Archive

Archive for the ‘Uncategorized’ Category

Vulnerability in Windows Shell Could Allow Remote Code Execution

August 4th, 2010 No comments

This alert is to provide you with an overview of the new security bulletin being released (out-of-band) on August 02, 2010.

New Security Bulletin Overview

Microsoft is releasing one new security bulletin (out-of-band) for newly discovered vulnerabilities:

Bulletin ID Bulletin Title Maximum Severity Rating Vulnerability Impact Restart Requirement Affected Software
MS10-046 Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198) Critical Remote Code Execution Requires restart Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

 

Affected software listed above is an abstract. Please see the bulletin at the link in the left column for complete details.

 

Executive Summary

This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for all supported editions of Microsoft Windows. The security update addresses the vulnerability by correcting validation of shortcut icon references.

This security update addresses the vulnerability first described in Microsoft Security Advisory 2286198.

Public Bulletin Webcast

Microsoft will host a webcast to address customer questions on this bulletin:

Title: Information About Microsoft’s August 2010 (Out-of-Band) Security Bulletin Release

Date: Monday, August 02, 2010, at 1:00 P.M. Pacific Time (U.S. & Canada).

URL: https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&EventID=1032456779

Public Resources related to this alert

 

 

 

 

 

 

New Security Bulletin Technical Details

In the following tables of affected and non-affected software, software editions that are not listed are past their support lifecycle. To determine the support lifecycle for your product and edition, visit the Microsoft Support Lifecycle website at http://support.microsoft.com/lifecycle/.

Bulletin Identifier Microsoft Security Bulletin MS10-046
Bulletin Title Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)
Executive Summary This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. The security update addresses the vulnerability by correcting validation of shortcut icon references. This security update also addresses the vulnerability first described in Microsoft Security Advisory 2286198.
Affected Software This security update is rated Critical for all supported editions of Microsoft Windows.
CVE, Exploitability Index Rating
  1. CVE-2010-2568: Shortcut Icon Loading Vulnerability (EI = 1)
Attack Vectors
  • A maliciously crafted shortcut file.
  • Common delivery mechanisms: a maliciously crafted Web page, an e-mail attachment, an instant message, a peer-to-peer file share, a network share, and/or a USB thumb drive.
Mitigating Factors
  • Users would have to be persuaded to visit a malicious web site.
  • Exploitation only gains the same user rights as the logged-on account. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • Blocking outbound SMB connections on the perimeter firewall reduces the risk of remote exploitation using file shares.
Restart Requirement The update will require a restart.
     

 

Bulletins Replaced by This Update None
Publicly Disclosed?
Exploited?
Yes – this vulnerability was publicly disclosed prior to release. More information is contained in Microsoft Security Advisory 2286198.Yes – this vulnerability has been exploited in the wild at release.
Full Details http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx 

 

     

 

Regarding Information Consistency

We strive to provide you with accurate information in static (this mail) and dynamic (web-based) content. Microsoft’s security content posted to the web is occasionally updated to reflect late-breaking information. If this results in an inconsistency between the information here and the information in Microsoft’s web-based security content, the information in Microsoft’s web-based security content is authoritative.

If you have any questions regarding this alert please contact your Technical Account Manager or Application Development Consultant.

Thank you,

Microsoft CSS Security Team

Alliance Technology Partners is a Microsoft Partner in St. Louis, MO

HP BL460c Blade Servers – 462873-B21, 461605-B21, 459487-B21, 459486-B21, 459485-B21

April 12th, 2010 No comments

HP BL460c Blade Servers – HP Factory Sealed/Refurbished/FULL HP Warranty

462873-B21 HP BL460C G1 Xeon L5410 2.33GHZ QC 2GB BLADE SERVER  $     995
461605-B21 HP BL460C E5205 1.86GHZ DUAL CORE 1GB BLADE  $     995
459487-B21 HP BL460c Xeon QC E5405 2.00GHz 1GB 0GB 2.5″  $     975
459486-B21 HP BL460c G1 Xeon QC E5420 2.5GHz 2GB 0GB 2.5″  $     850
459485-B21 HP BL460c G1 Xeon QC E5430 2.66GHz 2GB 0GB 2.5″  $ 1,095


Buy Now

HP DL380G6 SERVER DEALS – 491325-001, 491332-001

April 7th, 2010 No comments

HP Factory Sealed/Refurbished/FULL HP Warranty

491325-001  -  $2195 (Reg  $2849)
HP DL380G6 2U Xeon QC E5520 2.26GHz 6GB 0 2.5″ SAS

491332-001  – $ 2650 (Reg. $3349)
HP DL380G6 2U Xeon QC E5540 2.53GHz 6GB 0GB 2.5″

Options:
497767-b21  - $245
HP 8GB (2×4GB)PC2-6400 800MHz DDR2 Registered ECC qty 73 $210ea

512547-b21  – $385
HP 146GB 6G SAS 15K SFF DP ENT HDD

IN STOCK NOW – APC ACF126 AND AR8171BLK

April 6th, 2010 No comments

ACF126 – $145.00 – 2 AVAILABLE
APC RACK AIR REMOVAL UNIT SX DUCTING KIT

AR8171BLK – $75 – 2 AVAILALBE
APC RACK MOUNTING KIT

Categories: Uncategorized Tags: ,

HP Proliant Processors – 507674-b21, 507793-b21, 507722-b21, 507798-b21

April 5th, 2010 No comments

HP Proliant Processor – HP Renew – Factory Sealed/Refurbished/FULL HP WARRANTY

507674-b21 – $1595
HP Xeon QC X5570 2.93GHz L3 8MB Processor Upgrade DL360 G6

 507793-b21 – $1295
HP Xeon QC X5550 2.66GHz L3 8MB Processor Upgrade

507798-b21 – $595
HP Xeon L5520 X/2.26 60W BL460C G6 

507722-b21 – $545ea
HP ML150 G6 E5520 RMKT KIT


Buy Now

hp Proliant Server Options – 507676-B21, 507793-B21

April 2nd, 2010 No comments

507676-b21 HP XEON X5560 PROC KIT FOR DL360 G6 qty 10 $1450
507793-b21 HP X5550 2.6G BL460C G6 KIT qty 34 $1450


Buy Now

HP Proliant Server Deals – DL360 G6, ML370 G6

March 25th, 2010 No comments

Factory Sealed/Refurbished/Full HP Warranty

490666-001   $3195
HP DL360R05p Xeon QC E5450 3.00GHz x2 4GB 0GB 2.5″ Combo RPS

504633-001   $4595
HP DL360G6 1U Xeon QC X5550 2.66GHz x2 12GB 0GB 2.5″

487791-001   $2795
HP ML370 G6 E5540 2.53ghz 6GB(3×2GB) SFF DVD P400i/256mb TWR

509314-b21   $2795
HP BL490c G6 Xeon QC X5570 2.93GHz 6GB(3×2GB)0 GB 2.5″ SSD


Buy Now

HP Proliant BL490c G6 – 509315-B21 – $2295

March 25th, 2010 No comments

HP Factory Sealed/Refurbished/FUL HP Warranty

HP Proliant BL490c G6 – 509315-B21 – $2295
Quad-Core E5540 2.53 GHz / 8 MB Cache / 1066 MHz FSB – 6 GB RAM (2 x 3 GB) DDR3 PC3-10600 – Embedded NC532i Dual Port Flex-10 10GbE Multifunction Server Adapter and one (1) additional 10/100 server adapter dedicated to iLO 2 management
P/N 509315-B21, Blade Server

3 Yrs Parts, Labor & On-Site

HP Proliant DL360 G5 Servers – 457928-001, 457927-001

March 23rd, 2010 No comments

HP Factory Sealed/Refurbished/Full HP Warranty

457928-001 $1750
HP DL360G5 1U Xeon DC X5260 3.33GHz 2GB 0GB 2.5″ DVD

457927-001 $1750
HP DL360 G5 L5420 2.5GHZ QUAD CORE 2GB P400/256mb

457926-001 $1725
HP DL360G5 Xeon E5405 2.0ghz/12mb 1GB/E200i/64mb

457925-001 $1850
HP DL360G5 Xeon E5420 2.5ghz/12mb 2GB/ P400i/256mb

457924-001 $1890
HP DL360G5 Xeon E5430 2.66ghz/12mb 2GB/P400i/256mb

457923-001 $1950
HP DL360G5 Xeon E5440 2.83ghz/12mb 2GB/P400i/256mb

457922-001 $3195
HP DL360R05 Xeon QC X5450 x2 3.00 4GB 0GB 2.5″ Combo RPS

490666-001 $3195
HP DL360R05p Xeon QC E5450 3.00GHz x2 4GB 0GB 2.5″ Combo RPS

HP ProLiant DL145 G2- 390846-001 – $199

March 18th, 2010 No comments

HP ProLiant DL145 G2 AMD Opteron Dual-Core 2.2 GHz 2MB L2 Cache ( 2 x 1MB ) 2 GB RAM (2 x 1GB )- 1 x 80GB 7200 RPM SATA HDD Embedded SATA Controller No CD Ships Complete with Rails and Country Kit Open Original Box Never Used or Installed HP Part #390846-001 – $199.00