Jump to content
Fi8sVrs

Microsoft security patches

Recommended Posts

  • Active Members
Posted

This month’s patch batch contains 7 new Microsoft Security Bulletins.

Network%20Windows%20Security%20Warning.jpg


MS12-001
Windows Kernel SafeSEH Bypass Vulnerability
MS12-001 Introduces a new “Security Impact” type to the Microsoft Bulletins, “Security Feature Bypass”. This issue is a bypass of the SafeSEH setting on software compiled with Microsoft Visual C++ .NET 2003. In order to make use of it, there must also be a vulnerability in your compiled software. The bypass exists within Windows, and compiled software will not need to be recompiled.


MS12-002
Object Packager Insecure Executable Launching Vulnerability
MS12-002 Similar to the DLL preloading attack, except with Executables rather than DLLs, which means SafeDllSearchMode cannot help mitigate this issue. The issue applies to Microsoft Publisher (.PUB) files, where an attacker could place a malicious file in the same directory as a .PUB file.


MS12-003
CSRSS Elevation of Privilege Vulnerability
MS12-003 Affects the Windows Client Server Runtime Subsystem (CSRSS) on double-byte (Unicode) locale (such as Chinese, Japanese, or Korean system locales). Keep in mind that the locale on any system can be changed, so this patch should be applied regardless of the current locale.


MS12-004

  • DirectShow Remote Code Execution Vulnerability
    MS12-004 This patch contains two fixes for all except Windows 7 systems. One for DirectShow.


  • MIDI Remote Code Execution Vulnerability
    One for the Windows Multimedia Library. This is the only critical patch for the month, providing a potential drive-by vector related to MIDI files.


MS12-005
Assembly Execution Vulnerability
MS12-005 This patch fixes an issue related to malicious EXEs deployed as a ClickOnce application and embedded within Office Documents.


MS12-006
SSL and TLS Protocols Vulnerability
MS12-006 This patch fixes the well known “BEAST” vulnerability. Apply this patch as soon as possible.


MS12-007
AntiXSS Library Bypass Vulnerability
MS12-007 This patch resolves a bypass in the Microsoft AntiXSS Library similar to MS12-001. Although this should be in the new “Security Feature Bypass” category, the impact is considered Information Disclosure. Again when combined with a flaw in the website that lies behind the AntiXSS library, this vulnerability could be dangerous.

As always, these patches should be tested and implemented as quickly as possible.

VIA: https://kohi10.wordpress.com/2012/01/10/january-2012-microsoft-patches/

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...