2014 年 5 月のセキュリティ更新プログラムのリスク評価
Tuesday, May 13, 2014
本記事は、Security Research & Defense のブログ “ Assessing risk for the May 2014 security updates ” (2014 年 5 月 13 日公開) を翻訳した記事です。 本
Tuesday, May 13, 2014
本記事は、Security Research & Defense のブログ “ Assessing risk for the May 2014 security updates ” (2014 年 5 月 13 日公開) を翻訳した記事です。 本
Tuesday, May 13, 2014
皆さん、こんにちは! 先ほど 5 月のマイクロソフト ワンポイント セキュリティ情報を公開しました。 本日 5 月 14
Tuesday, May 13, 2014
Today we released eight security bulletins addressing 13 unique CVE’s. Two bulletins have a maximum severity rating of Critical while the other six have a maximum severity rating of Important. The table is designed to help you prioritize the deployment of updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max exploit-ability Likely first 30 days impact Platform mitigations and key notes MS14-029(Internet Explorer) Victim browses to a malicious webpage.
Tuesday, May 13, 2014
Dynamically loading libraries in an application can lead to vulnerabilities if not secured properly. In this blog post we talk about loading a library using LoadLibraryEx() API and make use of options to make it safe. Know the defaults: The library file name passed to LoadLibrary() / LoadLibraryEx() call need not contain an extension.
Tuesday, May 13, 2014
Today, we released an update to address a vulnerability in Group Policy Preferences (MS14-025). Group Policy Preferences was an addition made to Group Policy to extend its capabilities. Among other things, Group Policy Preferences allows an administrator to configure: Local administrator accounts (name of the account, account password, etc) Configure a service or scheduled task (allowed to specify alternate credentials to run as) Mount network drives when a user logs in (allowed to specify alternate credentials to connect with) Group Policy Preferences are distributed just like normal group policy: An XML file containing the settings is written to the SYSVOL share of the domain controllers, and computers periodically query the SYSVOL share (authenticating to it using their computer account) for updates to the group policy.
Tuesday, May 13, 2014
Today, we released eight security bulletins – two rated Critical and six rated Important – to address 13 Common Vulnerability & Exposures (CVEs) in .NET Framework, Office, SharePoint, Internet Explorer, and Windows. We encourage you to apply all of these updates, but for those who need to prioritize their deployment planning, we recommend focusing on MS14-024, MS14-025 and MS14-029.
Thursday, May 08, 2014
2014 年 5 月の月例セキュリティ リリースの事前通知を公開しました。 2014 年 5 月 14 日に公開を予定している新規月例
Thursday, May 08, 2014
Today we provide Advance Notification Service (ANS) for the release of eight bulletins, two rated Critical and six rated Important in severity. These updates will address vulnerabilities for .NET Framework, Office, Internet Explorer, and Windows. As we do every month, we’ve scheduled the security bulletin release for the second Tuesday of the month, May 13, 2014, at approximately 10:00 a.
Wednesday, May 07, 2014
[2014/06/02 追記] セキュリティ インテリジェンスレポート 第 16 版の日本語要約版を公開しました。 本記事は、Micro
Thursday, May 01, 2014
At approximately 10 a.m. PDT, we will release an out-of-band security update to address the issue affecting Internet Explorer (IE) that was first discussed in Security Advisory 2963983. This update is fully tested and ready for release for all affected versions of the browser. The majority of customers have automatic updates enabled and will not need to take any action because protections will be downloaded and installed automatically.