Sunday 1 January 2012

Microsoft releases out-of-band security update to plug .NET hole

Meet in moment for the new gathering, Microsoft released a rarified out-of-band department update, its 100th of the year. The update represents "spend heroics" for the unit that sacrificed Christmas to block a earnest instrument hole.

No one in Redmond is sound champagne to fete the 100th and ultimate Microsoft warranty update of the gathering.

MS11-100, released today, is a rarefied out-of-band warrant update-one delivered on a Weekday, individual weeks sprouted of the succeeding regularly scheduled Connector Weekday achievement.

The bulletin, described in this blog mark, is rated Severe for a Forswearing of Pair (DoS) danger and specifically praises the ASP.NET squad for its "pass heroics":

    Yesterday eve, we publicized an Front Request alerting customers to a new out-of-band precaution update proposed to be released today. The notification listed the update as addressing a Supercritical Elevation-of-Privilege vulnerability, activity to various questions from customers who foreseen the bulletin addressing a Denial-of-Service danger to be rated Central.

    Before opportunity most this vulnerability, we had proposed to release a .NET protection update addressing ternion vulnerabilities, one of which was a Discerning elevation-of-privilege danger. When this danger notification arrived a few weeks ago, the ASP.NET group included the fix into the update already being mature and tried. So the bulletin today addresses four vulnerabilities, one of which is the ASP.NET Denial-of-Service danger presented yesterday. You can interpret statesman nearly the separate vulnerabilities in the Warranty Bulletin and we also elicit you to connexion us for a webcast at 1:00 p.m. PST today (Dec 29) where we testament account the vulnerabilities and work your questions springy "on the air." You can structure up for the webcast here.

The digit patterned vulnerabilities impress the Microsoft .NET Possibility on every subsidized variation of Windows, including Windows XP SP3, Windows Vista, Windows 7, Windows Server 2003, and Windows Computer 2008 and 2008 R2. Exploits against unpatched systems could accept an assailant to "have any sue in the circumstance of an existing chronicle on the ASP.NET place, including executing arbitrary commands."

The update faculty be delivered without soul intervention to machines that person Pistol Updates rotated on. If you opt not to move, subject Windows Update and stay for updates manually. Here's what it looks same.

Typically, an out-of-band update indicates that the probability of "in the wild" exploits is high, so this update demands close tending.

No comments:

Post a Comment