SDA India is an online resource for Software, Development,IT, Architecture, Open Source, Mobile, Security, Databases, Delphi, C, OS, Asp, .Net, Php, Xml, Java

Enterprise solutions Enterprise IT Architecture Information Security Wireless And Mobility Hardware & Networking Data & Storage
Average Rating Rate this article Poor Below Average Average Good Excellent
1 2 3 4 5
Microsoft’s Security Release Addresses Four Vulnerabilities



Microsoft, this week, has issued security bulletins and patches for four vulnerabilities. Three of the flaws, in Microsoft Word, Publisher and the Jet database engine, are critical in at least some configurations. The fourth details a moderate vulnerability in Microsoft's Malware Protection Engine, which powers products like Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security.

MS08-026 fixes two privately reported holes in Word that could have been allowed an attacker to take control of a victim's computer using a maliciously crafted Word file. The second bulletin, MS08-027, describes a flaw in Microsoft Publisher which sounds very similar to one of the Word vulnerabilities. It too is critical on Publisher 2000 and less so on other versions because of the Confirmation Tool.

MS08-028 repairs a publicly reported flaw in the Microsoft Jet Database Engine (4.0) in Windows. If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code, mitigated by the user's administrative rights.

Finally, security researchers had concerns regarding patches for two vulnerabilities in the Microsoft Malware Protection Engine. While the error was rated "moderate," an unpatched vulnerability provides a remote attacker the potential to compromise malware protection applications. By creating a malicious file, an individual could clog up the system with a denial of service attack, which could cause the Malware Protection Engine to stop scanning infected files.

Commenting on the release of these patches, Amol Sarwate, vulnerability lab manager at Qualys, said that though these bugs are considered to be only a moderate risk, system administrators should take them seriously.

He further added saying that, "If someone sends a malformed e-mail and that is processed by any of these antivirus and antispyware products, it would cause the product to crash. If you can crash security software that is supposed to protect you, then you are left with no protection at all.”



Post a Comment
Name
Title
Comment
From the News Desk
Sprint Nextel has signed on several companies for its new location-enabled …
Zimbra, a Yahoo company, and an open source software developer, has …
In a recent announcement Fujitsu said that it has chosen Tata …
The Mozilla Foundation has released a very early prototype of mash-up …
Excellon Software, a company that specializes in software for managing chain …
According to the high-tech market research firm, In-Stat, cable telephony subscriber …
Analyst firm Gartner has positioned Wipro Technologies as ‘strong positive’ in …
Articles

Today we have easy access to software products in the market, with just a single degree of separation between the producer and the consumer. This has created new opportunities as well as problems, foremost among them being counterfeiting and piracy.Emerging and Existing Forms of PiracyIn 1929, Edwin Hubble, discovered …

Coping with a sea of data Enterprise backup policies haven’t evolved all that much in recent years. Backup data is still, for the most part, written to magnetic tape each night, duplicated and then sent off-site to meet disaster recovery needs. Of course, disk already plays a role in …

Mashups comes into picture when there is a demand in today’s global environment, a web site that should have the power of drawing upon content and functionality retrieved from external data sources with no organizational boundaries. Mashups are of-course a new bread of web based integrating data from the applications that …
Interviews

We are currently in the process of developing an Enterprise Information Management suite that would enable efficient management of both the structured and unstructured data of large organizations and provide a personalized digital dashboard to all the stakeholders to view critical reports and important documents. SDA-India.com in conversation with Mr Shastri, Chairman and Managing …

Microsoft Tech Day is an event of technology & only for technologists! Events like these add new dimensions to Sapient Technology Practice and solidify Sapient delivery capabilities in Microsoft Technology. SDA-India.com sits with Mr. Sandeep Dhar, Managing Director, Sapient, to know more about MS Tech days and how significant is the relationship between Sapient and Microsoft. …

Imagine data intensive enterprises like BFSI, IT and Telecom where huge amounts of data are churned everyday. In these enterprises, data changes often and the amount of stored data is large. In the event of lost data, damaged files, or extended downtime, this could lead to business getting affected. Mr. Basant Rajan, CTO India, Symantec Corporation, talks to SDA-India.com, enlightening our readership on the benefits of Back …
RSS
more »                                   
Menu
News Desk
Feature Stories
Articles
Interviews
Case Studies
White Paper
Analyst Corner
Planet SDA-India
SDA Events
INDIA IT Event Calender
IT Jobs
Advertise