<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; microsoft security bulletin</title> <atom:link href="http://www.ghacks.net/tag/microsoft-security-bulletin/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Security Bulletin Overview January 2011</title><link>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/</link> <comments>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/#comments</comments> <pubDate>Tue, 11 Jan 2011 23:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=38900</guid> <description><![CDATA[The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code execution. The maximum severity rating of the vulnerability is critical, the highest possible rating.</p><p>A closer look at the security vulnerability reveals that is is rated critical for all 32-bit and 64-bit Windows client operating systems from Windows XP to Windows 7. The same vulnerability is rated as important for all server based operating systems.</p><p>The second vulnerability, MS11-001, has a maximum severity rating of important. It fixes a vulnerability in the Windows Backup Manager that could allow remote code execution. The vulnerability affects only the Windows Vista operating system.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-002.mspx">MS11-002</a> &#8211; Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Data Access Components. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS11-001.mspx">MS11-001</a> &#8211; Vulnerability in Windows Backup Manager Could Allow Remote Code Execution (2478935) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Backup Manager. The vulnerability could allow remote code execution if a user opens a legitimate Windows Backup Manager file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the legitimate file from that location, which in turn could cause Windows Backup Manager to load the specially crafted library file.</li></ul><p><strong>Severity and Exploitability Index</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101-550x309.png" alt="" title="6011.sev-exp-1101" width="550" height="309" class="alignnone size-medium wp-image-38901" /></a></p><p><strong>Bulletin Deployment Priority</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101-550x309.png" alt="6153.deploy_2D00_1101" title="6153.deploy_2D00_1101" width="550" height="309" class="alignnone size-medium wp-image-38902" /></a></p><p>The images have been taken from the <a
href="http://blogs.technet.com/b/msrc/archive/2011/01/11/january-2011-security-bulletins.aspx">Technet</a> announcement which offers further information about the vulnerabilities and patch deployment.</p><p>Windows users are advised to apply the patches as soon as possible to protect their system from possible exploits. The patches can be applied directly via Windows Update or <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">directly from</a> Microsoft Download.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Bulletin December 2010</title><link>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/</link> <comments>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/#comments</comments> <pubDate>Wed, 15 Dec 2010 08:49:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37961</guid> <description><![CDATA[Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer. When we look at the severity rating of those vulnerabilities we notice that two of [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer.</p><p>When we look at the severity rating of those vulnerabilities we notice that two of the bulletins have a maximum severity rating of critical while the remaining ones a rating of important with the exception of one that has been rated as moderate.</p><p>Maximum severity rating means that at least one Microsoft product is affect this way by the vulnerability. The critical vulnerability MS10-090 affects Internet Explorer 6 to Internet Explorer 8 and is critical on all Microsoft operating systems. Vulnerability MS10-091 on the other hand is critical on Windows Vista and Windows 7 but not on Windows XP, something that we do not see very often thanks to improved security of the two operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority-550x309.png" alt="deployment priority" title="deployment priority" width="550" height="309" class="alignnone size-medium wp-image-37962" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index-550x309.png" alt="severity exploitability index" title="severity exploitability index" width="550" height="309" class="alignnone size-medium wp-image-37963" /></a></p><p>The updates are already available via Windows Update and the <a
href="http://www.microsoft.com/downloads/en/default.aspx">Microsoft Download Center</a>.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-090.mspx">MS10-090</a> &#8211; Cumulative Security Update for Internet Explorer (2416400) &#8211; This security update resolves four privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-091.mspx">MS10-091</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199) &#8211; This security update resolves several privately reported vulnerabilities in the Windows Open Type Font (OTF) driver that could allow remote code execution. An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a> &#8211; Vulnerability in Task Scheduler Could Allow Elevation of Privilege (2305420) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Task Scheduler. The vulnerability could allow elevation of privilege if an attacker logged on to an affected system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-093.mspx">MS10-093</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Movie Maker file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx">MS10-094</a> &#8211; Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Media Encoder. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-095.mspx">MS10-095</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2385678) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file type such as .eml and .rss (Windows Live Mail) or .wpost (Microsoft Live Writer) located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx">MS10-096</a> &#8211; Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Address Book. The vulnerability could allow remote code execution if a user opens a Windows Address Book file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx">MS10-097</a> &#8211; Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105) &#8211;  This security update resolves a publicly disclosed vulnerability in the Internet Connection Signup Wizard of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-098.mspx">MS10-098</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) &#8211; This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-099.mspx">MS10-099</a> &#8211; Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591) &#8211; This security update addresses a privately reported vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx">MS10-100</a> &#8211; Vulnerability in Consent User Interface Could Allow Elevation of Privilege (2442962) &#8211; This security update resolves a privately reported vulnerability in the Consent User Interface (UI). The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application on an affected system. An attacker must have valid logon credentials and the SeImpersonatePrivilege and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-101.mspx">MS10-101</a> &#8211; Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559) &#8211; This security update resolves a privately reported vulnerability in the Netlogon RPC Service on affected versions of Windows Server that are configured to serve as domain controllers. The vulnerability could allow denial of service if an attacker sends a specially crafted RPC packet to the Netlogon RPC Service interface on an affected system. An attacker requires administrator privileges on a machine that is joined to the same domain as the affected domain controller in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-102.mspx">MS10-102</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2345316) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx">MS10-103</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292970) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-104.mspx">MS10-104</a> &#8211; Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution (2455005) &#8211; This security update resolves a privately reported vulnerability in Microsoft SharePoint. The vulnerability could allow remote code execution in the security context of a guest user if an attacker sent a specially crafted SOAP request to the Document Conversions Launcher Service in a SharePoint server environment that is using the Document Conversions Load Balancer Service. By default, the Document Conversions Load Balancer Service and Document Conversions Launcher Service are not enabled in Microsoft Office SharePoint Server 2007.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx">MS10-105</a> &#8211; Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-106.mspx">MS10-106</a> &#8211; Vulnerability in Microsoft Exchange Server Could Allow Denial of Service (2407132) &#8211; This security update resolves a privately reported vulnerability in Microsoft Exchange Server. The vulnerability could allow denial of service if an authenticated attacker sent a specially crafted network message to a computer running the Exchange service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li></ul><p>Additional information are available at the <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-dec.mspx">security bulletin summary</a> and the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Bulletin November 2010</title><link>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/</link> <comments>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/#comments</comments> <pubDate>Wed, 10 Nov 2010 08:33:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[forefront]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36710</guid> <description><![CDATA[Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity rating of critical, the other two bulletins an important rating. Lets take a closer look at the bulletins.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-087.mspx">MS10-087</a> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930) &#8211; This security update resolves one publicly disclosed vulnerability and four privately reported vulnerabilities in Microsoft Office. The most severe vulnerability could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-088.mspx">MS10-088</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-089.mspx">MS10-089</a> &#8211; Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074) &#8211; This security update resolves four privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow elevation of privilege if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li></ul><p>The security patches are as usually available via Windows Update, Microsoft Update and <a
href="http://www.microsoft.com/downloads/en/default.aspx">direct</a> download. Office and Forefront users should patch the security vulnerabilities as soon as possible, everyone else can relax this month and wait for things to come. (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-nov.mspx">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Bulletins October 2010</title><link>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/</link> <comments>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/#comments</comments> <pubDate>Tue, 12 Oct 2010 20:52:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35831</guid> <description><![CDATA[Every second Tuesday in a month is patch day over at Microsoft. What does it mean? Microsoft pushes out all security patches of a month on that day to all users of their Windows operating systems and other applications like Microsoft Office. Only highly critical vulnerabilities receive out of band security patches. This month&#8217;s patch [...]]]></description> <content:encoded><![CDATA[<p>Every second Tuesday in a month is patch day over at Microsoft. What does it mean? Microsoft pushes out all security patches of a month on that day to all users of their Windows operating systems and other applications like Microsoft Office. Only highly critical vulnerabilities receive out of band security patches.</p><p>This month&#8217;s patch day is huge. While it is not the largest in history, it addresses the impressive amount of 49 vulnerabilities affecting Windows, Internet Explorer, Microsoft Office and the .net framework.</p><blockquote><p>Looking at the number and type of updates this month, we have a fairly standard number of bulletins affecting products like Windows and Office. This month we also have a few bulletins originating from product groups that we don&#8217;t see on a regular basis. For example, SharePoint, the Microsoft Foundation Class (MFC) Library (which is an application framework for programming in Windows), and the .NET Framework. It&#8217;s worth noting that only six of the 49 total vulnerabilities being addressed have a critical rating. Further, three of the bulletins account for 34 of the total vulnerabilities. (<a
href="http://blogs.technet.com/b/msrc/archive/2010/10/11/october-2010-security-bulletin-release.aspx">via</a>)</p></blockquote><p><strong>Deployment Priority</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/10/Deployment-Priority1.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/10/Deployment-Priority1-500x281.png" alt="Deployment Priority" title="Deployment Priority" width="500" height="281" class="alignnone size-medium wp-image-35833" /></a></p><p><strong>Severity and Exploitability</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/10/Severity-Exploitability.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/10/Severity-Exploitability-500x281.png" alt="Severity Exploitability" title="Severity Exploitability" width="500" height="281" class="alignnone size-medium wp-image-35834" /></a></p><p>Four of the vulnerabilities have a maximum severity rating of critical, 10 of important and the remaining 2 of moderate.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-071.mspx">MS10-071</a> &#8211; Cumulative Security Update for Internet Explorer (2360131) &#8211; This security update resolves seven privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-075.mspx">MS10-075</a> &#8211; Vulnerability in Media Player Network Sharing Service Could Allow Remote Code Execution (2281679) &#8211; This security update resolves a privately reported vulnerability in the Microsoft Windows Media Player network sharing service. The vulnerability could allow remote code execution if an attacker sent a specially crafted RTSP packet to an affected system. However, Internet access to home media is disabled by default. In this default configuration, the vulnerability can be exploited only by an attacker within the same subnet.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-076.mspx">MS10-076</a> &#8211; Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (982132) &#8211; This security update resolves a privately reported vulnerability in a Microsoft Windows component, the Embedded OpenType (EOT) Font Engine. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-077.mspx">MS10-077</a> &#8211; Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) &#8211; This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-072.mspx">MS10-072</a> &#8211; Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft SharePoint and Windows SharePoint Services. The vulnerabilities could allow information disclosure if an attacker submits specially crafted script to a target site using SafeHTML.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-073.mspx">MS10-073</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) &#8211; This security update resolves several publicly disclosed vulnerabilities in the Windows kernel-mode drivers. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application.<p>An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-078.mspx">MS10-078</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Format Driver Could Allow Elevation of Privilege (2279986) &#8211; This security update resolves two privately reported vulnerabilities in the Windows OpenType Font (OTF) format driver. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerabilities could allow elevation of privilege if a user views content rendered in a specially crafted OpenType font. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-079.mspx">MS10-079</a> &#8211; Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) &#8211; This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-080.mspx">MS10-080</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211) &#8211; This security update resolves thirteen privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file or a specially crafted Lotus 1-2-3 file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-081.mspx">MS10-081</a> &#8211; Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (2296011) &#8211; This security update resolves a privately reported vulnerability in the Windows common control library. The vulnerability could allow remote code execution if a user visited a specially crafted Web page. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-082.mspx">MS10-082</a> &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-083.mspx">MS10-083</a> &#8211; Vulnerability in COM Validation in Windows Shell and WordPad Could Allow Remote Code Execution (2405882) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted file using WordPad or selects or opens a shortcut file that is on a network or WebDAV share. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-084.mspx">MS10-084</a> &#8211; Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs specially crafted code that sends an LPC message to the local LRPC Server. The message could then allow an authenticated user to access resources that are running in the context of the NetworkService account. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-085.mspx">MS10-085</a> &#8211; Vulnerability in SChannel Could Allow Denial of Service (2207566) &#8211; This security update resolves a privately reported vulnerability in the Secure Channel (SChannel) security package in Windows. The vulnerability could allow denial of service if an affected Internet Information Services (IIS) server hosting a Secure Sockets Layer (SSL)-enabled Web site received a specially crafted packet message. By default, IIS is not configured to host SSL Web sites.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-074.mspx">MS10-074</a> &#8211; Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution (2387149) &#8211; This security update resolves a publicly disclosed vulnerability in the Microsoft Foundation Class (MFC) Library. The vulnerability could allow remote code execution if a user is logged on with administrative user rights and opens an application built with the MFC Library. An attacker who successfully exploited this vulnerability could obtain the same permissions as the currently logged-on user. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-086.mspx">MS10-086</a> &#8211; Vulnerability in Windows Shared Cluster Disks Could Allow Tampering (2294255) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 R2 when used as a shared failover cluster. The vulnerability could allow data tampering on the administrative shares of failover cluster disks. By default, Windows Server 2008 R2 servers are not affected by this vulnerability. This vulnerability only applies to the cluster disks used in a failover cluster.</li></ul><p>The patches are as usual available via Windows Update and <a
href="http://www.microsoft.com/downloads/en/resultsForCategory.aspx?nr=50&#038;sortOrder=Descending&#038;sortCriteria=Date&#038;period=30&#038;stype=ss_nd&#038;sterm=All+Categories">Microsoft Download</a>. Microsoft has furthermore <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=07c7c176-a801-4868-8f53-c8b1aebb2b11">released</a> the October 2010 Security Release ISO Image containing all references security patches and Knowledgebase articles.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Security Updates July 2010</title><link>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/</link> <comments>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/#comments</comments> <pubDate>Tue, 13 Jul 2010 21:11:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[office updates]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=28217</guid> <description><![CDATA[Microsoft has just released four security bulletins on this months&#8217; Patch Tuesday fixing vulnerabilities in Microsoft software products. Three of the four bulletins have a maximum severity rating of critical, the highest rated, while one is rated as important. Affected software includes several Microsoft operating systems and Microsoft Office, take a look at the listing [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just released four security bulletins on this months&#8217; Patch Tuesday fixing vulnerabilities in Microsoft software products. Three of the four bulletins have a maximum severity rating of critical, the highest rated, while one is rated as important.</p><p>Affected software includes several Microsoft operating systems and Microsoft Office, take a look at the listing below for additional details on every security bulletin released today.</p><p><span
id="more-28217"></span><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-042.mspx">MS10-042</a> &#8211; Critical<br
/> Vulnerability in Help and Support Center Could Allow Remote Code Execution (2229593) &#8211; This security update resolves a publicly disclosed vulnerability in the Windows Help and Support Center feature that is delivered with supported editions of Windows XP and Windows Server 2003. This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser or clicks a specially crafted link in an e-mail message. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful, a user must click a link listed within an e-mail message.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-043.mspx">MS10-043</a> &#8211; Critical<br
/> Vulnerability in Canonical Display Driver Could Allow Remote Code Execution (2032276) &#8211; This security update resolves a publicly disclosed vulnerability in the Canonical Display Driver (cdd.dll). Although it is possible that the vulnerability could allow code execution, successful code execution is unlikely due to memory randomization. In most scenarios, it is much more likely that an attacker who successfully exploited this vulnerability could cause the affected system to stop responding and automatically restart.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-044.mspx">MS10-044</a> &#8211; Critical<br
/> Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office Access ActiveX Controls. The vulnerabilities could allow remote code execution if a user opened a specially crafted Office file or viewed a Web page that instantiated Access ActiveX controls. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-045.mspx">MS10-045</a> &#8211; Important<br
/> Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution (978212) &#8211; This security update resolves a privately reported vulnerability. The vulnerability could allow remote code execution if a user opened an attachment in a specially crafted e-mail message using an affected version of Microsoft Office Outlook. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights</li></ul><div
id="attachment_28218" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-security-updates.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-security-updates-500x281.png" alt="microsoft security updates" title="microsoft security updates" width="500" height="281" class="size-medium wp-image-28218" /></a><p
class="wp-caption-text">microsoft security updates</p></div><div
id="attachment_28219" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-patch-day.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-patch-day-500x281.png" alt="microsoft patch day" title="microsoft patch day" width="500" height="281" class="size-medium wp-image-28219" /></a><p
class="wp-caption-text">microsoft patch day deployment priority</p></div><h3>Affected software:</h3><ul><li>MS10-042 &#8211; Windows XP, Windows XP Pro 64-bit, Windows Server 2003, Windows Server 2003 64-bit</li><li>MS10-043 &#8211; Windows 7 for x64-based Systems, Windows Server 2008 R2 for x64-based Systems</li><li>MS10-044 &#8211; Microsoft Office 2003 , Microsoft Office 2007</li><li>MS10-045 &#8211; Microsoft Office XP, Microsoft Office 2003,  Microsoft Office 2007</li></ul><p>All vulnerabilities allow remote code execution on compromised systems. Additional information about this months&#8217; patches are <a
href="http://blogs.technet.com/b/msrc/archive/2010/07/13/july-2010-security-bulletin-release.aspx">available</a> at the Technet blog post.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Microsoft Security Updates May 2010</title><link>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/</link> <comments>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/#comments</comments> <pubDate>Wed, 12 May 2010 10:35:14 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft security updates]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=25381</guid> <description><![CDATA[The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic. The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications. [...]]]></description> <content:encoded><![CDATA[<p>The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic.</p><p>The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications.</p><p>Both vulnerabilities can be exploited to execute code remotely on affected operating systems and applications.</p><p><span
id="more-25381"></span><ul><li>MS10-030 &#8211; Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-030.mspx">978542</a>) &#8211; This security update resolves a privately reported vulnerability in Outlook Express, Windows Mail, and Windows Live Mail. The vulnerability could allow remote code execution if a user visits a malicious e-mail server. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>MS10-031 &#8211; Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-031.mspx">978213</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Visual Basic for Applications. The vulnerability could allow remote code execution if a host application opens and passes a specially crafted file to the Visual Basic for Applications runtime. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>The security patches can be downloaded via Windows Update, Microsoft Update and the individual security bulletin pages.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates August 2009</title><link>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/</link> <comments>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/#comments</comments> <pubDate>Wed, 12 Aug 2009 10:09:08 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft security updates]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[office security]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=15276</guid> <description><![CDATA[Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A summary of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A <a
href="http://www.microsoft.com/technet/security/Bulletin/ms09-aug.mspx">summary</a> of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. Users who operate Microsoft operating systems or Microsoft products should install the security patches as soon as possible to protect their system from possible exploits.</p><p>Affected operating systems include Windows Vista, Windows XP, Windows Server 2003 and 2008, Windows 2000 but not Windows 7. Downloads are available from the usual locations including automatic updates, Windows Update, Microsoft Update or by following the links in the security bulletins below.</p><p><span
id="more-15276"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx">MS09-043</a> Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)<p>This security update resolves several privately reported vulnerabilities in Microsoft Office Web Components that could allow remote code execution if a user viewed a specially crafted Web page. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-044.mspx">MS09-044</a> Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)<p>This security update resolves two privately reported vulnerabilities in Microsoft Remote Desktop Connection. The vulnerabilities could allow remote code execution if an attacker successfully convinced a user of Terminal Services to connect to a malicious RDP server or if a user visits a specially crafted Web site that exploits this vulnerability. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx">MS09-039</a> Vulnerabilities in WINS Could Allow Remote Code Execution (969883)<p>This security update resolves two privately reported vulnerabilities in the Windows Internet Name Service (WINS). Either vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system version. Only customers who manually install this component are affected by this issue.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-038.mspx">MS09-038</a> &#8211; Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)<p>This security update resolves two privately reported vulnerabilities in Windows Media file processing. Either vulnerability could allow remote code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037</a> Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)<p>This security update resolves several privately reported vulnerabilities in Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-041.mspx">MS09-041</a> Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)<p>This security update resolves a privately reported vulnerability in the Windows Workstation Service. The vulnerability could allow elevation of privilege if an attacker created a specially crafted RPC message and sent the message to an affected system. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to a vulnerable system in order to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-040.mspx">MS09-040</a> Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)<p>This security update resolves a privately reported vulnerability in the Windows Message Queuing Service (MSMQ). The vulnerability could allow elevation of privilege if a user received a specially crafted request to an affected MSMQ service. By default, the Message Queuing component is not installed on any affected operating system edition and can only be enabled by a user with administrative privileges. Only customers who manually install the Message Queuing component are likely to be vulnerable to this issue.</p></li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-036.mspx">MS09-036</a> Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)<p>This security update addresses a privately reported Denial of Service vulnerability in the Microsoft .NET Framework component of Microsoft Windows. This vulnerability can be exploited only when Internet Information Services (IIS) 7.0 is installed and ASP.NET is configured to use integrated mode on affected versions of Microsoft Windows. An attacker could create specially crafted anonymous HTTP requests that could cause the affected Web server to become non-responsive until the associated application pool is restarted. Customers who are running IIS 7.0 application pools in classic mode are not affected by this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-042.mspx">MS09-042</a> Vulnerability in Telnet Could Allow Remote Code Execution (960859)<p>This security update resolves a publicly disclosed vulnerability in the Microsoft Telnet service. The vulnerability could allow an attacker to obtain credentials and then use them to log back into affected systems. The attacker would then acquire user rights on a system identical to the user rights of the logged-on user. This scenario could ultimately result in remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Patch Day March 2009</title><link>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/</link> <comments>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/#comments</comments> <pubDate>Tue, 10 Mar 2009 17:26:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[remote code execution]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[spoofing]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerabilities]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=11081</guid> <description><![CDATA[Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including [...]]]></description> <content:encoded><![CDATA[<p>Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including Windows 2000. This means the popular operating systems Windows XP and Vista are affected as well as Windows Server 2003 and 2008.</p><p>One security vulnerability has a critical rating for all affected operating systems while the other two are rated important by Microsoft&#8217;s security research team.</p><p>Details about the Security Bulletins can be found by following these links: Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-006.mspx">MS09-006</a>, <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-007.mspx">MS09-007</a> or <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-008.mspx">MS09-008</a>. Another possibility is to <a
href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx">access</a> the Security Bulletin Summary at Microsoft Technet.</p><p>The vulnerabilities fix one remote code execution vulnerability and two spoofing vulnerabilities on the affected Windows operating systems:</p><ul><li>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</li><li>Vulnerability in SChannel Could Allow Spoofing</li><li>Vulnerabilities in DNS and WINS Server Could Allow Spoofing</li></ul><p><span
id="more-11081"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>January 2009 Microsoft Security Bulletin</title><link>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/</link> <comments>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/#comments</comments> <pubDate>Wed, 14 Jan 2009 14:49:13 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[update windows]]></category> <category><![CDATA[windows patch]]></category> <category><![CDATA[windows vulnerability]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=9886</guid> <description><![CDATA[Microsoft has the habit of releasing security patches on one Tuesday each month. Time critical patches can be delivered out of schedule but that did not happen that often in the past. Only one security bulletin has been released on the patch Tuesday in January 2009. Security Bullein MS09-001 has been rated critical for Windows [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has the habit of releasing security patches on one Tuesday each month. Time critical patches can be delivered out of schedule but that did not happen that often in the past. Only one security bulletin has been released on the patch Tuesday in January 2009. Security Bullein <a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-001.mspx">MS09-001</a> has been rated critical for Windows XP and Windows Server 2003 respectively moderate for Windows Vista and Windows Server 2008.</p><p>The security bulletin resolves three vulnerabilities in Microsoft Server Message Block (SMB) Protocol which could allow remote code execution on affected systems. An attacker could run programs, create new user accounts and view, change or delete data on the computer system. It is <a
href="http://blogs.technet.com/b/msrc/archive/2009/01/13/january-2009-monthly-bulletin-release.aspx">interesting</a> to note that Windows 7 is affected as well even though it is not mentioned in the security bulletin.</p><p>The security vulnerability would be rated as moderate for the upcoming operating system which is why Microsoft will not provide a patch at the current time (They chose to only patch critical security vulnerabilities immediately). A patch will be released with the next public release of Windows 7.</p><p><span
id="more-9886"></span>Patches can be applied as usual through the various official update channels.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Microsoft Patch Tuesday November 08</title><link>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/</link> <comments>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/#comments</comments> <pubDate>Wed, 12 Nov 2008 13:55:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8233</guid> <description><![CDATA[Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins MS08-069 and MS08-068 patched two vulnerability with the status critical and important. The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069</a> and <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">MS08-068</a> patched two vulnerability with the status critical and important.</p><p>The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code execution in Microsoft Server Message Block (SMB) Protocol.</p><p>Both security vulnerabilities can be fixed by using Windows Update or by downloading the security updates directly from the Microsoft Download website by following the two links given above in this article.</p><p><span
id="more-8233"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
