Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Microsoft December Patches - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Microsoft December Patches
Details about the MSFT December patches just showed up online. We will update this page as we find out more.

MS 05-54: Cumulative Security Update for Internet Explorer

First look: This DOES NOT fix the javascript window() issue. Still translating from "Microsoft" to "English".

http://www.microsoft.com/technet/security/Bulletin/MS05-054.mspx

MS 05-55: Vulnerability in Windows Kernel Could Allow Elevation of Privilege.

A vulnerability in the Asynchronous Procedure Call queue allows local users to escalate their privileges. A regular user (who has to be logged in first) could use this vulnerability to gain Administrator privileges.
Microsoft rates this vulnerability as "Important" as there is no direct remote vector to exploit this issue. However, coupled with an Internet Explorer vulnerability or similar issues, this could be used to gain Administrator privileges even if a user runs Internet Explorer as a less privileged user.
Note that remote exploit may be possible if user credentials are known.
http://www.microsoft.com/technet/security/Bulletin/MS05-055.mspx

I will be teaching next: Defending Web Applications Security Essentials - SANS Security West 2019

Johannes

3508 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!