Featured Articles

Nvidia GTX 770 spec is out

Nvidia GTX 770 spec is out

In addition to the GK110 based Nvidia Geforce GTX 780, we managed to get some details regarding the GK104-based GTX 770…

More...
Nvidia Geforce GTX 780 detailed

Nvidia Geforce GTX 780 detailed

We managed to confirm the full spec of the upcoming Nvidia Geforce GTX 780 graphics card as well as some performance…

More...
AMD shares take rollercoaster ride

AMD shares take rollercoaster ride

In the last 52 weeks AMD was on a rollercoaster ride, with prices ranging from $1.81 to $6.46. Yesterday it closed…

More...
HIS iCooler Turbo HD 7790 reviewed

HIS iCooler Turbo HD 7790 reviewed

Today we’ll take a closer look at a factory overclocked HD 7790, courtesy of HIS. The HIS HD 7790 iCooler Turbo…

More...
Kingston DataTraveler Ultimate 3.0 Generation 3 (32GB) reviewed

Kingston DataTraveler Ultimate 3.0 Generation 3 (32GB) reviewed

High capacity USB drives have become commonplace a while ago, but although some memory outfits are peddling huge drives, up…

More...
Frontpage Slideshow | Copyright © 2006-2010 orks, a business unit of Nuevvo Webware Ltd.
Friday, 30 December 2011 23:28

Microsoft releases off-schedule critical Windows Updates

Written by Jon Worrel

windows update_logo

Credible and urgent Windows threats

In an effort to seal some last-minute Windows exploits as 2011 comes to an end, Microsoft has recently pushed out a last-minute patch to address three privately reported vulnerabilities in Microsoft .NET Framework.

The software giant lasted a total of 363 days without releasing an update outside of the monthly Patch Tuesday cycle. Nevertheless, researchers recently discovered that a flaw exists in a wide variety of Web application platforms, including Python, PHP, ASP.NET and others. According to the security bulletin:

“An attacker who successfully exploited this vulnerability could take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands. In order to exploit this vulnerability, an attacker must be able to register an account on the ASP.NET site, and must know an existing user name.”

The update is rated Critical for Microsoft .NET Framework 1.1 Service Pack 1, Microsoft .NET Framework 2.0 Service Pack 2, Microsoft .NET Framework 3.5. Service Pack 1, Microsoft .NET Framework 3.5.1, and Microsoft .NET Framework 4 on all supported editions of Windows, including Windows 7.

Nevertheless, Microsoft considers the threat to be credible and urgent enough that it released an out-of-band patch to address it and strongly recommends its users to run Windows Update as soon as possible. While the software giant hoped for a clean security bulletin record to finish off the year, Wolfgang Kandek, CTO of Qualys, notes that Microsoft developed and released this patch with lightning speed. “I'm sure a few people on Microsoft's security team are packing up the champagne that was ready for that end of year victory toast,” Andrew Storm of nCircle empathizes.

Last modified on Friday, 30 December 2011 23:36

Jon Worrel

E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
blog comments powered by Disqus

To be able to post comments please log-in with Disqus

 

Facebook activity

Latest Commented Articles

Recent Comments