<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; office security</title>
	<atom:link href="http://www.ghacks.net/tag/office-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 10 Nov 2009 01:33:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Security Updates August 2009</title>
		<link>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/</link>
		<comments>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 10:09:08 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security bulletin]]></category>
		<category><![CDATA[microsoft security updates]]></category>
		<category><![CDATA[microsoft updates]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows updates]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=15276</guid>
		<description><![CDATA[Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A summary of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released its monthly set of security patches yesterday which patch several security vulnerabilities in Microsoft software programs including Microsoft operating systems and Microsoft Office. A <a href="http://www.microsoft.com/technet/security/Bulletin/ms09-aug.mspx">summary</a> of the patches can be accessed at the Microsoft website which lists nine security bulletins. Of these nine security bulletins five are rated critical and four important. Users who operate Microsoft operating systems or Microsoft products should install the security patches as soon as possible to protect their system from possible exploits.</p>
<p>Affected operating systems include Windows Vista, Windows XP, Windows Server 2003 and 2008, Windows 2000 but not <a href="http://windows7news.com/">Windows 7</a>. Downloads are available from the usual locations including automatic updates, Windows Update, Microsoft Update or by following the links in the security bulletins below.</p>
<p><span id="more-15276"></span>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=128110">MS09-043</a> Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)
<p>This security update resolves several privately reported vulnerabilities in Microsoft Office Web Components that could allow remote code execution if a user viewed a specially crafted Web page. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=157861">MS09-044</a> Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)
<p>This security update resolves two privately reported vulnerabilities in Microsoft Remote Desktop Connection. The vulnerabilities could allow remote code execution if an attacker successfully convinced a user of Terminal Services to connect to a malicious RDP server or if a user visits a specially crafted Web site that exploits this vulnerability. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155974">MS09-039</a> Vulnerabilities in WINS Could Allow Remote Code Execution (969883)
<p>This security update resolves two privately reported vulnerabilities in the Windows Internet Name Service (WINS). Either vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system version. Only customers who manually install this component are affected by this issue.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155975">MS09-038</a> &#8211; Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)
<p>This security update resolves two privately reported vulnerabilities in Windows Media file processing. Either vulnerability could allow remote code execution if a user opened a specially crafted AVI file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=158695">MS09-037</a> Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)
<p>This security update resolves several privately reported vulnerabilities in Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155977">MS09-041</a> Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)
<p>This security update resolves a privately reported vulnerability in the Windows Workstation Service. The vulnerability could allow elevation of privilege if an attacker created a specially crafted RPC message and sent the message to an affected system. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to a vulnerable system in order to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=155979">MS09-040</a> Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)
<p>This security update resolves a privately reported vulnerability in the Windows Message Queuing Service (MSMQ). The vulnerability could allow elevation of privilege if a user received a specially crafted request to an affected MSMQ service. By default, the Message Queuing component is not installed on any affected operating system edition and can only be enabled by a user with administrative privileges. Only customers who manually install the Message Queuing component are likely to be vulnerable to this issue.</p>
</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=157296">MS09-036</a> Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)
<p>This security update addresses a privately reported Denial of Service vulnerability in the Microsoft .NET Framework component of Microsoft Windows. This vulnerability can be exploited only when Internet Information Services (IIS) 7.0 is installed and ASP.NET is configured to use integrated mode on affected versions of Microsoft Windows. An attacker could create specially crafted anonymous HTTP requests that could cause the affected Web server to become non-responsive until the associated application pool is restarted. Customers who are running IIS 7.0 application pools in classic mode are not affected by this vulnerability.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=157140">MS09-042</a> Vulnerability in Telnet Could Allow Remote Code Execution (960859)
<p>This security update resolves a publicly disclosed vulnerability in the Microsoft Telnet service. The vulnerability could allow an attacker to obtain credentials and then use them to log back into affected systems. The attacker would then acquire user rights on a system identical to the user rights of the logged-on user. This scenario could ultimately result in remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with </li>
</ul>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security-bulletin/" title="microsoft security bulletin" rel="tag">microsoft security bulletin</a>, <a href="http://www.ghacks.net/tag/microsoft-security-updates/" title="microsoft security updates" rel="tag">microsoft security updates</a>, <a href="http://www.ghacks.net/tag/microsoft-updates/" title="microsoft updates" rel="tag">microsoft updates</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-updates/" title="windows updates" rel="tag">windows updates</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/12/stop-restart-now-restart-later-dialog-after-windows-updates/" title="Stop Restart Now Restart Later Dialog After Windows Updates (August 12, 2009)">Stop Restart Now Restart Later Dialog After Windows Updates</a> (8)</li>
	<li><a href="http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/" title="Microsoft Security Updates October 2009 Online (October 13, 2009)">Microsoft Security Updates October 2009 Online</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/" title="Microsoft Patch Day March 2009 (March 10, 2009)">Microsoft Patch Day March 2009</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/08/12/microsoft-security-updates-august-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Updates April 2009</title>
		<link>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/</link>
		<comments>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 11:25:15 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[microsoft update]]></category>
		<category><![CDATA[microsoft-office]]></category>
		<category><![CDATA[microsoft-windows]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[office updates]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/</guid>
		<description><![CDATA[Microsoft releases security bulletins once a month that outline new security updates and patches for Microsoft products. The security updates for April 2009 list a total of eight vulnerabilities for various Microsoft applications including Microsoft Windows and Microsoft Office. Six of the eight patches affect various Microsoft operating systems. Windows XP and Windows Server 2003 [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft releases security bulletins once a month that outline new security updates and patches for Microsoft products. The security updates for April 2009 list a total of eight vulnerabilities for various Microsoft applications including Microsoft Windows and Microsoft Office. Six of the eight patches affect various Microsoft operating systems. Windows XP and Windows Server 2003 face three critical, two important and one moderate security vulnerability while Windows Vista and Windows Server 2008 bring it to two critical, one important and one moderate vulnerability. Below is a list of links that point to all eight Microsoft Security Bulletins. These bulletins contain extensive information about the vulnerabilities including the systems affected.</p>
<p><span id="more-12027"></span>
<ul>
<li>Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-009.mspx">968557</a>)</li>
<li>Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-010.mspx">960477</a>)</li>
<li>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/Bulletin/ms09-011.mspx">961373</a>)</li>
<li>Vulnerabilities in Windows Could Allow Elevation of Privilege (<a href="http://www.microsoft.com/technet/security/Bulletin/ms09-012.mspx">959454</a>)</li>
<li>Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-013.mspx">960803</a>)</li>
<li>Cumulative Security Update for <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> (<a href="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx">963027</a>)</li>
<li>Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (<a href="http://www.microsoft.com/technet/security/Bulletin/MS09-015.mspx">959426</a>)</li>
<li>Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (<a href="http://www.microsoft.com/technet/security/bulletin/MS09-016.mspx">961759</a>)</li>
</ul>
<p>The easiest way to update is by visiting Windows Update or Microsoft Update. Please read our <a href="http://www.ghacks.net/2009/04/13/windows-update-fix/">Windows Update Fix</a> article if Windows Update is not working properly on your computer system. Alternatives are so called offline updates like <a href="http://www.ghacks.net/2008/01/21/update-windows-with-offline-update/">Offline Update</a>, <a href="http://www.ghacks.net/2007/08/20/autopatcher-august-2007-released/">Autopatcher</a> or <a href="http://www.ghacks.net/2007/02/11/update-windows-without-microsoft/">Update Windows Without Microsoft</a>.</p>
<p>It is recommended to update the computer system as soon as possible to close the vulnerabilities.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-update/" title="microsoft update" rel="tag">microsoft update</a>, <a href="http://www.ghacks.net/tag/microsoft-office/" title="microsoft-office" rel="tag">microsoft-office</a>, <a href="http://www.ghacks.net/tag/microsoft-windows/" title="microsoft-windows" rel="tag">microsoft-windows</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/office-updates/" title="office updates" rel="tag">office updates</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/security-updates/" title="security updates" rel="tag">security updates</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/" title="Windows Security Updates September 2008 (September 10, 2008)">Windows Security Updates September 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/" title="Microsoft August 2008 Security Updates (August 13, 2008)">Microsoft August 2008 Security Updates</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/01/14/january-2009-microsoft-security-bulletin/" title="January 2009 Microsoft Security Bulletin (January 14, 2009)">January 2009 Microsoft Security Bulletin</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/05/windows-vista-service-pack-2-rc-download/" title="Windows Vista Service Pack 2 RC Download (March 5, 2009)">Windows Vista Service Pack 2 RC Download</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</title>
		<link>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 08:38:16 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7632</guid>
		<description><![CDATA[It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not [...]]]></description>
			<content:encoded><![CDATA[<p>It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not releasing them because they release them in one package on one day.</p>
<p>Microsoft released a batch of eleven security patches for various operating systems and products yesterday which are available by visiting Windows Update or Microsoft Technet which contains in depths information about the affected products and the security vulnerabilities.</p>
<p>The patches fix four critical, six important and 1 moderate security vulnerability:</p>
<p><span id="more-7632"></span>	</p>
<ul>
<li>Vulnerability in Active Directory Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128125">957280</a>)</li>
<li>Cumulative Security Update for <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> (<a href="http://go.microsoft.com/fwlink/?LinkID=128060">956390</a>)</li>
<li>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=125712">956695</a>)</li>
<li>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=124653">956416</a>)</li>
</ul>
<ul>
<li>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=125709">956803</a>)</li>
<li>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=121738">954211</a>)</li>
<li>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=120829">953155</a>)</li>
<li>Vulnerability in SMB Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=127994">957095</a>)</li>
<li>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=128103">956841</a>)</li>
<li>Vulnerability in Message Queuing Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128102">951071</a>)</li>
</ul>
<ul>
<li>Vulnerability in Microsoft Office Could Allow Information Disclosure (<a href="http://go.microsoft.com/fwlink/?LinkId=128145">957699</a>)</li>
</ul>
<p>It is highly recommended to update the products as soon as possible to protect the system from this attacks.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/office/" title="office" rel="tag">office</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/patch-day/" title="patch day" rel="tag">patch day</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/11/29/watch-three-webcasts-get-vista-and-office-for-free/" title="Watch three webcasts get vista and office for free (November 29, 2006)">Watch three webcasts get vista and office for free</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
