<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
    <channel>
        <title>IBM Internet Security Systems Internet Threat Information</title>
        <link>http://www.iss.net</link>
        <description><![CDATA[The latest Internet Threats, brought to you by XForce - the IBM Internet Security Systems' world-renowned security research and development team.]]></description>
        <language>en</language>
        <copyright>2007 IBM Internet Security Systems. All rights reserved worldwide.</copyright>

<item>
	<title>Microsoft Windows Shell Could Allow Remote Code Execution</title>
	<link>http://www.iss.net/threats/373.html</link>
	<description>A vulnerability in Microsoft&amp;nbsp;Windows exists&amp;nbsp;because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the icon of a specially crafted shortcut is displayed..</description>
	<pubDate>Fri, 23 Jul 2010 00:00:00 -0400</pubDate>
</item><item>
	<title>ACCWIZ Release-After-Free Remote Code Execution Vulnerability</title>
	<link>http://www.iss.net/threats/371.html</link>
	<description>A successful exploitation attempt results in code execution with privileges equal to the Microsoft Office program used as an attack vector. Restrictions in up-to-date versions of Internet Explorer prevent it being used as an exploitation vector.</description>
	<pubDate>Tue, 13 Jul 2010 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Office Outlook Could Allow Remote Code Execution</title>
	<link>http://www.iss.net/threats/372.html</link>
	<description>A vulnerability in Microsoft Office Outlook&amp;nbsp;can be&amp;nbsp;remotely executed. By convincing users to open an attachment in a specially crafted e-mail message, a remote attacker could execute arbitrary code on the system.</description>
	<pubDate>Tue, 13 Jul 2010 00:00:00 -0400</pubDate>
</item><item>
	<title>Microsoft Windows Help and Support Center Could Allow Remote Code Execution</title>
	<link>http://www.iss.net/threats/370.html</link>
	<description>Vulnerability in Windows Help and Support Center Could Allow Remote Code Execution</description>
	<pubDate>Mon, 14 Jun 2010 00:00:00 -0400</pubDate>
</item><item>
	<title>Improper Validation of COM Objects in Microsoft Office</title>
	<link>http://www.iss.net/threats/368.html</link>
	<description>Microsoft Office applications fail to properly validate COM objects embedded in compound documents.&amp;nbsp; This allows attackers to bypass the security settings of Office and embed known flawed objects in Office files.&amp;nbsp; Upon exploitation of the pre-existing flaws in these controls, attackers can achieve arbitrary code execution.</description>
	<pubDate>Tue, 08 Jun 2010 00:00:00 -0400</pubDate>
</item><item>
	<title>Flash Player, Adobe Acrobat and Acrobat Reader Remote Code Execution</title>
	<link>http://www.iss.net/threats/369.html</link>
	<description>A vulnerability in Flash Player, Adobe Acrobat and Acrobat Reader can result in remote code execution.&amp;nbsp; IBM ISS customer's have been protected preemptively since 2008 from this exploit with protection listed below.
This vulnerability was discovered being exploited in the wild on June 4, 2010, and publicly acknowledged by Adobe on June 4, 2010.&amp;nbsp; A Security Advisory has been posted in regards to a new Adobe Reader, Acrobat and Flash Player issue (CVE-2010-1297). A critical vulnerability exists in Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems..</description>
	<pubDate>Mon, 07 Jun 2010 00:00:00 -0400</pubDate>
</item>
   </channel>
</rss>