2013 年 10 月のセキュリティ情報 (月例) – MS13-080 ~ MS13-087
Tuesday, October 08, 2013
2013 年 10 月 9 日 (日本時間)、マイクロソフトは計 8 件 (緊急 4 件、重要 4 件) の新規セキュリティ情報を公開し
Tuesday, October 08, 2013
2013 年 10 月 9 日 (日本時間)、マイクロソフトは計 8 件 (緊急 4 件、重要 4 件) の新規セキュリティ情報を公開し
Tuesday, October 08, 2013
皆さん、こんにちは! 先ほど 10 月のマイクロソフト ワンポイント セキュリティ情報を公開しました。 本日 10 月 9
Tuesday, October 08, 2013
Today we released eight security bulletins addressing 25 CVE’s. Four bulletins have a maximum severity rating of Critical while the other four have a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max Exploit-ability Likely first 30 days impact Platform mitigations and key notes MS13-080(Internet Explorer) Victim browses to a malicious webpage.
Tuesday, October 08, 2013
Congratulations to James Forshaw for coming up with a new exploitation technique to get our first ever $100,000 bounty. A security vulnerability researcher with Context Information Security, James already came in hot with design level bugs he found during the IE11 Preview Bug Bounty, and we’re thrilled to give him even more money for helping us improve our platform-wide security by leaps.
Tuesday, October 08, 2013
Today we released MS13-080 which addresses nine CVEs in Internet Explorer. This bulletin fixes multiple security issues, including two critical vulnerabilities that haven been actively exploited in limited targeted attacks, which we will discuss in details in this blog entry. CVE-2013-3893: the final patch after Fix it workaround Previously, Microsoft released Security Advisory 2887505 and made available the Fix it workaround 51001 to provide earlier protection to all customers for an actively exploited security issue that was reported to us.
Monday, October 07, 2013
Back in June of this year, we announced three new bounty programs that will pay researchers for techniques that bypass built-in OS mitigations and protections, for defenses that stop those bypasses and for vulnerabilities in Internet Explorer 11 Preview. This past Friday, we provided some additional details about the results of the IE11 Preview bounty program, which covered the first 30 days of the preview period.
Monday, October 07, 2013
This month we release eight bulletins – four Critical and four Important - which address 25* unique CVEs in Microsoft Windows, Internet Explorer, SharePoint, .NET Framework, Office, and Silverlight. For those who need to prioritize their deployment planning, we recommend focusing on MS13-080, MS13-081, and MS13-083. Our Bulletin Deployment Priority graph provides an overview of this month’s priority releases (click for larger view).
Friday, October 04, 2013
Fall is a season traditionally associated with a harvest after planting the seeds and tending the crops. Today I’m proud to announce the names of six very smart people who have helped us make our products more secure by participating in our new bounty programs. When we launched our bounty programs in June this year, we had a few strategic goals in mind:
Thursday, October 03, 2013
2013 年 10 月の月例セキュリティ リリースの事前通知を公開しました。 2013 年 10 月 9 日に公開を予定している新規月例
Thursday, October 03, 2013
本記事は、 Microsoft Security Blog のブログ “ ** The Impact of Security Science in Protecting Customers ** ” (2013 年 7 月\ ** 25 日公開 ) を翻訳した記事です。 Trustworthy Computing 部門は