Submit a Story!
MS09-054: Extra info on the attack surface for the IE security bulletin
MS09-054   addresses an IE vulnerability (CVE-2009-2529), which was discovered and presented by Mark Dowd, Ryan Smith, and David Dewey at the BlackHat conference in July. First we’d like to make it clear that any customers that have applied the update associated with MS09-054 are ...
Comments
Blog Reactions

Stealthy Microsoft Plug-in Adds Vulnerability to Firefox
Maximum PC — ... The security weakness was introduced through the Windows Presentation Foundation plug-in, which was installed both in IE and Firefox. According to Annoyances.org, the update made Firefox susceptible to one of IE’s biggest weaknesses: “the ability for websites to easily and quietly install software on your PC.” Initially, the plug-in couldn’t be removed from Firefox, a problem rectified by a May update to the .NET Framework 3.5 SP1. However, given that Microsoft has revisited the issue in a newly released security bulletin, the problem seems to ...

Mozilla disables, reinstates Microsoft plugin for Firefox
Ars Technica — ... posted Friday in the official Mozilla security blog. He explains that Mozilla decided to block the plugin when Microsoft suggested that users should consider turning it off until the efficacy of the fix has been fully confirmed. The related .NET Framework Assistant add-on was initially blocked too, but Mozilla removed it from the blocklist when Microsoft later confirmed that it was not vulnerable. "Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today ...

Related Content
Microsoft Security Bulletin MS09-034 - Critical: Cumulative Security Update for Internet Explorer (972260)
microsoft.com 7/28/2009 — This security update is being released out of band in conjunction with Microsoft Security Bulletin MS09-035 , which describes vulnerabilities in those components and controls that have been developed using vulnerable versions of the Microsoft Active ...
Security Bulletin APSB09-15 Security Updates Available for Adobe Reader and Acrobat
adobe.com 10/14/2009 — Michael Schmidt of Compass Security ( http://www.csnc.ch ) (CVE-2007-0048, CVE-2007-0045) Didier Stevens (CVE-2009-2979) Drew Yao of Apple Product Security ( http://www.apple.com/support/security/ ) (CVE-2009-2980) Stefano Di Paola of Minded Security ...