Category Archives: Microsoft

2871997 – Update to Improve Credentials Protection and Management – Version: 3.0

Revision Note: V3.0 (September 9, 2014): Rereleased advisory to announce the release of update 2982378 to provide additional protection for users’ credentials when logging into a Windows 7 or Windows Server 2008 R2 system. See Updates Related to this Advisory for details.
Summary: Microsoft is announcing the availability of updates for supported editions of Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 that improve credential protection and domain authentication controls to reduce credential theft.

Insecure ASP.NET Site Configuration Could Allow Elevation of Privilege – Version: 2.0

Revision Note: V2.0 (September 9, 2014): Advisory rereleased to announce the offering of the security update via Microsoft Update, in addition to the Download-Center-only option that was provided when this advisory was originally released.Summary: Micr…

2755801 – Update for Vulnerabilities in Adobe Flash Player in Internet Explorer – Version: 27.0

Revision Note: V27.0 (August 12, 2014): Added the 2982794 update to the Current Update section.Summary: Microsoft is announcing the availability of an update for Adobe Flash Player in Internet Explorer on all supported editions of Windows 8, Windows Se…

2915720 – Changes in Windows Authenticode Signature Verification – Version: 1.4

Revision Note: V1.4 (July 29, 2014): Revised advisory to announce that Microsoft no longer plans to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. It remains available as an opt-in feat…

2982792 – Improperly Issued Digital Certificates Could Allow Spoofing – Version: 2.0

Revision Note: V2.0 (July 17, 2014): Advisory revised to announce the availability of update 2982792 for supported editions of Windows Server 2003. For more information, see the Suggested Actions section of this advisory.Summary: Microsoft is aware of …

2982792 – Improperly Issued Digital Certificates Could Allow Spoofing – Version: 1.0

Revision Note: V1.0 (July 10, 2014): Advisory published.Summary: Microsoft is aware of improperly issued SSL certificates that could be used in attempts to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. The SSL certifica…

2755801 – Update for Vulnerabilities in Adobe Flash Player in Internet Explorer – Version: 26.0

Revision Note: V26.0 (July 8, 2014): Added the 2974008 update to the Current Update section.Summary: Microsoft is announcing the availability of an update for Adobe Flash Player in Internet Explorer on all supported editions of Windows 8, Windows Serve…