Microsoft Active Protection Program Advisories

The Microsoft Active Protections Program (MAPP) is a program for security software providers that provides Enterasys with security vulnerability information from the Microsoft Security Response Center (MSRC) in advance of Microsoft's monthly security updates. Microsoft may release additional security advisories for vulnerabilities actively being exploited which requires additional protections from Enterasys.

Latest Advisory

(2639658) Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege

Microsoft has released an advisory (2639658) which addresses a zero-day vulnerability in Microsoft Windows. There is currently no patch available for this vulnerability. Microsoft is actively working with MAPP partners to provide protections against attacks exploiting this vulnerability until a patch is ready to be released.

The following signature(s) provide protection against this vulnerability:

MS:TTF-PRIVILEGE-ESCALATION

References:

Microsoft Security Advisory 2639658
W32.Dugu - The precursor to the next Stuxnet
CVE-2011-3402

All Advisories

(2639658) Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege

Microsoft has released an advisory (2639658) which addresses a zero-day vulnerability in Microsoft Windows. There is currently no patch available for this vulnerability. Microsoft is actively working with MAPP partners to provide protections against attacks exploiting this vulnerability until a patch is ready to be released.

The following signature(s) provide protection against this vulnerability:

MS:TTF-PRIVILEGE-ESCALATION

References:

Microsoft Security Advisory 2639658
W32.Dugu - The precursor to the next Stuxnet
CVE-2011-3402