November 2010 - Microsoft Releases 3 Security Advisories
Publish date: February 21, 2013
Severity: CRITICAL
Advisory Date: NOV 09, 2010
DESCRIPTION
Microsoft addresses the following vulnerabilities in its November batch of patches:
- (MS10-087) Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)
Risk Rating: Critical
This security update addresses vulnerabilities in Microsoft Office that could allow remote execution when an unsuspecting user opens a specially crafted .RTF email message. Read more . - (MS10-088) Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386)
Risk Rating: Important
This update resolves two vulnerabilities in Microsoft Office that could allow a malicious user to execute code remotely when users open a specially crafted PowerPoint file. Read more . - (MS10-089) Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074)
Risk Rating: Important
This security update resolves four vulnerabilities in Forefront Unified Access Gateway (UAG). Read more .
TREND MICRO PROTECTION INFORMATION
live casino online clients using OfficeScan with Intrusion Defense Firewall (IDF) may refer to the table below for the pattern filter identifier(s):
Microsoft Bulletin ID | Vulnerability ID | Identifier & Title | IDF First Pattern Version | IDF First Pattern Release Version |
---|---|---|---|---|
MS10-087 | CVE-2010-3333 | 1004498 - Word RTF File Parsing Stack Buffer Overflow Vulnerability | 10-035 | Nov 10, 2010 |
MS10-087 | CVE-2010-3336 | 1004500 - MSO Large SPID Read AV Vulnerability | 10-035 | Nov 10, 2010 |
MS10-088 | CVE-2010-2573 | 1004499 - PowerPoint Integer Underflow Causes Heap Corruption Vulnerability | 10-035 | Nov 10, 2010 |
MS10-089 | CVE-2010-2733 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
MS10-089 | CVE-2010-2734 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
MS10-089 | CVE-2010-2736 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
SOLUTION
PATCH:
Featured Stories
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more
- A Closer Exploration of Residential Proxies and CAPTCHA-Breaking ServicesThis article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.Read more
- How Residential Proxies and CAPTCHA-Solving Services Become Agents of AbuseThis article, the first of a two-part series, provides insights on how abusers and cybercriminals use residential proxies and CAPTCHA-solving services to enable bots, scrapers, and stuffers, and proposes security countermeasures for organizations.Read more