• About
  • Terminology
  • Links

Securing the Realm

~ UK Government Cyber Security

Securing the Realm

Monthly Archives: January 2010

IE Vulnerability – Critical

18 Monday Jan 2010

Posted by Andy in Information Assurance

≈ Leave a Comment

Over the weekend I got an SNS global alert through from McAfee about the IE Vulnerability currently being exploited on a global level.

From McAfee site:

Could my organization be at risk of being infected?

The computer code that exploits the Microsoft Internet Explorer vulnerability has unfortunately been released publicly and is available on the Web. The public release significantly increases the possibility of widespread attacks using the vulnerability, putting Microsoft Internet Explorer users at potentially serious risk.

Microsoft is aware of the targeted attacks and lists the following combinations to be vulnerable: Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet Explorer 7 and Internet Explorer 8 on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

For more information see: http://www.mcafee.com/us/threat_center/aurora_enterprise.html

Update (21/1) – Microsoft will today be releasing a patch for this vulnerability.

♣ Facebook

♣ Categories

  • ComSec
  • Education & Certification
  • Information Assurance
  • ISO27K ISMS
  • Papers & Presentations
  • PSN, GCN & G-Cloud
  • Standards & Policy
  • University

♣ Twitter

  • Anyone know of any online material about developing an internal penetration testing (Red/Tiger) team? Anyone developed one internally? 3 days ago
  • Flame: Massive cyber-attack discovered, researchers say bbc.in/JwCDbe 5 days ago
  • Maybe 'The Art of Deception' - another @kevinmitnick book.. again, in audio book :) - anyone read/listened to this book? what do you think? 1 week ago
  • Finished listening to the Ghost in the Wires by @kevinmitnick - great book, loved it so much now what am I going to listen to? #needanewbook 1 week ago
  • Government reveals PSN framework suppliers - information-age.com/channels/comms… #PSN 1 week ago
Follow @SecureTheRealm

♣

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 70 other followers

Popular Topics

#AccreditCamp Accreditation CCP CESG CIRT CLAS CloudStore comsec Crypto CSIRT Cyber Security Event G-Cloud G-Hosting Government Body Government Security GPG GPG43 GPG44 GPG45 HIPS HMG certification HMG IA HMG IA Course HMG IA Training ID assurance Incident Response Information Security Governance ISG ISO27001 ISO27002 Malware Password PSN SPF training UK Cyber Security Strategy

Blog at WordPress.com. Theme: Chateau by Ignacio Ricci.