Microsoft Environment Analysis Unit2 Assiginment 2
In:
Submitted By jayrezon Words 377 Pages 2
1. Advisory 2757760: Vulnerability in Internet Explorer could allow remote code execution. This vulnerability has been investigated my Microsoft and a link to the appropriate update has been issued on the Advisory page. 2. Advisory 2755801: Vulnerabilities in Adobe Flash Player in IE 10. The software affected by this vulnerability are both 32/64-bit Windows 8 systems, and also Windows Server 2012. An update has been published that fixes this by updating the Adobe Flash libraries in IE 10 that are affected. It is also possible to temporarily remedy this by changing up the registry files with the text provided on the Advisory page. The Administrator may also disable Flash Player from running on IE 10 via group policy on Windows 8 and Server 2012. 3. Advisory 2736233: Microsoft has released new kill bits for ActiveX after multiple requests by Cisco concerning vulnerabilities in some of its services; Cisco Secure Desktop, Cisco Host scan, and Cisco Any Connect Secure Mobility Client are all services that are affected by ActiveX vulnerability. This affects most Windows XP/7 systems, along with Server 2003/2008 software. 4. Advisory 2661254: Update for Minimum Key Certificate Length. RSA keys being used in certificates that are less than 1024 bits in length are vulnerable to attackers duplicating the certificates, phishing, and man in the middle attacks. Examples of the services that are affected are encrypted emails and private PKI environments. It is suggested that this update is tested out first before being pushed out throughout an entire organization to ensure time to solve potential problems that arise from blocking certificates less than the new minimum. 5. Advisory 2728973: Unauthorized Digital Certificates Could Allow Spoofing. A number of certificates have been blocked and replaced by Microsoft after they discovered that these certificates are outside our recommended secure storage practices. The update is a preventative measure since no misuse has been identified. On September 11, 2012, a Security bulletin was posted by Microsoft as Advisory 2741528: Vulnerability in System Center Configuration Manager Could Allow Elevation of Privilege. It is very obvious that these vulnerabilities are considered high priority as Microsoft repeatedly comments on the importance of the update and the severity of the consequences of not applying said update within the Advisory page.