Microsoft on Tuesday released security updates for two vulnerabilities categorised as important.
The update addressed a Visual Studio Team Foundation Server flaw that permitted privilege escalation for attackers if they visited a malicious web page.
A vulnerability in System Center Configuration Manager was also patched. This could allow similar privilege elevations.
None of the issues addressed were known to be under active exploit, according to a blog post at Microsoft Security Response Center.
“To be able to exploit these vulnerabilities, an attacker would craft a malicious link for a victim to click on, allowing them to compromise the victim's system,” Rapid7 security researcher Marcus Carey told SC.
"It's always a good idea to educate employees [or] end-users on how to spot and avoid suspect links."
The update also includes a new certificate requirement that RSA keys be a minimum of 1,024 bits in length. The new rule resulted from the sophisticated Flame virus, in which attackers beat weak crypto algorithms to spread onto target networks.
This article originally appeared at scmagazineus.com
Copyright © SC Magazine, US edition
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.