<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; microsoft patchday</title> <atom:link href="http://www.ghacks.net/tag/microsoft-patchday/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Security Bulletin Overview January 2011</title><link>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/</link> <comments>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/#comments</comments> <pubDate>Tue, 11 Jan 2011 23:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=38900</guid> <description><![CDATA[The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code execution. The maximum severity rating of the vulnerability is critical, the highest possible rating.</p><p>A closer look at the security vulnerability reveals that is is rated critical for all 32-bit and 64-bit Windows client operating systems from Windows XP to Windows 7. The same vulnerability is rated as important for all server based operating systems.</p><p>The second vulnerability, MS11-001, has a maximum severity rating of important. It fixes a vulnerability in the Windows Backup Manager that could allow remote code execution. The vulnerability affects only the Windows Vista operating system.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-002.mspx">MS11-002</a> &#8211; Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Data Access Components. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS11-001.mspx">MS11-001</a> &#8211; Vulnerability in Windows Backup Manager Could Allow Remote Code Execution (2478935) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Backup Manager. The vulnerability could allow remote code execution if a user opens a legitimate Windows Backup Manager file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the legitimate file from that location, which in turn could cause Windows Backup Manager to load the specially crafted library file.</li></ul><p><strong>Severity and Exploitability Index</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101-550x309.png" alt="" title="6011.sev-exp-1101" width="550" height="309" class="alignnone size-medium wp-image-38901" /></a></p><p><strong>Bulletin Deployment Priority</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101-550x309.png" alt="6153.deploy_2D00_1101" title="6153.deploy_2D00_1101" width="550" height="309" class="alignnone size-medium wp-image-38902" /></a></p><p>The images have been taken from the <a
href="http://blogs.technet.com/b/msrc/archive/2011/01/11/january-2011-security-bulletins.aspx">Technet</a> announcement which offers further information about the vulnerabilities and patch deployment.</p><p>Windows users are advised to apply the patches as soon as possible to protect their system from possible exploits. The patches can be applied directly via Windows Update or <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">directly from</a> Microsoft Download.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates April 2010</title><link>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/</link> <comments>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/#comments</comments> <pubDate>Tue, 13 Apr 2010 17:24:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[security bulletins]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows updates]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24511</guid> <description><![CDATA[Microsoft has just added the security updates for April 2010 to Windows Update from where every Windows user can download and install them on their operating system. A total of eleven security bulletins have been released that update the Windows operating system as well as other Microsoft software like Microsoft Office. The updates fix security [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just added the security updates for April 2010 to Windows Update from where every Windows user can download and install them on their operating system.</p><p>A total of eleven security bulletins have been released that update the Windows operating system as well as other Microsoft software like Microsoft Office.</p><p>The updates fix security vulnerabilities in Microsoft applications and it is generally recommended to update the operating systems and applications as soon as possible to close the security holes and protect the systems from malicious attacks exploiting these vulnerabilities.</p><p>Five of the vulnerabilities have received a critical rating, the highest and most severe rating that vulnerabilities can get.</p><p><span
id="more-24511"></span><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010WindowsBulletins.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010WindowsBulletins-500x281.png" alt="April2010WindowsBulletins" title="April2010WindowsBulletins" width="500" height="281" class="alignnone size-medium wp-image-24513" /></a><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010RiskImpact.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010RiskImpact-500x281.png" alt="April2010RiskImpact" title="April2010RiskImpact" width="500" height="281" class="alignnone size-medium wp-image-24514" /></a><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010DeploymentPriority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010DeploymentPriority-500x281.png" alt="April2010DeploymentPriority" title="April2010DeploymentPriority" width="500" height="281" class="alignnone size-medium wp-image-24515" /></a></p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-019.mspx">MS10-019</a> &#8211; Vulnerabilities in Windows Could Allow Remote Code Execution (981210) &#8211; This security update resolves two privately reported vulnerabilities in Windows Authenticode Verification that could allow remote code execution. An attacker who successfully exploited either vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx">MS10-020</a> &#8211; Vulnerabilities in SMB Client Could Allow Remote Code Execution (980232) &#8211; This security update resolves one publicly disclosed and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a specially crafted SMB server.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-025.mspx">MS10-025</a> &#8211; Vulnerability in Microsoft Windows Media Services Could Allow Remote Code Execution (980858) &#8211; This security update resolves a privately reported vulnerability in Windows Media Services running on Microsoft Windows 2000 Server. The vulnerability could allow remote code execution if an attacker sent a specially crafted transport information packet to a Microsoft Windows 2000 Server system running Windows Media Services. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate from outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. On Microsoft Windows 2000 Server, Windows Media Services is an optional component and is not installed by default.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-026.mspx">MS10-026</a> &#8211; Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (977816) &#8211;<br
/> This security update resolves a privately reported vulnerability in Microsoft MPEG Layer-3 audio codecs. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file containing an MPEG Layer-3 audio stream. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-027.mspx">MS10-027</a> &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (979402) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx">MS10-021</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (979683) &#8211; This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-022.mspx">MS10-022</a> &#8211; Vulnerability in VBScript Could Allow Remote Code Execution (981169) &#8211; This security update resolves a publicly disclosed vulnerability in VBScript on Microsoft Windows that could allow remote code execution. This security update is rated Important for Microsoft Windows 2000, Windows XP, and Windows Server 2003. On Windows Server 2008, Windows Vista, Windows 7, and Windows Server 2008 R2, the vulnerable code is not exploitable, however, as the code is present, this update is provided as a defense-in-depth measure and has no severity rating.<p>The vulnerability could allow remote code execution if a malicious Web site displayed a specially crafted dialog box on a Web page and a user pressed the F1 key, causing the Windows Help System to be started with a Windows Help File provided by the attacker. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx">MS10-023</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (981160)  &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx">MS10-024</a> &#8211; Vulnerabilities in Microsoft Exchange and Windows SMTP Service Could Allow Denial of Service (981832) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Exchange and Windows SMTP Service. The more severe of these vulnerabilities could allow denial of service if an attacker sent a specially crafted DNS response to a computer running the SMTP service. By default, the SMTP component is not installed on Windows Server 2003, Windows Server 2003 x64 Edition, or Windows XP Professional x64 Edition.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-028.mspx">MS10-028</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (980094) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-029.mspx">MS10-029</a> &#8211; Vulnerabilities in Windows ISATAP Component Could Allow Spoofing (978338) &#8211; This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Moderate for Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. Windows 7 and Windows Server 2008 R2 are not vulnerable because these operating systems include the feature deployed by this security update.<p>This vulnerability could allow an attacker to spoof an IPv4 address so that it may bypass filtering devices that rely on the source IPv4 address. The security update addresses the vulnerability by changing the manner in which the Windows TCP/IP stack checks the source IPv6 address in a tunneled ISATAP packet.</li></ul><p>The security updates can be downloaded by following the links listed above or by launching Windows Update or Microsoft Update to download and install them automatically on the computer system.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/feed/</wfw:commentRss> <slash:comments>18</slash:comments> </item> <item><title>Microsoft Patch Tuesday December 08</title><link>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/</link> <comments>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/#comments</comments> <pubDate>Wed, 10 Dec 2008 21:06:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8835</guid> <description><![CDATA[Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important. The easiest way to install the patches is by downloading and installing the security patches at Windows Update [...]]]></description> <content:encoded><![CDATA[<p>Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.</p><p>The easiest way to install the patches is by downloading and installing the security patches at <a
href="http://www.update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&amp;&amp;thankspage=5">Windows Update</a> which provides access to all security updates even for users who run a non legit version of Windows.</p><p>Microsoft did also release a new version of the Windows Malicious Software Removal Tool which is now able to detect two new families of malware (Win32/FakeXPA and Win32/Yektel)</p><p><span
id="more-8835"></span><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx">MS08-070</a>: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx">MS08-071</a>: Vulnerabilities in GDI Could Allow Remote Code Execution (956802) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx">MS08-072</a>: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx">MS08-073</a>: Cumulative Security Update for Internet Explorer (958215) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx">MS08-074</a>: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx">MS08-075</a>: Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx">MS08-076</a>: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807) which is rated &#8220;Important&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-077.mspx">MS08-077</a>: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175) which is rated &#8220;Important&#8221;</li></ul><p>Windows users should install the updates as soon as possible to secure their computer system.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Security Bulletin March 2008</title><link>http://www.ghacks.net/2008/03/12/microsoft-security-bulletin-march-2008/</link> <comments>http://www.ghacks.net/2008/03/12/microsoft-security-bulletin-march-2008/#comments</comments> <pubDate>Wed, 12 Mar 2008 20:35:08 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[security bulletin]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2008/03/12/microsoft-security-bulletin-march-2008/</guid> <description><![CDATA[Microsoft released their monthly Security Bulletin yesterday which consisted of four critical issues all affecting various editions of Microsoft Office. All four patches fix remote code execution vulnerabilities and it is recommended that they are installed as soon as possible if Microsoft Office is installed on the computer.]]></description> <content:encoded><![CDATA[<p>Microsoft released their monthly Security Bulletin yesterday which consisted of four critical issues all affecting various editions of Microsoft Office. All four patches fix remote code execution vulnerabilities and it is recommended that they are installed as soon as possible if Microsoft Office is installed on the computer.</p><p>Two of the vulnerabilities allow remote code execution if the user opens a specially prepared file while the the other two make it possible with specially crafted mailto links and websites. It should be noted that not only Office 2000, Office 2003 and Office 2007<br
/> are affected but also Office for Mac, to be price Office 2004 and 2008 for Mac.</p><p>You can use the Microsoft Baseline Analyzer [<a
href="http://technet.microsoft.com/en-us/security/cc184924.aspx">link</a>] to find out if your system is affected. My suggestion is to simply <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-mar.mspx">download</a> the four patches and see if they install. You would get an error message if your system would not be affected.</p><p><span
id="more-3496"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/03/12/microsoft-security-bulletin-march-2008/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Get your Microsoft Security Patches now</title><link>http://www.ghacks.net/2007/08/15/get-your-microsoft-security-patches-now/</link> <comments>http://www.ghacks.net/2007/08/15/get-your-microsoft-security-patches-now/#comments</comments> <pubDate>Wed, 15 Aug 2007 05:58:52 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/08/15/get-your-microsoft-security-patches-now/</guid> <description><![CDATA[Microsoft released a total of nine security patches yesterday fixing six critical and three important vulnerabilities on its August Patchday. Those updates were available on both my Windows XP and Windows Vista system and Microsoft in Windows Update but can also be downloaded as single updates from the Microsoft website.]]></description> <content:encoded><![CDATA[<p>Microsoft released a total of nine security patches yesterday fixing six critical and three important vulnerabilities on its August Patchday. Those updates were available on both my Windows XP and Windows Vista system and Microsoft in Windows Update but can also be downloaded as single updates from the Microsoft website.</p><p>I decided to list all patches with links to their downloads at the Microsoft website to make it easier to install all those patches if you do not want to use Windows Update. Remember that those patches fix serious vulnerabilities and should be installed immediately:</p><p><span
id="more-1874"></span>Installing those patches manually will take some time. Below are links that display a page listing the affected softwares and links to the patches.</p><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx">MS07-042</a> (critical) &#8211; This critical security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. The vulnerability could be exploited through attacks on Microsoft XML Core Services. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-043.mspx">MS07-043</a> (critical) &#8211; This critical security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Web page. The vulnerability could be exploited through attacks on Object Linking and Embedding (OLE). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-044.mspx">MS07-044</a> (critical) &#8211; This security update resolves a privately reported vulnerability in addition to other security issues identified during the course of the investigation. These vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx">MS07-045</a> (critical) &#8211;<p>This critical security update resolves three privately reported vulnerabilities. These vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-046.mspx">MS07-046</a> (critical) &#8211; This critical security update resolves a privately reported vulnerability. A remote code execution vulnerability exists in the Graphics Rendering Engine in the way that it handles specially crafted images. An attacker could exploit the vulnerability by constructing a specially crafted image that could potentially allow remote code execution if a user opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms07-050.mspx">MS07-050</a> (critical) &#8211; This security update resolves a privately reported vulnerability in the Vector Markup Language (VML) implementation in Windows. The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS07-047.mspx">MS07-047</a> (important) &#8211; This important security update resolves two privately reported vulnerabilities. These vulnerabilities could allow code execution if a user viewed a specially crafted file in Windows Media Player. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS07-048.mspx">MS07-048</a> (important) &#8211; This important security update resolves two privately reported vulnerabilities in addition to other vulnerabilities identified during the course of the investigation. These vulnerabilities could allow an anonymous remote attacker to run code with the privileges of the logged on user. If a user subscribed to a malicious RSS feed in the Feed Headlines Gadget or added a malicious contacts file in the Contacts Gadget or a user clicked on a malicious link in the Weather Gadget an attacker could potentially run code on the system. In all attack vectors, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS07-049.mspx">MS07-049</a> (important) &#8211; This important security update resolves one privately reported vulnerability. This is an elevation of privilege vulnerability. The vulnerability in Microsoft Virtual PC and Microsoft Virtual Server could allow a guest operating system user to run code on the host or another guest operating systems. Only guest operating system users who are granted administrative permissions to the guest operating system would be able to exploit this vulnerability. Guest operating system users not granted administrative permissions to the guest operating system would be unable to exploit this vulnerability.</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/08/15/get-your-microsoft-security-patches-now/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
