Microsoft fixes twin XSS, issues new cert requirement

By
Follow google news

Vulnerabilities aren't high-risk.

Microsoft on Tuesday released security updates for two vulnerabilities categorised as important.

Microsoft fixes twin XSS, issues new cert requirement

The update addressed a Visual Studio Team Foundation Server flaw that permitted privilege escalation for attackers if they visited a malicious web page.

A vulnerability in System Center Configuration Manager was also patched. This could allow similar privilege elevations.

None of the issues addressed were known to be under active exploit, according to a blog post at Microsoft Security Response Center.

“To be able to exploit these vulnerabilities, an attacker would craft a malicious link for a victim to click on, allowing them to compromise the victim's system,” Rapid7 security researcher Marcus Carey told SC.

"It's always a good idea to educate employees [or] end-users on how to spot and avoid suspect links."

The update also includes a new certificate requirement that RSA keys be a minimum of 1,024 bits in length. The new rule resulted from the sophisticated Flame virus, in which attackers beat weak crypto algorithms to spread onto target networks.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Microsoft releases fix for flawed January security update

Microsoft releases fix for flawed January security update

Starlink faces high-profile security test in Iran crackdown

Starlink faces high-profile security test in Iran crackdown

Single Windows image drove RedVDS disposable cybercrime server business

Single Windows image drove RedVDS disposable cybercrime server business

Microsoft patches single-click Copilot data stealing attack

Microsoft patches single-click Copilot data stealing attack

Log In

  |  Forgot your password?