jueves, 21 de enero de 2010

Security Advisory KB979352

Buenas tardes.Os informo de la próxima publicación de un nuevo boletín de seguridad considerado como Crítico y que afecta a todas las versiones de Internet Explorer, el cual será lanzado hoy 21 de Enero, fuera del ciclo mensual de boletines, debido a su alto impacto y criticidad.

Por este motivo, os recomiendo su revisión y la instalación de la actualización correspondiente.
A continuación os dejo los detalles técnicos de este boletín de seguridad.

--------------------------------------------------------

What is the purpose of this alert?

This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers using Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.

The purpose of the notification is to assist customers with resource planning for this security bulletin release. The information offered in the notification is purposely general in nature to provide enough information for customers to plan for deployment without disclosing vulnerability details or other information that could put them at risk.

New Bulletin Summary
Bulletin Identifier Internet Explorer
Maximum Severity Rating Critical
Impact of Vulnerability Remote Code Execution
Restart Requirement The update will require a restart.
Affected Software All supported versions of Internet Explorer on Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008*, Windows 7, and Windows Server 2008 R2*.

* Where indicated in the Affected Software table on the Advance Notification Web Page, the vulnerabilities addressed by this update do not affect supported editions of Windows Server 2008 or Windows Server 2008 R2, when installed using the Server Core installation option. Please see the Advance Notification Web page at the link below for more details.

Although we do not anticipate any changes, the information provided in this summary is subject to change until the release.

The full version of the Microsoft Security Bulletin Advance Notification for this release can be found at http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx.

Public Bulletin Webcast

Microsoft will host a webcast to address customer questions on these bulletins:
Title: Information about Microsoft January (OOB) Security Bulletin (Level 200)
Date: Thursday, January 21, 2010, at 1:00 PM Pacific Time (U.S. & Canada).
URL: http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032440627
At this time no additional information on these bulletins, such as details regarding severity or details regarding the vulnerability, will be made available until the bulletin is published.

Resources related to this alert

1. Security Advisory 979352 – Vulnerability in Internet Explorer Could Allow Remote Code Execution: http://www.microsoft.com/technet/security/advisory/979352.mspx

2. Microsoft Knowledge Base Article 979352: http://support.microsoft.com/kb/979352

3. Issue Landing Page: http://www.microsoft.com/security/updates/ie.aspx

4. Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/

5. Microsoft Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/

6. Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/

7. Microsoft Security Development Lifecycle (SDL) Blog: http://blogs.msdn.com/sdl/

No hay comentarios: