Archive for August, 2008

Microsoft Updates for August

August 13, 2008

Eleven new security bulletins have been published (from MS08-041 to MS08-051) as part of the usual launch of Microsoft updates.

We recommend you to update your system as soon as possible, as according to Microsoft's classification six of the bulletins are rated as "critical", while the others are rated as "important".

You can find more information about the security bulletins by clicking the following links:

  • MS08-041 – Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access.
  • MS08-042 – Vulnerability in Microsoft Word.
  • MS08-043 – Vulnerabilities in Microsoft Excel.
  • MS08-044 – Vulnerabilities in Microsoft Office Filters.
  • MS08-045 – Cumulative Security Update for Internet Explorer.
  • MS08-046 – Vulnerability in Microsoft Windows Image Color Management System.
  • MS08-047 – Vulnerability in IPsec Policy Processing.
  • MS08-048 – Security Update for Outlook Express and Windows Mail.
  • MS08-049 – Vulnerabilities in Event System.
  • MS08-050 – Vulnerability in Windows Messenger.
  • MS08-051 – Vulnerabilities in Microsoft PowerPoint.

Beijing’s Olympic Games Malware

August 8, 2008

It’s pretty clear that Beijing’s Olympic Games are a good chance for cybercrooks to infect users using the Games as a social engineering tool.

The Games have started today, and we have just seen a new malware, Bck/PcClient.HV, that seems to be a PowerPoint about the Games, but it installs in the infected computers the files PcCortr.dll and 81.dll, that lower the system security level, enabling the file wuauct.exe copied by the malware in the system folder to remotely connect to a Chinese IP to send information about the infected computer.

To avoid any suspect, it shows 12 slides about the real Beijing Olympic Stadium: