New User, Welcome!     Login

Next Page >>

Microsoft

RE: Microsot DID DISCLOSE potential Backdoor

I'm not sure the facts in evidence support the conclusions reached here (sorry, not posting inline as I don't want to address each conclusion built upon some other shaky conclusion.

From http://support.microsoft.com/kb/890830

======
Reporting component
The Malicious Software Removal Tool sends information to Microsoft if it detects malicious software or finds an error. The specific information that is sent to Microsoft consists of the following items: * The name of the malicious software that is detected
* The result of malicious software removal
* The operating system version
* The operating system locale

CORE-2009-0827: Microsoft Office Excel / Word OfficeArtSpgr Container Pointer Overwrite Vulnerability

Hash: SHA1

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

Microsoft Office Excel / Word OfficeArtSpgr Container Pointer Overwrite
Vulnerability



1. *Advisory Information*

CORE-2009-0813: Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap Overflow

Hash: SHA1

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap
Overflow



1. *Advisory Information*

Microsot DID DISCLOSE potential Backdoor

While you were sleeping and focusing on COFEE...

Microsoft Discloses Government Backdoor on Windows Operating Systems
Wednesday, April 30th, 2008 @ 6:00 am | Privacy, News
http://www.infiltrated.net/?p=92

Microsoft may have inadvertently disclosed a potential Microsoft backdoor for law 
enforcement earlier this week. To explain this all, here is the layman term of a backdoor 
from Wikipedia:


[CORE-2010-0427] Windows SMTP Service DNS query Id vulnerabilities

Advisory Id: CORE-2010-0427
Advisory URL:
[http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs]
Date published: 2010-05-04
Date of last update: 2010-05-04
Vendors contacted: Microsoft
Release mode: User release



2. *Vulnerability Information*

VUPEN Security Research - Microsoft Internet Explorer VML Remote Code Execution (MS12-023 / CVE-2012-0172)

VUPEN Security Research - Microsoft Internet Explorer VML Remote Code 
Execution (MS12-023 / CVE-2012-0172)

Website : http://www.vupen.com/english/research.php

Twitter : http://twitter.com/vupen


I. BACKGROUND
---------------------

VUPEN Security Research - Microsoft Internet Explorer Property Change Memory Corruption (CVE-2011-1345)

VUPEN Security Research - Microsoft Internet Explorer Property Change Memory
Corruption (CVE-2011-1345)

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Internet Explorer is a web browser developed by Microsoft and

VUPEN Security Research - Microsoft Internet Explorer "mshtml.dll" Dangling Pointer Vulnerability (CVE-2011-0036)

VUPEN Security Research - Microsoft Internet Explorer "mshtml.dll" Dangling 
Pointer Vulnerability (CVE-2011-0036)

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Internet Explorer is a web browser developed by Microsoft and

VUPEN Security Research - Microsoft Windows OpenType CFF Driver Stack Overflow Vulnerability (CVE-2011-0034)

VUPEN Security Research - Microsoft Windows OpenType CFF Driver Stack 
Overflow Vulnerability (CVE-2011-0034)

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is a series of software operating systems and graphical

[TOOL RELEASE] Exploit Next Generation SQL Fingerprint v.

The Exploit Next GenerationR SQL FingerprintT (f.k.a. Microsoft SQL Server
Fingerprint Tool) is a powerful tool which performs version fingerprinting
for:
        1. Microsoft SQL Server 2000;
        2. Microsoft SQL Server 2005; and
        3. Microsoft SQL Server 2008.

The Exploit Next GenerationR SQL FingerprintT (ESF) uses well-known
techniques based on several public tools that are capable to identify the
Microsoft SQL Server version (such as: SQLping and SQLver), but, instead of

VUPEN Security Research - Microsoft Internet Explorer "X-UA-COMPATIBLE" Use-after-free Vulnerability

VUPEN Security Research - Microsoft Internet Explorer "X-UA-COMPATIBLE" 
Use-after-free Vulnerability

Website : http://www.vupen.com/english/research.php

Twitter : http://twitter.com/vupen


I. BACKGROUND
---------------------

CORE-2009-0625: Internet Explorer Dynamic OBJECT tag and URLMON sniffing vulnerabilities

Advisory Id: CORE-2009-0625
Advisory URL:
http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag
Date published: 2010-02-03
Date of last update: 2010-02-03
Vendors contacted: Microsoft
Release mode: User release

2. *Vulnerability Information*

Class:  [CWE-497],  [CWE-501],  [CWE-612]

iDefense Security Advisory 09.13.11: Microsoft Excel Record Memory Corruption Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Sep 13, 2011

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at the
following website:

http://office.microsoft.com/excel/


iDefense Security Advisory 09.13.11: Microsoft Excel Record Integer Signedness Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Sep 13, 2011

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at the
following website:

http://office.microsoft.com/excel/


iDefense Security Advisory 09.13.11: Microsoft Excel Record Memory Corruption Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Sep 13, 2011

I. BACKGROUND

Excel is the spreadsheet application included with Microsoft Corp.'s
Office productivity software suite. More information is available at the
following website:

http://office.microsoft.com/excel/


CORE-2009-1103: Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability

Hash: SHA1

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability



1. *Advisory Information*


VUPEN Security Research - Microsoft Windows OLE Automation Integer Underflow Vulnerability (MS11-038)

VUPEN Security Research - Microsoft Windows OLE Automation Integer Underflow 
Vulnerability (MS11-038)

Website : http://www.vupen.com/english/research.php

Twitter : http://twitter.com/vupen


I. BACKGROUND
---------------------

VUPEN Security Research - Microsoft Windows Kernel "GetDCEx()" Memory Corruption Vulnerability (CVE-2010-0484)

VUPEN Security Research - Microsoft Windows Kernel "GetDCEx()" Memory 
Corruption Vulnerability (CVE-2010-0484)

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is the operating system developed by Microsoft. As of

[security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01530663
Version: 1

HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2008-08-18
Last Updated: 2008-08-18

VUPEN Security Research - Microsoft Internet Explorer Layouts Use-after-free Vulnerability (CVE-2011-0094)

VUPEN Security Research - Microsoft Internet Explorer Layouts Use-after-free 
Vulnerability (CVE-2011-0094)

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Internet Explorer is a web browser developed by Microsoft and

[CORE-2010-0623] Microsoft Windows CreateWindow function callback vulnerability

Hash: SHA1
 
      Core Security Technologies - CoreLabs Advisory
           http://corelabs.coresecurity.com/

Microsoft Windows CreateWindow function callback vulnerability


1. *Advisory Information*

Title: Microsoft Windows CreateWindow function callback vulnerability

[security bulletin] HPSBST02329 SSRT080048 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-018 to MS08-025

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01433452
Version: 1

HPSBST02329 SSRT080048 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-018 to MS08-025

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2008-04-15
Last Updated: 2008-04-15

[security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01579861
Version: 1

HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2008-10-20
Last Updated: 2008-10-20

VUPEN Security Research - Microsoft Office Excel Code Execution Vulnerabilities

VUPEN Security Research - Microsoft Office Excel Code Execution 
Vulnerabilities

http://www.vupen.com/english/research.php


I. BACKGROUND --------------------- 

"Microsoft Office Excel is a powerful tool you can use to create and
format spreadsheets, and analyze and share information to make more

VUPEN Security Research - Microsoft Windows Shell Graphics BMP "width" Integer Overflow Vulnerability

VUPEN Security Research - Microsoft Windows Shell Graphics BMP "width" 
Integer Overflow Vulnerability

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is a series of software operating systems and graphical

VUPEN Security Research - Microsoft Windows Shell Graphics BMP "height" Integer Overflow Vulnerability

VUPEN Security Research - Microsoft Windows Shell Graphics BMP "height" 
Integer Overflow Vulnerability

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is a series of software operating systems and graphical

VUPEN Security Research - Microsoft Windows Shell Graphics biCompression Buffer Overflow Vulnerability

VUPEN Security Research - Microsoft Windows Shell Graphics biCompression 
Buffer Overflow Vulnerability

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is a series of software operating systems and graphical

VUPEN Security Research - Microsoft Windows GDI+ Size Handling Integer Overflow Vulnerability

VUPEN Security Research - Microsoft Windows GDI+ Size Handling Integer 
Overflow Vulnerability

http://www.vupen.com/english/research.php


I. BACKGROUND
---------------------

"Microsoft Windows is a series of software operating systems and graphical

CORE-2008-0228: Microsoft Word Malformed FIB Arbitrary Free Vulnerability

Hash: SHA1

      Core Security Technologies - CoreLabs Advisory
           http://www.coresecurity.com/corelabs/

  Microsoft Word Malformed FIB Arbitrary Free Vulnerability



1. *Advisory Information*


[security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01372284
Version: 1

HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2008-02-20
Last Updated: 2008-02-20

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!