Security News > 2015 > March > Microsoft patches flaw exploited by Stuxnet - again (Help Net Security)

2015-03-11 14:36
Among the vulnerabilities patched by Microsoft in this month's Patch Tuesday is one that was supposedly patched back in 2010. The Windows Shell Shortcut Icon Loading Vulnerability (CVE-2010-2568) w...
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/u4rmNOjCjhc/secworld.php
Related news
- Microsoft shares workaround for Windows security update issues (source)
- URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days (source)
- Patch Tuesday: Microsoft Fixes 57 Security Flaws – Including Active Zero-Days (source)
- AI agents swarm Microsoft Security Copilot (source)
- After Detecting 30B Phishing Attempts, Microsoft Adds Even More AI to Its Security Copilot (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- Week in review: Chrome sandbox escape 0-day fixed, Microsoft adds new AI agents to Security Copilot (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-07-22 | CVE-2010-2568 | Unspecified vulnerability in Microsoft products Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems. | 7.8 |