Microsoft patched 15 bugs, continued to patch SSL certificates
TipsMake.com - Microsoft finally released an update patch after 4 days of leaked details.
The company also added a solution to the DigiNotar hacking by "kill switch" on the SSL (secure socket layer) certificate provided by DigiNotar (CA) security vendor.
However, news about 5 updates or 15 bugs that Microsoft released yesterday is not new: last Friday, the company leaked information about security bulletins, the term Microsoft used. for instructions included with each update.
All updates and vulnerabilities are rated as important, the second highest in the company's rating system.
2 of these vulnerabilities are in Windows; 5 in Excel - spreadsheet included in Office office applications; 2 vulnerabilities in non-Office applications; and the remaining 6 vulnerabilities affect SharePoint and other software, such as Groove and Office Web Apps.
Of the 15 vulnerabilities, there are two " DLL load hijacking " vulnerabilities, a term used to describe a type of error that has occurred since August 2010. Microsoft patched its software to solve this problem.
Obviously, this work has not been completed yet because Microsoft has not closed the 2010 consulting channel to warn users about DLL load hijacking vulnerabilities in its software.
According to security experts, the user update should be deployed first MS11-072.
This is a release containing vulnerability patches for all versions of Excel, including Excel 2010 on Windows and Excel 2011 on Mac.
When asked about which update deserves the top spot on the list, Andrew Storms, director of security operations at nCircle Security, said: ' That is an update to Excel because that is the direction. Public through the file has been changed '.
Other experts also agree with the above opinion.
Wolfgang Kandek, chief technology officer of Qualys security firm, said: ' The first priority should be on MS11-072, a patch that will help resolve pseudo executable code in Excel files. It affects all versions of Excel, including the most recent version of Excel 2010. To exploit this problem, hackers will create Excel files that contain malicious code and when opened on vulnerable hosts. , it will gain control of the system '.
Kurt Baumgartner, Kaspersky Lab's security expert, added: ' Excel-related attachments and links are often used to attack organizations and it deserves us to be of top concern '.
Other updates patched in WINS (Windows Internet Name Service), a component of Windows Server that was patched last May; and fix script vulnerabilities in SharePoint Server 2010.
Along with 5 updates, Microsoft provides another update to deal with the theft of more than 500 electronic certificates from DigiNotar (CA) security vendor.
According to Pete Voss, Microsoft Trustworthy Computing group expert, ' We also released another update, adding 6 original DigiNotar certificates for Untrusted Certificate Store (unsafe certification repository) " .
DigiNotar's signed certificates are then signed by another CA (in this case Entrust or GTE) to allow them to be used by Windows computers or browsers that are not yet authenticated. DigiNotar.
According to Storms, the certificates issued by Entrust or GTE will not affect this update.
Earlier, Microsoft and its competitors, such as Google, Mozilla or Apple, "competed" to ban or block DigiNotar certificates. September security patches can be downloaded and installed through Microsoft Update and Windows Update services, as well as through Windows Server Update Services.
You should read it
- Microsoft account enhances two-layer security
- Apple 'launched' a patch to deal with DigiNotar
- Questions that help you check your Facebook account's security knowledge
- Authenticate what two factors are and why you should use it
- Instructions for enabling 2-layer authentication for iCloud on Apple devices
- More than 90% of Gmail users still don't use the two-factor authentication feature
- Google: 2-factor authentication can prevent 100% of automated bot hacks
- Applications create authentication codes on Windows 10
May be interested
- Microsoft has just patched a critical security hole in Windows 10 discovered in 2018in patch tuesday released august 2020, microsoft patched a vulnerability that allowed hackers to turn msi files into java files that could spread malicious code on windows 10. and more importantly, malicious files. this harm retains the legal digital signature.
- Microsoft fixes 28 Windows and Office security bugsthe december security update with a total of 28 patched security bugs has become the largest security update in the last 5 years
- Top highest paid IT certificatesto get a job with a high salary in the information technology (it) field, candidates will need different qualifications and qualifications depending on their specific positions, this is required!
- Microsoft releases urgent patch for printer error emergency patchthe patch for microsoft's printer vulnerability on windows again caused an error, forcing the company to issue another urgent patch.
- Microsoft provides February patch to terminate 22 errorsyesterday, microsoft released 12 security updates and 22 bugs in windows, internet explorer (ie), office and its internet server software.
- Microsoft provides security patches for Windows, IEyesterday (april 12), microsoft provided a record patch package, up to 64 patches for windows, office, internet explorer (ie), and other software, including 30 bugs in windows and an error. in ie.
- What types of SSL Certificates are there?globalsign is the first ssl provider to provide simple ssl certificate - neat and simple in 3 ssl classes defined domain domain validation (dv), organization validation (ov) and extended validation (ev). with 15 years of experience in providing reliable ssl solutions, globalsign has pioneered and is one of the simplest methods for 3 classes of ssl to emerge in recent years.
- PrintNightMare vulnerability patch is flawed, attackers can still 'break through'yesterday, microsoft released a patch for the printnightmare zero-day vulnerability. this bug allows attackers to remotely execute code on fully patched print spooler devices.
- Apple 'launched' a patch to deal with DigiNotarapple has just released a security update for os x 10.6 snow leopard and os x 10.7 lion, in which the most important content to fix a potentially inherent vulnerability ...
- The Trojan Fire Zero-Day attacks Microsoft Wordattackers are exploiting the latest patch that has not been patched in microsoft word 2000. security experts warn of a growing threat.