On August, 2nd, 2010 Microsoft (http://www.microsoft.com/) released the the security bulletin MS10-046 (http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx).
The bulletin informs about release of the patch which closes the vulnerability of the OS (http://www.microsoft.com/technet/security/advisory/2286198.mspx). Vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. We remind that the experts from VirusBlokAda Ltd were the first who detected the given vulnerability (www.virusu.net).
Microsoft informs that the given vulnerability mentions all supported operating systems, from OS Windows XP SP3 to Windows Server 2008, including 64 bit systems. Thus it is also known that earlier operating systems, including Windows 2000 and Windows XP SP2 are also vulnerable.
Also we wish to mark that the vulnerability has started to be applied by some sets of malicious programs. So, it is already fixed that TmpHider (Stuxnet, Sality, Zeus actively use new vulnerability.
VirusBlokAda Ltd recommends its users use auto update of OS Windows for installation of patch MS10-046 (http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx). To users who don’t use auto update, we recommend to download and instal manually the patch as soon as possible.
|