Archive

Posts Tagged ‘vulnerability’

Windows Help Centre ATTACKS … (Zero-Day Vulnerability)!

June 10th, 2010 No comments

 
A recent discovery of a Zero-Day Vulnerability in the “Windows Help Centre” HCP Protocol Handler, which does not handle correctly malformed “Escape Sequences”. Hence, executing code remotely without the authorization of the user.
 
As per Microsoft, the vulnerability is applicable only to Windows XP and Windows Server 2003.
 
Scareware criminals are already taking advantage of the vulnerability to earn profit by installing unauthorized software on user machines (i.e. Fake Antivirus).
 
Here is what you can do to prevent damages:

Try the following harmless Proof-of-Concept (at your own risk):

 
UPDATE (2010/07/13): Microsoft has released a patch for this issue (MS10-042). Please update as soon as possible.
 

Citrix OnLine Plug-In Vulnerable to MITM Attack (Update Required)!

November 10th, 2009 No comments

 
An immediate update of “Citrix OnLine Plug-In” is required in order to be safe from the recent Man-In-The-Middle Attack exploiting the newly discovered SSL/TLS Renegotiation Vulnerability.
 
If you are connecting to a Citrix Gateway, we recommend you update your plug-in as soon as possible from here:

 

Categories: General Tags: ,