| Another month, another Windows patch - two, actually |
|
| by Stephen Withers | |
| Wednesday, 12 November 2008 | |
|
The worst case scenario is that a maliciously crafted web page displayed in Internet Explorer could cause remote code execution. The important bulletin relates to a single remote code execution vulnerability in the SMB protocol as implemented in Windows 2000, XP, Server 2003, Vista and Server 2008. It is a particular problem with XP, where it is common for SMB sharing to be enabled and administrator accounts are routinely used. The update improves the validation of SMB authentication replies to prevent the replay of credentials. Microsoft has warned that an XP exploit for this vulnerability is already publicly available. The company has also updated the Malicious Software Removal Tool and the Windows Mail Junk E-mail Filter.
Get stories like this delivered daily - FREE - subscribe now
|
| < Next story in category | Previous story in the category > |
|---|

TAG 
Tags




