US-CERT Technical Cyber Security Alert TA10-257A -- Microsoft Updates for Multiple Vulnerabilities




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


National Cyber Alert System

Technical Cyber Security Alert TA10-257A


Microsoft Updates for Multiple Vulnerabilities

Original release date: September 14, 2010
Last revised: --
Source: US-CERT


Systems Affected

* Microsoft Windows
* Microsoft Office


Overview

There are multiple vulnerabilities in Microsoft Windows and
Microsoft Office. Microsoft has released updates to address these
vulnerabilities.


I. Description

The Microsoft Security Bulletin Summary for September 2010
describes multiple vulnerabilities in Microsoft Windows and
Microsoft Office. Microsoft has released updates to address the
vulnerabilities.


II. Impact

A remote, unauthenticated attacker could execute arbitrary code or
cause a vulnerable system or application to crash.


III. Solution

Apply updates

Microsoft has provided updates for these vulnerabilities in the
Microsoft Security Bulletin Summary for September 2010. That
bulletin describes any known issues related to the updates.
Administrators are encouraged to note these issues and test for any
potentially adverse effects. In addition, administrators should
consider using an automated update distribution system such as
Windows Server Update Services (WSUS).


IV. References

* Microsoft Security Bulletin Summary for September 2010 -
<http://www.microsoft.com/technet/security/bulletin/ms10-sep.mspx>

* Microsoft Windows Server Update Services -
<http://technet.microsoft.com/en-us/wsus/default.aspx>

____________________________________________________________________

The most recent version of this document can be found at:

<http://www.us-cert.gov/cas/techalerts/TA10-257A.html>
____________________________________________________________________

Feedback can be directed to US-CERT Technical Staff. Please send
email to <cert@xxxxxxxx> with "TA10-257A Feedback VU#447990" in
the subject.
____________________________________________________________________

For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
____________________________________________________________________

Produced 2010 by US-CERT, a government organization.

Terms of use:

<http://www.us-cert.gov/legal.html>
____________________________________________________________________

Revision History

September 14, 2010: Initial release


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBTI/u6T6pPKYJORa3AQKfgQgAsBDEHMH+Dq73qHFwsGnUIBWi7DkAV64s
0tz109GDGQRXL/MkXwWfaFfDc+h4ZUgjfVv93GBjK0NI78mYOWxSS7Pd3WhD6TaH
YFcDcF4IW06Er4wEjgR+y5fTvF17k3Cix0GdsVzet/I2XMd4uCnIrHyLzLgZhf5s
sWtv+kLaqCKUl8zsmcpmTcKUt+V2U3VWGeICIwuZXjB8FNHWuzYN1r/togFt0tcA
16gtGSCmdJy6Er+FyXxTJvWX4uJywBTDtIZZY/xyhGp2dBWUdOfY1k+7C5Dp/tCY
Rq9tOY6caxHUYmitTtABaop83jTJFnS53lQJo4UizDNQoNbRSUIVFA==
=dDpT
-----END PGP SIGNATURE-----



Relevant Pages