Microsoft patched a critical vulnerability in Windows
Network Administration - Microsoft patched three vulnerabilities in Windows yesterday, one of which could be exploited by attacks that trick users into accessing malicious websites.
Microsoft also introduced a new prevention method to help users avoid attacks exploiting known vulnerabilities in IE.
It is known that users only need to download two security upgrades, or two bulletin boards by Microsoft, which were announced last week, which is an easier start in the beginning of this year compared to the month At the end of 2010, in that period Microsoft released a record number of 17 upgrades to patch for nearly 40 errors.
One of the two errors was classified as "critical" by Microsoft, while the other one was marked as 'important', the risk ranked second in the evaluation list.
MS11-002 is a security upgrade that researchers and Microsoft encourage users to use first. This upgrade will fix 'critical' and 'important' vulnerabilities.
' Newcomers can exploit the' critical 'vulnerability in MS11-002 by tricking users into browsing a malicious Web site ,' said Amol Sarwate, the center's director of research on Qualys's vulnerability. said so. This is a form of attack still called "drive-by", the attack is based on enticing users to click on a link provided in a fake email.
An error in the Microsoft Data Access Components (MDAC) components , a set of components that leads Windows access databases such as Microsoft SQL Server. The error here lies inside the MDAC ActiveX driver, allowing users to access databases from within IE.
Only users who are using the new IE browser are at risk when the attacker exploits the 'critical' vulnerability that Microsoft announced in MS11-002, both Sarwate and Andrew Storms, security operations director of nCircle Security. all said so.
Microsoft has also encouraged its customers to use MS11-002 first, noting that all client versions of Windows, including Service Pack 3 (SP3), Vista and Windows 7 are vulnerable. The server operating system versions are also vulnerable, but Microsoft only evaluates server operating system vulnerabilities at 'important'.
Surely hackers will use authentic attack code to exploit the vulnerabilities patched by MS11-002 in the next 30 days.
Another upgrade, available in MS11-001, is less important because it only applies to Windows Vista, Sarwate and Storms said.
Backup Manager error is one of the number of control errors loading dynamic DLL link library in Windows.
The patch for Vista today is known as the seventh patch that Microsoft has released to fix the bugs found by researchers in August. Microsoft released five patches to fix DLL hijacking errors last month, another patch was released in November.
You should read it
- Windows, Android and security intelligence issues
- Summary of popular network attacks today
- Warning: The number of vulnerabilities in open source software are increasing rapidly
- Viber has successfully overcome the lock screen error on Android
- Many serious vulnerabilities have been discovered that allow attackers to take full control of the 4G router
- 2011: malware transferred from computer to ... pocket pants
- The unsafe 'feature' on UC Browser allows hackers to take control of Android phones remotely
- New worm attacks attack dangerous Windows errors
May be interested
- Microsoft silently patched the KRACK WPA2 security holewhile other vendors are trying to release an update to patch the krack attack vulnerability yesterday, microsoft quietly corrected the problem in a patch last tuesday.
- The NSA issued an urgent warning about a critical vulnerability appearing in Windows serversthis is a vulnerability that exists in the cryptographic authentication scheme used by the netlogon remote protocol.
- Mozilla patches a vulnerability in Firefox that helps hackers gain admin rights of Windowsmozilla has just released a security update to patch a critical security vulnerability that allows hackers to escalate privileges on windows computers. this critical security flaw has been patched in the recently released version of firefox 97.
- Log4Shell zero-day vulnerability discovered, the new nightmare of enterpriseshow to exploit a critical zero-day vulnerability in the java-based apache log4j logging library has just been posted on the internet. this leaves users and businesses as well as organizations vulnerable to remote code execution attacks.
- Microsoft discovered a critical vulnerability on macOSmicrosoft has just discovered a critical vulnerability in apple's macos. a new vulnerability called shrootless on macos discovered by microsoft is very serious.
- Microsoft has released a critical update for Windows 10, users need to update nowmicrosoft recently released a critical update for windows 10 as well as windows server 2016 and windows server 2019 to fix a security vulnerability discovered by the u.s. national security agency (nsa) on april 14. 1 past.
- Microsoft found a security bug so powerful that it could shut down a power plantmicrosoft has disclosed 15 critical vulnerabilities in its toolkit intended for industrial use. although exploiting this bug will be quite difficult, the risk of insecurity is very high, causing great damage to the targets.
- New privilege escalation vulnerability called 'Dirty Pipe' is threatening all Linux distrosrecently, security researcher max kellermann shared about a security flaw called 'dirty pipe'. it affects linux kernel 5.8 and above and even android devices.
- Microsoft released an emergency patch for Windows, turned off the Specter patch, causing a drop in system performancemicrosoft's newly released emergency update for windows has removed the patch for two serious vulnerabilities specter and meltdown released since the beginning of the month.
- Microsoft admits a new zero-day vulnerability threatens millions of Windows usersaccording to microsoft, this new zero-day vulnerability affects all versions of windows from windows 7 to windows 10 and corresponding versions of windows server.