Microsoft Patch Tuesday - January 2012
by Paul Asadoorian on January 11, 2012
The first round of security bulletins from Microsoft this year raises some interesting questions about the vulnerabilities being patched. I found the following three advisories particularly interesting:
From MS12-002:
The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
MS12-002 is ranked by Microsoft as important. Sure, it does require that the user browse file systems, however users can be baited, or even forced, to browse to a network share. Social engineering attacks can lure victims to specific sites, and SMB share paths can be embedded inside web pages and URLS, forcing the user to browse to a share or even a specific file.