RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities

Microsoft has released advance notification that on November 9, 2010, they will be releasing three security bulletins covering 11 vulnerabilities.

The bulletins and their affected components are as follows:

One bulletin rated 'Critical' affecting Office
Two bulletins rated 'Important' affecting Office, PowerPoint, and Forefront Unified Access Gateway

This BID is being retired. The following individual records exist to better document the issues:

42628 Microsoft Office 'pptimpconv.dll' DLL Loading Arbitrary Code Execution Vulnerability
44626 Microsoft PowerPoint 'PP7X32.DLL' (CVE-2010-2572) Remote Heap-Based Buffer Overflow Vulnerability
44628 Microsoft PowerPoint (CVE-2010-2573) Heap Corruption Vulnerability
44631 Microsoft Forefront Unified Access Gateway Spoofing Vulnerability
44632 Microsoft Forefront Unified Access Gateway Web Monitor Cross-Site Scripting Vulnerability
44633 Microsoft Forefront Unified Access Gateway Mobile Portal Cross-Site Scripting Vulnerability
44634 Microsoft Forefront Unified Access Gateway 'Signurl.asp' Cross-Site Scripting Vulnerability
44652 Microsoft Office RTF File Stack Buffer Overflow Vulnerability
44656 Microsoft Office Art Drawing Record Remote Code Execution Vulnerability
44659 Microsoft Office Drawing Exception Handling Remote Code Execution Vulnerability
44660 Microsoft Office Large SPID Read AV Remote Code Execution Vulnerability


 

Privacy Statement
Copyright 2010, SecurityFocus