CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft

August 13th, 2008

This vulnerabilities exposes you to a risk that we rate as follows:

CyTRAP Labs security risk barometer - 4 = critical
low elevated moderately
critical
critical severe
1 2 3 4 5

For more information and explanations about the CyTRAP Labs risk barometer you can visit here:CyTRAP Labs security risk barometer

what Microsoft Patch Tuesday has in store for us this month
operating system affected
  • Windows (XP, Windows Vista, Windows Server),
affected software
  • Microsoft Access 2000, 2002, 2003
  • Microsoft Internet Explorer 5.1, 6, 7$
  • Microsoft Excel 2002, 2002, 2003, 2007
  • Microsoft Office Powerpoint 2000, 2002, 2003, 2007
  • Microsoft Office Powerpoint Viewer 2000, 2002, 2003, 2007
  • Microsoft Office 2000 Service Pack 3
  • Microsoft Office XP Service Pack 3
  • Microsoft Office 2000 Service Pack 2
    risk 6 security bulletins rated critical BY Microsoft (click on link - click on Login as guest - click on link again, access to free definition/explanations) were released …the risk rating given for these vulnerabilities by CyTRAP Labs is a 4 (four out of five levels) = CRITICAL - orange
    how long did this vulnerability remain unpatched since it was publicly disclosed ==> zero-day alert these vulnerabilities have been known for a while (several months), however, none were actively exploited.
    patch prioritization - client side impact users and administrators are urged to roll out this patch as soon as possible, once it has been verified that it does not break any internal applications.
    where is the patch? will be downloaded using Automatic Update, update is detected by the MBSA:
    CyTRAP Labs tip - using the Microsoft Baseline Security Analzyer called MBSA
    what should one do? If your Automatic Update is functioning properly, you are covered.
    CyTRAP Labs tip - how to make sure the latest security patch is installed
    how can I check that I do have the latest version installed find out more information how cou can check that this update is installed as well on your PC or server here:
    not patching the vulnerability could cause what kind of damage to my PC? could be exploited by attackers to execute arbitrary code on the user’s machine BETTER patch NOW
    Once updated, what do you need to do? These updates will require a restart for your PC.
    Where can you get the overall summary Microsoft has issued? full version of the Microsoft Security Bulletin Summary for August 2008
    where can one get details about each of the patches released on this month’s Microsoft Patch TuesdayWe list the critical ones only - there were 5 important ones as well - Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954) - Microsoft Security Bulletin MS08-046 - CRITICAL- Cumulative Security Update for Internet Explorer (953838) Microsoft Security Bulletin MS08-045 - CRITICAL - Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617) Microsoft Security Bulletin MS08-041 - CRITICAL- Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066) Microsoft Security Bulletin MS08-043 - CRITICAL

    - Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785) Microsoft Security Bulletin MS08-051 - CRITICAL

    - Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (924090) Microsoft Security Bulletin MS08-044 - CRITICAL

    release date from vendor 2008-06-12 - Pacific Standard Time
    why is this a reminder and not an alert? security alert or reminder - that’s the question
    did CASEScontact.org release an advisory about these vulnerabilities earlier? No we did not issue a zero-day alert
    CASEScontact.org release a zero-day advisory NO we did not issue a zero-day advisory see also patched zero-day archive)
    Common Vulnerabilities and Exposures (CVE) project has assigned the following numbers to these vulnerabilities that were patched by Microsoft CVE-2008-0120, CVE-2008-0121, CVE-2008-1455, CVE-2008-2245,
    CVE-2008-2254,CVE-2008-2255, CVE-2008-2256, CVE-2008-2257, CVE-2008-2258,
    CVE-2008-2259,

    CVE-2008-2463, CVE-2008-3003 CVE-2008-3004, CVE-2008-3005,
    CVE-2008-3006,

    CVE-2008-3018, CVE-2008-3019, CVE-2008-3020, CVE-2008-3021,
    CVE-2008-3460,

    Please make sure that your PC is patched - thank you.
    Also of interest:
    CyTRAP Labs: security reminder - 2008-04-08 - Patch Tuesday - Microsoft CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft why benchmark

    Please stay abreast the latest developments:appear here in this part of cyberspace.

    Also of interest:
    InfoSec InfoSec - follow us on Twitter sign up to our alerts about zero-day exploits and newsletters here
    CASEScontact CASEScontact follow us on Twitter What is Twitter good for
    Technorati , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

    Related Posts:

    1. CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft
    2. CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    3. CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft
    4. CyTRAP Labs’ reminder - 2008-05-08 - Adobe Reader AND Adobe Acrobat - critical update
    5. CyTRAP Labs’ tip - Microsoft Windows XP SP3 RC2

    Email This Post | Print This Post

    del.icio.us:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  digg:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  spurl:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  wists:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  simpy:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  newsvine:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  blinklist:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  furl:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  reddit:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  fark:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  blogmarks:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  Y!:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft  smarking:CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft

    CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft

    July 9th, 2008
      Microsoft has released 4 security bulletins - none of these are are ranked critical - by Microsoft.

      Does your automatic update work properly? If you are not sure if it does, check below, otherwise by mid-day 2008-07-09 the downloads should be on your machine…. remember, installing the downloads might necessitate a reboot.

      Just wait until you stop working once you shut down your machine that will suffice to get them installed.

    This vulnerabilities exposes you to a risk that we rate as follows:

    CyTRAP Labs security risk barometer - 3 = moderately critical
    low elevated moderately
    critical
    critical severe
    1 2 3 4 5

    For more information and explanations about the CyTRAP Labs risk barometer you can visit here:CyTRAP Labs security risk barometer

    Where can you get the overall summary Microsoft has issued? full version of the Microsoft Security Bulletin Summary for July 2008
    where is the patch? will be downloaded using Automatic Update, update is detected by the MBSA:
    CyTRAP Labs tip - using the Microsoft Baseline Security Analzyer called MBSA
    what should one do? If your Automatic Update is functioning properly, you are covered.
    CyTRAP Labs tip - how to make sure the latest security patch is installed

    More information that you should check out regarding Microsoft vulnerabilities and patches can be found here:

    Also of interest:
    CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    the mission of ComMetrics why benchmark

    Please stay abreast the latest developments:

    Sign up it is free:
    InfoSec InfoSec - follow us on Twitter sign up to our alerts about zero-day exploits and newsletters here
    CASEScontact CASEScontact follow us on Twitter What is Twitter good for

    Technorati , , , , , ,

    Related Posts:

    1. CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft
    2. CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    3. CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft
    4. CyTRAP Labs’ reminder - 2008-05-08 - Adobe Reader AND Adobe Acrobat - critical update
    5. CyTRAP Labs’ tip - Microsoft Windows XP SP3 RC2

    Email This Post | Print This Post

    del.icio.us:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  digg:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  spurl:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  wists:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  simpy:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  newsvine:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  blinklist:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  furl:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  reddit:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  fark:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  blogmarks:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  Y!:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft  smarking:CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft

    CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft

    June 10th, 2008
      Microsoft has released 7 security bulletins CVE-2008-1453, CVE-2008-1442, CVE-2008-1544, CVE-2008-0011, CVE-2008-1444.
      3 of these bulletings are ranked critical - by Microsoft, which means ‘can result in remote code execution’ 3 are important (this summary focuses on the critical ones only)

      If you have Automatic Update activated for your PC, these patches will be downloaded automatically.

      Does your automatic update work properly?If you are not sure if it does, check below, otherwise by mid-day 2008-06-11 the downloads should be on your machine…. remember, installing the downloads might necessitate a reboot. Just wait until you stop working once you shut down your machine that will suffice to get them installed.

    This vulnerabilities exposes you to a risk that we rate as follows:

    CyTRAP Labs security risk barometer - 4 = critical
    low elevated moderately
    critical
    critical severe
    1 2 3 4 5

    For more information and explanations about the CyTRAP Labs risk barometer you can visit here:CyTRAP Labs security risk barometer

    what Microsoft Patch Tuesday has in store for us this month
    operating system affected
    • Windows (XP, Windows Vista, Windows Server),
    • Microsoft DirectX 7.0, 8.1, 9.0, 10.0
    • Microsoft Internet Explorer 5.1, 6, 7
    affected software
    • see above
    risk 3 security bulletins rated critical BY Microsoft were released …the risk rating given for these vulnerabilities by CyTRAP Labs is a 4 (four out of five levels) = CRITICAL - orange
    how long did this vulnerability remain unpatched since it was publicly disclosed ==> zero-day alert these vulnerabilities have been known for a while (several months), however, none were actively exploited.
    patch prioritization - client side impact users and administrators are urged to roll out this patch as soon as possible, once it has been verified that it does not break any internal applications.
    where is the patch? will be downloaded using Automatic Update, update is detected by the MBSA:
    CyTRAP Labs tip - using the Microsoft Baseline Security Analzyer called MBSA
    what should one do? If your Automatic Update is functioning properly, you are covered.
    CyTRAP Labs tip - how to make sure the latest security patch is installed
    how can I check that I do have the latest version installed find out more information how cou can check that this update is installed as well on your PC or server here:
    not patching the vulnerability could cause what kind of damage to my PC? could be exploited by attackers to execute arbitrary code on the user’s machine BETTER patch NOW
    Once updated, what do you need to do? These updates will require a restart for your PC.
    Where can you get the overall summary Microsoft has issued? full version of the Microsoft Security Bulletin Summary for July 2008
    where can one get details about each of the patches released on this month’s Microsoft Patch TuesdayWe list the critical ones only - there were 5 important ones as well - Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376) - Microsoft Security Bulletin MS08-030 - CRITICAL- Cumulative Security Update for Internet Explorer (950759) Microsoft Security Bulletin MS08-031 - CRITICAL - Vulnerabilities in DirectX Could Allow Remote Code Execution (951698) Microsoft Security Bulletin MS08-033 - CRITICAL
    release date from vendor 2008-06-10 - Pacific Standard Time
    why is this a reminder and not an alert? security alert or reminder - that’s the question
    did CASEScontact.org release an advisory about these vulnerabilities earlier? No we did not issue a zero-day alert
    CASEScontact.org release a zero-day advisory NO we did not issue a zero-day advisory see also patched zero-day archive)
    Common Vulnerabilities and Exposures (CVE) project has assigned the following numbers to these vulnerabilities that were patched by Microsoft CVE-2008-1453, CVE-2008-1442, CVE-2008-1544, CVE-2008-0011,
    CVE-2008-1444,

    Please make sure that your PC is patched - thank you.

    If this post was helpful to you, please consider stumbling it this WinCurity post from CyTRAP Labs.
    Also of interest:
    CyTRAP Labs: security reminder - 2008-04-08 - Patch Tuesday - Microsoft CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    the mission of ComMetrics why benchmark

    Please stay abreast the latest developments:appear here in this part of cyberspace.

    Also of interest:
    InfoSec InfoSec - follow us on Twitter sign up to our alerts about zero-day exploits and newsletters here
    CASEScontact CASEScontact follow us on Twitter What is Twitter good for

    Technorati , , , , , , , , , , , , , , , , , , ,

    Related Posts:

    1. CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft
    2. CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft
    3. CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft
    4. CyTRAP Labs’ reminder - 2008-05-08 - Adobe Reader AND Adobe Acrobat - critical update
    5. CyTRAP Labs’ tip - Microsoft Windows XP SP3 RC2

    Email This Post | Print This Post

    del.icio.us:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  digg:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  spurl:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  wists:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  simpy:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  newsvine:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  blinklist:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  furl:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  reddit:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  fark:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  blogmarks:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  Y!:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft  smarking:CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft

    CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft

    May 13th, 2008


    Microsoft has released 3 security bulletinsCVE-2008-1091, CVE-2008-1434, CVE-2008-0119, CVE-2008-1437, CVE-2008-1438,
    All 3 of these bulletings are ranked critical - by Microsoft, which means ‘can result in remote code execution’ 3 are important (this summary focuses on the critical ones only)
    If you have Automatic Update activated for your PC, these patches will be downloaded automatically
    Does your automatic update work properly?

    If you are not sure if it does, check below, otherwise by mid-day 2008-05-14 the downloads should be on your machine…. remember, installing the downloads might necessitate a reboot.

    Just wait until you stop working once you shut down your machine that will suffice to get them installed.

    This vulnerabilitiies exposes you to a risk that we rate as follows:

    CyTRAP Labs security risk barometer - 4 = critical
    low elevated moderately
    critical
    critical severe
    1 2 3 4 5

    For more information and explanations about the CyTRAP Labs risk barometer you can visit here:
    CyTRAP Labs security risk barometer

    what Microsoft Patch Tuesday has in store for us this month
    operating system affected
    • Microsoft Office
    • Microsoft Publisher
    • Microsoft Malware Protection Engine
    affected software
    • see above
    risk 3 security bulletins rated critical BY Microsoft were released …the risk rating given for these vulnerabilities by CyTRAP Labs is a 4 (four out of five levels) = CRITICAL - orange
    how long did this vulnerability remain unpatched since it was publicly disclosed ==> zero-day alert these vulnerabilities have been known for a while (several months), however, none were actively exploited.
    patch prioritization - client side impact users and administrators are urged to roll out this patch as soon as possible, once it has been verified that it does not break any internal applications.
    where is the patch? will be downloaded using Automatic Update, update is detected by the MBSA:
    CyTRAP Labs tip - using the Microsoft Baseline Security Analzyer called MBSA
    what should one do? If your Automatic Update is functioning properly, you are covered.
    CyTRAP Labs tip - how to make sure the latest security patch is installed
    how can I check that I do have the latest version installed find out more information how cou can check that this update is installed as well on your PC or server here:
    not patching the vulnerability could cause what kind of damage to my PC? could be exploited by attackers to execute arbitrary code on the user’s machine BETTER patch NOW
    Once updated, what do you need to do? These updates will require a restart for your PC.
    Where can you get the overall summary Microsoft has issued? full version of the Microsoft Security Bulletin Summary for May 2008
    where can one get details about each of the patches released on this month’s Microsoft Patch TuesdayWe list the critical ones only - there were 5 important ones as well - Vulnerabilities in Microsoft Word Could Allow Remote Code Executionu (951207) - Microsoft Security Bulletin MS08-026 - CRITICAL

    - Vulnerability in Microsoft Publisher Could Allow Remote Code Execution (951208) MS08-027 - CRITICAL

    - Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service (952044) Microsoft Security Bulletin MS08-028 - CRITICAL

    release date from vendor 2008-04-08 - Pacific Standard Time
    why is this a reminder and not an alert? security alert or reminder - that’s the question
    did CASEScontact.org release an advisory about these vulnerabilities earlier? No we did not issue a zero-day alert
    CASEScontact.org release a zero-day advisory NO we did not issue a zero-day advisory see also patched zero-day archive)
    Common Vulnerabilities and Exposures (CVE) project has assigned the following numbers to these vulnerabilities that were patched by Microsoft CVE-2008-1091, CVE-2008-1434, CVE-2008-0119, CVE-2008-1437,
    CVE-2008-1438,

    Please make sure that your PC is patched - thank you.

    If this post was helpful to you, please consider stumbling it this WinCurity post from CyTRAP Labs.
    Also of interest:
    CyTRAP Labs: security reminder - 2008-04-08 - Patch Tuesday - Microsoft CyTRAP Labs: security reminder - 2008-03-11 - Patch Tuesday - Microsoft
    the mission of ComMetrics why benchmark

    Technorati , , , , , , , , , , , , , , , , , ,

    Related Posts:

    1. CyTRAP Labs: security reminder - 2008-08-12 - Patch Tuesday - Microsoft
    2. CyTRAP Labs: security reminder - 2008-07-08 - Patch Tuesday - Microsoft
    3. CyTRAP Labs: security reminder - 2008-06-10 - Patch Tuesday - Microsoft
    4. CyTRAP Labs’ reminder - 2008-05-08 - Adobe Reader AND Adobe Acrobat - critical update
    5. CyTRAP Labs’ tip - Microsoft Windows XP SP3 RC2

    Email This Post | Print This Post

    del.icio.us:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  digg:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  spurl:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  wists:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  simpy:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  newsvine:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  blinklist:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  furl:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  reddit:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  fark:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  blogmarks:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  Y!:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft  smarking:CyTRAP Labs: security reminder - 2008-05-13 - Patch Tuesday - Microsoft

    CyTRAP Labs’ reminder - 2008-05-08 - Adobe Reader AND Adobe Acrobat - critical update

    May 8th, 2008

    Adobe has issued an important security patch for its Adobe Reader and Adobe Acrobat that fixes several critical vulnerabilities (Please click on the link, choose Login as guest - click on this link again and voila free access)
    If you have default Update installed with the program, the latest version should be downloadd automatically next time you log onto the internet (for more details see below)

    This vulnerabilitiy exposes you to a risk that we rate as follows:

    CyTRAP Labs security risk barometer - 4 = critical
    low elevated moderate- ly critical critical severe
    1 2 3 4 5

    For more information and explanations about the CyTRAP Labs risk barometer you can visit here:

    CyTRAP Labs security risk barometer

    WHAT CAN YOU DO?

    operating system affected
    affected software
    • Adobe Reader 8.1.1 and prior
    • Adobe Reader 7.0.9 and prior
    • Adobe Acrobat Professional
    • Adobe Acrobat Standard
    • Adobe Acrobat 3D

    Hence, start your Adobe Reader or Adoba Acrobat on your PC go to Help > Update check

    risk rating given for these vulnerabilities is a 4 (four)
    where is the patch? depending upon the operating system you run:

    • Adobe Reader
    • Adobe Acrobat

    for Windows, you need admin rights to install the patch!

    what should one do? The Software Update preference pane is set to automatically check by default if you have the latest version installed.Hence, once you go onto the internet, the latest version should be downloaded automatically, if you are not sure, read below we tell you how to check and download manually if need be - quick and easy.
    how can I check that I do have the latest version installed click UPDATES in Adobe Reader or Adobe Acrobat from the Help menu
    this shows which version runs on your machineAdobe recommends users of
    - Acrobat 8 and Adobe Reader install 8.1.2 update and
    - Acrobat 7 install the 7.1.0 updateDetails and all downloads available here
    not patching the vulnerability could cause what kind of damage to my PC? DO NOT OPEN IMAGES, MOVIES, ETC. from untrusted sources 1 could be exploited by unauthorized attacker enabling him or her to execute arbitary commands on your machine2 more nasty things…
    where can one get more details from the vendor? vendor