<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; microsoft security</title> <atom:link href="http://www.ghacks.net/tag/microsoft-security/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Security Patches for July 2011</title><link>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/</link> <comments>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/#comments</comments> <pubDate>Tue, 12 Jul 2011 20:25:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft download center]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47740</guid> <description><![CDATA[It is the second Tuesday of the month which means it is patch day over at Microsoft. The Redmond based company has released a total of four security bulletins that month. One bulletin has received a maximum severity rating of critical, while the three others one of important. The critical vulnerability addresses a issue in [...]]]></description> <content:encoded><![CDATA[<p>It is the second Tuesday of the month which means it is patch day over at Microsoft. The Redmond based company has released a total of four security bulletins that month. One bulletin has received a maximum severity rating of critical, while the three others one of important. The critical vulnerability addresses a issue in the Bluetooth stack that could allow remote code execution. Affected are only Microsoft Windows Vista and Windows 7, and not Windows XP or earlier operating systems.</p><p>Two of the three remaining vulnerabilities address issues in the Windows operating system as well. Security bulletin MS11-054 describes a vulnerability in Windows Kernel-Mode drivers that could allow elevation of privileges, while bulletin MS11-056 a vulnerability in the Windows Client and Server run-time subsystem.</p><p>All supported Microsoft client and server operating systems are affected by the two security vulnerabilities. The last issue is a vulnerability in Microsoft Visio.</p><p>Here is an overview of all four security bulletins with links to their pages at the Microsoft Technet website.</p><ul><li> <a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-053.mspx">MS11-053</a> &#8211; Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-054.mspx">MS11-054</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-056.mspx">MS11-056</a> &#8211; Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-055.mspx">MS11-055</a> &#8211; Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847)</li></ul><p>The patches are as usual already available via Windows Update, Microsoft Update and via the Microsoft Download Center. The monthly exploit mitigation guide at the Technet Security blog provides additional information about the vulnerabilities and deployment strategies.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/07/7367.201107-severity-xi.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/7367.201107-severity-xi-600x337.png" alt="" title="7367.201107-severity-xi" width="600" height="337" class="alignnone size-medium wp-image-47741" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/07/7418.201107-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/7418.201107-deployment-600x337.png" alt="" title="7418.201107-deployment" width="600" height="337" class="alignnone size-medium wp-image-47742" /></a></p><p>Probably the easiest way to deploy the security updates to a single system is via Windows Update.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/windows-update.png" alt="windows update" title="windows update" width="575" height="280" class="alignnone size-full wp-image-47743" /></p><p>Just click on Start > All Programs > Windows Update to open the update screen. You may need to click on Check for updates on the left sidebar if your computer has been up for some time and the updates are not displayed directly in the main window.</p><p>Have you updated your system yet? Am I the only user who feels that Microsoft&#8217;s Download Center is not usable at all at the moment?</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft May 2011 Patch Day Overview</title><link>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/</link> <comments>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/#comments</comments> <pubDate>Tue, 10 May 2011 20:34:53 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44985</guid> <description><![CDATA[Microsoft has released two security bulletins on this month&#8217;s patch day. Every second Tuesday of a month is so called patch day at Microsoft where a number of security related updates are released. One of the security bulletin addresses securities in Microsoft Windows, the other in Microsoft Office. If you look at the maximum severity [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released two security bulletins on this month&#8217;s patch day. Every second Tuesday of a month is so called patch day at Microsoft where a number of security related updates are released. One of the security bulletin addresses securities in Microsoft Windows, the other in Microsoft Office.</p><p>If you look at the maximum severity rating you notice that the Windows vulnerabilities have received a severity rating of critical, the highest possible rating. The Office bulletin on the other hand received a rating of important, the second highest rating.</p><p>Microsoft Security Bulletin MS11-035 offers detailed information about the Windows vulnerability. It affects only Windows Server products, from Windows Server 2003 to Windows Server 2008 R2. Not affected are all client operating systems of Microsoft.</p><p>If you look at Microsoft Security Bulletin MS11-036 you notice that Office XP, 2003 and 2007 are affected on Windows. Furthermore affected are Microsoft Office 2004 and 2008 for Mac, the Open XML File Format Converter for Mac and the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2.</p><p>Why is not Office 2010 affected by the vulnerability? Because Office File Validation mitigates the risk of the vulnerability.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-035.mspx">MS11-035</a> &#8211; Vulnerability in WINS Could Allow Remote Code Execution (2524426) &#8211; This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system. Only customers who manually installed this component are affected by this issue.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-036.mspx">MS11-036</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1269 and CVE-2011-1270.</li></ul><p>Additional information on both vulnerabilities are available at the <a
href="http://blogs.technet.com/b/msrc/archive/2011/05/10/may-2011-security-bulletin-release.aspx">MSRC</a> Technet Blog.</p><p>The patches are available via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> or the <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">Microsoft Download Center</a>. The May Security Release ISO image is <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f134d93b-dd1e-401a-a214-343f99b77350&#038;pf=true">available</a> there as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Security Bulletin December 2010</title><link>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/</link> <comments>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/#comments</comments> <pubDate>Wed, 15 Dec 2010 08:49:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37961</guid> <description><![CDATA[Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer. When we look at the severity rating of those vulnerabilities we notice that two of [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer.</p><p>When we look at the severity rating of those vulnerabilities we notice that two of the bulletins have a maximum severity rating of critical while the remaining ones a rating of important with the exception of one that has been rated as moderate.</p><p>Maximum severity rating means that at least one Microsoft product is affect this way by the vulnerability. The critical vulnerability MS10-090 affects Internet Explorer 6 to Internet Explorer 8 and is critical on all Microsoft operating systems. Vulnerability MS10-091 on the other hand is critical on Windows Vista and Windows 7 but not on Windows XP, something that we do not see very often thanks to improved security of the two operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority-550x309.png" alt="deployment priority" title="deployment priority" width="550" height="309" class="alignnone size-medium wp-image-37962" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index-550x309.png" alt="severity exploitability index" title="severity exploitability index" width="550" height="309" class="alignnone size-medium wp-image-37963" /></a></p><p>The updates are already available via Windows Update and the <a
href="http://www.microsoft.com/downloads/en/default.aspx">Microsoft Download Center</a>.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-090.mspx">MS10-090</a> &#8211; Cumulative Security Update for Internet Explorer (2416400) &#8211; This security update resolves four privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-091.mspx">MS10-091</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199) &#8211; This security update resolves several privately reported vulnerabilities in the Windows Open Type Font (OTF) driver that could allow remote code execution. An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a> &#8211; Vulnerability in Task Scheduler Could Allow Elevation of Privilege (2305420) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Task Scheduler. The vulnerability could allow elevation of privilege if an attacker logged on to an affected system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-093.mspx">MS10-093</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Movie Maker file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx">MS10-094</a> &#8211; Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Media Encoder. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-095.mspx">MS10-095</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2385678) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file type such as .eml and .rss (Windows Live Mail) or .wpost (Microsoft Live Writer) located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx">MS10-096</a> &#8211; Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Address Book. The vulnerability could allow remote code execution if a user opens a Windows Address Book file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx">MS10-097</a> &#8211; Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105) &#8211;  This security update resolves a publicly disclosed vulnerability in the Internet Connection Signup Wizard of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-098.mspx">MS10-098</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) &#8211; This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-099.mspx">MS10-099</a> &#8211; Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591) &#8211; This security update addresses a privately reported vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx">MS10-100</a> &#8211; Vulnerability in Consent User Interface Could Allow Elevation of Privilege (2442962) &#8211; This security update resolves a privately reported vulnerability in the Consent User Interface (UI). The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application on an affected system. An attacker must have valid logon credentials and the SeImpersonatePrivilege and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-101.mspx">MS10-101</a> &#8211; Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559) &#8211; This security update resolves a privately reported vulnerability in the Netlogon RPC Service on affected versions of Windows Server that are configured to serve as domain controllers. The vulnerability could allow denial of service if an attacker sends a specially crafted RPC packet to the Netlogon RPC Service interface on an affected system. An attacker requires administrator privileges on a machine that is joined to the same domain as the affected domain controller in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-102.mspx">MS10-102</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2345316) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx">MS10-103</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292970) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-104.mspx">MS10-104</a> &#8211; Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution (2455005) &#8211; This security update resolves a privately reported vulnerability in Microsoft SharePoint. The vulnerability could allow remote code execution in the security context of a guest user if an attacker sent a specially crafted SOAP request to the Document Conversions Launcher Service in a SharePoint server environment that is using the Document Conversions Load Balancer Service. By default, the Document Conversions Load Balancer Service and Document Conversions Launcher Service are not enabled in Microsoft Office SharePoint Server 2007.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx">MS10-105</a> &#8211; Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-106.mspx">MS10-106</a> &#8211; Vulnerability in Microsoft Exchange Server Could Allow Denial of Service (2407132) &#8211; This security update resolves a privately reported vulnerability in Microsoft Exchange Server. The vulnerability could allow denial of service if an authenticated attacker sent a specially crafted network message to a computer running the Exchange service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li></ul><p>Additional information are available at the <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-dec.mspx">security bulletin summary</a> and the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Collection of Recent Microsoft Security News</title><link>http://www.ghacks.net/2010/10/13/collection-of-recent-microsoft-security-news/</link> <comments>http://www.ghacks.net/2010/10/13/collection-of-recent-microsoft-security-news/#comments</comments> <pubDate>Wed, 13 Oct 2010 19:07:58 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[internet explorer 9]]></category> <category><![CDATA[Malicious Software Removal Tool]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[SDL Regex Fuzzer]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[Zbot]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35858</guid> <description><![CDATA[Yesterday was one of the largest patch days in Windows history, with 16 security bulletins and way of 40 different vulnerabilities patched. If you have not updated your version of Windows yet you should consider doing so immediately to protect it from exploits that target these new vulnerabilities. But that was not the only good [...]]]></description> <content:encoded><![CDATA[<p>Yesterday was one of the largest <a
href="http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/">patch days</a> in Windows history, with 16 security bulletins and way of 40 different vulnerabilities patched. If you have not updated your version of Windows yet you should consider doing so immediately to protect it from exploits that target these new vulnerabilities.</p><p>But that was not the only good news yesterday concerning Microsoft and security. Lets take a closer look at some of the more interesting topics:</p><p>If you have taken a closer <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-071.mspx">look</a> at the vulnerabilities that have been patched yesterday you may have noticed that some target Microsoft&#8217;s web browser Internet Explorer. New security concepts in Internet Explorer 9, a browser that is currently available as a public beta version, have made the browser immune, which means that it was not affected by the security vulnerabilities.</p><p>That&#8217;s good news considering that Microsoft intends to release Internet Explorer 9 in the near future and that it will add to the security of the computer system.</p><p>In other news, Microsoft has added detection and removal routines for Zbot to the Malicious Software Removal Tool. Zbot is one of the largest active botnets and the ability to detect and clean Windows PCs using the free security gives users a tool at hand to effectively remove it from their computer systems. The MSRT is <a
href="http://www.microsoft.com/security/pc-security/malware-removal.aspx">available</a> for download at the official Microsoft website, and via Windows Update.</p><p>SDL Regex Fuzzer is another tool that Microsoft has created recently. The free software &#8220;will evaluate regular expression patterns to determine whether they could be vulnerable to ReDoS&#8221;. SDL Regex Fuzzer integrates with the SDL Process Template and MSF-Agile+SDL Process Template to help you track and eliminate detected vulnerabilities.</p><p>More information about SDL Regex Fuzzer is available <a
href="http://blogs.msdn.com/b/sdl/archive/2010/10/12/new-tool-sdl-regex-fuzzer.aspx">here</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/13/collection-of-recent-microsoft-security-news/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Releases Out Of Band Security Patch</title><link>http://www.ghacks.net/2010/09/28/microsoft-releases-out-of-band-security-patch/</link> <comments>http://www.ghacks.net/2010/09/28/microsoft-releases-out-of-band-security-patch/#comments</comments> <pubDate>Tue, 28 Sep 2010 20:29:10 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows server]]></category> <category><![CDATA[windows server update]]></category> <category><![CDATA[windows vulnerability]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35362</guid> <description><![CDATA[Microsoft today released a new out of band security bulletin addressing a vulnerability in ASP.NET that affects all versions of the Microsoft .Net Framework when used on Windows Server operating systems, or on client systems that run a web server from their computer. While that excludes the majority of desktop users, it may still affect [...]]]></description> <content:encoded><![CDATA[<p>Microsoft today released a new out of band security bulletin addressing a vulnerability in ASP.NET that affects all versions of the Microsoft .Net Framework when used on Windows Server operating systems, or on client systems that run a web server from their computer.</p><p>While that excludes the majority of desktop users, it may still affect some that run web servers on their desktop systems. Those users are asked to update immediately once the patch is released.</p><p>About the release: Microsoft will make the security patch available on Microsoft Download first, before it will be distributed via Windows Update.  Dave Forstrom, Director, Trustworthy Computing said it will take approximately a few days before the update is released on Windows Update and Windows Server Update as well.</p><p>For now, Windows Server users and Windows client users running a web server should <a
href="http://www.microsoft.com/downloads/en/default.aspx">monitor</a> Microsoft&#8217;s Download Center for the patch, which will be made available there later today.</p><p>Admins who want additional information can take a closer look at the Microsoft Security Bulletin, which lists the affected operating systems, the maximum security impact and additional information about the vulnerability.</p><blockquote><p>This security update resolves a publicly disclosed vulnerability in ASP.NET. The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.</p><p>This security update is rated Important for all supported editions of ASP.NET except Microsoft .NET Framework 1.0 Service Pack 3. For more information, see the subsection, Affected and Non-Affected Software, in this section.<br
/> The security update addresses the vulnerability by additionally signing all data that is encrypted by ASP.NET. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.</p></blockquote><p>Windows client users who are not running a web server are not affected by the vulnerability. Some may want to consider installing the update nevertheless.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/28/microsoft-releases-out-of-band-security-patch/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Security Updates July 2010</title><link>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/</link> <comments>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/#comments</comments> <pubDate>Tue, 13 Jul 2010 21:11:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[office updates]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=28217</guid> <description><![CDATA[Microsoft has just released four security bulletins on this months&#8217; Patch Tuesday fixing vulnerabilities in Microsoft software products. Three of the four bulletins have a maximum severity rating of critical, the highest rated, while one is rated as important. Affected software includes several Microsoft operating systems and Microsoft Office, take a look at the listing [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just released four security bulletins on this months&#8217; Patch Tuesday fixing vulnerabilities in Microsoft software products. Three of the four bulletins have a maximum severity rating of critical, the highest rated, while one is rated as important.</p><p>Affected software includes several Microsoft operating systems and Microsoft Office, take a look at the listing below for additional details on every security bulletin released today.</p><p><span
id="more-28217"></span><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-042.mspx">MS10-042</a> &#8211; Critical<br
/> Vulnerability in Help and Support Center Could Allow Remote Code Execution (2229593) &#8211; This security update resolves a publicly disclosed vulnerability in the Windows Help and Support Center feature that is delivered with supported editions of Windows XP and Windows Server 2003. This vulnerability could allow remote code execution if a user views a specially crafted Web page using a Web browser or clicks a specially crafted link in an e-mail message. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful, a user must click a link listed within an e-mail message.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-043.mspx">MS10-043</a> &#8211; Critical<br
/> Vulnerability in Canonical Display Driver Could Allow Remote Code Execution (2032276) &#8211; This security update resolves a publicly disclosed vulnerability in the Canonical Display Driver (cdd.dll). Although it is possible that the vulnerability could allow code execution, successful code execution is unlikely due to memory randomization. In most scenarios, it is much more likely that an attacker who successfully exploited this vulnerability could cause the affected system to stop responding and automatically restart.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-044.mspx">MS10-044</a> &#8211; Critical<br
/> Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office Access ActiveX Controls. The vulnerabilities could allow remote code execution if a user opened a specially crafted Office file or viewed a Web page that instantiated Access ActiveX controls. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-045.mspx">MS10-045</a> &#8211; Important<br
/> Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution (978212) &#8211; This security update resolves a privately reported vulnerability. The vulnerability could allow remote code execution if a user opened an attachment in a specially crafted e-mail message using an affected version of Microsoft Office Outlook. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights</li></ul><div
id="attachment_28218" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-security-updates.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-security-updates-500x281.png" alt="microsoft security updates" title="microsoft security updates" width="500" height="281" class="size-medium wp-image-28218" /></a><p
class="wp-caption-text">microsoft security updates</p></div><div
id="attachment_28219" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-patch-day.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/microsoft-patch-day-500x281.png" alt="microsoft patch day" title="microsoft patch day" width="500" height="281" class="size-medium wp-image-28219" /></a><p
class="wp-caption-text">microsoft patch day deployment priority</p></div><h3>Affected software:</h3><ul><li>MS10-042 &#8211; Windows XP, Windows XP Pro 64-bit, Windows Server 2003, Windows Server 2003 64-bit</li><li>MS10-043 &#8211; Windows 7 for x64-based Systems, Windows Server 2008 R2 for x64-based Systems</li><li>MS10-044 &#8211; Microsoft Office 2003 , Microsoft Office 2007</li><li>MS10-045 &#8211; Microsoft Office XP, Microsoft Office 2003,  Microsoft Office 2007</li></ul><p>All vulnerabilities allow remote code execution on compromised systems. Additional information about this months&#8217; patches are <a
href="http://blogs.technet.com/b/msrc/archive/2010/07/13/july-2010-security-bulletin-release.aspx">available</a> at the Technet blog post.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/13/microsoft-security-updates-july-2010/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Microsoft Security Updates June 2010</title><link>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/</link> <comments>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/#comments</comments> <pubDate>Tue, 08 Jun 2010 18:41:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26349</guid> <description><![CDATA[Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of 34 30 different security vulnerabilities. The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of <del
datetime="2010-06-08T20:06:40+00:00">34</del> 30 different security vulnerabilities.</p><p>The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed on computer systems without Internet connection.</p><p><span
id="more-26349"></span><div
id="attachment_26350" class="wp-caption alignnone" style="width: 509px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/06/windows_update-499x248.png" alt="windows update" title="windows update" width="499" height="248" class="size-medium wp-image-26350" /><p
class="wp-caption-text">windows update</p></div></p><p>The severity rating differs depending on the operating system and software version installed. Three security bulletins have a maximum security rating of critical, the most severe one, while the remaining seven are all rated as important.</p><p>Vulnerabilities affect various Windows operating systems from Windows 2000 to Windows 7, Microsoft Office, Internet Explorer, Microsoft Server and the Microsoft .net Framework.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx">MS10-033</a> &#8211; Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (980195) &#8211; This security update addresses two privately reported vulnerabilities for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Vista, and Windows 7, and Moderate for all supported editions of Windows Server 2003, Windows Server2008, and Windows Server 2008 R2.<p>The vulnerabilities could allow remote code execution if a user views a specially crafted Web page that instantiates a specific ActiveX control with Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> &#8211; Cumulative Security Update for Internet Explorer (982381) &#8211; This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559) &#8211;<br
/> This security update resolves two publicly disclosed vulnerabilities and one privately reported vulnerability in the Windows kernel-mode drivers. The vulnerabilities could allow elevation of privilege if a user views content rendered in a specially crafted TrueType font.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> &#8211; Vulnerability in COM Validation in Microsoft Office Could Allow Remote Code Execution (983235) &#8211; This security update resolves a privately reported vulnerability in COM validation in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel, Word, Visio, Publisher, or PowerPoint file with an affected version of Microsoft Office. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful a user must open an attachment that is sent in an e-mail message.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-037.mspx">MS10-037</a> &#8211; Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Elevation of Privilege (980218) &#8211; This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow elevation of privilege if a user views content rendered in a specially crafted CFF font. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx">MS10-038</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) &#8211; This security update resolves fourteen privately reported vulnerabilities in Microsoft Office. The more severe vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> &#8211; Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2028554) &#8211; This security update resolves one publicly disclosed and two privately reported vulnerabilities in Microsoft SharePoint. The most severe vulnerability could allow elevation of privilege if an attacker convinced a user of a targeted SharePoint site to click on a specially crafted link.</li><li>MS10-040 &#8211; Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666) &#8211; This security update resolves a privately reported vulnerability in Internet Information Services (IIS). The vulnerability could allow remote code execution if a user received a specially crafted HTTP request. An attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx">MS10-041</a> &#8211; Vulnerability in Microsoft .NET Framework Could Allow Tampering (981343) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft .NET Framework. The vulnerability could allow data tampering in signed XML content without being detected. In custom applications, the security impact depends on how the signed content is used in the specific application. Scenarios in which signed XML messages are transmitted over a secure channel (such as SSL) are not affected by this vulnerability.</li></ul><p>It is advised to install the security patches immediately to protect the PC from exploits that are targeting unpatched computer systems. Additional information are provided by the <a
href="http://blogs.technet.com/b/srd/">Security Research &#038; Defense</a> team which offers additional information that are helpful for system administrators and advanced users.</p><p>Lastly there is the <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx">security bulletin</a> overview which lists all relevant information.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates May 2010</title><link>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/</link> <comments>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/#comments</comments> <pubDate>Wed, 12 May 2010 10:35:14 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft security updates]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=25381</guid> <description><![CDATA[The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic. The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications. [...]]]></description> <content:encoded><![CDATA[<p>The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic.</p><p>The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications.</p><p>Both vulnerabilities can be exploited to execute code remotely on affected operating systems and applications.</p><p><span
id="more-25381"></span><ul><li>MS10-030 &#8211; Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-030.mspx">978542</a>) &#8211; This security update resolves a privately reported vulnerability in Outlook Express, Windows Mail, and Windows Live Mail. The vulnerability could allow remote code execution if a user visits a malicious e-mail server. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>MS10-031 &#8211; Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-031.mspx">978213</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Visual Basic for Applications. The vulnerability could allow remote code execution if a host application opens and passes a specially crafted file to the Visual Basic for Applications runtime. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>The security patches can be downloaded via Windows Update, Microsoft Update and the individual security bulletin pages.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates March 2010</title><link>http://www.ghacks.net/2010/03/10/microsoft-security-updates-march-2010/</link> <comments>http://www.ghacks.net/2010/03/10/microsoft-security-updates-march-2010/#comments</comments> <pubDate>Wed, 10 Mar 2010 09:07:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft excel]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security updates]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows secuirty]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23601</guid> <description><![CDATA[Microsoft yesterday released security patches for Windows and Office products on their monthly Patch Tuesday. A total of two security bulletins have been released by Microsoft that patch flaws in Microsoft Excel, Windows Movie Maker and Microsoft Producer 2003. The severity of both security bulletins has been rated as important. Attackers can exploit the issues [...]]]></description> <content:encoded><![CDATA[<p>Microsoft yesterday released security patches for Windows and Office products on their monthly Patch Tuesday. A total of two security bulletins have been released by Microsoft that patch flaws in Microsoft Excel, Windows Movie Maker and Microsoft Producer 2003.</p><p>The severity of both security bulletins has been rated as important. Attackers can exploit the issues for remote code execution.</p><p>The security updates are offered through the usual channels including Windows Update, Microsoft Update or directly from Microsoft websites.</p><p><span
id="more-23601"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx">MS10-016</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561) &#8211; This security update addresses a privately reported vulnerability in Windows Movie Maker and Microsoft Producer 2003. Windows Live Movie Maker, which is available for Windows Vista and Windows 7, is not affected by this vulnerability. The vulnerability could allow remote code execution if an attacker sent a specially crafted Movie Maker or Microsoft Producer project file and convinced the user to open the specially crafted file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx">MS10-017</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office Excel. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>Users who have Microsoft Excel, Microsoft Producer 2003 or Windows Movie Maker installed should install the security patches right away to protect their computer system from exploits that target those vulnerabilities.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/10/microsoft-security-updates-march-2010/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Microsoft and Adobe January 2010 Patch Day</title><link>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/</link> <comments>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/#comments</comments> <pubDate>Wed, 13 Jan 2010 16:43:46 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe update]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22289</guid> <description><![CDATA[Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service [...]]]></description> <content:encoded><![CDATA[<p>Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service Pack 4.</p><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx">MS10-001</a> &#8211; Critical  Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed content rendered in a specially crafted Embedded OpenType (EOT) font in client applications that can render EOT fonts, such as Microsoft Internet Explorer, Microsoft Office PowerPoint, or Microsoft Office Word. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs, view, change, or delete data, or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<p>This security update is rated Critical for Microsoft Windows 2000, and is rated Low for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.</li></ul><p><span
id="more-22289"></span>Adobe <a
href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">has</a> released security updates for Adobe Reader and Adobe Acrobat which patch critical vulnerability in Adobe Reader 9.2 and Adobe Acrobat 9.2 for Windows, Macintosh and Unix as well as Adobe Reader 8.1.7 and Acrobat 8.1.7 for Windows and Macintosh.</p><ul><li>These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. Adobe recommends users of Adobe Reader 9.2 and Acrobat 9.2 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3 and Acrobat 9.3. Adobe recommends users of Acrobat 8.1.7 and earlier versions for Windows and Macintosh update to Acrobat 8.2. For Adobe Reader users on Windows and Macintosh who cannot update to Adobe Reader 9.3, Adobe has provided the Adobe Reader 8.2 update. Updates apply to all platforms: Windows, Macintosh and UNIX.</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Updates December 2009</title><link>http://www.ghacks.net/2009/12/09/microsoft-security-updates-december-2009/</link> <comments>http://www.ghacks.net/2009/12/09/microsoft-security-updates-december-2009/#comments</comments> <pubDate>Wed, 09 Dec 2009 09:58:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21203</guid> <description><![CDATA[Microsoft has released a new batch of security updates on this month&#8217;s Patch Tuesday which patch various security vulnerabilities in Microsoft software products. The vulnerabilities are affecting several popular Microsoft products including various Windows operating systems, Microsoft Internet Explorer and Microsoft Office. Three of the vulnerabilities have a maximum severity rating of critical while the [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released a new batch of security updates on this month&#8217;s Patch Tuesday which patch various security vulnerabilities in Microsoft software products. The vulnerabilities are affecting several popular Microsoft products including various Windows operating systems, Microsoft Internet Explorer and Microsoft Office.</p><p>Three of the vulnerabilities have a maximum severity rating of critical while the other three are rated as important. The vulnerability impact is either a remote code execution or denial of service attack. It is recommended to patch computer systems and programs that are affected by these vulnerabilities as soon as possible to prevent attacks that are making use of these vulnerabilities.</p><p><span
id="more-21203"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-071.mspx">MS09-071</a> &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if messages received by the Internet Authentication Service server are copied incorrectly into memory when handling PEAP authentication attempts. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. Servers using Internet Authentication Service are only affected when using PEAP with MS-CHAP v2 authentication.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx">MS09-074</a> &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Project. The vulnerability could allow remote code execution if a user opens a specially crafted Project file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-072.mspx">MS09-072</a> &#8211; Cumulative Security Update for Internet Explorer (976325) &#8211; This security update resolves four privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. An ActiveX control built with Microsoft Active Template Library (ATL) headers could also allow remote code execution; this vulnerability has been described in Microsoft Security Advisory 973882 and Microsoft Security Bulletin MS09-035.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-069.mspx">MS09-069</a> &#8211; Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow a denial of service if a remote, authenticated attacker, while communicating through Internet Protocol security (IPsec), sends a specially crafted ISAKMP message to the Local Security Authority Subsystem Service (LSASS) on an affected system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-070.mspx">MS09-070</a> &#8211; Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow remote code execution if an attacker sent a specially crafted HTTP request to an ADFS-enabled Web server. An attacker would need to be an authenticated user in order to exploit either of these vulnerabilities.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-073.mspx">MS09-073</a> &#8211; Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) &#8211; This security update resolves a privately reported vulnerability in Microsoft WordPad and Microsoft Office text converters. The vulnerability could allow remote code execution if a specially crafted Word 97 file is opened in WordPad or Microsoft Office Word. An attacker who successfully exploited this vulnerability could gain the same privileges as the user. Users whose accounts are configured to have fewer privileges on the system could be less impacted than users who operate with administrative privileges.</li></ul><p>Patches can be downloaded from the usual sources including Automatic Update, Windows Update, Microsoft Update or by following the links of individual vulnerabilities above.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/09/microsoft-security-updates-december-2009/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>New Security Vulnerability Affects Windows Operating Systems</title><link>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/</link> <comments>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/#comments</comments> <pubDate>Wed, 09 Sep 2009 20:18:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[operating system]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=16177</guid> <description><![CDATA[Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are [...]]]></description> <content:encoded><![CDATA[<p>Microsoft yesterday released a security advisory that described a new security vulnerability affecting several Microsoft operating systems. The article, which was posted only a few hours after the release of security patches for this month&#8217;s patch-day affects the Microsoft Server Message Block (SMB) implementation. The operating systems that are affected by the new vulnerability are Windows Vista, Windows Server 2008 and the Windows 7 Release Candidate.</p><p>Operating systems that are not affected include Windows XP, Windows 7 final and Windows Server 2003. No patch is currently available to fix the vulnerability. Microsoft has published workarounds to protect the operating system from possible attacks.</p><p><span
id="more-16177"></span></p><blockquote><p>Disable SMB v2</p><p>To modify the registry key, perform the following steps:</p><p>Note Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the &#8220;Changing Keys And Values&#8221; Help topic in Registry Editor (Regedit.exe) or view the &#8220;Add and Delete Information in the Registry&#8221; and &#8220;Edit Registry Data&#8221; Help topics in Regedt32.exe.</p><p>1. Click Start, click Run, type Regedit in the Open box, and then click OK.<br
/> 2. Locate and then click the following registry subkey:<br
/> HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services<br
/> 3. Click LanmanServer.<br
/> 4. Click Parameters.<br
/> 5. Right-click to add a new DWORD (32 bit) Value.<br
/> 6. Enter smb2 in the Name data field, and change the Value data field to 0.<br
/> 7. Exit.<br
/> 8. Restart the &#8220;Server&#8221; service by performing one of the following:<br
/> - Open up the computer management MMC, navigate to Services and Applications, click Services, right-click the Server service name and click Restart. Answer Yes in the pop-up menu.<br
/> - From a command prompt and with administrator privileges, type net stop server and then net start server.</p><p>Impact of workaround. Host will not be able to communicate using SMB2.</p></blockquote><blockquote><p>Block TCP ports 139 and 445 at the firewall</p><p>These ports are used to initiate a connection with the affected component. Blocking TCP ports 139 and 445 at the firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability. Microsoft recommends that you block all unsolicited inbound communication from the Internet to help prevent attacks that may use other ports. For more information about ports, see TCP and UDP Port Assignments.</p><p>Impact of Workaround: Several Windows services use the affected ports. Blocking connectivity to the ports may cause various applications or services to not function. Some of the applications or services that could be impacted are listed below:</p><p>• Applications that use SMB (CIFS)<br
/> • Applications that use mailslots or named pipes (RPC over SMB)<br
/> • Server (File and Print Sharing)<br
/> • Group Policy<br
/> • Net Logon<br
/> • Distributed File System (DFS)<br
/> • Terminal Server Licensing<br
/> • Print Spooler<br
/> • Computer Browser<br
/> • Remote Procedure Call Locator<br
/> • Fax Service<br
/> • Indexing Service<br
/> • Performance Logs and Alerts<br
/> • Systems Management Server<br
/> • License Logging Service</p></blockquote><p>Users that are running one of the operating systems that are affected by the vulnerability are encouraged to use one of the workarounds to protect their computer systems. More information are available at the Microsoft Security Advisory <a
href="http://www.microsoft.com/technet/security/advisory/975497.mspx">page</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/09/09/new-security-vulnerability-affects-windows-operating-systems/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Patches July 2009</title><link>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/</link> <comments>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/#comments</comments> <pubDate>Wed, 15 Jul 2009 11:49:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14410</guid> <description><![CDATA[Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are pretty much all from Windows 2000 onwards although the severity rating varies depending on the operating system.</p><p>Critical ratings for Windows XP or Windows Server 2003 are usually important or moderate ratings for Windows Vista or Windows Server 2008 thanks to the increased security in those operating systems. Downloads are already available from various official sources including Automatic Updates, Windows Update or Microsoft Update.</p><p><span
id="more-14410"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx">MS09-028</a> &#8211; Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371) &#8211; This security update resolves two privately reported vulnerabilities in the Microsoft Windows component, Embedded OpenType (EOT) Font Engine. The vulnerabilities could allow remote code execution. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-029.mspx">MS09-029</a> &#8211; Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) &#8211; This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx">MS09-030</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (973346) &#8211; This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability in Microsoft Video ActiveX Control could allow remote code execution if a user views a specially crafted Web page with Internet Explorer, instantiating the ActiveX control. This ActiveX control was never intended to be instantiated in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-031.mspx">MS09-031</a> &#8211; Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856) &#8211; This security update resolves a privately reported vulnerability in Microsoft Virtual PC and Microsoft Virtual Server. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected guest operating system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032</a> -Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953) &#8211; This security update resolves a privately reported vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2006. The vulnerability could allow elevation of privilege if an attacker successfully impersonates an administrative user account for an ISA server that is configured for Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-033.mspx">MS09-033</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>It is recommended to install the Microsoft Security Patches as soon as possible to close the security vulnerabilities.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Patches for June 2009</title><link>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</link> <comments>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/#comments</comments> <pubDate>Tue, 09 Jun 2009 22:45:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[office patches]]></category> <category><![CDATA[office update]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</guid> <description><![CDATA[Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office. The easiest way to download [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office.</p><p>The easiest way to download and install the patches is by pointing the Internet Explorer web browser to <a
href="http://update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&#038;&#038;thankspage=5">Microsoft Update</a> which will automatically detect and install the available patches for the computer system. Other possibilities include downloading the security patches from <a
href="http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&#038;freetext=security%20update">Microsoft Download Center</a> from where they are available as well.</p><p><span
id="more-13419"></span>Six vulnerabilities have been rated as critical, three as important and one as moderate. Critical security vulnerabilities can usually be exploited for remote code execution meaning it is essential to fix these vulnerabilities quickly. You can follow the links below for additional information about each vulnerability.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx">MS09-018</a> &#8211; Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx">MS09-019</a> &#8211; Cumulative Security Update for Internet Explorer (969897)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx">MS09-020</a> &#8211; Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-021.mspx">MS09-021</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx">MS09-022</a> &#8211; Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx">MS09-023</a> &#8211; Vulnerability in Windows Search Could Allow Information Disclosure (963093)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-024.mspx">MS09-024</a> &#8211; Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx">MS09-025</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx">MS09-026</a> &#8211; Vulnerability in RPC Could Allow Elevation of Privilege (970238)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx">MS09-027</a> &#8211; Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/feed/</wfw:commentRss> <slash:comments>12</slash:comments> </item> <item><title>Microsoft Patch Day March 2009</title><link>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/</link> <comments>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/#comments</comments> <pubDate>Tue, 10 Mar 2009 17:26:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[remote code execution]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[spoofing]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerabilities]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=11081</guid> <description><![CDATA[Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including [...]]]></description> <content:encoded><![CDATA[<p>Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including Windows 2000. This means the popular operating systems Windows XP and Vista are affected as well as Windows Server 2003 and 2008.</p><p>One security vulnerability has a critical rating for all affected operating systems while the other two are rated important by Microsoft&#8217;s security research team.</p><p>Details about the Security Bulletins can be found by following these links: Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-006.mspx">MS09-006</a>, <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-007.mspx">MS09-007</a> or <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-008.mspx">MS09-008</a>. Another possibility is to <a
href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx">access</a> the Security Bulletin Summary at Microsoft Technet.</p><p>The vulnerabilities fix one remote code execution vulnerability and two spoofing vulnerabilities on the affected Windows operating systems:</p><ul><li>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</li><li>Vulnerability in SChannel Could Allow Spoofing</li><li>Vulnerabilities in DNS and WINS Server Could Allow Spoofing</li></ul><p><span
id="more-11081"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft February Security Updates</title><link>http://www.ghacks.net/2009/02/11/microsoft-february-security-updates/</link> <comments>http://www.ghacks.net/2009/02/11/microsoft-february-security-updates/#comments</comments> <pubDate>Wed, 11 Feb 2009 07:18:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[ie]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[ie security updates]]></category> <category><![CDATA[internet explorer 7]]></category> <category><![CDATA[internet explorer 8]]></category> <category><![CDATA[internet explorer security]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft exchange]]></category> <category><![CDATA[microsoft office visio]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft sql server]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=10470</guid> <description><![CDATA[Microsoft has released a cumulative security update for Internet Explorer 7 and 8 that fixes several critical vulnerabilities in the web browser. It is recommended to update Internet Explorer as soon as possible to fix those vulnerabilities. The vulnerabilities are rated critical for Internet Explorer versions running under Windows XP or Windows Vista and moderate [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has <a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx">released</a> a cumulative security update for Internet Explorer 7 and 8 that fixes several critical vulnerabilities in the web browser. It is recommended to update Internet Explorer as soon as possible to fix those vulnerabilities. The vulnerabilities are rated critical for Internet Explorer versions running under Windows XP or Windows Vista and moderate for Windows Server 2003 and Windows Server 2008. The article is mentioning downloads for Internet Explorer 8 beta but the linked article is not containing any. This seems to suggest that Internet Explorer 8 is affected by the vulnerability as well. This probably only affects pre release candidate builds of Internet Explorer 8.</p><p>The security update fixes the following two vulnerabilities: Uninitialized Memory Corruption Vulnerability and CSS Memory Corruption Vulnerability. Since it is a cumulative update it does apply all previous security updates for Internet Explorer on the computer system.</p><p>The easiest way to update affected systems is to use Microsoft Update which will download and apply the security updates automatically. The other possibility is to <a
href="Http://www.microsoft.com/download/en/default.aspx">download</a> the patch from Microsoft Download and apply it manually.</p><p><span
id="more-10470"></span>Microsoft has released three additional security bulletins:</p><ul><li>Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS09-003.mspx">959239</a>)</li><li>Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms09-004.mspx">959420</a>)</li><li>Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS09-005.mspx">957634</a>)</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/02/11/microsoft-february-security-updates/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Patch Tuesday November 08</title><link>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/</link> <comments>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/#comments</comments> <pubDate>Wed, 12 Nov 2008 13:55:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8233</guid> <description><![CDATA[Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins MS08-069 and MS08-068 patched two vulnerability with the status critical and important. The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069</a> and <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">MS08-068</a> patched two vulnerability with the status critical and important.</p><p>The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code execution in Microsoft Server Message Block (SMB) Protocol.</p><p>Both security vulnerabilities can be fixed by using Windows Update or by downloading the security updates directly from the Microsoft Download website by following the two links given above in this article.</p><p><span
id="more-8233"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Melissa Strip Captcha Breaker Trojan</title><link>http://www.ghacks.net/2007/12/07/melissa-strip-captcha-breaker-trojan/</link> <comments>http://www.ghacks.net/2007/12/07/melissa-strip-captcha-breaker-trojan/#comments</comments> <pubDate>Fri, 07 Dec 2007 13:00:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Spyware]]></category> <category><![CDATA[captcha]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[trojan]]></category> <category><![CDATA[virus]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/12/07/melissa-strip-captcha-breaker-trojan/</guid> <description><![CDATA[I bet you have never seen such a tempting Trojan before. The Trojan named Melissa Strip, identified as TROJ_CAPTCHAR.A by TrendMicro and Trj/RompeCaptchas.A by Panda, starts by asking the user if he wants to play a game where she (Melissa) will strip for the user if the enters the correct code. ]]></description> <content:encoded><![CDATA[<p>I bet you have never seen such a tempting Trojan before. The Trojan named Melissa Strip, identified as TROJ_CAPTCHAR.A by TrendMicro and Trj/RompeCaptchas.A by Panda, starts by asking the user if he wants to play a game where she (Melissa) will strip for the user if the enters the correct code.</p><p>After clicking Start Play the image of a women on the left side and a captcha on the right is displayed. The program asks the user to enter the captcha to see another picture of the woman with less clothes on. After entering the captcha correctly and clicking on enter the Trojan loads another picture and captcha asking the user again to type the correct code to see Melissa strip even more.</p><p>You might have already guessed that the captcha is actually the captcha of another website, Yahoo for instance, and the Trojan uses the help of users to enter those captchas correctly on those websites. Captchas are used to tell human users from bots apart and make it more difficulty to create automatic process to signup or submit data.</p><p><span
id="more-2448"></span><img
src='http://www.ghacks.net/wp-content/uploads/2007/12/melissa1.jpg' alt='melissa strip 1' /></p><p>The Trojan does not seem to cause harm on the users system. It simply uses him to create correct responses to captcha codes that are used to create accounts on websites like Yahoo Mail.</p><p><img
src='http://www.ghacks.net/wp-content/uploads/2007/12/melissa2.jpg' alt='melissa strip 2' /></p><p>Trend Micro reports that the Trojan most likely arrives as a file downloaded by other malware on the system. It could also be send as an email attachement.</p><p><img
src='http://www.ghacks.net/wp-content/uploads/2007/12/melissa3.jpg' alt='melissa strip 3' /></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/12/07/melissa-strip-captcha-breaker-trojan/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Auto logon into Windows</title><link>http://www.ghacks.net/2007/12/04/auto-logon-into-windows/</link> <comments>http://www.ghacks.net/2007/12/04/auto-logon-into-windows/#comments</comments> <pubDate>Tue, 04 Dec 2007 15:51:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[windows tips]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/12/04/auto-logon-into-windows/</guid> <description><![CDATA[Auto logon should not be configured if more than one user is working with a computer or if the computer is part of a local area network. A PC that is only used by one user could be configured to automatically log that user in when he boots his computer. I have auto logon enabled in Windows XP and really enjoy the faster boot speed.]]></description> <content:encoded><![CDATA[<p>Auto logon should not be configured if more than one user is working with a computer or if the computer is part of a local area network. A PC that is only used by one user could be configured to automatically log that user in when he boots his computer. I have auto logon enabled in Windows XP and really enjoy the faster boot speed.</p><p>There is however a discrepancy among users on how to enable automatic logons in Windows XP. If you search for this on the Internet you will find the advice to configure it directly in the Registry. This works fine but has the disadvantage that the password of the user is stored in clear text.</p><p>While this is not really that problematic if you are the single user of the computer it still poses a greater security risk than storing the auto logon password unencrypted. Since it is not difficulty to store the encrypted password you should always use this way to store it.</p><p><span
id="more-2394"></span><a
href="http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx">Tweak UI</a> for Windows XP offers an auto logon function that makes it possible to enable auto logon in Windows XP and store the password that has to be saved in encrypted form.</p><p><img
src='http://www.ghacks.net/wp-content/uploads/2007/12/auto-logon-windows-xp.jpg' alt='auto logon windows xp' /></p><p>Another way would be to simply change the password of that user account to one that does not reveal any information about the user and that also is not similar to passwords normally used by the user. I do prefer the Tweak UI solution though.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/12/04/auto-logon-into-windows/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> </channel> </rss>
