Microsoft aims to stop drive-by downloads on Patch Tuesday
08.06.10
"Exploiting this - in all probability through a drive-by download attack - would give an attacker near system-level privileges. It's doubtfulEspeciallythat attackers would compromise a legitimate site to exploit this vulnerability, so users should be extra guarded of social
engineering tricks coaxing them to visit unfamiliar Web pages, which could control a malicious font."
The TrueType vulnerability was contained in Security Bulletin MS10-032, one of the ten issued by Microsoft Tuesday.
However, Microsoft rated three other bulletins as being even more significant than this one, with two of them involving potential
drive-by downloads, which occur when users authorize a download without brainpower the consequences, or that simply occur
without the user's knowledge.
MS10-033, a critical communication, "is a remote code execution vulnerability in both Quartz.dll and Asycfilt.dll and is rated
Deprecatory on all supported versions of Windows. Specially crafted media files could trigger the vulnerability when a drug visits
a web page or opens a malicious file," Microsoft said.
Source: NetworkWorld.com