Latest IT News » Security » November’s Patch Tuesday: Microsoft fixes critical vulnerability in TCP / IP

November’s Patch Tuesday: Microsoft fixes critical vulnerability in TCP / IP

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on a system.

“Because the vulnerability does not require interaction with a user or authentication, all Windows machines, workstations and servers that are connected to the Internet, are freely attacked,” said Amol Sarwat, employees of the security provider Qualys. However, it is complicated to carry out an attack on the gap. Assessed with the Microsoft exploitability “2″, which means that an exploit is not functioning reliably.

In addition, Microsoft eliminated a vulnerability in Windows Mail and Windows Meeting Space (MS11-085), which can be exploited by DLL hijacking. The other two updates plug holes in Active Directory (MS11-086) and the Windows kernel-mode drivers (MS11-084). The latter are running Windows 7 and Windows Server 2008 R2 vulnerable to denial-of-service attacks.

Remains an unpatched zero-day vulnerability in the Windows kernel, which is exploited by the Trojan Duque. In the past week, Microsoft had provided a workaround that fixes the error in the processing of Win32k-True Type fonts, at least temporarily.

The latest news from "Security"

U.S. report: China makes progress in the fight against copyright infringement

U.S. report: China makes progress in the fight against copyright infringement

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

Mozilla speaks out against CISPA

Mozilla speaks out against CISPA

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

Google closes five vulnerabilities in Chrome

Google closes five vulnerabilities in Chrome

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

Cross-Platform Malware attacks Macs and PCs

Cross-Platform Malware attacks Macs and PCs

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

Avast Software presents freeware antivirus tool for Mac OS

Avast Software presents freeware antivirus tool for Mac OS

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

Microsoft fixes critical vulnerability Hotmail

Microsoft fixes critical vulnerability Hotmail

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]

British police raised ring of credit card data from retailers

British police raised ring of credit card data from retailers

Microsoft has announced four security updates as released. Below is a patch for a “critical”-rated vulnerability in TCP / IP (MS11-083) under Windows Vista, Server 2008, 7 and Server 2008 R2. An attacker could exploit with specially-crafted UDP packets that are sent to a closed port, a memory vulnerability and execute arbitrary malicious code on [...]