Windows security flaw being exploited by cyber criminals got an urgent patch apart from November Patch Tuesday. Kerberos - an authentication system used by all versions of Microsoft Windows is responsible for the issue that allows remote attackers to gain elevated privileges of domain administrator. Microsoft advisory states, "A remote elevation of privilege vulnerability exists in implementations of Kerberos KDC in Microsoft Windows. The vulnerability exists when the Microsoft Kerberos KDC implementations fail to properly validate signatures, which can allow for certain aspects of a Kerberos service ticket to be forged." Microsoft credits information security and risk management team of Qualcomm for identifying the issue. According to company, Windows Server 2012 and Windows Server 2012 R2 machines are not prone to this vulnerability. Users are advised to apply the patch on earliest basis. <more>
Friday, November 28, 2014
Google patches 42 flaws for Chrome
Google rolls out Chrome 39.0.2171.65 that fixes 42 security flaws in the web browser. Google Chrome now supports Apple Mac OS X running on 64-bit. Google has rewarded $41,500 to cyber security researchers for 12 security flaws reported. Researcher identified as "biloulehibou" got the highest reward of $7,500 for finding out an issue related to Adobe Flash player used in Chrome. Adobe advisory covered this issue under "double-free" vulnerability that allows intruders to execute arbitrary code. Chen Zhang of the NSFocus Security Team rewarded $5,500 for finding two bugs in the Blink rendering engine and Pepper plug-in interface used by Chrome. These issues are related to use-after-free vulnerabilities that allow remote code execution or possibly crash the vulnerable application. Latest version of Google Chrome disable fallback support for SSL 3.0 due to POODLE vulnerability. <more>
Friday, November 21, 2014
BIG Patch Tuesday fixes 33 vulns
November Patch Tuesday contains 14 security bulletins providing fixes for 33 vulnerabilities affecting all versions of Windows. Out of 14 bulletins, 4 bulletins are rated 'CRITICAL' whereas 8 bulletins declared 'Important' and the remaining 2 bulletins indicate moderate level severity. MS14-065 bulletin addresses 17 vulnerabilities affecting Internet Explorer. Most of the vulns are related to memory corruption and allows remote code execution by enticing a user to view malformed webpage. A vulnerability related to OLE which was previously exploited during Sandworm campaign is also patched under the CVE-2014-6352. A security flaw in the TCP/IP stack in Windows Server that allows remote attackers to execute arbitrary code on the vulnerable system is also patched along with other security bypass and privilege escalation issues. <more>
Subscribe to:
Posts (Atom)