-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 National Cyber Alert System Technical Cyber Security Alert TA10-194A Microsoft Updates for Multiple Vulnerabilities Original release date: July 13, 2010 Last revised: -- Source: US-CERT Systems Affected * Microsoft Windows * Microsoft Office Overview Microsoft has released updates to address vulnerabilities in Microsoft Windows and Microsoft Office. I. Description The Microsoft Security Bulletin Summary for July 2010 describes multiple vulnerabilities in Microsoft Windows and Microsoft Office. Microsoft has released updates to address the vulnerabilities. One of the bulletins released, MS10-042, addresses a previously identified vulnerability in the Windows Help and Support Center that is actively being exploited. This vulnerability was also described in US-CERT Vulnerability Note VU#578319. II. Impact A remote, unauthenticated attacker could execute arbitrary code or cause a vulnerable system or application to crash. III. Solution Apply updates Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for July 2010. The security bulletin describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. Administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS). IV. References * Microsoft Security Bulletin Summary for July 2010 - <http://www.microsoft.com/technet/security/bulletin/ms10-jul.mspx> * Microsoft Security Bulletin MS10-042 - <http://www.microsoft.com/technet/security/Bulletin/MS10-042.mspx> * US-CERT Vulnerability Note VU#578319 - <http://www.kb.cert.org/vuls/id/578319> * Microsoft Windows Server Update Services - <http://technet.microsoft.com/en-us/wsus/default.aspx> ____________________________________________________________________ The most recent version of this document can be found at: <http://www.us-cert.gov/cas/techalerts/TA10-194A.html> ____________________________________________________________________ Feedback can be directed to US-CERT Technical Staff. Please send email to <cert@xxxxxxxx> with "TA10-194A Feedback VU#578319" in the subject. ____________________________________________________________________ For instructions on subscribing to or unsubscribing from this mailing list, visit <http://www.us-cert.gov/cas/signup.html>. ____________________________________________________________________ Produced 2010 by US-CERT, a government organization. Terms of use: <http://www.us-cert.gov/legal.html> ____________________________________________________________________ Revision History July 13, 2010: Initial release -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iQEVAwUBTDzX2T6pPKYJORa3AQIMqAf8DAtXkaZDApO+QDMfycnnbMhgGHEcxT4/ rgdllq0xLXfTY7YlMUZiamqtJGcqibjlYJ6Hs62j7wXDjU7dhge9vKFij6AY6ZxY fXss0Qa63RmslfHQNYoF34kfgtbrRLahbF7iBpNysXN7gHi/DC0WZ/AWCFxoxWvf NhuFz/8h3BDFc6JprPMo+R2Y/YIegJAeds12awMxCkJh9iEuBLSoTrZ70IJBDObd 5NO5U/mwpCOJDedCCOiEZGKqfrrSXffpaunheuniTBSXJMzkYm9/jaqQ19Zb/+bb 9C4paLvLoH5rByEO7NWPzBlrFNr4WPUSlUf0UQEYcvWRZiCZoO/q/g== =+OxL -----END PGP SIGNATURE-----