Global Security Watch > New Microsoft Security Program & Vulnerability Data Now Available ...

[Site Home] For me, some of the most interesting new data in the report is on the Exploitability Index that gets included with security bulletins from Microsoft. If you use the exploitability index to help manage risk associated with Microsoft security bulletins, it could help you with deployment decisions and potentially reduce the number of reboots you need to perform in your environment.

Previous [Previous] Vulnerability Found In Android That Allows For Phishing Sca...

Next [Next] Apple Store security plan irks merchants, locals | TUAW -...

Some related posts from Technorati and Google.

[IT Support Services for Small Business in Florida] Microsoft Fixes 22 Flaws with Updates | IT Support Services for ...: Administrators should prioritize the two critical updates fixing vulnerabilities in Internet Explorer and the Microsoft DNS server running in Windows Server 2003 and 2008 first, Angela Gunn, senior response communications manager at Microsoft Trustworthy Computing, wrote on the Microsoft Security Response Center blog on TechNet. Even though there are no exploits currently targeting the flaw in the wild, according to Gunn, the exploitability index on the IE issue is “1,”

[MyTechGuides.com] A live BlueHat Prize webcast and the August 2011 security updates ...: You can find more information about this month’s security updates on the Microsoft Security Bulletin Summary web page. In addition, the SRD blog today has more information on MS11-058’s Exploitability Index rating and on the month’s deployment priorities.

[Dark Note] Microsoft Expects to See Exploits for Critical IE | Dark Note: The MS11-057 IE security bulletin addresses seven security vulnerabilities that affect all versions of the browser on all supported Windows .According to Microsoft's vulnerability exploitability index, MS11-057 has the highest score with the note “likely to see reliable exploits developed within next 30 days.

[Ninja X Service | Blogger Package service] Microsoft Fixes 22 Flaws in August Patch Tuesday - Ninja X Service ...: Microsoft released 13 security bulletins addressing 22 unique vulnerabilities for its August Patch Tuesday update. Of the 13 bulletins, two were rated as "critical,"

[Gev.com - Latest Technology, Entertainment and Lifestyle News] Microsoft Releases 13 Security Patches for 22 Vulnerabilities: According to Angela Gunn, who is a senior response communication manager at Microsoft Trustworthy Computing, administrators should prioritize the two critical updates first. Those two updates fix vulnerabilities in the Microsoft DNS server and in Internet Explorer.

[MSRC] Exploitability Index Improvements & Advance Notification Service ...: The Exploitability Index will continue to provide an aggregate exploitability rating across all affected products, and the improvements made to Exploitability Index will now offer additional information to help customers prioritize bulletins, specifically for the most recent platforms, e.g. Windows 7 Service Pack 1 and Office 2010.

[Enterprise Security Today] Enterprise Security Today | Patch Tuesday Brings a Flood of Low ...: "Internet Explorer is affected by two critical vulnerabilities being patched, both of which can be exploited by a drive-by download," Talbot added. "The fact that vulnerabilities such as these continue to be so common is one reason why web-based attacks are so prevalent.

[Servers Tech Blog] web hostingMicrosoft Patch Day August 2011 Overview - Servers Tech ...: The vulnerabilities could allow denial of service if an attacker sends a sequence of specially crafted Internet Control Message Protocol (ICMP) messages to a target system or sends a specially crafted URL request to a server that is serving Web content and has the URL-based Quality of Service (QoS) feature enabled.

[Site Home] A live BlueHat Prize webcast and the August 2011 security updates ...: The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. Microsoft is not aware of any attacks leveraging the vulnerabilities addressed in this bulletin.

[The Security Blog » Latest InfoSec Threat Research & News | TheSecurityBlog.com] August 2011 Patch Tuesday – Update – Security Threat Research News: The vulnerabilities in Flash, Shockwave, Photoshop and Flash Media Server are critical and IT admins should apply the patches as fast as possible, if they have these software packages installed..

[MSRC] Exploitability Index Improvements Now Offer Additional Guidance ...: If consistent exploit code was considered likely for any supported version, despite being made significantly more difficult with ASLR, the Exploitability Index rating of that vulnerability would receive Microsoft’s highest rating of "1," indicating that a reliable exploit within 30 days is likely. While this is accurate for the older version, it does not correctly reflect risk for users with Windows 7.

[The Security Blog » Latest InfoSec Threat Research & News | TheSecurityBlog.com] Exploitability Index Improvements & Advance Notification Service ...: The Exploitability Index will continue to provide an aggregate exploitability rating across all affected products, and the improvements made to Exploitability Index will now offer additional information to help customers prioritize bulletins, specifically for the most recent platforms, e.g. Windows 7 Service Pack 1 and Office 2010.

Reflected tags on Technorati: Blog, ,