lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
From: insecure at ameritech.net (insecure) Subject: Critical update for IE disables the ADODB.Stream object Microsoft just released a critical update for IE, Windows-KB870669-x86-ENU.exe. This update is applicable to Windows NT, 2000, XP, and 2003. There is no associated security bulletin. The download is available here: http://www.microsoft.com/downloads/details.aspx?FamilyID=4D056748-C538-46F6-B7C8-2FBFD0D237E3&DisplayLang=en The update disables the ADODB.Stream object from Internet Explorer. This vulnerability has been known for about a year, but has not previously been acknowledged by Microsoft. It has been used in dozens of attacks to silently install and run malicious software, including the last week's Download.Ject attack (also known as JS.Scob.Trojan, Scob, and JS.Toofeer), and this week's attack which installs a malicious BHO through compromised advertisement servers which then steals on-line banking account names and passwords, called "Trojan.Spy.Small.AA", "PWS.Banker.C.Trojan", "PWS-WebMoney.gen", and "bankhook.a".
Powered by blists - more mailing lists