Video | Business Headlines | Internet | Science | Scientific Ethics | Technology | Search

 


Microsoft given info on new product vulnerability

Tuesday May 11

Microsoft issued information on a new product vulnerability

Symantec Security Response and Symantec DeepSight Vulnerability analysts have rated this vulnerability as a high risk due to the impact if the vulnerability was successfully exploited.

The Help and Support Center (HSC) of Microsoft Windows is a feature in Windows that provides help on a variety of topics such as downloading software updates, etc. If exploited, the HSC vulnerability could allow remote code execution, allowing an attacker to gain complete control of an affected system. This would allow the attacker the ability to install programs, view or change information, or create new accounts with full privileges. Windows operating systems that are affected include Microsoft XP and Microsoft Server 2003.

This vulnerability exists because of the way the HSC handles HCP URL validation. (HCP URL is another type of content that is loaded into a browser, similar to HTTP.) There are a number of steps the user would have to follow in order for the system to be compromised. An attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability. The attacker would also have to use social engineering to persuade the user to visit the Web site and perform several actions.

Users are encouraged to apply the security patch for the HSC vulnerability as soon as possible. Symantec reminds users that it is important to exercise caution when browsing the Internet, and when reading email. The success of recent email and web-based threats such as the Netsky and Bagle variants reinforce the importance of validating content received from outside parties. Symantec cautions users to be suspicious of actions that they are asked to perform by unknown parties.

"Symantec urges computer users to always keep their systems up to date, no matter how severe the vulnerability," said Alfred Huger, senior director, Symantec Security Response. "Also, because hackers and virus writers are getting more sophisticated in the use of social engineering, users need to exercise great caution when clicking on links and visiting unfamiliar websites."

In addition, Symantec strongly advises Windows users to apply the security patch for the Local Security Authority Subsystem Service (LSASS) Vulnerability, announced on April 13 in the MS Security Bulletin MS04-011. This vulnerability still poses a significant threat and users should take immediate steps to ensure their systems are protected. Additional information can be found at http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

ENDS

© Scoop Media

 
 
 
 
 
Business Headlines | Sci-Tech Headlines

 

Sky City : Auckland Convention Centre Cost Jumps By A Fifth

SkyCity Entertainment Group, the casino and hotel operator, is in talks with the government on how to fund the increased cost of as much as $130 million to build an international convention centre in downtown Auckland, with further gambling concessions ruled out. The Auckland-based company has increased its estimate to build the centre to between $470 million and $530 million as the construction boom across the country drives up building costs and design changes add to the bill.
More>>

ALSO:

RMTU: Mediation Between Lyttelton Port And Union Fails

The Rail and Maritime Union (RMTU) has opted to continue its overtime ban indefinitely after mediation with the Lyttelton Port of Christchurch (LPC) failed to progress collective bargaining. More>>

Earlier:

Science Policy: Callaghan, NSC Funding Knocked In Submissions

Callaghan Innovation, which was last year allocated a budget of $566 million over four years to dish out research and development grants, and the National Science Challenges attracted criticism in submissions on the government’s draft national statement of science investment, with science funding largely seen as too fragmented. More>>

ALSO:

Scoop Business: Spark, Voda And Telstra To Lay New Trans-Tasman Cable

Spark New Zealand and Vodafone, New Zealand’s two dominant telecommunications providers, in partnership with Australian provider Telstra, will spend US$70 million building a trans-Tasman submarine cable to bolster broadband traffic between the neighbouring countries and the rest of the world. More>>

ALSO:

More:

Statistics: Current Account Deficit Widens

New Zealand's annual current account deficit was $6.1 billion (2.6 percent of GDP) for the year ended September 2014. This compares with a deficit of $5.8 billion (2.5 percent of GDP) for the year ended June 2014. More>>

ALSO:

Still In The Red: NZ Govt Shunts Out Surplus To 2016

The New Zealand government has pushed out its targeted return to surplus for a year as falling dairy prices and a low inflation environment has kept a lid on its rising tax take, but is still dangling a possible tax cut in 2017, the next election year and promising to try and achieve the surplus pledge on which it campaigned for election in September. More>>

ALSO:

Job Insecurity: Time For Jobs That Count In The Meat Industry

“Meat Workers face it all”, says Graham Cooke, Meat Workers Union National Secretary. “Seasonal work, dangerous jobs, casual and zero hours contracts, and increasing pressure on workers to join non-union individual agreements. More>>

ALSO:

Get More From Scoop

 
 
Standards New Zealand

Standards New Zealand
 
 
 
 
 
 
 
 
Sci-Tech
Search Scoop  
 
 
Powered by Vodafone
NZ independent news