GoGoDNS.COM Domain Names

微软正式公布MS10-018安全公告 修补10个IE漏洞

微软今天如约公布了MS10-018安全公告,内含一个IE软件的累积更新,一共修复了从IE5到IE8在 Windows2000-Windows 7,Server2003-2008 下的10个漏洞,其中许多被评级为危急。

微软还将本次累积更新添加到了三月份的安全公告中,作为一次补充,请所有IE用户注意该更新的部署。

Microsoft Security Bulletin MS10-018 – Critical

Cumulative Security Update for Internet Explorer (980182)
Published: March 30, 2010

Version: 1.0
General Information
Executive Summary

This security update resolves nine privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for all supported releases of Internet Explorer: Internet Explorer 5.01, Internet Explorer 6 Service Pack 1, Internet Explorer 6 on Windows clients, Internet Explorer 7, and Internet Explorer 8 on Windows clients. For Internet Explorer 6 on Windows servers, this update is rated Important. And for Internet Explorer 8 on Windows servers, this update is rated Moderate. For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses these vulnerabilities by modifying the way that Internet Explorer verifies the origin of scripts and handles objects in memory, content using encoding strings, and long URL. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection under the next section, Vulnerability Information.

This security update also addresses the vulnerability first described in Microsoft Security Advisory 981374. The vulnerability, CVE-2010-0806, does not affect Windows 7, Windows Server 2008 R2, or Internet Explorer 8.

Recommendation. The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.

For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.

See also the section, Detection and Deployment Tools and Guidance, later in this bulletin.

Known Issues. None
Top of sectionTop of section
Affected and Non-Affected Software

The software listed here have been tested to determine which versions or editions are affected. Other versions or editions are either past their support life cycle or are not affected. To determine the support life cycle for your software version or edition, visit Microsoft Support Lifecycle.

…… 点击这里阅读更多

本文链接地址:http://blog.pipolife.com/archives/3387
如转载,请注明:“转载自 品理博客 - http://Blog.Pipolife.com/”,并注明链接地址!
GoGoDNS.COM Reseller

GoGoDNS.COM Domain Names

GoGoDNS.COM Web Hosting

GoGoDNS.COM SSL Certificates


您可能感兴趣的相关文章:


GoGoDNS.COM Email Accounts


更多搜索(包含站外相关内容):

Loading


You can leave a response, or trackback from your own site.

Leave a Reply

You must be logged in to post a comment.

Search, Register and Transfer Web Domain Names and More - GoGoDNS.COM | Domain Names | Web Hosting | SSL Certificates | Email Accounts | Marketing Tools | Build a Website | Reseller Plans