Results 1 to 8 of 8
Like Tree6Likes
  • 2 Post By Ceyfer √
  • 2 Post By JayCub
  • 1 Post By Bearcat
  • 1 Post By Ceyfer √

Thread: Microsoft Vulnerability Research/Advisories.

  1. #1
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645

    Thumbs up Microsoft Vulnerability Research/Advisories.

    Microsoft Vulnerability Research (MSVR) is a program specifically designed to help improve the security ecosystem as a whole. Our goal is to share our collective experience in dealing with security vulnerabilities with the greater security community and by doing so foster positive change.

    MSVR Advisories

    Beginning in April 2011 the MSVR program began issuing MSVR Advisories detailing software vulnerabilities that Microsoft had privately disclosed to third-party vendors. Microsoft will never reveal vulnerability details before a vendor-supplied update is available for issues reported though the MSVR program unless there is significant evidence of active attacks in the wild. If attacks begin before the vendor has released their remediation, Microsoft will continue to coordinate to release consistent mitigation and workaround guidance with the vendor. This cooperative approach ensures that affected customers understand their risk and what to do to mitigate that risk, without revealing details with which attackers can use to commit cybercrime.

    Latest Advisories:
    -Use-After-Free Object Lifetime Vulnerability in Chrome Could Allow Sandboxed Remote Code Execution.
    http://www.microsoft.com/technet/security/advisory/msvr11-001.mspx

    -HTML5 Implementation in Chrome and Opera Could Allow Information Disclosure.
    http://www.microsoft.com/technet/security/advisory/msvr11-002.mspx
    "Stars and the Sun"


  2. #2
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks for the interesting read Ceyfer. Your efforts are always appreciated!
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  3. #3
    Experienced User
    Overall activity: 26.0%

    Join Date
    Oct 2010
    Location
    North Carolina USA
    Posts
    1,288
    Liked
    214 times
    Points
    5,508
    Thanks ceyfer very interesting. Good work.

  4. #4
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    "Microsoft will never reveal vulnerability details before a vendor-supplied update is available for issues reported though the MSVR program unless there is significant evidence of active attacks in the wild."

    Interesting as always Ceyfer, it's just amazing that if there is a vunerability with Windows it's all over the net before MS can issue a fix or reply.
    Stutz Bearcat

  5. #5
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    it's just amazing that if there is a vunerability with Windows it's all over the net before MS can issue a fix or reply
    True and it must drive them crazy!

  6. #6
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Thanks for the heads up Ceyfer . Let's see .
    I don't need to know everything, I just need to know where to find it, when I need it.

  7. #7
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    LOL
    nice implementation and very tactful move from Microsoft:- P
    Roger and out

  8. #8
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Quote Originally Posted by JayCub View Post
    Interesting as always Ceyfer, it's just amazing that if there is a vunerability with Windows it's all over the net before MS can issue a fix or reply.
    Drawing upon our years of experience, we have seen that disclosing vulnerability details and/or exploits before a vendor has a chance to address the issue amplifies the risk of attacks.
    That's the problem with most third party vulnerability sniffers out there, they are so obsessed with Windows faulty ecosystem, murders it and gains a lot of profit from it, but they didn't really care about protecting the user in the process, do they really care?. Well, it's a bit late but indeed a rewarding initiative. Coordination and collaboration is a definite option in this very noisy atmosphere.
    Last edited by Ceyfer √; 04-21-2011 at 02:48 PM.

 

 

Similar Threads

  1. Vulnerability in Microsoft Malware Protection Engine
    By leofelix in forum Security Bulletin
    Replies: 5
    Last Post: 02-25-2011, 04:45 PM
  2. Replies: 3
    Last Post: 12-08-2010, 12:30 AM
  3. Replies: 1
    Last Post: 07-10-2010, 11:04 PM
  4. Replies: 2
    Last Post: 05-08-2010, 05:37 AM

Tags for this Thread

All times are GMT +8. The time now is 06:18 AM.