Current Activity Calendar
| September 26, 2006 - Current ActivityThis is an archived copy of current activity, if you would like to see the most recent version, please click here.Active Exploitation of a Vulnerability in Microsoft Internet Explorer VMLadded September 19, 2006 | updated September 26, 2006Microsoft has released Security Bulletin MS06-055 to address a vulnerability in the way Internet Explorer handles Vector Markup Language (VML). This vulnerability is being actively exploited. By persuading a user to access a specially crafted HTML document, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user or cause a denial of service condition in Internet Explorer. More information about this vulnerability can be found in the following:
We recommend the following actions to help mitigate the security risks:
We will continue to monitor this issue and provide additional information as it becomes available. Microsoft to Release Internet Explorer VML Security Updateadded September 26, 2006Microsoft will be releasing security update MS06-055, outside of the regular monthly update release schedule. The update addresses a publicly known vulnerability in the Windows implementation of Vector Markup Language (VML). More information will be made available as soon as the update is published. Apple AirPort Wireless Drivers Vulnerabilitiesadded September 22, 2006Apple has released Security Update 2006-005 to correct multiple vulnerabilities affecting Apple AirPort wireless drivers. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. Note that because device drivers execute with kernel (ring 0) privileges, exploitation of device drivers can lead to full, unrestricted access to the vulnerable system. More information about the vulnerabilities can be found in these Vulnerability Notes and Apple Security Update 2006-005. We recommend applying the updates in Apple Security Update 2006-005. We will continue to monitor this issue and provide additional information as it becomes available. Adobe Releases Security Bulletin for Flash Playeradded September 13, 2006 | updated September 18, 2006Adobe has released Security Bulletin APSB06-11 to address multiple vulnerabilities in Flash Player. Additionally, Microsoft has released Microsoft Security Advisory 925143 to alert users that affected versions of Flash Player were distributed with Microsoft Windows XP Service Pack 1, Windows XP Service Pack 2, and Windows XP Professional x64 Edition. More information about the vulnerabilities can be found in these Vulnerability Notes. US-CERT recommends the following actions to help mitigate the security risks:
Note: Users who are unable to upgrade to a more recent version of Flash Player, should refer to Adobe's Flash Player TechNote. US-CERT will continue to investigate these vulnerabilities and provide additional information as it becomes available. Public Exploit Code for Microsoft DirectAnimation Path ActiveX Control Vulnerabilityadded September 14, 2006 | updated September 15, 2006US-CERT is aware of a public exploit for a vulnerability in Microsoft Internet Explorer. The exploit code targets a vulnerability in the Microsoft DirectAnimation Path ActiveX control. By persuading a user to access a specially crafted HTML document, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user or cause a denial of service condition in Internet Explorer. More information about this vulnerability can be found in the following:
Until an update, patch, or more information becomes available, US-CERT strongly recommends the following:
US-CERT will continue to monitor this issue and provide additional information as it becomes available. Apple Releases Security Update for QuickTimeadded September 13, 2006Apple has released Apple QuickTime 7.1.3 to address several vulnerabilities in the way different types of image and media files are handled. More information about the vulnerabilities can be found in these Vulnerability Notes and Technical Cyber Security Alert TA06-256A. US-CERT encourages Quicktime users to upgrade to Quicktime 7.1.3. US-CERT will continue to investigate these vulnerabilities and provide additional information as it becomes available. Microsoft Re-Releases Windows Server Service Security Bulletin MS06-040added September 12, 2006Microsoft has released a new version of Security Bulletin MS06-040 and the associated security updates. The new version corrects the problem described in Microsoft Knowledge Base Article 921883. Programs that request large amounts of contiguous memory running on Windows Server 2003 SP1 and Windows XP Professional x64 Edition systems with the previous version of the MS06-040 update installed could crash. US-CERT strongly encourages affected users to apply the updates in the newly released Security Bulletin MS06-040 as soon as possible. Microsoft Releases September Security Bulletinadded September 8, 2006 | updated September 12, 2006Microsoft has released updates to address vulnerabilities in Microsoft Windows and Office as part of the Microsoft Security Bulletin Summary for September 2006. US-CERT strongly encourages users to review and apply these updates as soon as possible. Additionally, more information about these vulnerabilities can be found in these Vulnerability Notes and Technical Cyber Security Alert TA06-255A. US-CERT will provide additional information as it becomes available. Active Exploitation of a Vulnerability in Microsoft Word 2000added September 5, 2006 | updated September 12, 2006US-CERT is aware of active exploitation of a memory corruption vulnerability in Microsoft Word 2000. Successful exploitation could allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the user running Word 2000. More information about this vulnerability can be found in the following:
Additionally, US-CERT recommends the following actions to help mitigate the security risks:
US-CERT strongly encourages users not to open unfamiliar or unexpected email attachments, even if sent by a known and trusted source. Users may wish to read Cyber Security Tip ST04-010 for more information on working with email attachments. US-CERT will continue to monitor this issue and provide additional information as it becomes available. Hurricane Season and Phishing Sitesadded August 30, 2006In recent years, US-CERT has received reports of an increased number of phishing sites during the hurricane season. US-CERT reminds users to remain cautious when receiving unsolicited email that could be a potential phishing email. We have already received reports of malicious activity associated with Tropical Storm Ernesto. Phishing emails may appear as requests for donations from a charitable organization asking the users to click on a link that will then take them to a fraudulent web site that appears to be a legitimate charity. The users are then asked to provide personal information that can further expose them to future compromises. Users are encouraged to take the following measures to protect themselves from this type of phishing attack:
For additional information regarding phishing, US-CERT recommends reading the following documents:
Public Exploit Code Being Used to Actively Exploit a Vulnerability in Microsoft Server Serviceadded August 10, 2006 | updated August 15, 2006In addition to the previously reported active exploitation of a vulnerability in Microsoft Server Service, US-CERT has received reports of automated attacks and bot activity involving systems that have not been patched against this vulnerability. Successful exploitation could allow an attacker to execute arbitrary code with SYSTEM privileges. US-CERT will continue to monitor this issue and provide additional information as it becomes available. US-CERT strongly recommends users and administrators apply the appropriate updates in Microsoft Security Bulletin MS06-040 as soon as possible. More information about this vulnerability can be found in Vulnerability Note VU#650769 and Technical Cyber Security Alert TA06-220A. Active Exploitation of a Vulnerability in Microsoft Server Serviceadded August 8, 2006 | updated August 8, 2006US-CERT is aware of active exploitation of a buffer overflow vulnerability in the Microsoft Windows Server service. If a remote attacker sends a specially crafted packet to a vulnerable Windows system, that attacker may be able to execute arbitrary code with SYSTEM privileges. US-CERT recommends users and administrators apply the appropriate updates in Microsoft Security Bulletin MS06-040 as soon as possible. More information about this vulnerability can be found in Vulnerability Note VU#650769 and Technical Cyber Security Alert TA06-220A. US-CERT recommends users and administrators apply the appropriate updates in Microsoft Security Bulletin MS06-040 as soon as possible. Additionally, US-CERT strongly encourages users to review the Microsoft Security Bulletin Summary for August 2006 for additional information about vulnerabilities in Microsoft Windows, Office, Works, Visual Basic for Applications, and Internet Explorer. Multiple Vulnerabilities in Microsoft Internet Explorer 6.0added July 3, 2006 | updated August 1, 2006US-CERT is aware of multiple vulnerabilities in Microsoft Internet Explorer (IE) 6.0. US-CERT is also aware of a public blog that will be posting new web browser bugs on a daily basis in July. US-CERT will be analyzing relevant vulnerabilities, as well as actively monitoring the site to provide additional information as it becomes available. When available, more information about these vulnerabilities can be found in the following:
Until an update, patch, or more information becomes available, US-CERT strongly recommends the following:
We will continue to update current activity as more information becomes available. |
|||||||||||||||||||||||||||||||||||||||||||||||||||
Information For
Sign Up
Reporting
DHS Threat Advisory
The threat level in the airline sector is High or Orange. Read more

Mailing Lists & Feeds
