<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>US-CERT Technical Cyber Security Alerts</title>
  <id>http://www.us-cert.gov/</id>
  <author>
<name>US-CERT</name>
<email>info@us-cert.gov</email>
<uri>http://www.us-cert.gov</uri>
</author>
  <rights>Produced 2010 by US-CERT, a government organization.</rights>
  <subtitle>US-CERT Technical Cyber Security Alerts provide timely
information about current security issues, vulnerabilities, and
exploits.</subtitle>
  <updated>2010-03-09T21:42:24Z</updated>
  <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas" hreflang="en"/>
  <link type="application/atom+xml" rel="self" href="http://www.us-cert.gov/cas/techalerts.atom" hreflang="en"/>
  <entry>
    <title>TA10-068A: Microsoft Updates for Multiple Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-068A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: March 09, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul> <li>Microsoft Windows</li><li>Microsoft Office</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released updates to address vulnerabilities in Microsoft
Windows and Microsoft Office.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft has released security bulletins for multiple vulnerabilities in
Microsoft Movie Maker, Microsoft Office Producer 2003, and Microsoft Office
Excel. These bulletins are described in the <a href="http://www.microsoft.com/technet/security/bulletin/MS10-mar.mspx">Microsoft
Security Bulletin Summary for March 2010</a>. Microsoft notes that affected
versions of Microsoft Movie Maker were either included with Microsoft Windows or
available as an optional download.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>A remote, unauthenticated attacker could execute arbitrary code or cause a
vulnerable application to crash.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates from Microsoft</strong><br/> <br/> Microsoft has
provided updates for these vulnerabilities in the <a href="http://www.microsoft.com/technet/security/bulletin/MS10-mar.mspx">Microsoft
Security Bulletin Summary for March 2010</a>. The security bulletin describes
any known issues related to the updates. Administrators are encouraged to note
these issues and test for any potentially adverse effects. Administrators should
consider using an automated update distribution system such as <a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">Windows
Server Update Services</a> (WSUS).</p> <p>Microsoft notes that there is no
security update available for Microsoft Producer 2003 at this time of this
writing. Users can mitigate the impact to systems with Microsoft Producer 2003
by applying the automated solution to remove the Microsoft Producer file
associations using the Fix it found in <a href="http://support.microsoft.com/kb/975561">Microsoft Knowledge Base Article
975561</a>, and by applying the workarounds in <a href="http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx">Microsoft
Security Bulletin MS10-016</a>.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin Summary for March 2010 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/MS10-mar.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-mar.mspx</a>&gt;</li><li>Microsoft
Windows Server Update Services - &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li><li>Microsoft
Knowledge Base Article 975561 - &lt;<a href="http://support.microsoft.com/kb/975561">http://support.microsoft.com/kb/975561</a>&gt;</li><li>Microsoft
Security Bulletin MS10-016 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-068A%20Feedback%20VU#586853">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>March 09, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-03-09T21:42:24Z</updated>
    <published>2010-03-09T21:42:24Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-068A.html"/>
  </entry>
  <entry>
    <title>TA10-055A: Malicious Activity Associated with &amp;quot;Aurora&amp;quot; Internet Explorer Exploit</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-055A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: February 24, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul><li>Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000
Service Pack 4</li><li>Microsoft Internet Explorer 6, 7, and 8 on supported
editions of Windows XP, Windows Server 2003, Windows Vista, Windows 2008,
Windows 7, and Windows Server 2008 R2</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Malicious activity detected in mid-December targeted at least 20
organizations representing multiple industries including chemical, finance,
information technology, and media.  Investigation into this activity
revealed that third parties routinely accessed the personal email accounts of
dozens of users based in the United States, China, and Europe. Further analysis
revealed these users were victims of previous phishing scams through which
threat actors successfully gained access to their email accounts.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Through analysis of the malware used in this incident, McAfee discovered one
of the malware samples exploited a vulnerability in Microsoft Internet Explorer
(IE). The vulnerability exists as an invalid pointer reference within IE and, if
successfully exploited, allows for remote code execution.</p><p>Microsoft has
released Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">MS10-002</a>,
which provides updates for Internet Explorer that address this and other
vulnerabilities.</p><p>US-CERT is providing technical indicators that can be
incorporated into an organization's security posture to detect and
mitigate any malicious activity.</p><p>In addition to the discovery of the IE
exploit, the following malicious domains were identified as associated with this
incident:</p> <table cellspacing="0" border="1"> <tbody><tr> <th>Domain</th>
<th>IP Resolution as of 15 January</th> <th>Notes</th> </tr> <tr>
<td>blogspot[dot]blogsite[dot]org</td> <td>209[dot]200[dot]236[dot]253</td>
<td>IP address hosts at least 4 domains</td> </tr> <tr> <td>voanews[dot]
ath[dot]cx</td> <td>200[dot]55[dot]186[dot]66</td> <td> </td> </tr> <tr>
<td>ymail[dot]ath[dot]cx</td> <td>59[dot]36[dot]101[dot]217</td> <td>IP address
hosts at least 3 domains</td> </tr> <tr> <td>tyuqwer[dot]dyndns[dot]org</td>
<td>75[dot]101[dot]212[dot]55</td> <td> </td> </tr> <tr>
<td>google[dot]homeunix[dot]com</td> <td>173[dot]201[dot]21[dot]161</td>
<td> </td> </tr> <tr> <td>ftp2[dot]homeunix[dot]com</td>
<td>127[dot]0[dot]0[dot]2</td> <td>Domain resolution indicative of offline site
status. Call-back discovered through analysis of malware file AppMgmt.dll</td>
</tr> <tr> <td>360[dot]homeunix[dot]com</td> <td>127[dot]0[dot]0[dot]2</td>
<td>Domain resolution indicative of offline site status. Call-back domain
discovered through analysis of malware file rasmon.dll</td> </tr> <tr>
<td>update[dot]ourhobby[dot]com</td> <td>127[dot]0[dot]0[dot]1</td> <td>Domain
resolution indicative of offline site status. Call-back discovered through
analysis of malware file securmon.dll</td> </tr> <tr>
<td>demo1[dot]ftpaccess[dot]cc/demo/ad[dot]jpg</td>
<td>127[dot]0[dot]0[dot]2</td> <td>Domain resolution indicative of offline site
status</td> </tr> <tr> <td>360[dot]homeunix[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>ad01[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>ads1[dot]homelinux[dot]org</td> <td> </td>
<td> </td> </tr> <tr> <td>ads1[dot]webhop[dot]org</td> <td> </td>
<td> </td> </tr> <tr> <td>Aep[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>Aka[dot]homeunix[dot]net</td> <td> </td>
<td> </td> </tr> <tr> <td>alt1[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>Amd[dot]homeunix[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>amt1[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>amt1[dot]homeunix[dot]org</td> <td> </td>
<td> </td> </tr> <tr> <td>aop01[dot]homeunix[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>aop1[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>app1[dot]homelinux[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>asic1[dot]homeunix[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>Bbsnewss[dot]ath[dot]cx</td> <td> </td>
<td> </td> </tr> <tr> <td>Bdc[dot]homeunix[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>blog1[dot]servebeer[dot]com</td> <td> </td>
<td> </td> </tr> <tr> <td>Connectproxy[dot]3322[dot]org</td>
<td> </td> <td> </td> </tr> <tr> <td>Corel[dot]ftpaccess[dot]cc</td>
<td> </td> <td> </td> </tr> <tr> <td>Csport[dot]2288[dot]org</td>
<td> </td> <td> </td> </tr> <tr> <td>ddd1[dot]homelinux[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>demo1[dot]ftpaccess[dot]cc</td>
<td> </td> <td> </td> </tr> <tr> <td>du1[dot]homeunix[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>Filoups[dot]info</td>
<td> </td> <td> </td> </tr> <tr> <td>fl12[dot]ftpaccess[dot]cc</td>
<td> </td> <td> </td> </tr> <tr> <td>ftp1[dot]ftpaccess[dot]cc</td>
<td> </td> <td> </td> </tr> <tr> <td>ftp2[dot]homeunix[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>Ftpaccess[dot]cc</td>
<td> </td> <td> </td> </tr> <tr> <td>hho1[dot]homeunix[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>hp1[dot]homelinux[dot]org</td>
<td> </td> <td> </td> </tr> <tr> <td>i1024[dot]homelinux[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>i1024[dot]homeunix[dot]org</td>
<td> </td> <td> </td> </tr> <tr> <td>Ice[dot]game-host[dot]org</td>
<td> </td> <td> </td> </tr> <tr> <td>il01[dot]homeunix[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>il01[dot]servebbs[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>il02[dot]servebbs[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>il03[dot]servebbs[dot]com</td>
<td> </td> <td> </td> </tr> <tr> <td>Jlop[dot]homeunix[dot]com</td>
<td> </td> <td> </td> </tr> <tr>
<td>li107-40[dot]members[dot]linode[dot]com</td> <td> </td> <td> </td>
</tr> <tr> <td>lih001[dot]webhop[dot]net</td> <td> </td> <td> </td>
</tr> <tr> <td>lih002[dot]webhop[dot]net</td> <td> </td> <td> </td>
</tr> <tr> <td>lih003[dot]webhop[dot]net</td> <td> </td> <td> </td>
</tr> <tr> <td>list1[dot]homelinux[dot]org</td> <td> </td> <td> </td>
</tr> <tr> <td>live1[dot]webhop[dot]org</td> <td> </td> <td> </td>
</tr> <tr> <td>Members[dot]linode[dot]com</td> <td> </td> <td> </td>
</tr> <tr> <td>on1[dot]homeunix[dot]com</td> <td> </td> <td> </td>
</tr> <tr> <td>Patch[dot]homeunix[dot]org</td> <td> </td> <td> </td>
</tr> <tr> <td>patch1[dot]ath[dot]cx</td> <td> </td> <td> </td> </tr>
<tr> <td>patch1[dot]gotdns[dot]org</td> <td> </td> <td> </td> </tr>
<tr> <td>patch1[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr>
<tr> <td>ppp1[dot]ftpaccess[dot]cc</td> <td> </td> <td> </td> </tr>
<tr> <td>sc01[dot]webhop[dot]biz</td> <td> </td> <td> </td> </tr> <tr>
<td>sl1[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr> <tr>
<td>temp1[dot]homeunix[dot]com</td> <td> </td> <td> </td> </tr> <tr>
<td>Tor[dot]homeunix[dot]com</td> <td> </td> <td> </td> </tr> <tr>
<td>ttt1[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr> <tr>
<td>up01[dot]homelinux[dot]com</td> <td> </td> <td> </td> </tr> <tr>
<td>up1[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr> <tr>
<td>up1[dot]mine[dot]nu</td> <td> </td> <td> </td> </tr> <tr>
<td>up1[dot]serveftp[dot]net</td> <td> </td> <td> </td> </tr> <tr>
<td>up2[dot]mine[dot]nu</td> <td> </td> <td> </td> </tr> <tr>
<td>Update[dot]ourhobby[dot]com</td> <td> </td> <td> </td> </tr> <tr>
<td>update1[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr>
<tr> <td>update1[dot]merseine[dot]nu</td> <td> </td> <td> </td> </tr>
<tr> <td>vm01[dot]homeunix[dot]com</td> <td> </td> <td> </td> </tr>
<tr> <td>Voanews[dot]ath[dot]cx</td> <td> </td> <td> </td> </tr> <tr>
<td>Vvpatch[dot]homelinux[dot]org</td> <td> </td> <td> </td> </tr>
<tr> <td>war1[dot]game-host[dot]org</td> <td> </td> <td> </td> </tr>
<tr> <td>Webswan[dot]33iqst[dot]com</td> <td> </td> <td> </td> </tr>
<tr> <td>Xil[dot]homeunix[dot]com</td> <td> </td> <td> </td> </tr>
<tr> <td>Yahoo[dot]8866[dot]org</td> <td> </td> <td> </td> </tr> <tr>
<td>Yahoo[dot]8866[dot]org</td> <td> </td> <td> </td> </tr>
</tbody></table> <p>McAfee provided several IP addresses involved in the
incident:</p> <p><code>69[dot]164[dot]192[dot]46 <br/>
69[dot]164[dot]192[dot]0/24 <br/> 72[dot]32[dot]6[dot]235 <br/>
203[dot]69[dot]40[dot]128/27 <br/> 203[dot]69[dot]41[dot]0/26 <br/>
203[dot]69[dot]41[dot]64/27 <br/> 203[dot]69[dot]66[dot]0/27 <br/>
203[dot]69[dot]68[dot]96/27 <br/> 203[dot]69[dot]68[dot]128/25 <br/>
168[dot]95[dot]1[dot]1</code> -- Call-back IP address discovered in file
rasmon.dll.</p> <p>The table below contains the file characteristics of the
malware analyzed:</p> <table cellspacing="0" border="1"> <tbody><tr> <th>File
Name</th> <th>IPs/Domains</th> <th>File Details</th> <th>Description</th> </tr>
<tr> <td>uploaded_data</td> <td> </td> <td>MD5:
1AEA206AA64EBEABB07237F1E2230D0F Byte Size: 17310</td> <td>ASCII text, with very
long lines, with CRLF line terminators</td></tr> <tr> <td>securmon.dll</td>
<td>call-back: update[dot]ourhobby[dot]com:443</td> <td>MD5:
E3798C71D25816611A4CAB031AE3C27A Byte Size: 62464</td> <td>MS-DOS executable PE
for MS Windows (DLL) (GUI) Intel 80386 32-bit</td></tr> <tr> <td>Rasmon.dll</td>
<td>call-backs: 360[dot]homeunix[dot]com:443, 168.95.1.1:DNS</td> <td>MD5:
0F9C5408335833E72FE73E6166B5A01B Byte Size: 90112</td> <td>Path:
C:Windows\system32\Rasmon.dll Type: MS-DOS executable PE for MS Windows (DLL)
(GUI) Intel 80386 32-bit Installs as service that begins with "UPS",
followed by a random string. Example: Upskvk command-line:
C:\WINDOWS\System32\svchost.exe -k SysIns</td></tr> <tr> <td>ad_1_.jpg</td>
<td> </td> <td>MD5: CD36A3071A315C3BE6AC3366D80BB59C Byte Size: 34816</td>
<td>Appears to be packed executable. Significant portion of file is XOR'd
0x95</td></tr> <tr> <td>b.exe</td> <td> </td> <td>MD5:
9F880AC607CBD7CDFFFA609C5883C708 Byte Size: 34816</td> <td>MS-DOS executable PE
for MS Windows (GUI) Intel 80386 32-bit, UPX compressed Drops:
Rasmon.dll</td></tr> <tr> <td>cdef</td> <td> </td> <td>MD5:
29F52213E171C3D4B4418939D9E466C3 Byte Size: 41984</td> <td>MS-DOS executable PE
for MS Windows (GUI) Intel 80386 32-bit Drops: AppMgmt.dll</td></tr> <tr>
<td>AppMgmt.dll</td> <td>call-backs: ftp2[dot]homeunix[dot]com:443</td> <td>MD5:
6A89FBE7B0D526E3D97B0DA8418BF851 Byte Size: 31744</td> <td>MS-DOS executable PE
for MS Windows (DLL) (GUI) Intel 80386 32-bit. Installs as service
"Application Management"</td></tr> <tr> <td>A0029670.dll</td>
<td> </td> <td>MD5: 3A33013A47C5DD8D1B92A4CFDCDA3765 Byte Size: 90112</td>
<td>MS-DOS executable PE for MS Windows (DLL) (GUI) Intel 80386 32-bit</td></tr>
<tr> <td>msconfig32.sys</td> <td> </td> <td>MD5:
7A62295F70642FEDF0D5A5637FEB7986</td> <td> </td></tr> <tr>
<td>VedioDriver.dll</td> <td> </td> <td>MD5:
467EEF090DEB3517F05A48310FCFD4EE</td> <td> </td></tr> <tr>
<td>acelpvc.dll</td> <td> </td> <td>MD5:
4A47404FC21FFF4A1BC492F9CD23139C</td> <td> </td></tr> <tr>
<td>wuauclt.exe</td> <td> </td> <td>MD5:
69BAF3C6D3A8D41B789526BA72C79C2D</td> <td> </td></tr> <tr>
<td>jucheck.exe</td> <td> </td> <td>MD5:
79ABBA920201031147566F5418E45F34</td> <td> </td></tr> <tr>
<td>AdobeUpdateManager.exe</td> <td> </td> <td>MD5:
9A7FCEE7FF6035B141390204613209DA</td> <td> </td></tr> <tr>
<td>zf32.dll</td> <td> </td> <td>MD5: EB4ECA9943DA94E09D22134EA20DC602</td>
<td> </td></tr> </tbody></table> <p>The following signatures can be
deployed to assist in detecting malicious activity associated with this
incident:</p><p>Primary Malware Beacon</p><p><code>alert tcp any any -&gt; any
any (msg:"Targeted Malware Communication Beacon Detected";
flow:to_server,established; dsize:20; content:"|ff ff ff ff ff ff 00 00 fe
ff ff ff ff ff ff ff ff ff 88 ff|"; depth:20; sid:7777777;
rev:1;)   </code></p><p>Secondary Malware Beacon</p><p><code>alert tcp
any any &lt;&gt; any any (msg:"ORC:DIS:BEACON_380DFF";
content:"|38 0d ff 0a d7 ee 9d d7 ec 59 13 56|"; sid:99980060;
rev:1;)</code></p><p><em><strong>Note: US-CERT has not verified or tested these
signatures and recommends proper testing prior to
deployment.</strong></em></p><p> </p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>By convincing a user to view a specially crafted HTML document or Microsoft
Office document, an attacker may be able to execute arbitrary code with the
privileges of the user.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p>The Internet Explorer vulnerability used in these attacks is addressed with
the updates provided in Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">MS10-002</a>.</p><p>Other
recommendations include:</p><ul><li>As a best practice, limit end-user
permissions on systems by granting minimal administrative rights.</li><li>Enable
Data Execution Prevention (DEP) for IE 6 Service Pack 2 or IE 7. IE 8
automatically enables DEP.</li><li>Inspect network traffic history for
communication with external systems associated with the attack.</li><li>Examine
computers for specific files or file attributes related to the attack.</li></ul>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>How Can I Tell if I Was Infected By Aurora? - &lt;<a href="http://www.mcafee.com/us/local_content/reports/how_can_u_tell.pdf">http://www.mcafee.com/us/local_content/reports/how_can_u_tell.pdf</a>&gt;</li><li>How
do I know if my organization has been infected? - &lt;<a href="http://www.mcafee.com/us/threat_center/aurora_enterprise.html">http://www.mcafee.com/us/threat_center/aurora_enterprise.html</a>&gt;</li><li>McAfee
Labs Tools Aurora Stinger 10.0.1.765 - &lt;<a href="http://download.nai.com/products/mcafee-avert/aurora_stinger.exe">http://download.nai.com/products/mcafee-avert/aurora_stinger.exe</a>&gt;</li><li>Operation
Aurora Hit Google, Others - &lt;<a href="http://siblog.mcafee.com/cto/operation-%25E2%2580%259Caurora%25E2%2580%259D-hit-google-others/">http://siblog.mcafee.com/cto/operation-%25E2%2580%259Caurora%25E2%2580%259D-hit-google-others/</a>&gt;</li><li>Vulnerability
in Internet Explorer Could Allow Remote Code Execution - &lt;<a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a>&gt;</li><li>Microsoft
Security Bulletin MS10-002 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-055A%20Feedback%20VU#492515">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>February 24, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-02-25T00:24:15Z</updated>
    <published>2010-02-25T00:24:15Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-055A.html"/>
  </entry>
  <entry>
    <title>TA10-040A: Microsoft Updates for Multiple Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-040A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: February 09, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul> <li>Microsoft Windows and Windows Server</li><li>Microsoft Internet
Explorer</li><li>Microsoft Office</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released updates to address vulnerabilities in Microsoft
Windows, Windows Server, Internet Explorer, and Microsoft Office.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft has released multiple security bulletins for critical
vulnerabilities in Microsoft Windows, Windows Server, Internet Explorer, and
Microsoft Office. These bulletins are described in the <a href="http://www.microsoft.com/technet/security/bulletin/MS10-feb.mspx">Microsoft
Security Bulletin Summary for February 2010</a>.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>A remote, unauthenticated attacker could execute arbitrary code, gain
elevated privileges, or cause a vulnerable application or system to crash.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates from Microsoft</strong><br/> <br/> Microsoft has
provided updates for these vulnerabilities in the <a href="http://www.microsoft.com/technet/security/bulletin/MS10-feb.mspx">Microsoft
Security Bulletin Summary for February 2010</a>. The security bulletin describes
any known issues related to the updates. Administrators are encouraged to note
these issues and test for any potentially adverse effects. Administrators should
consider using an automated update distribution system such as <a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">Windows
Server Update Services</a> (WSUS).</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin Summary for February 2010 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/MS10-feb.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-feb.mspx</a>&gt;</li><li>Microsoft
Windows Server Update Services - &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-040A%20Feedback%20VU#799780">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>February 09, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-02-09T20:47:41Z</updated>
    <published>2010-02-09T20:47:41Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-040A.html"/>
  </entry>
  <entry>
    <title>TA10-021A: Microsoft Internet Explorer Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-021A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: January 21, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul><li>Microsoft Internet Explorer</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released out-of-band updates to address critical
vulnerabilities in Internet Explorer.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft has released updates for multiple vulnerabilities in Internet
Explorer, including the vulnerability detailed in Microsoft Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">979352</a>
and US-CERT Vulnerability Note <a href="http://www.kb.cert.org/vuls/id/492515">VU#49251</a>.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>By convincing a user to view a specially crafted HTML document or Microsoft
Office document, an attacker may be able to execute arbitrary code with the
privileges of the user.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates</strong></p> <p>Microsoft has released updates to
address these vulnerabilities. Please see Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">MS10-002</a>
for more information.</p><p><strong>Apply workarounds</strong></p><p>Microsoft
has provided workarounds for some of the vulnerabilities in <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">MS10-002</a>.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin MS10-002 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a>&gt;</li><li>Microsoft
Security Advisory 979352 - &lt;<a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a>&gt;</li><li>US-CERT
Vulnerability Note VU#49251 - &lt;<a href="http://www.kb.cert.org/vuls/id/492515">http://www.kb.cert.org/vuls/id/492515</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-021A%20Feedback%20VU#49251">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>January 21, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-01-21T20:52:16Z</updated>
    <published>2010-01-21T20:52:16Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-021A.html"/>
  </entry>
  <entry>
    <title>TA10-013A: Adobe Reader and Acrobat Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-013A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: January 13, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul><li>Adobe Reader and Acrobat 9.2 and earlier 9.x versions</li><li>Adobe
Reader and Acrobat 8.1.7 and earlier 8.x versions</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Adobe has released Security bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">APSB10-02</a>,
which describes multiple vulnerabilities affecting Adobe Reader and
Acrobat.</p><p> </p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Adobe Security Advisory <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">APSB10-02</a>
describes a number of vulnerabilities affecting Adobe Reader and Acrobat. These
vulnerabilities affect Reader  9.2 and earlier 9.x versions and 8.1.7 and
earlier 8.x versions.  Further details are available in the US-CERT <a href="http://www.kb.cert.org/vuls/byid?searchview&amp;query=APSB10-02">Vulnerability
Notes Database</a>.</p> <p>An attacker could exploit these vulnerabilities by
convincing a user to open a specially crafted PDF file. The Adobe Reader browser
plug-in is available for multiple web browsers and operating systems, which can
automatically open PDF documents hosted on a website.</p><p>Some of these
vulnerabilities are being actively exploited.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>These vulnerabilities could allow a remote attacker to execute arbitrary
code, write arbitrary files or folders to the file system, escalate local
privileges, or cause a denial of service on an affected system as the result of
a user opening a malicious PDF document.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Update</strong></p><p>Adobe has released updates to address this
issue. Users are encouraged to read Adobe Security Bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">APSB10-02</a>
and update vulnerable versions of Adobe Reader and Acrobat.</p><p><b>Disable
JavaScript in Adobe Reader and Acrobat</b></p><p>Disabling JavaScript may
prevent some exploits from resulting in code execution. Acrobat JavaScript can
be disabled using the Preferences menu (<tt>Edit</tt> -&gt; <tt>Preferences</tt>
-&gt; <tt>JavaScript;</tt> un-check <tt>Enable Acrobat JavaScript</tt>).<br/>
<br/> <b>Prevent Internet Explorer from automatically opening PDF
documents</b><br/> <br/> The installer for Adobe Reader and Acrobat configures
Internet Explorer to automatically open PDF files without any user interaction.
This behavior can be reverted to a safer option that prompts the user by
importing the following as a .REG file:</p><p style="margin-left: 40px;"><tt>Windows Registry Editor Version 5.00<br/> <br/>[HKEY_CLASSES_ROOT\AcroExch.Document.7]<br/>"EditFlags"=hex:00,00,00,00</tt></p><p><b>Disable the display of PDF
documents in the web browser</b><br/> <br/> Preventing PDF documents from
opening inside a web browser will partially mitigate this vulnerability. If this
workaround is applied it may also mitigate future vulnerabilities.<br/> <br/>
To prevent PDF documents from automatically being opened in a web browser, do
the following:<br/> <br/> 1. Open Adobe Acrobat Reader.<br/> 2. Open the
<tt>Edit</tt> menu.<br/> 3. Choose the <tt>preferences</tt> option.<br/> 4.
Choose the <tt>Internet</tt> section.<br/> 5. Un-check the "<tt>Display
PDF in browser</tt>" check box.<br/> <br/> <b>Do not access PDF documents
from untrusted sources<br/> <br/> </b>Do not open unfamiliar or unexpected PDF
documents, particularly those hosted on websites or delivered as email
attachments. Please see Cyber Security Tip <a href="http://www.us-cert.gov/cas/tips/ST04-010.html">ST04-010</a>.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Adobe Security Bulletin APSB10-02 - &lt;<a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">http://www.adobe.com/support/security/bulletins/apsb10-02.html</a>&gt;</li><li>Vulnerability
Note VU#508357 - &lt;<a href="https://www.kb.cert.org/vuls/id/508357">https://www.kb.cert.org/vuls/id/508357</a>&gt;</li><li>Vulnerability
Note VU#773545 - &lt;<a href="https://www.kb.cert.org/vuls/id/773545">https://www.kb.cert.org/vuls/id/773545</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-013A%20Feedback%20VU#508357">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>January 13, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-01-13T21:04:47Z</updated>
    <published>2010-01-13T21:04:47Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-013A.html"/>
  </entry>
  <entry>
    <title>TA10-012B: Microsoft Windows EOT Font and Adobe Flash Player 6 Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-012B.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: January 12, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul> <li>Microsoft Windows and Internet Explorer</li><li>Adobe (Macromedia)
Flash Player 6</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released updates to address a vulnerability in the Windows
Embedded Open Type (EOT) font engine. Microsoft has also published an Advisory
about multiple vulnerabilities in Adobe (Macromedia) Flash Player 6 that is
included with Windows XP.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms10-001.mspx">MS10-001</a>
describes a vulnerability in the Embedded Open Type (EOT) font engine in
Windows. Microsoft Security Advisory (<a href="http://www.microsoft.com/technet/security/advisory/979267.mspx">979267</a>)
recommends that Windows XP users remove or upgrade Adobe Flash Player 6
(formerly Macromedia Flash Player) that is included with Windows XP.
Vulnerability Note <a href="http://www.kb.cert.org/vuls/id/204889">VU#204889</a>
discusses one vulnerability in Flash Player 6 and provides several
workarounds.</p><p>These vulnerabilities could be exploited by loading specially
crafted fonts or Flash content via Internet Explorer.</p><p>Microsoft assigns
the EOT font vulnerability a "low" severity rating in most current
versions of Windows and notes that reliable code execution is unlikely. The
severity rating for Windows 2000, however, is "critical."</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>A remote, unauthenticated attacker could execute arbitrary code, gain
elevated privileges, or cause a vulnerable application to crash.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates from Microsoft</strong><br/> <br/> Microsoft Security
Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms10-001.mspx">MS10-001</a>
provides updates for the EOT font vulnerability. The security bulletin describes
any known issues related to the updates. Administrators are encouraged to note
these issues and test for any potentially adverse effects. Administrators should
consider using an automated update distribution system such as <a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">Windows
Server Update Services</a> (WSUS).</p><p><strong>Upgrade, Remove, or Disable
Adobe Flash Player 6</strong></p><p>Adobe Flash Player 6 is included with
Windows XP. Adobe has addresssed these vulnerabilities in newer versions of
Flash Player. <a href="http://get.adobe.com/flashplayer/">Upgrade</a> to a more
recent version of Flash Player (such as Flash Player 10). Alternatively, <a href="http://kb2.adobe.com/cps/141/tn_14157.html">uninstall</a> Flash Player or
set the kill bit for the Flash Player ActiveX control as described in Microsoft
Security Advisory (<a href="http://www.microsoft.com/technet/security/advisory/979267.mspx">979267</a>)
and Vulnerability Note <a href="http://www.kb.cert.org/vuls/id/204889">VU#204889</a>.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin Summary for January 2010 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a>&gt;</li><li>Microsoft
Security Bulletin MS10-001 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-001.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-001.mspx</a>&gt;</li><li>MS10-001:
Font file decompression vulnerability - &lt;<a href="http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx">http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx</a>&gt;</li><li>CVE-2010-0018
- &lt;<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018">http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018</a>&gt;</li><li>Vulnerabilities
in Adobe Flash Player 6 Provided in Windows XP Could Allow Remote Code Execution
- &lt;<a href="http://www.microsoft.com/technet/security/advisory/979267.mspx">http://www.microsoft.com/technet/security/advisory/979267.mspx</a>&gt;</li><li>Vulnerability
Note VU#204889 - &lt;<a href="http://www.kb.cert.org/vuls/id/204889">http://www.kb.cert.org/vuls/id/204889</a>&gt;</li><li>Adobe
Flash Player - &lt;<a href="http://get.adobe.com/flashplayer/">http://get.adobe.com/flashplayer/</a>&gt;</li><li>How
to uninstall the Adobe Flash Player plug-in and ActiveX control - &lt;<a href="http://kb2.adobe.com/cps/141/tn_14157.html">http://kb2.adobe.com/cps/141/tn_14157.html</a>&gt;</li><li>Windows
Server Update Services (WSUS) - &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-012B%20Feedback%20VU#552113">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>January 12, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-01-12T22:48:56Z</updated>
    <published>2010-01-12T22:48:56Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-012B.html"/>
  </entry>
  <entry>
    <title>TA10-012A: Oracle Updates for Multiple Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA10-012A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: January 12, 2010<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul><li>Oracle Database 11<em>g</em>, version 11.1.0.7</li><li>Oracle Database
10<em>g</em> Release 2, versions 10.2.0.3, 10.2.0.4</li><li>Oracle Database
10<em>g</em>, version 10.1.0.5</li><li>Oracle Database 9<em>i</em> Release 2,
versions 9.2.0.8, 9.2.0.8DV</li><li>Oracle Application Server 10<em>g</em>
Release 3 (10.1.3), versions 10.1.3.4.0, 10.1.3.5, 10.1.3.5.1</li><li>Oracle
Application Server 10<em>g</em> Release 2 (10.1.2), version
10.1.2.3.0</li><li>Oracle Access Manager versions 7.0.4.3,
10.1.4.2</li><li>Oracle E-Business Suite Release 12, versions 12.0.4, 12.0.5,
12.0.6, 12.1.1 and 12.1.2</li><li>Oracle E-Business Suite Release 11<em>i</em>,
version 11.5.10.2</li><li>PeopleSoft Enterprise HCM (TAM), versions 8.9 and
9.0</li><li>Oracle WebLogic Server 10.0 through MP2, 10.3.0 and
10.3.1</li><li>Oracle WebLogic Server 9.0 GA, 9.1 GA and 9.2 through 9.2
MP3</li><li>Oracle WebLogic Server 8.1 through 8.1 SP6</li><li>Oracle WebLogic
Server 7.0 through 7.0 SP7</li><li>Oracle JRockit R27.6.5 and earlier (JDK/JRE
6, 5, 1.4.2)</li><li>Primavera P6 Enterprise Project Portfolio Management 6.1,
6.2.1 and 7.0</li><li>Primavera P6 Web Services 6.2.1, 7.0 and 7.0SP1</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Oracle products and components are affected by multiple vulnerabilities. The
impacts of these vulnerabilities include remote execution of arbitrary code,
information disclosure, and denial of service.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>The <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html">Oracle
Critical Patch Update Advisory - January 2010</a> addresses 24 vulnerabilities
in various Oracle products and components. The document provides information
about affected components, access and authorization required for successful
exploitation, and the impact from the vulnerabilities on data confidentiality,
integrity, and availability.</p> <p>Oracle has associated CVE identifiers with
the vulnerabilities addressed in this Critical Patch Update. If significant
additional details about vulnerabilities and remediation techniques become
available, we will update the <a href="http://www.kb.cert.org/vuls/">Vulnerability Notes Database</a>.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>The impact of these vulnerabilities varies depending on the product,
component, and configuration of the system. Potential consequences include the
execution of arbitrary code or commands, information disclosure, and denial of
service. Vulnerable components may be available to unauthenticated, remote
attackers. An attacker who compromises an Oracle database may be able to access
sensitive information.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p>Apply the appropriate patches or upgrade as specified in the <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html">Oracle
Critical Patch Update Advisory - January 2010</a>. Note that this document only
lists newly corrected issues. Updates to patches for previously known issues are
not listed.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Oracle Patch Update Advisory - January 2010 - &lt;<a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</a>&gt;</li><li>Critical
Patch Updates and Security Alerts - &lt;<a href="http://www.oracle.com/technology/deploy/security/alerts.htm">http://www.oracle.com/technology/deploy/security/alerts.htm</a>&gt;</li><li>Map
of Public Vulnerability to Advisory/Alert - &lt;<a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/public_vuln_to_advisory_mapping.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/public_vuln_to_advisory_mapping.html</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA10-012A%20Feedback%20VU#148385">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2010 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>January 12, 2010: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2010-01-12T21:42:27Z</updated>
    <published>2010-01-12T21:42:27Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA10-012A.html"/>
  </entry>
  <entry>
    <title>TA09-343A: Adobe Flash Vulnerabilities Affect Flash Player and Adobe AIR</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA09-343A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: December 09, 2009<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul><li>Adobe Flash Player 10.0.32.18 and earlier versions</li><li>Adobe AIR
1.5.2 and earlier versions</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Adobe has released Security bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a>,
which describes vulnerabilities affecting Adobe Flash Player and Adobe AIR.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Adobe Security Bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a>
describes vulnerabilities affecting Adobe Flash Player and Adobe AIR. Flash
Player version 10.0.32.18 and earlier versions as well as Adobe AIR versions
1.5.2 and earlier are affected.</p> <p>An attacker could exploit this
vulnerability by convincing a user to visit a website that hosts a specially
crafted SWF file. The Adobe Flash browser plugin is available for multiple web
browsers and operating systems, any of which could be affected.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>This vulnerability allows a remote attacker to execute arbitrary code as the
result of a user viewing a web page.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p>Users are encouraged to update Flash Player 10.0.32.18 and earlier versions
as well as Adobe AIR 1.5.2 and earlier versions to the latest
version.</p><p>These vulnerabilities can be mitigated by disabling the Flash
plugin or by using the <a href="https://addons.mozilla.org/addon/722">NoScript</a> extension for Mozilla
Firefox or SeaMonkey to whitelist websites that can access the Flash plugin. For
more information about securely configuring web browsers, please see the <a href="http://www.us-cert.gov/reading_room/securing_browser/">Securing Your Web
Browser</a> document.</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Adobe Security Bulletin APSB09-19 - &lt;<a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">http://www.adobe.com/support/security/bulletins/apsb09-19.html</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA09-343A%20Feedback%20VU#392637">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2009 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>December 09, 2009: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2009-12-09T18:59:38Z</updated>
    <published>2009-12-09T18:59:38Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA09-343A.html"/>
  </entry>
  <entry>
    <title>TA09-342A: Microsoft Updates for Multiple Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA09-342A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: December 08, 2009<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul> <li>Microsoft Windows and Windows Server</li><li>Microsoft Internet
Explorer</li><li>Microsoft Office Word, Works, and Project</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released updates to address vulnerabilities in Microsoft
Windows, Windows Server, Internet Explorer, and Microsoft Office.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft has released multiple security bulletins for critical
vulnerabilities in Microsoft Windows, Windows Server, Internet Explorer, and
Microsoft Office. These bulletins are described in the <a href="http://www.microsoft.com/technet/security/bulletin/MS09-dec.mspx">Microsoft
Security Bulletin Summary for December 2009</a>.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>A remote, unauthenticated attacker could execute arbitrary code, gain
elevated privileges, or cause a vulnerable application to crash.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates from Microsoft</strong><br/> <br/> Microsoft has
provided updates for these vulnerabilities in the <a href="http://www.microsoft.com/technet/security/bulletin/MS09-dec.mspx">Microsoft
Security Bulletin Summary for December 2009</a>. The security bulletin describes
any known issues related to the updates. Administrators are encouraged to note
these issues and test for any potentially adverse effects. Administrators should
consider using an automated update distribution system such as <a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">Windows
Server Update Services</a> (WSUS).</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin Summary for December 2009 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/MS09-dec.mspx">http://www.microsoft.com/technet/security/bulletin/MS09-dec.mspx</a>&gt;</li><li>Windows
Server Update Services (WSUS) - &lt;<a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">http://www.microsoft.com/windowsserversystem/updateservices/default.mspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA09-342A%20Feedback%20VU#115525">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2009 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>December 08, 2009: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2009-12-08T21:37:13Z</updated>
    <published>2009-12-08T21:37:13Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA09-342A.html"/>
  </entry>
  <entry>
    <title>TA09-314A: Microsoft Updates for Multiple Vulnerabilities</title>
    <id>http://www.us-cert.gov/cas/techalerts/TA09-314A.html</id>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">Original release date: November 10, 2009<br/>
Last <a href="#revisions">revised</a>: --<br/>
Source: US-CERT<br/>
<br/>
<a name="affected"/>
<h3>Systems Affected</h3>
<ul> <li>Microsoft Windows and Windows Server</li><li>Microsoft Office Word and
Excel</li></ul>

<br/>
<a name="overview"/>
<h2>Overview</h2>
<p>Microsoft has released updates to address vulnerabilities in Microsoft
Windows and Windows Server and Office Word and Excel.</p>

<br/>
<a name="description"/>
<h2>I. Description</h2>
<p>Microsoft has released multiple security bulletins for critical
vulnerabilities in Microsoft Windows and Windows Server and Office Word and
Excel. These bulletins are described in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx">Microsoft
Security Bulletin Summary for November 2009</a>.</p>

<br/>
<a name="impact"/>
<h2>II. Impact</h2>
<p>A remote, unauthenticated attacker could execute arbitrary code, gain
elevated privileges, or cause a vulnerable application to crash.</p>

<br/>
<a name="solution"/>
<h2>III. Solution</h2>
<p><strong>Apply updates from Microsoft</strong><br/> <br/> Microsoft has
provided updates for these vulnerabilities in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx">Microsoft
Security Bulletin Summary for November 2009</a>. The security bulletin describes
any known issues related to the updates. Administrators are encouraged to note
these issues and test for any potentially adverse effects. Administrators should
consider using an automated update distribution system such as <a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx">Windows
Server Update Services</a> (WSUS).</p>

<br/>
<a name="references"/>
<h2>IV. References</h2>
<ul><li>Microsoft Security Bulletin Summary for November 2009 - &lt;<a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx</a>&gt;</li><li>Microsoft
Windows Server Update Services - &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li></ul>

   

<br/>
<hr noshade="noshade"/>                               
<p><a href="mailto:cert@cert.org?subject=TA09-314A%20Feedback%20VU#825685">Feedback</a> can be directed to US-CERT.</p>
<hr noshade="noshade"/>

<p>Produced 2009 by US-CERT, a government organization. <a href="http://www.us-cert.gov/legal.html">Terms of use</a></p>
<a name="revisions"/>
<br/><b>Revision History</b>
<p><small>November 10, 2009: Initial release<br/></small></p>                         
</div>
    </content>
    <updated>2009-11-10T22:50:51Z</updated>
    <published>2009-11-10T22:50:51Z</published>
    <link type="text/html" rel="alternate" href="http://www.us-cert.gov/cas/techalerts/TA09-314A.html"/>
  </entry>
</feed>
