Microsoft is going to fix two critical Vulnerabilities this Tuesday

Please find the details below:

Microsoft will release just two security updates next Patch Tuesday,
the 11th of May. The updates will fix a vulnerability in Windows and a
vulnerability in Office and Visual Basic for Applications. Microsoft
say only the bugs in Windows and VBA are rated critical. The operating
system bug is also present in Windows 7 and Server 2008, but cannot be
exploited under the default installation of these operating systems.
The cross-site scripting vulnerability in SharePoint will remain
unpatched. It can be exploited by attackers to read authentication
cookies, manipulate user accounts or access confidential data.
However, users do have to click on a crafted link to fall victim to
this attack.
According to Microsoft, the problem does not arise with Internet
Explorer 8, as it contains an XSS filter which detects and blocks the
attack. Until the patch is deployed, Microsoft is advising users to
block access to the script in question.

Demo:
According to Microsoft, administrators can do so by executing the
following commands on a SharePoint server:
cacls "%ProgramFiles%\Common Files\Microsoft Shared\Web Server
Extensions\12\TEMPLATE\LAYOUTS\Help.aspx" /E /P everyone:N
cacls "%ProgramFiles(x86)%\Common Files\Microsoft Shared\Web Server
Extensions\12\TEMPLATE\LAYOUTS\Help.aspx" /E /P everyone:N


Source: http://www.microsoft.com/technet/security/bulletin/ms10-may.mspx

Regards,
0xN41K

-- 
You received this message because you are subscribed to the Google Groups 
"nforceit" group.
To post to this group, send an email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/nforceit?hl=en-GB.

Reply via email to