Foundstone Labs to Present Information on New Microsoft Vulnerabilities

From: James Foster (James.Foster_at_FOUNDSTONE.COM)
Date: 10/16/03

  • Next message: NGSSoftware Insight Security Research: "Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)"
    Date:         Thu, 16 Oct 2003 08:28:35 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Foundstone Security Briefing:
    MS03-041 through MS03-047 - Severe Vulnerabilities from Messenger to
    Exchange
     
    Yesterday, Microsoft announced seven new patches for a series of
    critical vulnerabilities that will affect nearly every Microsoft
    customer. These vulnerabilities, named MS03-041 through MS03-047, are
    found in the Microsoft Messenger service, Microsoft Exchange, Outlook
    Web Access, Windows Help and other popular Microsoft software. The
    impact of the vulnerabilities could be severe-many of the issues are
    buffer overruns that can result in remote code execution on un-patched
    hosts. The vulnerabilities that are remotely exploitable bear
    resemblance to previous Microsoft issues that were widely exploited by
    both remote attackers as well as worms that resulted in widespread
    damage.
     
    Foundstone is offering this Security Briefing as part of a coordinated
    effort designed to protect current customers and other organizations,
    globally.
     
    Web Seminar Outline:
    Introduction
    Overview of the 7 New Microsoft Vulnerabilities
    MS03-043 In-depth: Buffer Overrun in Messenger Service
    MS03-046/47 In-depth: Critical Vulnerabilities in MS Exchange Server
    The Other 4 Vulnerabilities: ActiveX, Authenticode & More
    Protective Measures
    Questions and Answers
     
    Presenters:
    Brian Kenyon - Director of Product Services
    Dave Cole - VP Product Management
     
    Go to Foundstone's Website - www.foundstone.com
    <http://www.foundstone.com/> to register for the these free briefings.
     
    Enjoy and hope to see everyone there!
     
    -Foster
     
    ...
     
    James C. Foster
    Director, Research and Development
    Foundstone, Inc.
    Strategic Security
     
    949.297.5600 Tel
    949.463.3373 Mobile
    949.297.5575 Fax
     
    http://www.foundstone.com <http://www.foundstone.com/>
     
    software | services | education
     
    This email may contain confidential and privileged information for the
    sole use of the intended recipient. Any review or distribution by others
    is strictly prohibited. If you are not the intended recipient, please
    contact the sender and delete all copies of this message. Thank you.
     

    ----
    NTBugtraq subscribers save $103.00 off the TICSA exam by using promo
    code "NT1003" when registering to take the TICSA exam at www.2test.com.
    Prove to your employer and peers that you have the knowledge and
    abilities to be an active stakeholder in today's enterprise security.
    Become TICSA certified www.trusecure.com/ticsa.  Promotion expires
    12/31/03 and cannot be used in combination with other offers.
    ----
    

  • Next message: NGSSoftware Insight Security Research: "Microsoft PCHealth 2003/XP Buffer Overflow (#NISR15102003)"

    Relevant Pages

    • SecurityFocus Microsoft Newsletter #305
      ... Microsoft Office security, part one ... Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities ... An attacker may leverage these issues to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. ...
      (Focus-Microsoft)
    • [Full-Disclosure] Foundstone Labs to Present Information on New Microsoft Vulnerabilities
      ... MS03-041 through MS03-047 - Severe Vulnerabilities from Messenger to ... critical vulnerabilities that will affect nearly every Microsoft ... found in the Microsoft Messenger service, Microsoft Exchange, Outlook ... Foundstone is offering this Security Briefing as part of a coordinated ...
      (Full-Disclosure)
    • SecurityFocus Microsoft Newsletter #306
      ... Microsoft Office security, part two ... Microsoft Internet Explorer COM Object Instantiation Daxctle.OCX Heap Buffer Overflow vulnerability. ... Cybozu Garoon Multiple SQL Injection Vulnerabilities ...
      (Focus-Microsoft)
    • Re: [Full-disclosure] Microsofts Real Test with Vista is Vulnerabilities
      ... So if they can earn more from the subscription based security solution where is the incentive to make the OS more secure? ... I am far from a Microsoft marketing expert... ... Microsoft's Real Test with Vista is Vulnerabilities ...
      (Full-Disclosure)
    • SecurityFocus Microsoft Newsletter #360
      ... A Method of Testing VoIP security or Voice VLANs ... MICROSOFT VULNERABILITY SUMMARY ... Online Armor Personal Firewall SSDT Hooks Multiple Local Vulnerabilities ...
      (Focus-Microsoft)