Microsoft reacts to kernel hacks, updates Vista's defenses 15 Aug 2007 11:43 GMTWith little fanfare, Microsoft released an update to Vista's Kernel Patch Protection -- a key defensive feature of the operating system -- on Tuesday, hoping to swat back an assortment of attacks plaguing the OS over the past few weeks. The patch targets all 64-bit editions of Windows.

Source: Computerworld Record-breaking 'Storm' linked to spam surge 14 Aug 2007 09:01 GMTSober's been supplanted. The Storm Trojan, which inducts hapless PCs into hacker-controlled botnets, is now the most prolific malware ever to be transmitted via e-mail. And as happens all too frequently, the new recordholder is far more unpleasant than the previous home-run king.

Source: Computerworld MS07-050 - Critical: Vulnerability in Vector Markup Language Could Allow Remote Code Execution (938127) 14 Aug 2007 08:00 GMTBulletin Severity Rating:Critical - This security update resolves a privately reported vulnerability in the Vector Markup Language (VML) implementation in Windows. The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS07-047 - Important: Vulnerabilities in Windows Media Player Could Allow Remote Code Execution (936782) 14 Aug 2007 08:00 GMTBulletin Severity Rating:Important - This important security update resolves two privately reported vulnerabilities. These vulnerabilities could allow code execution if a user viewed a specially crafted file in Windows Media Player. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Source: TechNet MS07-046 - Critical: Vulnerability in GDI Could Allow Remote Code Execution (938829) 14 Aug 2007 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves a privately reported vulnerability. A remote code execution vulnerability exists in the Graphics Rendering Engine in the way that it handles specially crafted images. An attacker could exploit the vulnerability by constructing a specially crafted image that could potentially allow remote code execution if a user opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Source: TechNet MS07-045 - Critical: Cumulative Security Update for Internet Explorer (937143) 14 Aug 2007 08:00 GMTBulletin Severity Rating:Critical - This critical security update resolves three privately reported vulnerabilities. These vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights
Source: TechNet