English | VietNam
Home
About Us
Press Center
Products
Customers
Security Blog
Bkav Forum
Contact Us
Buy Online
Downloads
Virus, Spyware, Rootkit, Security
Microsoft Security Bulletin for March 2010
10:16:09, 15/03/2010

1. General Information

On Tuesday 9 March, 2010, Microsoft released its periodic security bulletin for March with 2 patches for 8 vulnerabilities in Windows Movie Maker and Microsoft Office Excel. Simultaneously, the company also warned of a critical zero-day vulnerability in Internet Explorer.

 ID

Affected Software

Severity

MS10-016

Windows Movie Maker

Critical

MS10-017

Microsoft Office Excel

Critical

2. Technical details

Windows Movie Maker is a video edit tool available in Windows operating system. A hole found in "IsValidWMToolsStream()" function may lead to buffer overflow error while processing malformed project files (.mswmm). By seducing users to open a specially crafted .mswmm file, the attacker may execute arbitrary code on their computers.

A series of vulnerabilities in processing records of Microsoft Office Excel, a popular office application have been patched. These holes are rated critical because the hacker, if successfully exploiting them, could execute arbitrary code on users? computers.

Besides the two patches, Microsoft also warned of a zero-day vulnerability in Internet Explorer (IE) that has already been exploited among the Internet community. This hole was found in library file iepeers.dll file in IE 6 and 7. It is rated critical since it allows remote attacks and malicious code execution.

3. Solution

Most of these holes are found in widely used softwares and rated critical. Thus, Bkis recommends users to update new patches by one of the following ways:

1. Click ?Start?, ?All Programs? and choose ?Windows Update?, and the system will automatically download and install security updates.

2. Access website Microsoft Update to manually download and install security updates for your computer.

As for the zero-day vulnerability in IE, users are recommended to set IE?s security at the highest level and take caution not to access unknown websites and regularly update security patches from Microsoft.

 Analyst: Le Manh Tung

 


  Other news:
  • Windows 7: Secure but still require users’ awareness
  • 39,000 computers in Vietnam lose network connection upon virus disinfection
  • Google exploited to spread virus
  • Virus posing as Microsoft to delete users’ data has emerged
  • Metamorphic virus Sality rages because of Shortcut vulnerability
  • Vulerability in Vbulletin 3.8.4 and 3.8.5
  • Critical vulnerability in vBulletin 3.8.6
  • Vulnerability in processing marquee tag causes Firefox to crash
  • Security patches for January 2010
  • Microsoft Security Bulletin for December 2009

     Other news  
        
     News in focus
    Bkav: Want the world to know who we are

    Data of more than 85,000 computers in Vietnam has been stolen

    “We are underestimating cyber warfare”

    Safe Run Technology and Bkav 2011

    How your Yahoo! Accounts are stolen

    Bkav 2011 launching ceremony

    7,500 computers in Vietnam infected with “express” virus

    Bkav Enterprise deployed at Daewoo Hotel

    The definition of “filthy attack” does not exist

    Drop virus, swindle unlicensed Windows users for money

    Read more >>

      © 2010 Bkis - Internet Security
      Hitech Building, 1A Dai Co Viet Str., Hai Ba Trung Dist., Ha Noi, Vietnam  * Contact us
    © Please specify "source: Bkis" when using any information from this website.