Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: Microsoft December Patches SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Microsoft December Patches
Details about the MSFT December patches just showed up online. We will update this page as we find out more.

MS 05-54: Cumulative Security Update for Internet Explorer

First look: This DOES NOT fix the javascript window() issue. Still translating from "Microsoft" to "English".

http://www.microsoft.com/technet/security/Bulletin/MS05-054.mspx

MS 05-55: Vulnerability in Windows Kernel Could Allow Elevation of Privilege.

A vulnerability in the Asynchronous Procedure Call queue allows local users to escalate their privileges. A regular user (who has to be logged in first) could use this vulnerability to gain Administrator privileges.
Microsoft rates this vulnerability as "Important" as there is no direct remote vector to exploit this issue. However, coupled with an Internet Explorer vulnerability or similar issues, this could be used to gain Administrator privileges even if a user runs Internet Explorer as a less privileged user.
Note that remote exploit may be possible if user credentials are known.
http://www.microsoft.com/technet/security/Bulletin/MS05-055.mspx

Johannes

3910 Posts
ISC Handler
Dec 13th 2005

Sign Up for Free or Log In to start participating in the conversation!