Security 10805 Published by

Microsoft published the following security bulletin updates:

- MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.2
- MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.2
- Microsoft Security Advisory (2458511): Vulnerability in Internet Explorer Could Allow Remote Code Execution



MS10-079 - Important: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) - Version:1.2
Severity Rating: Important - Revision Note: V1.2 (November 3, 2010): Corrected the bulletin replacement information for the Microsoft Word Viewer update (KB2345009). This is an informational change only. There were no changes to the detection logic or the update files.

Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Read more

MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042) - Version:2.2
Severity Rating: Important - Revision Note: V2.2 (November 3, 2010): Added a note to the Affected Software table to clarify that the .NET Framework 4.0 Client Profile is not affected.

Summary: This security update resolves a publicly disclosed vulnerability in ASP.NET. The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.
Read more

Microsoft Security Advisory (2458511): Vulnerability in Internet Explorer Could Allow Remote Code Execution
Revision Note: V1.1 (November 3, 2010): Added the opening of HTML mail in the Restricted sites zone as a mitigating factor, the automated Microsoft Fix it solution to the CSS workaround, and a finder acknowledgment. Removed reading e-mail in plain text as a workaround. Also clarified content in the EMET, DEP, and CSS workarounds.

Summary: Microsoft is investigating new, public reports of a vulnerability in all supported versions of Internet Explorer. The main impact of the vulnerability is remote code execution. This advisory contains workarounds and mitigations for this issue.
Read more