|
|

|
|
Important Microsoft Security Notice
Microsoft
announced a security vulnerability yesterday in Microsoft Video ActiveX
control which could allow remote code execution by affected
users. Microsoft explained the threat as follows: "The
Microsoft Video Control object is a Microsoft ActiveX control that
connects Microsoft DirectShow filters for use in capturing, recording,
and playing video. It is the main component that Microsoft Windows Media
Center uses to build filter graphs for recording and playing television
video. When the ActiveX control is used in Internet Explorer, the
control may corrupt the system state in such a way that an attacker
could run arbitrary code. If a user is logged on with
administrative user rights, an attacker could take complete control of
the affected system. An attacker could then install programs; view,
change, or delete data; or create new accounts with full user rights.
Users whose accounts are configured to have fewer user rights on the
system could be less impacted than users who operate with
administrative user rights." The bulletin is titled
"Microsoft Security Advisory: Vulnerability in Microsoft Video
ActiveX control could allow remote code execution" http://support.microsoft.com/kb/972890
The bulletin explains that "In a Web-based attack scenario, an
attacker could host a Web site that contains a Web page that is used to
exploit this vulnerability. In addition, compromised Web sites and Web
sites that accept or host user-provided content or advertisements could
contain specially crafted content that could exploit this
vulnerability. In all cases, however, an attacker would have no way to
force users to visit these Web sites. Instead, an attacker would have
to persuade users to visit the Web site, typically by getting them to
click a link in an e-mail message or Instant Messenger message that
takes users to the attacker's Web site."
Microsoft
Windows Server 2003 Service Pack 2, when used with:
Microsoft
Windows Server 2003, Standard Edition (32-bit x86)
Microsoft
Windows Server 2003, Enterprise Edition (32-bit x86)
Microsoft
Windows Server 2003, Datacenter Edition (32-bit x86)
Microsoft
Windows Server 2003, Web Edition
Microsoft
Windows Server 2003, Datacenter x64 Edition
Microsoft
Windows Server 2003, Enterprise x64 Edition
Microsoft
Windows Server 2003, Standard x64 Edition
Microsoft
Windows XP Professional x64 Edition
Microsoft
Windows Server 2003, Datacenter Edition for Itanium-Based Systems
Microsoft
Windows Server 2003, Enterprise Edition for Itanium-based Systems
Microsoft
Windows XP Service Pack 2, when used with:
Microsoft
Windows XP Home Edition
Microsoft
Windows XP Professional
Microsoft
Windows XP Service Pack 3, when used with:
Microsoft
Windows XP Home Edition
Microsoft has
provided a "fix it" executable file
to '"implement the workaround that disables the Microsoft
Video ActiveX Control automatically on a computer that is running
Windows XP or Windows Server 2003." Click
here to visit the Microsoft Fix-it Page.
Customers who
are using Windows Vista or Windows Server 2008 are not affected because
the ability to pass data to this control within Internet Explorer has
been restricted. Microsoft, however, is still recommending that
"Windows Vista and Windows Server 2008 customers remove support
for this ActiveX Control within Internet Explorer using the same Class
Identifiers as a defense-in-depth measure."
For more information about the vulnerability visit Microsoft
Security Advisory (972890)
If you need
assistance implementing these recommendations, please contact our
helpdesk at (502) 253-4525 x1.
|
|
|
|
|
|

Exchange Server 2007
Promotion Extended
Microsoft has extended its 2007
Exchange Server promotion through September. In Open and Open Value
licensing you can save 20% off License only purchases (Exchange Standard
Server and Exchange Standard CAL) or 35% off License with Software
Assurance purchases (Exchange Standard Server and Exchange Standard CAL).
Order by: 9/30/09
Redeem by: 9/30/09
Call us for details!
|
|
Attention:
Please
remember
to call (502)253-4525
x1 for service.
To make sure you
get prompt service, please use the helpline number instead of an
individual employee's cell phone number
.
|
|
|
David Ely
CisCom Solutions, LLC
502-253-4525 x200
|
|