<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>WatchGuard Security Center</title>
	<atom:link href="http://watchguardsecuritycenter.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://watchguardsecuritycenter.com</link>
	<description>Everything you need to take threats head on</description>
	<lastBuildDate>Mon, 21 May 2012 05:28:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='watchguardsecuritycenter.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/39819bc1ad49c571f27bdc04634b8772?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>WatchGuard Security Center</title>
		<link>http://watchguardsecuritycenter.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://watchguardsecuritycenter.com/osd.xml" title="WatchGuard Security Center" />
	<atom:link rel='hub' href='http://watchguardsecuritycenter.com/?pushpress=hub'/>
		<item>
		<title>WatchGuard Security Week in Review: Episode 18</title>
		<link>http://watchguardsecuritycenter.com/2012/05/18/watchguard-security-week-in-review-episode-18/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/18/watchguard-security-week-in-review-episode-18/#comments</comments>
		<pubDate>Fri, 18 May 2012 11:28:22 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[AusCERT 2012]]></category>
		<category><![CDATA[Avira]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[DNSChanger]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2100</guid>
		<description><![CDATA[AusCERT 2012, QuickTime Updates, and a New Zeus Variant This week&#8217;s &#8220;on the road&#8221; edition of WatchGuard Security Week in Review comes to you from the sunny Gold Coast of Australia, where I&#8217;ve spent the week learning about the latest mobile attacks, cloud threats, and SCADA security issues with the vibrant Australian security community. In [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2100&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>AusCERT 2012, QuickTime Updates, and a New Zeus Variant</h3>
<p>This week&#8217;s &#8220;on the road&#8221; edition of WatchGuard Security Week in Review comes to you from the sunny Gold Coast of Australia, where I&#8217;ve spent the week learning about the latest mobile attacks, cloud threats, and SCADA security issues with the vibrant Australian security community. In this week&#8217;s video podcast, I quickly summarize a few of the presentations I saw at AusCERT this year.</p>
<p>Of course, normal security news continued marching along despite my little jaunt to the land down under. So I also cover this week&#8217;s important software updates, some new malware variants, and a potentially catastrophic antivirus update mistake. If you&#8217;re ready to catch up on the week&#8217;s most interesting security stories, check out the video below.</p>
<p>If you&#8217;d like to read the original sources for many of these stories, be sure to check out the Reference section. Also, make sure to post any feedback or questions in the comments section below, and share this podcast with your friends if you like it. Cheers!</p>
<p><em>(Episode Runtime: 5:35)</em></p>
<span style="text-align:center; display: block;"><a href="http://watchguardsecuritycenter.com/2012/05/18/watchguard-security-week-in-review-episode-18/"><img src="http://img.youtube.com/vi/KI9astTaRjU/2.jpg" alt="" /></a></span>
<p><em>Direct YouTube Link:</em> <a href="http://www.youtube.com/watch?v=KI9astTaRjU">http://www.youtube.com/watch?v=KI9astTaRjU</a></p>
<h4>Episode References:</h4>
<ul>
<li><a href="http://www.theregister.co.uk/2012/05/17/dns_changer_blackouts/">Paul Vixie talks DNSChanger at AusCERT</a> - <em>The Register</em></li>
<li><a href="http://conference.auscert.org.au/conf2012/speaker_Mark_Fabro.html">Mark Fo on SCADA forensics</a> - <em>AusCERT</em></li>
<li><a href="http://support.apple.com/kb/HT5261">Quicktime security update</a> - <em>Apple</em>
<ul>
<li><a href="http://support.apple.com/kb/HT5283">Also a Leopard security update</a><em>- <em>Apple</em></em></li>
</ul>
</li>
<li><a href="http://www.theregister.co.uk/2012/05/16/google_chrome_update/">Chrome 19 security update</a> &#8211; <em>The Re</em><em>gister</em></li>
<li><a href="http://www.informationweek.com/news/security/vulnerabilities/240000575">Fake Google Chrome Installer Malware</a> - <em>Information Week</em></li>
<li><a href="http://www.eweek.com/c/a/Security/Facebook-Gmail-Hotmail-Yahoo-Users-Hit-By-Zeus-Debit-Card-Scam-886976/">New Zeus variant targets Facebook, Gmail, and Hotmail</a> <em>-eWeek</em></li>
<li><a href="http://www.zdnet.com/blog/security/avira-antivirus-update-cripples-millions-of-windows-pcs/12129">Avira update kills windows computers</a><em> - ZDNet</em></li>
</ul>
<p>— <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2100&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/18/watchguard-security-week-in-review-episode-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>WatchGuard Security Week in Review: Episode 17</title>
		<link>http://watchguardsecuritycenter.com/2012/05/11/watchguard-security-week-in-review-episode-17/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/11/watchguard-security-week-in-review-episode-17/#comments</comments>
		<pubDate>Fri, 11 May 2012 15:41:12 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Team Poison]]></category>
		<category><![CDATA[Wiretap]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2088</guid>
		<description><![CDATA[Twitter Hacks, Gas Pipeline Cyber Attacks, and FBI Wiretaps Though the primary theme for this week was, &#8220;patch, patch, patch,&#8221; I saw many other interesting, non-update related security stories in the news as well. This week&#8217;s vlog packs all those stories into a brisk eight and a half minutes. Topics include: Highlights on Microsoft, Adobe, and Apple security [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2088&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Twitter Hacks, Gas Pipeline Cyber Attacks, and FBI Wiretaps</h3>
<p>Though the primary theme for this week was, &#8220;patch, patch, patch,&#8221; I saw many other interesting, non-update related security stories in the news as well. This week&#8217;s vlog packs all those stories into a brisk eight and a half minutes. Topics include:</p>
<ul>
<li>Highlights on Microsoft, Adobe, and Apple security updates</li>
<li>FBI lobbying for online wiretaps</li>
<li>Warnings of Gas Pipeline Cyber Attacks</li>
<li>Some new Geo-aware malware</li>
<li>A seemingly big Twitter breach</li>
<li>Some hacker arrests</li>
</ul>
<p>For details on all these stories, and a few security tips along the way, check out the latest WatchGuard Security Week in Review video below.</p>
<p>As always, if you don&#8217;t have time for a video but want to check out individual stories later, you can find links to all the issues I cover in the &#8221;Reference&#8221; section at the end of this post. You can also let us know what you think about this video series in the comments section.</p>
<p>Finally, I&#8217;m attending AusCERT next week; a security conference in Australia. Though I plan to release an episode next week, I will either post it significantly earlier or later than normal, due to the time zone difference. So keep your eyes peeled for next week&#8217;s episode, but don&#8217;t expect it at the regular time.</p>
<p><em>(Episode Runtime: 8:31)</em></p>
<span style="text-align:center; display: block;"><a href="http://watchguardsecuritycenter.com/2012/05/11/watchguard-security-week-in-review-episode-17/"><img src="http://img.youtube.com/vi/BcIoc3OwJKY/2.jpg" alt="" /></a></span>
<p><em>Direct YouTube Link:</em> <a title="WatchGuard Security Week in Review: Episode 17" href="http://www.youtube.com/watch?v=BcIoc3OwJKY">http://www.youtube.com/watch?v=guqTuUatEwc</a></p>
<h4>Episode References:</h4>
<ul>
<li>Software Updates
<ul>
<li><a href="http://watchguardsecuritycenter.com/2012/05/08/microsoft-black-tuesday-may-brings-windows-office-and-net-patches/">Microsoft Patch Day</a>
<ul>
<li><a href="http://watchguardsecuritycenter.com/2012/05/08/word-visio-and-excel-suffer-from-document-handling-vulnerabilities/">Consolidated Office alert</a> - <em>WatchGuard Security Center</em></li>
<li><a href="http://watchguardsecuritycenter.com/2012/05/08/adobe-patch-day-shockwave-flash-professional-photoshop-and-illustrator-updates/">Consolidated Windows+ alert</a> - <em>WatchGuard Security Center</em></li>
</ul>
</li>
<li>Adobe
<ul>
<li><a href="http://watchguardsecuritycenter.com/2012/05/08/adobe-patch-day-shockwave-flash-professional-photoshop-and-illustrator-updates/">Consolidated Adobe alert</a> - <em>WatchGuard Security Center</em></li>
<li><a href="http://watchguardsecuritycenter.com/2012/05/04/flash-update-mends-a-serious-zero-day-vulnerability/">Last week&#8217;s Flash alert</a> - <em>WatchGuard Security Center</em></li>
</ul>
</li>
<li>Apple
<ul>
<li><a href="http://watchguardsecuritycenter.com/2012/05/10/apple-os-x-patch-corrects-clear-text-password-issue/">OS X and Safari alert</a> - <em>WatchGuard Security Center</em></li>
</ul>
</li>
</ul>
</li>
<li><a href="http://news.cnet.com/8301-1009_3-57428067-83/fbi-we-need-wiretap-ready-web-sites-now/">FBI wants backdoors in products</a> - <em>CNET</em></li>
<li><a href="http://security.blogs.cnn.com/2012/05/08/cyber-attack-targets-gas-pipeline-companies/">DHS warns of gas pipeline cyber attacks</a> - <em>CNN</em></li>
<li><a href="http://www.theregister.co.uk/2012/05/08/geo_location_malware/">Geo-aware malware leverages 4square</a> - <em>The Register</em></li>
<li><a href="http://www.airdemon.net/hacker107.html,">Attackers steal 55,000 Twitter credentials</a> &#8211; <em>Airdemon</em>
<ul>
<li><a href="http://mashable.com/2012/05/08/twitter-hacked-accounts/">Twitter debunks attack</a><em> &#8211; Mashable</em></li>
</ul>
</li>
<li><a href="http://www.bbc.com/news/technology-18017387">Scotland Yard arrests Team Poison hackers</a> - <em>BBC News</em></li>
</ul>
<p>— <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2088/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2088/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2088/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2088&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/11/watchguard-security-week-in-review-episode-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple OS X Patch Corrects Clear Text Password Issue</title>
		<link>http://watchguardsecuritycenter.com/2012/05/10/apple-os-x-patch-corrects-clear-text-password-issue/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/10/apple-os-x-patch-corrects-clear-text-password-issue/#comments</comments>
		<pubDate>Thu, 10 May 2012 17:14:09 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[filevault]]></category>
		<category><![CDATA[OS X]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2074</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: All current versions of OS X 10.6.x (Snow Leopard) and OS X 10.7.x (Lion). How an attacker exploits them: Multiple vectors of attack, including enticing your users to visit a malicious web site, or into downloading and viewing various images or media files. Impact: Various results; in the worst [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2074&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Severity: High</h3>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect:</strong> All current versions of OS X 10.6.x (Snow Leopard) and OS X 10.7.x (Lion).</li>
<li><strong>How an attacker exploits them:</strong> Multiple vectors of attack, including enticing your users to visit a malicious web site, or into downloading and viewing various images or media files.</li>
<li><strong>Impact:</strong> Various results; in the worst case, an attacker executes code on your user’s computer. Attackers could combine these issues to gain full control of your Mac.</li>
<li><strong>What to do:</strong> OS X administrators should download, test and install OS X 10.7.4 or Security Update 2012-002 as soon as possible, or let Apple’s Software updater do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Late Yesterday, Apple released a <a href="http://support.apple.com/kb/HT5281">security update</a> to fix vulnerabilities in all current versions of OS X. The update fixes around 36 (number based on <a href="http://cve.mitre.org/">CVE-ID</a>s) security issues in 19  components that ship as part of OS X or OS X Server, including QuickTime, the Kernel, Time Machine, and many others. Some of the corrected vulnerabilities include:</p>
<ul>
<li><strong>Local File Vault Password Disclosure Vulnerability.</strong> File Vault is an OS X component that encrypts files on a Mac, while Login Window is the component that allows you to log in to your Mac. Earlier this week, researchers <a href="http://www.techspot.com/news/48473-os-x-lion-security-blunder-exposes-login-passwords-in-plain-text.html">disclosed</a> a flaw in Apple&#8217;s File Vault that potentially exposes your password locally. The researcher found that when you upgrade OS X Snow Leopard to OS X Lion, the upgrade process sets a debug flag, which results in your passwords being stored to a local log file, in clear text. This means anyone with local access to that Mac can see the passwords for everyone that logged into that system.  Today&#8217;s Login Window update corrects this issue, preventing your passwords from being stored in this file. However, it does not clear out any existing passwords already in the log. To learn how to manually clear these logs, see this <a href="reviews.cnet.com/8301-13727_7-57431220-263/os-x-10.7.4-fixes-filevault-password-snafu/?part=rss&amp;subj=news&amp;tag=title">article</a>.</li>
</ul>
<ul>
<li><strong><strong>Multiple ImageIO Buffer Overflow Vulnerability.</strong> </strong>ImageIO is one of the components that helps OS X handle and display various images. It suffers from four security vulnerabilities (two being <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow">buffer overflow</a> vulnerabilities) involving the way it handles <a href="http://en.wikipedia.org/wiki/TIFF">TIFF</a> image files. Though these vulnerabilities differ technically, most of them share the same general scope and impact. If an attacker can trick you into viewing a specially crafted image file (perhaps hosted on a malicious website), he could exploit the worst of these flaws to either crash an image application or to execute attack code on your Mac, with your privileges. The attacker could also exploit other vulnerabilities described in Apple&#8217;s alert to gain full control of your Mac.</li>
</ul>
<ul>
<li><strong>Several QuickTime Vulnerabilities.</strong> QuickTime is the popular video and media player that ships with OS X (and iTunes). QuickTime suffers from four security issues (number based on <a href="http://cve.mitre.org/">CVE-ID</a>s) involving how it handles certain  video files and streaming media. While the vulnerabilities differ technically, they share the same basic scope and impact. If an attacker can trick one of your users into viewing a maliciously crafted content in QuickTime, she could exploit any of these flaws to execute code on that user’s computer, with that user’s privileges. Again, attackers could then leverage other flaws described in Apple&#8217;s alert to gain complete control of your Mac.</li>
</ul>
<p>Apple’s alert also describes many other code execution vulnerabilities, as well as some <a href="http://www.watchguard.com/glossary/d.asp#DoS">Denial of Service (DoS)</a> flaws, <a href="http://www.watchguard.com/glossary/e.asp#elevation">elevation of privilege</a> vulnerabilities, and information disclosure flaws. Components patched by this security update include:</p>
<table border="1" cellpadding="0">
<tbody>
<tr>
<td valign="top">Login Window</td>
<td valign="top">Bluetooth</td>
</tr>
<tr>
<td valign="top">curl</td>
<td valign="top">Directory Service</td>
</tr>
<tr>
<td>HFS</td>
<td>ImageIO</td>
</tr>
<tr>
<td valign="top">Kernel</td>
<td valign="top">libarchive</td>
</tr>
<tr>
<td valign="top">libsecurity</td>
<td valign="top">libxml</td>
</tr>
<tr>
<td valign="top">LoginUIFramework</td>
<td valign="top">PHP</td>
</tr>
<tr>
<td>Quartz Composer</td>
<td valign="top">Quicktime</td>
</tr>
<tr>
<td valign="top">Ruby</td>
<td valign="top">Samba</td>
</tr>
<tr>
<td valign="top">Security Framework</td>
<td valign="top">Time Machine</td>
</tr>
<tr>
<td valign="top"></td>
<td valign="top"></td>
</tr>
<tr>
<td>X11</td>
<td></td>
</tr>
</tbody>
</table>
<p>Please refer to Apple’s <a href="http://support.apple.com/kb/HT5281">OS X 10.6.x and 10.7.x alert</a> for more details.</p>
<p><strong>Note</strong>: Apple also released a <a href="http://support.apple.com/kb/HT5282">Safari</a> alert and update, which fixes four vulnerabilities in the Mac and Windows version of Apple&#8217;s web browser. Attackers could leverage at least one of these flaws in a drive-by download attack. If you use Safari on a Mac or PC, you should update it to version 5.1.7, or let Apple&#8217;s automatic updater do it for you.</p>
<h3>Solution Path:</h3>
<p>Apple has released OS X Security Update 2012-002 and OS X 10.7.4 to fix these security issues. OS X administrators should download, test, and deploy the corresponding update as soon as they can, or let Apple&#8217;s automatic Software Update utility do it for you.</p>
<ul>
<li><a href="http://support.apple.com/kb/DL1525">OS X Lion Update 10.7.4 (Client)</a></li>
<li><a href="http://support.apple.com/kb/DL1524">OS X Lion Update 10.7.4 (Client Combo)</a></li>
<li><a href="http://support.apple.com/kb/DL1530">OS X Lion Update 10.7.4 (Server)</a></li>
<li><a href="http://support.apple.com/kb/DL1529">OS X Lion Update 10.7.4 (Server) Combo</a></li>
<li><a href="http://support.apple.com/kb/DL1527">Security Update 2012-002 Server (Snow Leopard)</a></li>
<li><a href="http://support.apple.com/kb/DL1526">Security Update 2012-002 (Snow Leopard)</a></li>
</ul>
<p><strong><br />
</strong>Mac or PC Safari users should also update it to <a href="http://support.apple.com/kb/DL1531">version 5.1.7</a>.</p>
<h3>For All Users:</h3>
<p>These flaws enable many diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack. Therefore, installing these updates is the most secure course of action.</p>
<h3>Status:</h3>
<p>Apple has released updates to fix these flaws.</p>
<h3>References:</h3>
<ul>
<li><a href="http://support.apple.com/kb/HT5281">May 2012 OS X  Security Update</a></li>
<li><a href="http://support.apple.com/kb/HT5282">May 2012 Safari  Security Update</a></li>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2074/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2074&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/10/apple-os-x-patch-corrects-clear-text-password-issue/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>Adobe Patch Day: Shockwave, Flash Professional, Photoshop, and Illustrator Updates</title>
		<link>http://watchguardsecuritycenter.com/2012/05/08/adobe-patch-day-shockwave-flash-professional-photoshop-and-illustrator-updates/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/08/adobe-patch-day-shockwave-flash-professional-photoshop-and-illustrator-updates/#comments</comments>
		<pubDate>Tue, 08 May 2012 23:35:02 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Flash Player]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Photoshop]]></category>
		<category><![CDATA[shockwave]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2059</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: Adobe Shockwave Player, Flash Professional, Photoshop, and Illustrator How an attacker exploits them: Multiple vectors of attack, including enticing your users to open malicious files or visit specially crafted web sites Impact: Various results; in the worst case, an attacker can gain complete control of your computer What to do: Install the appropriate [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2059&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>Severity: High</h2>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect:</strong> Adobe Shockwave Player, Flash Professional, Photoshop, and Illustrator</li>
<li><strong>How an attacker exploits them:</strong> Multiple vectors of attack, including enticing your users to open malicious files or visit specially crafted web sites</li>
<li><strong>Impact:</strong> Various results; in the worst case, an attacker can gain complete control of your computer</li>
<li><strong>What to do:</strong> Install the appropriate Adobe patches immediately, or let Adobe&#8217;s updater do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Adobe released four security bulletins describing vulnerabilities in many of their popular software packages, including Shockwave Player, Flash Professional, Photoshop, and Illustrator.</p>
<p><a href="http://www.adobe.com/support/security/"><img class="aligncenter size-medium wp-image-2070" title="May Adobe Patch Day Summary" src="http://watchguardwire.files.wordpress.com/2012/05/adobepd.jpg?w=300&h=96" alt="" width="300" height="96" /></a></p>
<p>A remote attacker could exploit the worst of these flaws to gain complete control of your computer. The summary below details some of the vulnerabilities in these popular software packages.</p>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb12-13.html">APSB12-13</a>: Five Shockwave Code Execution Vulnerabilities</strong></li>
</ul>
<div>
<blockquote><p><a href="http://en.wikipedia.org/wiki/Adobe_Shockwave">Adobe Shockwave</a> Player displays interactive, animated web content and movies called <a href="http://en.wikipedia.org/wiki/Adobe_Shockwave">Shockwave</a>. According to Adobe, the Shockwave Player is installed on some 450 million PCs.</p>
<p>Adobe’s bulletin warns of five security vulnerabilities that affect Shockwave Player 11.6.4.634 and earlier for Windows and Macintosh. Adobe’s bulletin doesn’t describe the flaws in technical detail, only characterizing them as memory corruption vulnerabilities. All five flaws share the same impact. If an attacker can entice one of your users into visiting a website containing some sort of malicious Shockwave content, he could exploit these vulnerabilities to execute code on that user’s computer, with that user’s privileges. If your Windows users have local administrator privileges, an attacker could exploit this flaw to gain full control of their PC.</p>
<p><em><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>2 </strong>(Patch within 30 days)</em></em></p></blockquote>
</div>
<ul>
<li><strong><strong></strong><strong><a href="http://www.adobe.com/support/security/bulletins/apsb12-12.html">APSB12-12</a></strong>: Flash Professional Buffer Overflow Vulnerability</strong></li>
</ul>
<div>
<blockquote><p>Adobe <a href="http://www.webopedia.com/TERM/F/Flash.html">Flash</a> is a platform for creating interactive or animated web content and video. <a href="http://www.adobe.com/products/flash.edu.html">Flash Professional</a> is the Adobe authoring environment used to create Flash content.</p>
<p>Flash Professional 11.5.1.348 and earlier for Windows and Mac suffers from a <a href="http://www.watchguard.com/glossary/b.asp#buffer_overflow">buffer overflow</a> vulnerability. Adobe does not share any relevant detail about this flaw, nor how an attacker might exploit it. However, we assume that if you open specially crafted Flash content in Flash Professional, an attacker can leverage this flaw to execute code on your computer, with your privileges. As usual, if you have administrative or root privileges, the attacker would gain complete control of your machine.</p>
<p><em><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>3 </strong>(Patch at your discretion)</em></em></p></blockquote>
</div>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb12-11.html">APSB12-11</a>: Photoshop TIFF Handling Vulnerability</strong></li>
</ul>
<blockquote><p>Photoshop is a popular image editing program. Photoshop CS5.5 (for Windows and Mac) suffers from two vulnerabilities; a vulnerability involving its inability to properly handle specially crafted TIFF images, and an unspecified buffer overflow vulnerability. By tricking you into downloading and opening a malicious image in Photoshop, an attacker can exploit the TIFF flaw to execute code on your machine, with your privileges. If you have local admin privileges, the attacker gains complete control of your computer. Adobe doesn&#8217;t describe how an attacker might leverage the second buffer overflow vulnerability.</p>
<p><em><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>3 </strong>(Patch at your discretion)</em></em></p></blockquote>
<ul>
<li><strong><a href="http://www.adobe.com/support/security/bulletins/apsb12-10.html">APSB12-10</a>: <strong> Five Illustrator Code Execution Vulnerabilities</strong></strong></li>
</ul>
<blockquote><p>Illustrator is Adobe&#8217;s vector drawing software. It suffers from five unspecified memory corruption vulnerabilities. Adobe doesn&#8217;t describe these flaws in any other detail, other than calling them code execution vulnerabilities. If forced to guess, we assume that if you handle specially crafted, Illustrator-compatible files (perhaps an image), an attacker could exploit this flaw to execute code on your computer with your privileges. Again, if you are an administrator, the attacker gains full control.</p>
<p><em><em><a href="http://www.adobe.com/support/security/severity_ratings.html">Adobe Priority Rating</a>: <strong>3 </strong>(Patch at your discretion)</em></em></p></blockquote>
<p>While we&#8217;re on Adobe updates, if you haven&#8217;t installed the <a href="http://watchguardsecuritycenter.com/2012/05/04/flash-update-mends-a-serious-zero-day-vulnerability/">early Flash Player update</a> that Adobe released last week, we recommend you do so immediately. That update is much more severe than the ones released today.</p>
<h3>Solution Path:</h3>
<p>Adobe has released updates for all their affected software. If you use any of the software below, we recommend you download and deploy the corresponding updates as soon as possible, or let Adobe’s automatic updater do it for you.</p>
<p><strong>NOTE:</strong> Adobe has chosen to <em>only</em> release some of these fixes as <strong>paid</strong> updates (CS6). If you didn&#8217;t already plan to pay for these updates, you will have to decide if these security issues change your mind. On a positive note, attackers don&#8217;t often target the products in question (Photoshop, Illustrator, Flash Professional). Nonetheless, it&#8217;s difficult for us not to recommend the latest security updates, and we wish that Adobe had extended these security updates to previous versions as well.</p>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb12-13.html">APSB12-13</a><strong>: </strong>Upgrade to <a href="http://get.adobe.com/shockwave/">Shockwave 11.6.5.635</a></li>
<li><a title="http://tinyurl.com/preview.php?num=5h8lzy" href="http://www.adobe.com/support/security/bulletins/apsb12-12.html">APSB12-12</a><strong>: </strong>Your only recourse is upgrading to <a href="http://www.adobe.com/products/flash.html">Flash Professional CS6</a>, which is a <strong><em>paid </em></strong>update.</li>
<li><a title="http://tinyurl.com/preview.php?num=5h8lzy" href="http://www.adobe.com/support/security/bulletins/apsb12-11.html">APSB12-11</a><strong>: </strong>Your only recourse is upgrading to <a href="http://www.adobe.com/products/photoshop.html">Photoshop CS6</a>, which is a <em><strong>paid</strong> </em>update.</li>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb12-10.html">APSB12-10</a><strong>: </strong>Your only recourse is upgrading to <a href="http://www.adobe.com/products/illustrator.html">Illustrator CS6</a>, which is a <em><strong>paid</strong> </em>update.</li>
</ul>
<h4>For All WatchGuard Users:</h4>
<p>Attackers can exploit these flaws using diverse exploitation methods. A properly configured UTM device may mitigate the risk of some of these issues. That said, it cannot protect you from local attacks, nor can it prevent attacks that leverage normal HTTP traffic. Therefore, installing Adobe&#8217;s updates is your most secure course of action.</p>
<h3>Status:</h3>
<p>Adobe has released patches correcting these issues.</p>
<h3>References:</h3>
<ul>
<ul>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb12-10.html">APSB12-10</a></li>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb12-11.html">APSB12-11</a></li>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb12-12.html">APSB12-12</a></li>
<li>Adobe Security Update <a href="http://www.adobe.com/support/security/bulletins/apsb12-13.html">APSB12-13</a></li>
</ul>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2059/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2059/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2059/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2059&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/08/adobe-patch-day-shockwave-flash-professional-photoshop-and-illustrator-updates/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2012/05/adobepd.jpg?w=300" medium="image">
			<media:title type="html">May Adobe Patch Day Summary</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows Security Updates Also Fix Flaws in .NET Framework and Office</title>
		<link>http://watchguardsecuritycenter.com/2012/05/08/windows-security-updates-also-fix-flaws-in-net-framework-and-office/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/08/windows-security-updates-also-fix-flaws-in-net-framework-and-office/#comments</comments>
		<pubDate>Tue, 08 May 2012 22:04:16 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[.NET Framework]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[silverlight]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2043</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: All current versions of Windows and its optional .NET Framework component. One bulletin also affects Office and Silverlight How an attacker exploits them: Multiple vectors of attack, including enticing your users into running specially crafted documents or into visiting web sites with malicious content Impact: In the worst case, an [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2043&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Severity: High</h3>
<h3>Summary:</h3>
<ul type="disc">
<li><strong>These vulnerabilities affect:</strong> All current versions of Windows and its optional .NET Framework component. One bulletin also affects Office and Silverlight</li>
<li><strong>How an attacker exploits them:</strong> Multiple vectors of attack, including enticing your users into running specially crafted documents or into visiting web sites with malicious content</li>
<li><strong>Impact:</strong> In the worst case, an attacker can gain complete control of your Windows computer</li>
<li><strong>What to do:</strong> Install the appropriate Microsoft patches as soon as possible, or let Windows Automatic Update do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Microsoft released four security bulletins describing 15 vulnerabilities that primarily affect Windows and its optional .NET Framework component. However, one of the bulletins also affects Office and Silverlight. Each vulnerability affects different versions of these products to varying degrees. However, a remote attacker could exploit the worst of them to gain complete control of your Windows PC. We recommend you download, test, and deploy these updates &#8211; especially the critical ones &#8212; as quickly as possible.</p>
<p>The summary below lists the vulnerabilities, in order from highest to lowest severity.</p>
<ul>
<li><strong><a href="http://www.microsoft.com/technet/security/Bulletin/MS12-034.mspx">MS12-034</a>: Various Vulnerabilities in Windows, Office, .NET Framework, and Silverlight</strong></li>
</ul>
<blockquote><p>This unusual Microsoft bulletin fixes ten seemingly dissimilar vulnerabilities in four different Microsoft products; Windows, Office, the .NET Framework, and Silverlight. Microsoft combined them into one bulletin since the flaws affect related files found in all of these products.</p>
<p>The ten vulnerabilities differ quite widely, and include various code execution vulnerabilities, <a href="http://www.watchguard.com/education/video/play.asp?vid=dbd-cubecast">drive-by download</a> type issues, local <a href="http://www.watchguard.com/glossary/e.asp#elevation">privilege elevation</a> flaws, and even a <a href="http://www.watchguard.com/glossary/d.asp#DoS">Denial of Service (DoS)</a> vulnerability. According to the bulletin, researchers or attackers have publicly disclosed three of these vulnerabilities before they were patched, and attackers have leveraged at least one in limited targeted attacks.</p>
<p>We suspect the font and image handling vulnerabilities pose the most risk to typical users. The components Windows uses to handle <a href="http://en.wikipedia.org/wiki/Truetype">TrueType</a> fonts and <a href="http://en.wikipedia.org/wiki/Windows_Metafile">EMF images</a> both suffer from multiple code execution flaws. If an attacker can lure one of your users into interacting with a specially crafted image or TrueType font, he can exploit these flaws to gain access to that user&#8217;s computer, with that user&#8217;s privileges. If your user has local administrator privileges, the attacker gains full control of the user&#8217;s computer. Attackers could embed these malicious fonts and images in web sites, documents, or emails, but some of these attack vectors require more user interaction than others to succeed. Since this bulletin fixes many serious vulnerabilities in many products &#8212; one of which attackers have already started exploiting in the wild &#8212; we recommend you download, test, deploy the updates as quickly as possible. <em>Note, this update fixes flaws related to the advanced <a href="http://watchguardsecuritycenter.com/2011/11/08/duqu-malware-leverages-a-zero-day-windows-kernel-flaw/">Duqu attack</a> we&#8217;ve talked about in previous posts.</em></p>
<p><em><em>Microsoft rating: </em><strong>Critical</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035">MS12-035</a>: Two .NET Framework Remote Code Execution Vulnerabilities</strong></li>
</ul>
<blockquote><p><a title="http://en.wikipedia.org/wiki/MP3" href="http://en.wikipedia.org/wiki/MP3">The </a><a title="http://en.wikipedia.org/wiki/.NET_framework" href="http://en.wikipedia.org/wiki/.NET_framework">.NET Framework</a> is <a title="http://en.wikipedia.org/wiki/Software_framework" href="http://en.wikipedia.org/wiki/Software_framework">software framework</a> used by developers to create new Windows and web applications. In computing, <a href="http://en.wikipedia.org/wiki/Serialization"><em>serializatio</em>n</a> is the process of converting a data structure or object to a state that allows for digital storage or transmission. Unfortunately, the .NET Framework suffers from two code execution vulnerabilities involving its serialization process. If an attacker can entice a user who’s installed the .NET Framework to a specially crafted web site, he can exploit these flaws to execute code on that user’s computer, with that user’s privileges. As always, if your users have local administrator privileges, attackers can leverage these flaws to gain full control of their computers. This flaw can also affect custom .NET Framework-based programs, which you might develop and run in-house. If you use the .NET Framework in your network, you should apply this update as quickly as you can.</p>
<p><em><em>Microsoft rating: </em><strong>Critical</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032">MS12-032</a>: TCP/IP Elevation of Privilege Flaw and Firewall Bypass</strong></li>
</ul>
<blockquote><p>Two of Windows&#8217; networking components suffer from security flaws. The Windows <a href="http://www.watchguard.com/glossary/t.asp#TCP_IP">TCP/IP</a> stack suffers from a local elevation of privilege flaw involving the way it binds IPv6 addresses to local network interfaces. By running a specially crafted program, a local attacker could leverage this flaw to gain complete control of your Windows computers. However, the attacker would first need to gain local access to your Windows computers using valid credentials.</p>
<p>Also, the Windows host-based Firewall suffers from a firewall bypass vulnerability. Apparently, the Windows firewall doesn&#8217;t properly apply outbound firewall policies to <a href="http://www.watchguard.com/glossary/b.asp#broadcast">broadcast</a> packets. Attackers with access to your Windows computers could exploit this issue to get past outbound firewall policies you may have applied to your Windows computer. While this flaw doesn&#8217;t allow external attackers to gain access to your system, it could make it easier for malware that infects your system to make its command and control (C&amp;C) connection back to the attacker.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<ul>
<li><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-033">MS12-033</a>: Partition Manager Elevation of Privilege Flaw</strong></li>
</ul>
<blockquote><p>In computing, <a href="http://en.wikipedia.org/wiki/Disk_partitioning">disk partitioning</a> is the act of dividing your hard drive into more than one logical storage unit. Windows ships with the Partition Manager component to allow you to partition your hard drive. Unfortunately, the Partition Manager suffers from an elevation of privilege vulnerability having to do with how it interacts with another Windows component (specifically, the Plug and Play Configuration Manager). By running a specially crafted program, a local attacker could leverage this flaw to gain complete control of your Windows computers. However, the attacker would first need to gain local access to your Windows computers using valid credentials, which significantly lowers the severity of this issue.</p>
<p><em><em>Microsoft rating: </em><strong>Important</strong></em></p></blockquote>
<h3>Solution Path:</h3>
<p>Microsoft has released Windows patches that correct all of these vulnerabilities. You should download, test, and deploy the appropriate Windows patches throughout your network immediately. If you choose, you can also let Windows Update automatically download and install these updates for you.</p>
<p>The links below point directly to the “Affected and Non-Affected Software” section of each bulletin, where you can find the various updates:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034#section2">MS12-034</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035#section2">MS12-035</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032#section2">MS12-032</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-033#section2">MS12-033</a></li>
</ul>
<h4>For All WatchGuard Users:</h4>
<p>Attackers can exploit these flaws in many ways, including by convincing users to run an executable file locally. Since your gateway WatchGuard appliance can&#8217;t protect you against local attacks, we recommend you install Microsoft’s updates to completely protect yourself from these flaws.</p>
<p>That said, WatchGuard&#8217;s firewalls and XTM security appliances can mitigate the risk of many of these flaws. For instance, though attackers may leverage the Windows Firewall flaw to bypass host-based firewall policies, that attack will not trick our gateway firewall. Furthermore, if you use our Gateway Antivirus our appliance may block the malware attackers try to deliver to your computer when leveraging these vulnerabilities.</p>
<h3>Status:</h3>
<p>Microsoft has released patches correcting these issues.</p>
<h3>References:</h3>
<ul type="disc">
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032">MS12-032</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-033">MS12-033</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></li>
<li>Microsoft Security Bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035">MS12-035</a></li>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<div>
<hr size="2" />
</div>
<p>What did you think of this alert? Let us know at <a href="mailto:lsseditor@watchguard.com">your.opinion.matters@watchguard.com</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2043/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2043/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2043/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2043&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/08/windows-security-updates-also-fix-flaws-in-net-framework-and-office/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>Word, Visio, and Excel Suffer from Document Handling Vulnerabilities</title>
		<link>http://watchguardsecuritycenter.com/2012/05/08/word-visio-and-excel-suffer-from-document-handling-vulnerabilities/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/08/word-visio-and-excel-suffer-from-document-handling-vulnerabilities/#comments</comments>
		<pubDate>Tue, 08 May 2012 19:28:39 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[RTF]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[visio]]></category>
		<category><![CDATA[word]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2030</guid>
		<description><![CDATA[Severity: High Summary: These vulnerabilities affect: Most current versions of Microsoft Office for Windows and Mac, and related products like Visio Viewer and the Office Compatibility Packs How an attacker exploits them: Typically, by enticing you to open maliciously crafted Office documents Impact: An attacker can execute code, potentially gaining complete control of your computer [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2030&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Severity: High</h3>
<h3>Summary:</h3>
<ul>
<li><strong>These vulnerabilities affect:</strong> Most current versions of Microsoft Office for Windows and Mac, and related products like Visio Viewer and the Office Compatibility Packs</li>
<li><strong>How an attacker exploits them:</strong> Typically, by enticing you to open maliciously crafted Office documents</li>
<li><strong>Impact:</strong> An attacker can execute code, potentially gaining complete control of your computer</li>
<li><strong>What to do:</strong> Install the appropriate Office patches as soon as possible, or let Windows Update do it for you.</li>
</ul>
<h3>Exposure:</h3>
<p>Today, Microsoft released three security bulletins describing eight vulnerabilities <em>specifically</em> affecting Microsoft Office and its related components. Some of these issues affect Office running on either Windows or Mac computers, while others also affect components like the Office Compatibility Pack and Visio Viewer.</p>
<p>Microsoft also released a fourth Office-related bulletin (<a href="http://technet.microsoft.com/en-gb/security/bulletin/ms12-034">MS12-034</a>), which affects many other Microsoft products as well. Since this fourth bulletin also affects Windows users, we will detail it in our upcoming Windows alert. If you use Office, you should also refer to this Windows bulletin, and apply its update as well.</p>
<p>Microsoft&#8217;s three Office-specific bulletins describe eight code execution vulnerabilities, all of which involve the way Office (and its related applications) handle different types of documents. These document-handling flaws differ technically, but share the same general scope and impact. If an attacker can entice one of your users to download and open a maliciously crafted Office document, she can exploit any of these vulnerabilities to execute code on that user&#8217;s computer, inheriting that user&#8217;s level of privileges and permissions. If your user has local administrative privileges, the attacker gains full control of the user&#8217;s machine.</p>
<p>The only difference of note between these flaws is which type of Office document attackers use to trigger them. The affected Office documents include Rich Text Files (RTF) opened in Word, Excel (XLS) documents, and Visio (VSD, VSS, etc.) files.</p>
<p>If you&#8217;d like to learn more about each individual flaw, drill into the &#8220;Vulnerability Details&#8221; section of the security bulletins listed below:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-029"><strong>MS12-029</strong></a>: Word RTF Code Execution Vulnerability, rated Critical</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030"><strong>MS12-030</strong></a>: Multiple Excel Code Execution Vulnerabilities, rated Important</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-031"><strong>MS12-031</strong></a>: Visio Viewer Code Execution Vulnerability, rated Important</li>
</ul>
<h3>Solution Path</h3>
<div>
<p>Microsoft has released many updates to correct these vulnerabilities. If you use Office or any of the Office-related components mentioned in this alert, you should download, test, and deploy the appropriate patches as quickly as possible, or let Windows Update automatically install them for you.</p>
<p>The links below take you directly to the “Affected and Non-Affected Software” section for each bulletin, where you will find the various updates:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-029#section2">MS12-029</a> - Office and Word Updates</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-030#section2">MS12-030</a> - Office and Excel Updates</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-031#section2">MS12-031</a> - Visio Viewer Updates</li>
</ul>
</div>
<h4>For All WatchGuard Users:</h4>
<p>Many WatchGuard appliances <em>can</em> block incoming Office documents. However, most administrators prefer to allow these file types for business purposes. Nonetheless, if Office documents are not absolutely necessary to your business, you may consider blocking them using our proxies, at least until you install these patches.</p>
<p>If you would like to use our XTM and Firebox appliance&#8217;s proxy policies to block the affected documents, follow the links below for general proxy instructions:</p>
<ul>
<li><strong>XTM Appliance with WSM 11.x</strong>
<ul>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/ftp/proxy_ftp_content_c.html" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/smtp/proxy_smtp_filenames_c.html" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/pop3/proxy_pop3_filesnames_c.html" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/smtp/proxy_smtp_filenames_c.html">How do I block files with the SMTP Proxy?</a></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Firebox X Edge running 10.x</strong>
<ul>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_ftp" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_http" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_pop3" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_smtp" rel="htmltooltip">How do I block files with the SMTP proxy</a></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Firebox X Core and X Peak running Fireware 10.x</strong>
<ul>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_ftp" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_http" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_pop3" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_smtp" rel="htmltooltip">How do I block files with the SMTP proxy?</a></li>
</ul>
</li>
</ul>
<h3>Status:</h3>
<p>Microsoft has released Office updates to fix these vulnerabilities.</p>
<h3>References:</h3>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-029">MS Security Bulletin MS12-029</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-030">MS Security Bulletin MS12-030</a></li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/MS12-031">MS Security Bulletin MS12-031</a></li>
</ul>
<p><em>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</em>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2030/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2030/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2030/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2030&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/08/word-visio-and-excel-suffer-from-document-handling-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Black Tuesday: May Brings Windows, Office and .NET Patches</title>
		<link>http://watchguardsecuritycenter.com/2012/05/08/microsoft-black-tuesday-may-brings-windows-office-and-net-patches/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/08/microsoft-black-tuesday-may-brings-windows-office-and-net-patches/#comments</comments>
		<pubDate>Tue, 08 May 2012 18:09:15 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[.NET Framework]]></category>
		<category><![CDATA[Black Tuesday]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[silverlight]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[visio]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[word]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2020</guid>
		<description><![CDATA[Microsoft has offered its May security updates to the masses. As expected, the theme this month seems to revolve around Office document parsing vulnerabilities. If you use Office in your network, you will want to apply these updates as soon as possible. In their May security bulletin summary, Microsoft highlights seven security bulletins that fix 23 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2020&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft has offered its May security updates to the masses. <a href="http://watchguardsecuritycenter.com/2012/05/04/microsofts-may-patch-day-looks-office-centric/">As expected</a>, the theme this month seems to revolve around Office document parsing vulnerabilities. If you use Office in your network, you will want to apply these updates as soon as possible.</p>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may"><img class="alignright size-medium wp-image-2028" title="Microsoft Patch Day Summary: May 2012" src="http://watchguardwire.files.wordpress.com/2012/05/msmay1.jpg?w=300&h=193" alt="" width="300" height="193" /></a>In their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">May security bulletin summary</a>, Microsoft highlights seven security bulletins that fix 23 vulnerabilities in four primary products, including:</p>
<ul>
<li>Windows</li>
<li>Office</li>
<li> .NET Framework</li>
<li>Silverlight</li>
</ul>
<p>They rate three of these bulletins as <strong>Critical</strong>, which typically means remote attackers can exploit them to gain control of affected computers.</p>
<p>The two most serious flaws appear to be a vulnerability in Word (<a href="http://technet.microsoft.com/en-gb/security/bulletin/ms12-029">MS12-029</a>) involving the way it handles Rich Text Files (RTF), and ten flaws that affect Office, Windows, the .NET Framework, and Silverlight (<a href="http://technet.microsoft.com/en-gb/security/bulletin/ms12-034">MS12-034</a>); many of which also have to do with how these products handle documents or fonts. I would apply these updates in the same order Microsoft recommends in their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">summary post</a>.</p>
<p>I&#8217;ll share more details about these issues, and how to fix them, in consolidated alerts I&#8217;ll post here shortly.</p>
<p><strong>[UPDATE]</strong> <em>I mistakenly published an unfinished version of this post as I was writing it. This may have resulted in you receiving an email containing the incomplete post. I apologize for the confusion this may have caused, and the extra email.</em>  — <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#corey">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2020/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2020&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/08/microsoft-black-tuesday-may-brings-windows-office-and-net-patches/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2012/05/msmay1.jpg?w=300" medium="image">
			<media:title type="html">Microsoft Patch Day Summary: May 2012</media:title>
		</media:content>
	</item>
		<item>
		<title>Flash Update Mends a Serious Zero Day Vulnerability</title>
		<link>http://watchguardsecuritycenter.com/2012/05/04/flash-update-mends-a-serious-zero-day-vulnerability/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/04/flash-update-mends-a-serious-zero-day-vulnerability/#comments</comments>
		<pubDate>Sat, 05 May 2012 02:14:48 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[Flash Player]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=2008</guid>
		<description><![CDATA[Summary: This vulnerability affects: Adobe Flash Player  11.2.202.233 and earlier, running on all platforms (including Android) How an attacker exploits it: By enticing users to visit a website containing malicious Flash content Impact: In the worst case, an attacker can execute code on the user&#8217;s computer, potentially gaining control of it What to do: Download and install [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2008&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Summary:</h3>
<ul>
<li><strong>This vulnerability affects</strong>: Adobe Flash Player  11.2.202.233 and earlier, running on all platforms (including Android)</li>
<li><strong>How an attacker exploits it</strong>: By enticing users to visit a website containing malicious Flash content</li>
<li><strong>Impact</strong>: In the worst case, an attacker can execute code on the user&#8217;s computer, potentially gaining control of it</li>
<li><strong>What to do</strong>: Download and install the latest version of Adobe Flash Player (version 11.2.202.235 for computers)</li>
</ul>
<h3>Exposure:</h3>
<p>Adobe Flash Player displays interactive, animated web content called <a title="http://www.webopedia.com/TERM/F/Flash.html" href="http://www.webopedia.com/TERM/F/Flash.html">Flash</a>. Although Flash is optional, <a href="http://www.adobe.com/products/flashplatformruntimes/statistics.html">99% of PC users</a> download and install it to view multimedia web content. It runs on many operating systems, including mobile operating systems like Android.</p>
<p><img class="alignright size-medium wp-image-1489" title="FlashUpdate" src="http://watchguardwire.files.wordpress.com/2012/02/flashupdate1.png?w=300&h=188" alt="" width="300" height="188" />In a <a title="APSB12-09" href="http://www.adobe.com/support/security/bulletins/apsb12-09.html">security bulletin</a> released today, Adobe announced a patch that fixes a critical vulnerability in Adobe Flash Player 11.2.202.233 and earlier, running on all platforms (including Android platforms).</p>
<p>Adobe&#8217;s bulletin describes the serious flaw as an &#8220;object confusion&#8221; vulnerability (CVE-2012-0779), and warns that attackers are currently exploiting it in the wild. They don&#8217;t describe the object confusion issue in detail, but they do describe its impact. If an attacker can entice one of your users to visit a malicious website, or into handling specially crafted Flash content, he could exploit this flaw to execute code on that user&#8217;s computer, with that user&#8217;s privileges. If your users have administrator privileges, the attacker could gain full control of their computers.</p>
<p>So far, Adobe has only seen attackers exploiting this vulnerability against Windows computers, which is why they rate this a &#8220;<a href="http://www.adobe.com/devnet/security/severity_ratings.html">Priority 1</a>&#8221; issue for Windows, and recommend you apply the updates as soon as possible (within 72 hours).   However, the vulnerability technically affects other platforms as well, so I recommend you update any Flash capable device as soon as you can.</p>
<h3>Solution Path</h3>
<p>Adobe has released new versions of Flash Player (11.2.202.235 for computers and the latest 11.1.11x.x for Android) to fix these issues. If you allow Adobe Flash in your network, you should download and install the new versions immediately. If you&#8217;ve enabled Flash Player&#8217;s recent &#8220;silent update&#8221; option, you will receive this update automatically.</p>
<ul>
<li>Download Flash Player for your computer:</li>
</ul>
<div style="padding-left:60px;padding-bottom:15px;"><a href="http://www.adobe.com/go/getflash"><img class="alignnone size-full wp-image-1477" title="160x41_get_flashplayer" src="http://watchguardwire.files.wordpress.com/2012/02/160x41_get_flashplayer.gif?w=600" alt=""   /></a></div>
<div style="padding-left:60px;"></div>
<ul>
<li><a href="https://market.android.com/details?id=com.adobe.flashplayer&amp;hl=en">Download the latest Android Flash Player from Google Play</a> <em>[Visit from your Android device]</em></li>
</ul>
<div><em><strong>NOTE:</strong> </em>Chrome ships with its own version of Flash, built-in. If you use Chrome as you web browser, you will also have to update it separately, though Chrome often receive its updates automatically.</div>
<h4>For All WatchGuard Users:</h4>
<p>If you choose, you can configure the HTTP proxy on your XTM appliance to block Flash content. Keep in mind, doing so blocks all Flash content, whether legitimate or malicious.</p>
<p>Our proxies offer many ways for you to block files and content, including by<a href="http://en.wikipedia.org/wiki/File_extension"> file extension</a>, <a href="http://en.wikipedia.org/wiki/Mime_type">MIME type</a>, or by using very specific hexidecimal patterns found in the body of a message – a technique sometimes referred to as Magic Byte detection. Below I list the various ways you can identify various Flash files:</p>
<h4>File Extension:</h4>
<ul>
<li>.flv –  Adobe Flash file <em>(file typically used on websites)</em></li>
<li>.fla &#8211; Flash movie file</li>
<li>.f4v &#8211; Flash video file</li>
<li>.f4p - Protected Flash video file</li>
<li>.f4a &#8211; Flash audio file</li>
<li>.f4b &#8211; Flash audiobook file</li>
</ul>
<h4>MIME types:</h4>
<ul>
<li>video/x-flv</li>
<li>video/mp4 <em>(used for more than just Flash)</em></li>
<li>audio/mp4 <em>(used for more than just Flash)</em></li>
</ul>
<h4>FILExt.com reported Magic Byte Pattern:</h4>
<ul>
<li>Hex FLV: 46 4C 56 01</li>
<li>ASCII FLV: FLV</li>
<li>Hex FLA:  D0 CF 11 E0 A1 B1 1A E1 00</li>
</ul>
<p style="padding-left:30px;"><em>(Keep in mind, not all the Hex and ASCII patterns shared here are appropriate for content blocking. If the pattern is too short, or not unique enough, blocking with them could result in many false positives) </em></p>
<p>If you decide you want to block Flash files, the links below contain instructions that will help you configure your Firebox proxy’s content blocking features using the file and MIME information listed above.</p>
<ul>
<li><strong>XTM Appliance with WSM 11.x</strong>
<ul>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/ftp/proxy_ftp_content_c.html" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/smtp/proxy_smtp_filenames_c.html" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/pop3/proxy_pop3_filesnames_c.html" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/help/docs/webui/11-XTM/en-US/Content/en-US/proxies/smtp/proxy_smtp_filenames_c.html">How do I block files with the SMTP Proxy?</a></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Firebox X Edge running 10.x</strong>
<ul>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_ftp" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_http" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_pop3" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_edge_smtp" rel="htmltooltip">How do I block files with the SMTP proxy</a></li>
</ul>
</li>
</ul>
<ul>
<li><strong>Firebox X Core and X Peak running Fireware 10.x</strong>
<ul>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_ftp" rel="htmltooltip">How do I block files with the FTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_http" rel="htmltooltip">How do I block files with the HTTP proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_pop3" rel="htmltooltip">How do I block files with the POP3 proxy?</a></li>
<li><a href="http://www.watchguard.com/education/video/play.asp?vid=ff_fireware_smtp" rel="htmltooltip">How do I block files with the SMTP proxy?</a></li>
</ul>
</li>
</ul>
<h3>Status:</h3>
<p>Adobe has released updates to fix these Flash vulnerabilities.</p>
<h3>References:</h3>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb12-09.html">April 2012 Adobe Flash Security Bulletin</a></li>
</ul>
<p>This alert was researched and written by <em><a href="http://www.watchguard.com/archive/bios.asp">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<div></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/2008/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/2008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/2008/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=2008&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/04/flash-update-mends-a-serious-zero-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2012/02/flashupdate1.png?w=300" medium="image">
			<media:title type="html">FlashUpdate</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2012/02/160x41_get_flashplayer.gif" medium="image">
			<media:title type="html">160x41_get_flashplayer</media:title>
		</media:content>
	</item>
		<item>
		<title>WatchGuard Security Week in Review: Episode 16</title>
		<link>http://watchguardsecuritycenter.com/2012/05/04/watchguard-security-week-in-review-episode-16/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/04/watchguard-security-week-in-review-episode-16/#comments</comments>
		<pubDate>Fri, 04 May 2012 18:51:48 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Editorial Articles]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft patch day]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[vlog]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[WatchGuard Security Week in Review]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=1995</guid>
		<description><![CDATA[Lots of New Malware, Microsoft Patch Day, and Oracle Updates This week&#8217;s security summary podcast includes information about Microsoft&#8217;s upcoming Patch Day, stories about three interesting new malware variants, and updates to a few stories from previous episodes. Watch the video below for the details. If you&#8217;d prefer to read, see the &#8220;Reference&#8221; section for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=1995&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Lots of New Malware, Microsoft Patch Day, and Oracle Updates</h3>
<p>This week&#8217;s security summary podcast includes information about Microsoft&#8217;s upcoming Patch Day, stories about three interesting new malware variants, and updates to a few stories from previous episodes. Watch the video below for the details.</p>
<p>If you&#8217;d prefer to read, see the &#8220;Reference&#8221; section for links to all these security stories. I&#8217;ve seen a few late-breaking stories since I shot this week&#8217;s video, so be sure to check out those updates below. Also, don&#8217;t forget to share your thoughts or feedback in the comments section. <em>(Episode Runtime: 8:37)</em></p>
<span style="text-align:center; display: block;"><a href="http://watchguardsecuritycenter.com/2012/05/04/watchguard-security-week-in-review-episode-16/"><img src="http://img.youtube.com/vi/guqTuUatEwc/2.jpg" alt="" /></a></span>
<p><em>Direct YouTube Link:</em> <a href="http://www.youtube.com/watch?v=guqTuUatEwc">http://www.youtube.com/watch?v=guqTuUatEwc</a></p>
<h4>Episode References:</h4>
<ul>
<li><a href="http://watchguardsecuritycenter.com/2012/05/04/microsofts-may-patch-day-looks-office-centric/">Microsoft&#8217;s May Patch Day notification</a> &#8211; <em>WatchGuard Security Center</em></li>
<li>Interesting Malware:
<ul>
<li><a href="http://www.zdnet.com/blog/security/cross-platform-malware-exploits-java-to-attack-pcs-and-macs/11739?">Cross-platform Java malware</a> <em>- <em>ZDNET</em></em></li>
<li><a href="http://threatpost.com/en_us/blogs/malware-poses-us-department-justice-violation-notice-050112">U.S. Dept. of Justice ransomware</a> - <em>ThreatPost</em></li>
<li><a href="http://arstechnica.com/gadgets/news/2012/05/android-users-targeted-for-the-first-time-in-drive-by-download-attacks.ars">Android drive-by download malware (NotCompatible)</a> - <em>Ars Technica</em>
<ul>
<li><a href="http://blog.mylookout.com/blog/2012/05/02/security-alert-hacked-websites-serve-suspicious-android-apps-noncompatible/">Lookout&#8217;s analysis of NotCompatible</a><em> &#8211; Lookout Blog</em></li>
</ul>
</li>
</ul>
</li>
<li>Updates to Past Stories:
<ul>
<li>VMware source code
<ul>
<li><a href="http://www.computing.co.uk/ctg/news/2171662/-stolen-vmware-source-code-released-saturday">Attacker plans to release VMware source Saturday</a> - <em>Computing.co.uk</em></li>
<li><strong>UPDATE:</strong> <a href="http://www.vmware.com/security/advisories/VMSA-2012-0009.html">VMware releases emergency patches related to source leak</a><em> &#8211; VMware</em></li>
</ul>
</li>
<li>Flashback Updates
<ul>
<li><a href="http://www.securityweek.com/flashback-botnet-updated-include-twitter-cc">Flashback variant uses Twitter C&amp;C</a> <em>- <em>Security Week</em></em></li>
<li><a href="http://blogs.oucs.ox.ac.uk/oxcert/2012/04/25/musings-on-mac-malware/">Oxford University&#8217;s OxCERT talks about Flashback</a><em><em> <em>- <em>OxCERT</em></em></em></em></li>
</ul>
</li>
<li><a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-1675-1608180.html">Oracle Patch Day update fixes zero day exploit</a> <em>- Oracle</em></li>
</ul>
</li>
<li><strong>LATE BREAKING UPDATE</strong>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb12-09.html">Adobe releases critical Flash patch for zero day exploit</a><em> &#8211; Adobe</em></li>
</ul>
</li>
</ul>
<p>— <em><a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp#coreyn">Corey Nachreiner, CISSP</a></em> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/1995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/1995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/1995/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=1995&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/04/watchguard-security-week-in-review-episode-16/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft&#8217;s May Patch Day Looks Office-centric</title>
		<link>http://watchguardsecuritycenter.com/2012/05/04/microsofts-may-patch-day-looks-office-centric/</link>
		<comments>http://watchguardsecuritycenter.com/2012/05/04/microsofts-may-patch-day-looks-office-centric/#comments</comments>
		<pubDate>Fri, 04 May 2012 18:04:20 +0000</pubDate>
		<dc:creator>Corey Nachreiner</dc:creator>
				<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[.net]]></category>
		<category><![CDATA[Black Tuesday]]></category>
		<category><![CDATA[Developer tools]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[silverlight]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://watchguardsecuritycenter.com/?p=1989</guid>
		<description><![CDATA[Microsoft&#8217;s May Patch Day will likely include many patches that prevent attackers from leveraging malicious Office documents. According to May&#8217;s advanced notification post, Microsoft plans to release several security bulletins next Tuesday, fixing 23 flaws affecting Windows, Office, the .NET Framework, and Silverlight. Microsoft rates three of these bulletins as Critical. In a nutshell, this month&#8217;s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=1989&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may"><img class="alignright size-medium wp-image-1992" title="Microsoft Patch Day Notification: May 2012" src="http://watchguardwire.files.wordpress.com/2012/05/msmay2012.jpg?w=300&h=125" alt="" width="300" height="125" /></a>Microsoft&#8217;s May Patch Day will likely include many patches that prevent attackers from leveraging malicious Office documents.</p>
<p>According to May&#8217;s <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">advanced notification post</a>, Microsoft plans to release several security bulletins next Tuesday, fixing 23 flaws affecting Windows, Office, the .NET Framework, and Silverlight. Microsoft rates three of these bulletins as <strong>Critical</strong>.</p>
<p>In a nutshell, this month&#8217;s Patch Day looks fairly average. If forced to pick a theme, I&#8217;d say next week&#8217;s update leans towards Office-centric patches. At least two of the bulletins will probably fix Word and Excel document parsing flaws, which attackers could leverage to hijack your computer. While this month&#8217;s Patch Day won&#8217;t break any records, you&#8217;ll still want to download test and deploy Microsoft&#8217;s Critical updates as soon as you can, since they often allow remote attackers to gain full control or your machine.</p>
<p>I&#8217;ll know more about Microsoft&#8217;s May Update, and will post detailed information here on Tuesday, May 8th. — <a href="http://www.watchguard.com/corporate-info/speakers-bureau.asp"><em>Corey Nachreiner, CISSP</em></a> (<a href="http://twitter.com/SecAdept">@SecAdept</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/watchguardwire.wordpress.com/1989/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/watchguardwire.wordpress.com/1989/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/watchguardwire.wordpress.com/1989/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=watchguardsecuritycenter.com&#038;blog=13781276&#038;post=1989&#038;subd=watchguardwire&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://watchguardsecuritycenter.com/2012/05/04/microsofts-may-patch-day-looks-office-centric/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/69e1f11be8245e0be517d6c0b4b630e3?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">coreynach</media:title>
		</media:content>

		<media:content url="http://watchguardwire.files.wordpress.com/2012/05/msmay2012.jpg?w=300" medium="image">
			<media:title type="html">Microsoft Patch Day Notification: May 2012</media:title>
		</media:content>
	</item>
	</channel>
</rss>
