new reports of a vulnerability in the WordPad Text Converter for Word 97 files on Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2.

Windows XP Service Pack 3, Windows Vista, and Windows Server 2008 are not affected as these operating systems do not contain the vulnerable code.

Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability. Additionally, as the issue has not been publicly disclosed broadly, we believe the risk at this time to be limited.

Mitigating Factors

* This issue does not affect Windows XP Service Pack 3, Windows Vista, and Windows Server 2008.

* An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

* The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful, a user must open an attachment that is sent in an e-mail message.

* When Microsoft Office Word is installed, Word 97 documents are by default opened using Microsoft Office Word, which is not affected by this vulnerability. However, an attacker could rename a malicious file to have a Windows Write (.wri) extension, which would still invoke WordPad. This file type can be blocked at the Internet perimeter.

Recommendations

Review Microsoft Security Advisory 960906 for an overview of the issue, details on affected components, mitigating factors, suggested actions, frequently asked questions (FAQ), and links to additional resources.

Customers who believe they are affected can contact Customer Service and Support. Contact CSS in North America for help with security update issues or viruses at no charge using the PC Safety line (866)PCSAFETY. International customers can contact Customer Service and Support by using any method found at this location: http://www.microsoft.com/protect/support/default.mspx (click on the select your region hyperlink in the first paragraph).

Additional Resources

* Microsoft Security Advisory 960906 - Vulnerability in WordPad Text Converter Could Allow Remote Code Execution - http://www.microsoft.com/technet/sec...ry/960906.mspx.

* Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc.

Regarding Information Consistency

We strive to provide you with accurate information in static (this mail) and dynamic (Web-based) content. Microsoft's security content posted to the Web is occasionally updated to reflect late-breaking information. If this results in an inconsistency between the information here and the information in Microsoft's Web-based security content, the information in Microsoft's Web-based security content is authoritative.

If you have any questions regarding this alert please contact your Technical Account Manager or Application Development Consultant.

Thank you,
Microsoft CSS Security Team


Bitte beachten, das hier Braindumps unerwünscht sieht. Sie dazu auch hier!
Mit Zitat antworten
Sponsored Links
Antwort

Lesezeichen

Themen-Optionen
Ansicht

Forumregeln
Es ist Ihnen nicht erlaubt, neue Themen zu verfassen.
Es ist Ihnen nicht erlaubt, auf Beiträge zu antworten.
Es ist Ihnen nicht erlaubt, Anhänge hochzuladen.
Es ist Ihnen nicht erlaubt, Ihre Beiträge zu bearbeiten.

BB-Code ist an.
Smileys sind an.
[IMG] Code ist an.
HTML-Code ist aus.
Trackbacks are an
Pingbacks are an
Refbacks are an





Powered by vBulletin® Version 3.8.7 (Deutsch)
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.5.0 RC2
Powered by vBCMS® 2.7.1 ©2002 - 2012 vbdesigns.de
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122