TLS Implementations Vulnerabilities and vulnerabilities in Exchange, Windows, Internet Explorer, and Office.
Connectikpeople.co, also available via www.retinknow.ga
reminds that, Microsoft has released updates to address vulnerabilities in
Exchange, Windows, Internet Explorer, and Office as part of the Microsoft
Security Bulletin Summary for December 2014. Some of these vulnerabilities
could allow elevation of privilege, remote code execution, or disclosure of
information.
We encourage users and administrators to review Microsoft Security Bulletin
MS14-DEC and apply the necessary updates.
When it comes to Certain TLS
Implementations Vulnerable to POODLE Attacks, we remind that, a new variant of the POODLE
attack may affect some TLS implementations on account of an issue similar to
one present in SSL 3.0. Successful exploitation may enable actors to derive
plaintext from encrypted communications.
Therefore, we encourage users and administrators to review TA14-290A for additional information on the POODLE attack and apply any
necessary updates to address the vulnerability.