Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Sunday, November 22, 2009

Microsoft Internet Explorer CSS Handling Code Execution Vulnerability (0day)

Title : Microsoft Internet Explorer CSS Handling Code Execution Vulnerability (0day)
VUPEN ID : VUPEN/ADV-2009-3301
CVE ID : GENERIC-MAP-NOMATCH
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-11-21




A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the "getElementsByTagName()" method, which could allow attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a malicious web page.

VUPEN has confirmed the vulnerability on fully patched Windows XP SP3 systems with Internet Explorer 7 and 6.

Affected Products

Microsoft Internet Explorer 7
Microsoft Internet Explorer 6

Solution

Disable Active Scripting in the Internet and Local intranet security zones.

VUPEN Security is not aware of any vendor-supplied patch.

References

http://www.vupen.com/english/advisories/2009/3301

Friday, October 30, 2009

New Vulnerabilities Microsoft / Adobe

* Microsoft .NET Framework Remote Code Execution Exploit (MS09-061)

This remote code execution exploit takes advantage of a vulnerability
in Microsoft .NET Framework when processing certain code e.g. in
a XAML browser application (XBAP).

CVE ID: CVE-2009-0091


* Adobe Reader U3D Clod Declaration Code Execution Exploit (APSB09-15)

This code execution exploit takes advantage of an array indexing
vulnerability in Adobe Reader when processing U3D Clod Declarations
within a PDF file.

CVE ID: CVE-2009-2994


* Microsoft Internet Explorer Remote Memory Corruption PoC (MS09-052)

This code demonstrates a memory corruption vulnerability in Microsoft
Internet Explorer when processing certain HTML elements.


CVE ID: CVE-2009-2531

Thursday, August 13, 2009

Microsoft ordered to stop selling Word

* By Trudy Walsh
* Aug 12, 2009

"A federal court in Texas has ordered Microsoft to stop selling Microsoft Word.

Judge Leonard Davis of the U.S. District Court for the Eastern District of Texas, Tyler Division, ruled yesterday in favor of Toronto-based i4i, stating that Microsoft unlawfully infringed the Canadian company’s patent.

At a jury trial that began on May 11, representatives for i4i said that Microsoft’s use of Word 2007 for processing XML documents with custom XML elements “willfully” infringed i4i’s Patent 449.

The ruling prohibits Microsoft from selling or importing to the U.S. any Word products that have the capability of opening XML, .DOCX or DOCM files that contain custom XML.

The ruling is set to go into effect in 60 days. The judge has also granted an award and damages of $290 million to i4i."

More on FCW's

Monday, July 13, 2009

Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution

Microsoft is investigating a privately reported vulnerability in Microsoft Video ActiveX Control. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.

We are aware of attacks attempting to exploit the vulnerability.

Our investigation has shown that there are no by-design uses for this ActiveX Control in Internet Explorer which includes all of the Class Identifiers within the msvidctl.dll that hosts this ActiveX Control. For Windows XP and Windows Server 2003 customers, Microsoft is recommending removing support for this ActiveX Control within Internet Explorer using all the Class Identifiers listed in the Workaround section. Though unaffected by this vulnerability, Microsoft is recommending that Windows Vista and Windows Server 2008 customers remove support for this ActiveX Control within Internet Explorer using the same Class Identifiers as a defense-in-depth measure.

Read more...

Saturday, May 30, 2009

Critical Windows vulnerability under attack, Microsoft warns

Posted in Anti-Virus, 28th May 2009 22:37 GMT

Microsoft has warned of a critical security bug in older versions of its Windows operating system that is already being exploited in the wild to remotely execute malware on vulnerable machines.

The vulnerability in a Windows component known as DirectX is being targeted using booby-trapped QuickTime files, which when parsed can allow attackers to gain complete control of a computer. Because many browsers are designed to automatically play video, people can be compromised simply by visiting a site serving malicious files. Vista, Windows Server 2008 and the beta version of Windows 7 are not affected, and neither is Apple's QuickTime player, Microsoft said.


Read more...

Hack the Box Blue

https://arcy24.medium.com/hack-the-box-blue-f5ae5b602a5c