100 likes | 215 Vues
On Tuesday, a significant security update was rolled out, addressing 32 vulnerabilities across various software and systems. Among these, 9 were rated as critical, affecting essential Windows components and applications like Internet Explorer, Microsoft Office, and Adobe products. With threats ranging from remote code execution to elevation of privilege, users are urged to apply the updates promptly. The release also includes updates for MSRT, Defender definitions, and several browser vulnerabilities. Stay protected by updating your systems regularly.
E N D
Patch Tuesday • 15 Patches / 32 Vulns – 9 Critical • Affecting most everything • Other updates, MSRT, Defender Definitions, Junk Mail Filter • MS10-046 - Windows Shell, Remote Code Execution (out of Band) • MS10-047 - Windows Kernel, Elevation of Privilege • MS10-048 - Windows Kernel-Mode Drivers, Elevation of Privilege (exploit) • MS10-049 – Schannel, Remote Code Execution • MS10-050 - Windows Movie Maker, Remote Code Execution • MS10-051 - Microsoft XML Core Services, Remote Code Execution • MS10-052 - Microsoft MPEG Layer-3 Codecs, Remote Code Execution • MS10-053 - Cumulative Security Update for Internet Explorer • MS10-054 - SMB Server Could Allow Remote Code Execution • MS10-055 - Cinepak Codec Could Allow Remote Code Execution • MS10-056 - Microsoft Office Word, Remote Code Execution • MS10-057 - Microsoft Office Excel, Remote Code Execution • MS10-058 - Vulnerabilities in TCP/IP, Elevation of Privilege • MS10-059 - Vulnerabilities in the Tracing Feature for Services Could Allow an Elevation of Privilege (982799) • MS10-060 - Microsoft .NET Common Language Runtime and in Microsoft Silverlight, Remote Code Execution
Holes / Patches • Adobe, 2 patches • APSA10-16, Flash Player • APSA10-17, Adobe Reader and Acrobat • APSA10-18, ColdFusion (hotfix update) • APSA10-19, Flash Media Server • Apple, • iTune 9.2.1 • Safari 5.0.1 • Cisco • 9 patches, multiple products • ASA, SNMPv3, FWSM • Browsers • Firefox 3.6.8, Chrome, Opera
Hacking / Holes • Open LDAP • slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22
Corp. Hell • Securita vs. Sourcefire. • To thread an IDS or not to thread • Apple to force iAds??? • Vote Fraud in S. Carolina • ES&S machines
Papers Verizon 2010 Breach Report
Updates snorby 1.4 snort / sourcfire new rule categories damn vuln linux nmap dc edition 5.35DC1
Con Pwnies (redsand thought he had one) Hacking Recapthca with 30% return Hacking ATMs, full stealth control
Future Con Software Freedom Day 18 Sept 2010
All images scavenged without permission All images scavenged without permission