Urgente, a actualizar el bug de Internet Explorer:
This security update resolves a publicly disclosed vulnerability in
Internet Explorer. The vulnerability could allow remote code execution
if a user views a specially crafted webpage using an affected version of
Internet Explorer. An attacker who successfully exploited this
vulnerability could gain the same user rights as the current user. Users
whose accounts are configured to have fewer user rights on the system
could be less impacted than users who operate with administrative user
rights.
This security update is rated Critical for Internet Explorer 6
(IE 6), Internet Explorer 7 (IE 7), Internet Explorer 8 (IE 8),
Internet Explorer 9 (IE 9), Internet Explorer 10 (IE 10), and Internet
Explorer 11 (IE 11) on affected Windows clients, and Moderate for
Internet Explorer 6 (IE 6), Internet Explorer 7 (IE 7), Internet
Explorer 8 (IE 8), Internet Explorer 9 (IE 9), Internet Explorer 10 (IE
10), and Internet Explorer 11 (IE 11) on affected Windows servers. For
more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerability by modifying
the way that Internet Explorer handles objects in memory. For more
information about the vulnerability, see the Frequently Asked Questions
(FAQ) subsection for the specific vulnerability entry later in this
bulletin.
This security update addresses the vulnerability first described in Microsoft Security Advisory 2963983.
Recommendation. Most customers have automatic
updating enabled and will not need to take any action because this
security update will be downloaded and installed automatically. For
information about specific configuration options in automatic updating,
see Microsoft Knowledge Base Article 294871. For Customers who do not have automatic updating enabled, the steps in Turn automatic updating on or off can be used to enable automatic updating.
For administrators and enterprise installations, or end users
who want to install this security update manually (including customers
who have not enabled automatic updating), Microsoft recommends that
customers apply the update immediately using update management software,
or by checking for updates using the Microsoft Update service. The updates are also available via the download links in the Affected Software table later in this bulletin.
See also the section, Detection and Deployment Tools and Guidance, later in this bulletin.
Fuente: https://technet.microsoft.com/library/security/ms14-021
No hay comentarios:
Publicar un comentario