Tuesday 31 July 2012

(Microsoft) Vulnerabilities in Gadgets Could Allow Remote Code Execution



Microsoft has posted about a vulnerability through which Hackers or Crackers can pass remote Information to your computer which inturn will pass information to them about your computer and eventually gaining control over your computer. So, Microsoft has released a Security Software which will disable your Vulnerable Gadgets!! 

Information From Microsoft :

General Information

Executive Summary

Microsoft is announcing the availability of an automated Microsoft Fix it solution that disables the Windows Sidebar and Gadgets on supported editions of Windows Vista and Windows 7. Disabling the Windows Sidebar and Gadgets can help protect customers from vulnerabilities that involve the execution of arbitrary code by the Windows Sidebar when running insecure Gadgets. In addition, Gadgets installed from untrusted sources can harm your computer and can access your computer's files, show you objectionable content, or change their behavior at any time. 
An attacker who successfully exploited a Gadget vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Applying the automated Microsoft Fix It solution described in Microsoft Knowledge Base Article 2719662 disables the Windows Sidebar experience and all Gadget functionality.
Recommendation. Customers who are concerned about vulnerable or malicious Gadgets should apply the automated Fix It solution as soon as possible. 

INTRODUCTION

Microsoft has released a Microsoft security advisory about this issue for IT professionals. The security advisory contains additional security-related information. To view the security advisory, visit the following Microsoft website:

To have us fix this problem for you, go to the "Fix it for me" section.

Fix it for me

The Fix it solution that is described in this section is not intended to be a replacement for any security update. We recommend that you always install the latest security updates. However, we offer this Fix it solution as a workaround option for some scenarios.

For more information about this workaround, visit the following Microsoft Security Advisory webpage:
The advisory provides more information about the issue, including the following:
  • The scenarios in which you might apply or disable the workaround.
  • How to manually apply the workaround.
Specifically, to see this information, expand the Suggested actions section, and then expand the Workarounds section.

To enable or disable this Fix it solution, click the Fix it button or link under the Enable heading or under the Disableheading. Click Run in the File Download dialog box, and then follow the steps in the Fix it wizard.
EnableDisable
Disable Windows Sidebar and Gadgets
Microsoft Fix it 50906
Enable Windows Sidebar and Gadgets 
Microsoft Fix it 50907
Notes
  • These wizards may be in English only. However, the automatic fixes also work for other language versions of Windows.
  • If you are not on the computer that has the problem, you can save the automatic fix to a flash drive or to a CD, and then you can run it on the computer that has the problem.


Share it :)

No comments:

Post a Comment