CisCom Solutions, LLC     502-253-4525

Bits & Bytes Newsletter

July 7, 2009

 

 

 

Important Microsoft Security Notice

Microsoft announced a security vulnerability yesterday in Microsoft Video ActiveX control which could allow remote code execution by affected users.  Microsoft explained the threat as follows:  "The Microsoft Video Control object is a Microsoft ActiveX control that connects Microsoft DirectShow filters for use in capturing, recording, and playing video. It is the main component that Microsoft Windows Media Center uses to build filter graphs for recording and playing television video. When the ActiveX control is used in Internet Explorer, the control may corrupt the system state in such a way that an attacker could run arbitrary code.  If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."  The bulletin is titled "Microsoft Security Advisory: Vulnerability in Microsoft Video ActiveX control could allow remote code execution" http://support.microsoft.com/kb/972890  The bulletin explains that "In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site."

 

Affected Software

Microsoft Windows Server 2003 Service Pack 2, when used with:

Microsoft Windows Server 2003, Standard Edition (32-bit x86)

Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)

Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)

Microsoft Windows Server 2003, Web Edition

Microsoft Windows Server 2003, Datacenter x64 Edition

Microsoft Windows Server 2003, Enterprise x64 Edition

Microsoft Windows Server 2003, Standard x64 Edition

Microsoft Windows XP Professional x64 Edition

Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems

Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems

Microsoft Windows XP Service Pack 2, when used with:

Microsoft Windows XP Home Edition

Microsoft Windows XP Professional

Microsoft Windows XP Service Pack 3, when used with:

Microsoft Windows XP Home Edition


 

Microsoft has provided a "fix it" executable file to '"implement the workaround that disables the Microsoft Video ActiveX Control automatically on a computer that is running Windows XP or Windows Server 2003."  Click here to visit the Microsoft Fix-it Page. 

 

Customers who are using Windows Vista or Windows Server 2008 are not affected because the ability to pass data to this control within Internet Explorer has been restricted.  Microsoft, however, is still recommending that "Windows Vista and Windows Server 2008 customers remove support for this ActiveX Control within Internet Explorer using the same Class Identifiers as a defense-in-depth measure."

For more information about the vulnerability visit Microsoft Security Advisory (972890)

 

If you need assistance implementing these recommendations, please contact our helpdesk at (502) 253-4525 x1.

Issue: 19

 

chip

 

Microsoft 2007 Exchange Server

Exchange Server 2007
 Promotion Extended

Microsoft has extended its 2007 Exchange Server promotion through September.  In Open and Open Value licensing you can save 20% off License only purchases (Exchange Standard Server and Exchange Standard CAL) or 35% off License with Software Assurance purchases (Exchange Standard Server and Exchange Standard CAL).

Order by: 9/30/09
Redeem by: 9/30/09

 

Call us for details!

 

Attention:
Please remember
 to
call (502)253-4525 x1 for service.

  To make sure you get prompt service, please use the helpline number instead of an individual employee's cell phone number

.help key

 

 

Join Our Mailing List

 

David Ely

CisCom Solutions, LLC
502-253-4525 x200

Safe Unsubscribe

This email was sent to pmason@ciscom.com by news@ciscom.com.

CisCom Solutions, LLC | 9462 Brownsboro Rd. #190 | Louisville | KY | 40241