As announced on Friday, Microsoft released an out-of-band bulletin to address the recent Shortcut/LNK exploits. As confirmed in Microsoft's announcement, various malware is now attempting to exploit this vulnerability. The vulnerability is rather easy to exploit in particular given the tools available to craft necessary shortcuts. Clients are the main target but servers are as vulnerable and should be patched as soon as possible. Please report any issues you have with the patch !
----- |
Johannes 4473 Posts ISC Handler Aug 12th 2010 |
||||||||||||||||||||||
Thread locked Subscribe |
Aug 12th 2010 1 decade ago |
||||||||||||||||||||||
The word "bulletin" in the link for MS10-046 should be lowercase, not initial caps. The correct link is here:
http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx |
Jim 4 Posts |
||||||||||||||||||||||
Quote |
Aug 2nd 2010 1 decade ago |
||||||||||||||||||||||
The link above worked just fine for me.
|
Jim 423 Posts ISC Handler |
||||||||||||||||||||||
Quote |
Aug 2nd 2010 1 decade ago |
||||||||||||||||||||||
I don't see support for Windows 2000 or XP SP2. This was anticipated, but unfortunate for the millions of XP users who don't read security bulletins. The Automatic Updates service will give them some limited information about needing SP3 - but won't tell them about missing this patch or subsequent patches in the months that follow.
|
Gary 5 Posts |
||||||||||||||||||||||
Quote |
Aug 2nd 2010 1 decade ago |
||||||||||||||||||||||
According to this link, this update IS AVAILABLE for Windows XP Service Pack 2.
http://www.microsoft.com/downloads/details.aspx?familyid=12361875-B453-45E8-852B-90F2727894FD&displaylang=en |
Gary 5 Posts |
||||||||||||||||||||||
Quote |
Aug 2nd 2010 1 decade ago |
||||||||||||||||||||||
In Microsoft’s August 2010 OOB Security Bulletin Release webcast today, they said that the support for XP SP2 was a typo and it is going to be corrected on the website.
|
Gary 1 Posts |
||||||||||||||||||||||
Quote |
Aug 2nd 2010 1 decade ago |
||||||||||||||||||||||
What are some good sites / discussion groups for determining if anyone has seen any problems with MSPatches, post installation. Tend to worry a bit more about the out of band patches.
|
Paul 4 Posts |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
Applied the "fix" a few weeks ago and was hoping that MS10-046 would restore the display of nice colorful icons.
Unfortunately, our icons did NOT return after applying the MS10-046 patch. As a result we are having to revert the previous 'Fix' to get the icons to display. However, with SP2 still lingering... careful scripting is reverting the 'fix' for only systems with MS10-046 installed. Anyone else experience this? |
Anonymous |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
Did you run the Disable workaround Fixit, too ? MS recommends that if the Enable workaround Fixit was run that the Disable Fixit be run after installing KB2286198. I'd recommend running it prior to the installation of KB2286198.
|
Anonymous |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
Microsoft security update (KB2286198) for Windows 7 hangs or causes a BSOD on restart
http://kb.eset.com/esetkb/index?page=content&id=SOLN2523 " If you are experiencing a system hang or blue screen error after attempting to install Microsoft security update (KB2286198), you will need to update your ESET security product. This issue is due to a potential conflict with the Windows update and ESET NOD32 Antivirus and ESET Smart Security. Downloading a new ESET virus signature update (version 5338 and later) will resolve this issue. " |
Anonymous |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
The Microsoft patch takes care of LNK shortcuts, but does it do PIF shortcuts as well?
|
joberoi 2 Posts |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
@MowGreen
Thanks for the comment. Guess we were just hoping to not have to run the 'Disable Fixit'. Like I said, after applying the patch, running the 'Disable Fixit' returns icons to normal functionality. We're not running it 'before' as it's harder to guarantee a patched machine. We're allowing WSUS to deploy the patch and don't want to 'Disable Fixit' until that successfully occurs. fwiw |
Anonymous |
||||||||||||||||||||||
Quote |
Aug 3rd 2010 1 decade ago |
||||||||||||||||||||||
We uninstalled patch MS10-046 in our BlackBerry server. According with the administrator, the users can't reply their messages.
|
Anonymous |
||||||||||||||||||||||
Quote |
Aug 4th 2010 1 decade ago |
||||||||||||||||||||||
To: AGzz, why did you uninstall from the BES, did it cause a problem when installed?
|
Anonymous |
||||||||||||||||||||||
Quote |
Aug 4th 2010 1 decade ago |
||||||||||||||||||||||
To: AGzz, why did you uninstall from the BES, did it cause a problem when installed?
|
Anonymous |
||||||||||||||||||||||
Quote |
Aug 4th 2010 1 decade ago |
||||||||||||||||||||||
To ARS: According with our BES administrator this problem (users can't send/reply emails) occurred just after we installed MS10-046. The issue was solved when we uninstalled it. I don't know if this patch was the root cause or we have another kind of problem with the BES. Best wishes!
|
Anonymous |
||||||||||||||||||||||
Quote |
Aug 4th 2010 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!