KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows 7 RTM 7600.16385.090713-1255 HERE !

How to activate Windows 7 RC build 7600, 7264, 7231 and olders


Microsoft patches critical Windows kernel flaw

section: microsoft, for your questions: KezNews forum, 11.3.2009

    Tip: Click here to update all your PC's outdated drivers

Microsoft patched critical vulnerabilities in the Windows kernel that could be remotely exploited by an attacker to gain control of a computer. In all three bulletins patching eight Windows flaws were released Tuesday as part of Microsoft's monthly patching cycle.




Microsoft's MS09-006 bulletin is rated critical for Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008. The kernel contains three vulnerabilities, a remote code execution vulnerability, rated critical, and two elevation of privilege vulnerabilities, rated important. Validation errors in the kernel graphics rendering component could be exploited to install programs; view, change, or delete data; or create new accounts with full user rights.

An end user can fall victim to an attack by opening a malicious email attachment or browsing to a malicious website that contains a malicious .WMF or .EMF picture file. But Microsoft gives the flaw a "3" on its exploitability index, indicating that exploit code is unlikely in the wild, said Andrew Storms, director of security operations at security and compliance auditing vendor nCircle Network Security Inc..

"Microsoft is saying that it's a pretty darn critical and nasty bug in Windows and easy to get users to go to a malicious website, but the exploit index says its more than likely not going to happen because it's very difficult to exploit this piece of code," Storms said. "It's still important to get it patched."

The MS09-007 bulletin is rated important and addresses a vulnerability in authentication handling of Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. The vulnerability is within Microsoft Windows Secure Channel, which processes SSL and TLS digital signatures. The update corrects the way Secure Channel parses key exchange data during the TLS handshake. A similar vulnerability was updated by Microsoft in 2007

source: searchsecurity.techtarget.com

  >> Click Here to Run a Free Scan for PC Errors <<

send email Send link 2 friend  |  Permalink
<< previouse article
Side by side: UI changes from Windows 7 beta to build 7048
next article >>
Critical Security Update for Windows 7 Beta

MORE RELATED ARTICLES:
No Critical Patches for Vista SP2 || Windows 7 Kernel version remains unchanged - still 7.0 || Microsoft patches 31 Windows, IE, Office security holes || Microsoft backpedals on UAC flaw || Microsoft to supply ALL patches to All users

Comments(0)


No new comments are allowed for this article.

For your questions use our KezNews Forum