[BigFix-Announcements] BES Auto Notification: New Fixlets Published in Fixlet Site: 'Patches for Windows (English)'

autonotify at us.ibm.com autonotify at us.ibm.com
Wed Jun 20 02:01:04 PDT 2012


Fixlet Site - 'Patches for Windows (English)'
Current Version: 1618	Published: Tue, 19 Jun 2012 10:26:50  GMT

New Fixlets:
============

***************************************************************
Title: 2719615: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution - Windows XP SP3 / 2003 SP2 / Vista SP2 / 2008 SP2 / 7 Gold/SP1
Severity: <Unspecified>
Fixlet ID: 271961501
Fixlet Link: http://technet.microsoft.com/en-us/security/advisory/2719615

Fixlet Description: Microsoft is aware of active attacks that leverage a vulnerability in Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website. The vulnerability affects all supported releases of Microsoft Windows, and all supported editions of Microsoft Office 2003 and Microsoft Office 2007. After downloading and installing this update, affected computers will no longer be susceptible to this vulnerability.

***************************************************************
Title: 2719615: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution - Windows XP SP2 / 2003 SP2 / Vista SP2 / 2008 SP2 / 7 Gold/SP1 / 2008 R2 Gold/SP1 (x64)
Severity: <Unspecified>
Fixlet ID: 271961503
Fixlet Link: http://technet.microsoft.com/en-us/security/advisory/2719615

Fixlet Description: Microsoft is aware of active attacks that leverage a vulnerability in Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website. The vulnerability affects all supported releases of Microsoft Windows, and all supported editions of Microsoft Office 2003 and Microsoft Office 2007. After downloading and installing this update, affected computers will no longer be susceptible to this vulnerability.

***************************************************************
Title: 2719615: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution - Office 2003 SP3 / 2007 SP2/SP3
Severity: <Unspecified>
Fixlet ID: 271961505
Fixlet Link: http://technet.microsoft.com/en-us/security/advisory/2719615

Fixlet Description: Microsoft is aware of active attacks that leverage a vulnerability in Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website. The vulnerability affects all supported releases of Microsoft Windows, and all supported editions of Microsoft Office 2003 and Microsoft Office 2007. After downloading and installing this update, affected computers will no longer be susceptible to this vulnerability.



More information about the BigFix-Announcements mailing list