July 14, 2009Microsoft published its monthly security bulletin release on July 14, 2009. Six bulletins were released that address nine individual vulnerabilities. Three of the bulletins are rated as Critical, and the remainder are rated as Important. The three Critical bulletins address vulnerabilities in Microsoft Windows that could allow attacker to execute arbitrary code. However, an attacker must rely on user interaction to accomplish an exploit of these vulnerabilities. The Important bulletin for Microsoft Publisher also corrects a vulnerability that could allow attackers to execute arbitrary code. The remaining Important bulletins correct privilege escalation vulnerabilities in Microsoft ISA Server and Microsoft Virtual PC and Virtual Server. Two previously reported vulnerabilities, CVE-2009-1537 (MS09-028) and CVE-2008-0015 (MS09-032), were addressed by Microsoft as part of this release; current reports indicate active and ongoing exploitation of each vulnerability. |
|
| |||||||||||||||||||||||||||||||||||||||||||||||
Event IntelligenceThe following table identifies Cisco Security Intelligence Operations content and Cisco mitigation information that is associated with this Microsoft release:
Cisco Security Intelligence OperationsCisco Applied Mitigation Bulletins provide identification and mitigation techniques that administrators can deploy on Cisco network devices. Cisco Intrusion Prevention System (IPS) signatures, Cisco Security Monitoring, Analysis, and Response System Incidents, Cisco ACE Application Control Engine, and firewall inspection are discussed in this bulletin. Cisco Applied Mitigation Bulletin: Microsoft Security Bulletin Release for July 2009 Impact on Cisco ProductsImpact Assessment of July 2009 Microsoft Security Bulletins on Cisco Contact Center and Self Service Products Cisco IP Telephony Operating System, SQL Server, Security Updates Related LinksCisco ACE 4710 Application Control Engine Cisco IPS 6.x Signature Downloads
|
|||||||||||||||||||||||||||||||||||||||||||||||||
