Critical: This Content Update contains 19 new events to address vulnerabilities in Microsoft product implementation of the DNS client and the Microsoft Server Service, Internet Explorer, JavaScript, and the SIP protocol. Also in this XPU are 4 new blocking response and 4 security content updates. Refer to the following X-Force advisory for details: http://xforce.iss.net/xforce/alerts/id/232 http://xforce.iss.net/xforce/alerts/id/235



Checks:

RiskVulnIDCheck NameCategory
Low26712SIP_Incomplete_MessageSuspicious Activity
High26810HTML_IE_Url_OverflowDenial of Service
Medium27075HTML_WinSCP_Command_ExecUnauthorized Access Attempt
High27456HTTP_IE_HTA_Remote_ExecUnauthorized Access Attempt
High27456SMB_IE_HTA_Remote_ExecUnauthorized Access Attempt
High27573JavaScript_HHCtrl_OverflowUnauthorized Access Attempt
High27740CompoundFile_PowerPoint_MSO_CodeExecUnauthorized Access Attempt
Low27791HTTP_Executable_TransferSuspicious Activity
High28002MSRPC_Srvsvc_BoUnauthorized Access Attempt
High28005HTML_MMc_XSSUnauthorized Access Attempt
High28013DNS_Client_OverflowUnauthorized Access Attempt
High28023CompoundFile_VBA_Properties_BOUnauthorized Access Attempt
High28025CompoundFile_PowerPoint_SlideList_CodeExecUnauthorized Access Attempt
High28034HTML_JS_Layout_PositionUnauthorized Access Attempt
High28037JavaScript_CSS_Mem_Corruption_VulnUnauthorized Access Attempt
High28039Javascript_COM_ObjectUnauthorized Access Attempt
High28043HTML_Rendering_Memory_CorruptUnauthorized Access Attempt
High28063HTTP_LDAP_Mod_Rewrite_BOUnauthorized Access Attempt
High28240DNS_RDATA_String_BOUnauthorized Access Attempt

If you are an existing customer or partner, and you wish to download X-Press Updates from our download center, click here.