Details about the MSFT December patches just showed up online. We will update this page as we find out more.
MS 05-54: Cumulative Security Update for Internet ExplorerFirst look: This DOES NOT fix the javascript window() issue. Still translating from "Microsoft" to "English".http://www.microsoft.com/technet/security/Bulletin/MS05-054.mspx MS 05-55: Vulnerability in Windows Kernel Could Allow Elevation of Privilege.A vulnerability in the Asynchronous Procedure Call queue allows local users to escalate their privileges. A regular user (who has to be logged in first) could use this vulnerability to gain Administrator privileges.Microsoft rates this vulnerability as "Important" as there is no direct remote vector to exploit this issue. However, coupled with an Internet Explorer vulnerability or similar issues, this could be used to gain Administrator privileges even if a user runs Internet Explorer as a less privileged user. Note that remote exploit may be possible if user credentials are known. http://www.microsoft.com/technet/security/Bulletin/MS05-055.mspx I will be teaching next: Application Security: Securing Web Apps, APIs, and Microservices - SANS London June 2022 |
Johannes 4479 Posts ISC Handler Dec 13th 2005 |
Thread locked Subscribe |
Dec 13th 2005 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!