Content

BREAKING ADVISORY

August 10, 2010:  As announced, Microsoft has released their August 2010 Security Bulletins. A total of 14 bulletins addressing 34 vulnerabilities have been released. Affected components include Microsoft Windows, Office, Internet Explorer, the Microsoft .NET Framework, and Microsoft Silverlight. Eight of the bulletins are rated 'Critical' and five are rated as 'Important'. All eight of the critical vulnerabilities also carry a potential impact of remote code execution.

 

Learn More

August 2, 2010:   Microsoft has released out-of-band bulletin MS10-046.  This release addresses a critical code execution vulnerability in Windows, which is currently being exploited by malware in-the-wild.  This vulnerability was first disclosed in Microsoft Security Advisory 2286198 (CVE-2010-2568).  McAfee product coverage and mitigation details are available here.


Learn More

Current Malware

Malware-

A malicious program. Viruses and Trojans are examples of malware. Potentially unwanted programs (PUPs) are not considered malware.

ThreatDate Updated
Exploit-CVE2010-081422 Jul 2010
Exploit-CVE2010-256821 Jul 2010
MSIL/Terdial.D20 Jul 2010
Stuxnet16 Jul 2010
Downloader-CJX10 Jul 2010
W32/Autorun.worm.g03 Jul 2007

Most Prevalent Potentially Unwanted Programs (PUPs)

PUPs-

Software programs written by legitimate companies that may alter the security state or the privacy posture of the computer on which they are installed. This software can but does not necessarily include spyware, adware, and dialers, and could be downloaded in conjunction with a program that the user wants. Security-minded users know about such programs and, in some case, have them removed.

Threat Date Discovered

Current Vulnerabilities

Vulnerability-

Exploitable defect in a software application or operating system, allowing others to crash systems, access information on systems, or use systems for their own purposes.

ThreatDate Public
MSFT SChnl RCE Vuln10 Aug 2010
MSFT Win Movie Mem V..10 Aug 2010
MSFT Win SMB ovrflo ..10 Aug 2010
MSFT Win SMB Val Vuln10 Aug 2010
MS Win 2010256814 Jul 2010
IE Mem Corr Vuln08 Jun 2010