internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Rates Patched Flaws by Exploitability
October Patch Tuesday Intros New Exploitability Index
Sean Michael Kerner

Microsoft's latest monthly Patch Tuesday roundup of fixes came with a little something extra today — the company's first rankings of how likely each vulnerability is to be exploited by an attacker.

The update thus marks not just a large patch count — with 20 vulnerabilities spread among 11 advisories, four of which are considered "critical" — but it's also the debut of the Exploitability Index from Microsoft, which assigns a numerical score to each vulnerability. The highest score for the Exploitability Index is 1, which is assigned to vulnerabilities that can be consistently exploited with exploit code that already exists or is likely to exist soon.

Among the vulnerabilities listed in today's update, an issue with Excel that could allow for remote code execution rated a 1. According to Microsoft's advisory, an attacker who successfully exploited these vulnerabilities could take complete control of an affected system.

Microsoft has also issued a pair of Exploit 1 advisories for its Internet Explorer browser. In its advisory, the company said that the vulnerabilities are triggered by a user visiting a specially crafted Web page that could then lead to remote code execution or unintended information disclosure.

Internet Explorer also received two additional advisories from Microsoft, one rated a level 2 and the other a level 3 in terms of exploitability. A level 2 on the Exploit Index signifies the possibility of an inconsistent exploit code that could be produced and which may work some of the time. A rating of 3 identifies vulnerabilities for which Microsoft believes exploit code will be released within 30 days.

The October Patch haul includes two additional level 1 Exploitability advisories — one for the Windows Kernel, which could lead to a privileged escalation attack. The other is for a vulnerability in the Microsoft Host Integration Server Remote Procedure Call (RPC) service. According to Microsoft's advisory, the vulnerability could allow remote code execution if an attacker sent a specially crafted RPC request to an affected system.

Microsoft first announced the Exploitability Index initiative at the Black Hat Las Vegas conference in August.

News courtesy of internetnews.com

October 15, 2008

Download Windows Live OneCare Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. October Patch Tuesday Intros New Exploitability Index


Additional Articles:

  • Microsoft Issues Major Patch Release in Feb. Cycle
  • Mini-Patch Day for Microsoft
  • Full Plate of Microsoft Patches Expected
  • Microsoft Plugs 10 on Patch Tuesday
  • Critical Windows Patch Around the Corner
  • Warily Watching Worm Variants
  • 'Critical' Patch Released For Windows
  • Microsoft Patches Newest 'Dirty Dozen'
  • Zombies Control Half of Windows PCs
  • Six Fixes on Tap from Microsoft
  • An 'Important' Patch Tuesday
  • Patch Tuesday Targets 'Mammoth' Set of Flaws
  • Microsoft Nabs 28 Flaws in Year's Last Patch Haul
  • Microsoft Fixes IE in February Patch Update
  • Patch Tuesday Won't Fix Excel Hole
  • Microsoft Patch Tuesday Shores Up DNS
  • Microsoft Has Eight Patches on Tap For Tuesday
  • Microsoft Patches PowerPoint Zero-Day
  • Six Critical Microsoft Patches Coming Tuesday
  • 'Patch Tuesday' Will Fix ActiveX Zero-Day
  • Microsoft Plays Catch-Up with Biggest Patch Drop
  • Microsoft's Patch Tuesday Targets Fewer Holes


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs