Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 21st, 2012, 01:11 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Microsoft Security Bulletin MS12-063 - Critical

Quote:
Cumulative Security Update for Internet Explorer (2744842)

Published: Friday, September 21, 2012

Version: 1.0
General Information
Executive Summary

This security update resolves one publicly disclosed and four privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9 on Windows clients and Moderate for Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9 on Windows servers. Internet Explorer 10 is not affected. For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses the vulnerabilities by modifying the way that Internet Explorer handles objects in memory. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.

This security update also addresses the vulnerability first described in Microsoft Security Advisory 2757760.

Recommendation. Most customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.

For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.
https://technet.microsoft.com/en-us/...letin/ms12-063
  #2  
Old September 21st, 2012, 01:17 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Quote:
Microsoft releases MS12-063 – Cumulative Security Update for Internet Explorer
MSRCTeam
21 Sep 2012 10:07 AM

Today we released Security Update MS12-063 to address limited attacks against a small number of computers through a vulnerability in Internet Explorer versions 9 and earlier. The majority of customers have automatic updates enabled and will not need to take any action because protections will be downloaded and installed automatically. For those manually updating, we encourage you to apply this update as quickly as possible.

In addition to addressing the issue described in Security Advisory 2757760, MS12-063 also resolves four privately disclosed vulnerabilities that are currently not being exploited.
https://blogs.technet.com/b/msrc/arc...edirected=true
  #3  
Old September 21st, 2012, 03:24 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,135
Post Re: Microsoft Security Bulletin MS12-063 - Critical

MS12-063 applied, a reboot was required. No issues, thus far.
  #4  
Old September 21st, 2012, 03:36 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Got the updates Ron, for both XP and W7.
Like siljaline, a reboot was required. Also no issues, so far.
Thanks for the always good info!
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #5  
Old September 21st, 2012, 03:49 PM
kC_'s Avatar
kC_ kC_ is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 436
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Quote:
Originally Posted by siljaline
MS12-063 applied, a reboot was required. No issues, thus far.


phew what a relief you have done it thanks so much for posting
  #6  
Old September 21st, 2012, 04:08 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,090
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Same no issues. Although it did ask if I wanted to make IE the default browser,which it already was.
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT.
  #7  
Old September 21st, 2012, 04:35 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Yikes I have not updated yet.Since my kids took over all the windows systems, its like pulling a binky out of a baby's mouth. Thanks ron,I wasn't aware of the security vulnerability.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #8  
Old September 21st, 2012, 07:33 PM
Dragon1952's Avatar
Dragon1952 Dragon1952 is offline
Regular Poster
 
Join Date: Sep 2012
Location: Hollow Earth - Telos
Posts: 65
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Quote:
Originally Posted by ronjor
Should i keep using EMET 3.0 that i installed or can i get rid of it. If i should keep EMET do i leave it as is or have to do any config and add iexplorer.exe as a configured app..
  #9  
Old September 21st, 2012, 07:43 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Keep it. Learn it and use it. http://support.microsoft.com/kb/2458544
  #10  
Old September 22nd, 2012, 07:02 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Microsoft Security Bulletin MS12-063 - Critical

EMET is your best friend
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #11  
Old September 22nd, 2012, 11:12 AM
Securon's Avatar
Securon Securon is offline
Frequent Poster
 
Join Date: Jan 2009
Location: Toronto,Canada
Posts: 880
Cool Re: Microsoft Security Bulletin MS12-063 - Critical

Good Morning ! The update popped up on my sys tray this morning...I promptly installed. Thanks for the heads up ronjor. Sincerely...Securon
  #12  
Old September 22nd, 2012, 03:11 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Good to see everyone keeping their software updated.
  #13  
Old September 23rd, 2012, 12:46 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,135
Post Re: Microsoft Security Bulletin MS12-063 - Critical

Be sure your Browser settings are set to IE, assuming you want IE as your default Browser.
Quote:
Originally Posted by The Hammer
Same no issues. Although it did ask if I wanted to make IE the default browser,which it already was.
  #14  
Old September 23rd, 2012, 12:31 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Microsoft Security Bulletin MS12-063 - Critical

Updated finally after getting the kids to sleep.It would have done so automatic but being in Shadow Mode full time the updates get trashed on every reboot.A small inconvenience to keep the system safe.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #15  
Old September 24th, 2012, 11:07 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,135
Exclamation Re: Microsoft Security Bulletin MS12-063 - Critical

Microsoft Could Have Known About IE Security Flaw In Advance
Quote:
It has been suggested that Microsoft knew about the recent IE security flaw which hit its Internet Explorer browser last week, almost two months before it came to the attention of the experts.

On 15 September, Microsoft acknowledged that an IE security flaw was being actively targeted for attacks using a previously unknown and unpatched vulnerability, after it was identified by Romang, a security researcher from the Metasploit project.

The vulnerability was present in Internet Explorer 9 and earlier versions. According to Microsoft, it “could allow remote code execution if a user views a specially crafted webpage using Internet Explorer.” An attacker who successfully exploited this vulnerability “could gain the same user rights as the current user.”
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:18 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums