<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; patch day</title> <atom:link href="http://www.ghacks.net/tag/patch-day/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Patch Day November 2011 Overview</title><link>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/</link> <comments>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/#comments</comments> <pubDate>Tue, 08 Nov 2011 18:42:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52475</guid> <description><![CDATA[Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating. In this case, [...]]]></description> <content:encoded><![CDATA[<p>Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating.</p><p>In this case, the critical rating applies to all operating systems that Microsoft supplies with security patches. This includes the client operating systems Windows XP, Vista and Windows 7 as well as the server operating systems Windows Server 2008 and 2008 R2.</p><p>Here are two graphs visualizing the severity and exploitability index and the bulletin deployment priority.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment-600x337.png" alt="november2011 bulletin deployment" title="november2011 bulletin deployment" width="600" height="337" class="alignnone size-medium wp-image-52476" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity-600x337.png" alt="november2011 severity" title="november2011 severity" width="600" height="337" class="alignnone size-medium wp-image-52477" /></a></p><p>Here is the list of security bulletins released in November 2011 by Microsoft.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-083">MS11-083</a> &#8211; Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-085">MS11-085</a> &#8211; Vulnerability in Windows Mail and Windows Meeting Space Could Allow Remote Code Execution (2620704) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .eml or .wcinv file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Mail or Windows Meeting Space could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .eml or .wcinv file) from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-086">MS11-086</a> &#8211; Vulnerability in Active Directory Could Allow Elevation of Privilege (2630837) &#8211; This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow elevation of privilege if Active Directory is configured to use LDAP over SSL (LDAPS) and an attacker acquires a revoked certificate that is associated with a valid domain account and then uses that revoked certificate to authenticate to the Active Directory domain. By default, Active Directory is not configured to use LDAP over SSL.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-084">MS11-084</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Denial of Service (2617657) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user opens a specially crafted TrueType font file as an e-mail attachment or navigates to a network share or WebDAV location containing a specially crafted TrueType font file. For an attack to be successful, a user must visit the untrusted remote file system location or WebDAV share containing the specially crafted TrueType font file, or open the file as an e-mail attachment. In all cases, however, an attacker would have no way to force users to perform these actions. Instead, an attacker would have to persuade users to do so, typically by getting them to click a link in an e-mail message or Instant Messenger message.</li></ul><p>Microsoft has published a video in which Jerry Bryant discusses this month&#8217;s bulletins (Silverlight required).</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><p>Additional information about this month's security bulletins are available on the Technet Blog <a
href="http://blogs.technet.com/b/msrc/">page</a> and the Microsoft Security bulletin <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-nov">Summary</a> for November 2011.</p><p>The updates are already available on Windows Update. Users who have started their computer earlier today may need to run a manual update check in Windows Update.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg" alt="windows updates" title="windows updates" width="567" height="275" class="alignnone size-full wp-image-52478" /></a></p><p>The updates will also be available <a
href="http://www.microsoft.com/download/en/default.aspx">shortly</a> at Microsoft's Download center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/feed/</wfw:commentRss> <slash:comments>3</slash:comments> <enclosure
url="http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft Patch Day October 2011 Overview</title><link>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/</link> <comments>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/#comments</comments> <pubDate>Tue, 11 Oct 2011 17:32:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=51391</guid> <description><![CDATA[Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest [...]]]></description> <content:encoded><![CDATA[<p>Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest possible severity rating critical, the remaining six one of important. Maximum severity means that there is at least one product affected by that vulnerability impact.</p><p>You find information about each security bulletin below. Please follow the links for information about affected operating systems and Microsoft applications. You find a summary of all security bulletins <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-oct">here</a>.</p><p>Here are the Bulletin Deployment Priority and Severity and Exploitability Index screenshots for October 2011:</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011-600x337.jpg" alt="bulletin deployment priority october 2011" title="bulletin deployment priority october 2011" width="600" height="337" class="alignnone size-medium wp-image-51408" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011-600x337.png" alt="severity exploitability index october 2011" title="severity exploitability index october 2011" width="600" height="337" class="alignnone size-medium wp-image-51409" /></a></p><p>And a video in which Jerry Bryant discusses this month&#8217;s bulletins:</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-078">MS11-078</a> - Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930) -<br
/> This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-081">MS11-081</a> - Cumulative Security Update for Internet Explorer (2586448) - This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-075">MS11-075</a> - Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699) - This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, the Microsoft Active Accessibility component could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-076">MS11-076</a> - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926) - This security update resolves a publicly disclosed vulnerability in Windows Media Center. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Media Center could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-077">MS11-077</a> - Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053) - This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment. For a remote attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the specially crafted font file, or open the file as an e-mail attachment.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-079">MS11-079</a> - Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641) - This security update resolves five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-080">MS11-080</a> - Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-082">MS11-082</a> - Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670) - This security update resolves two publicly disclosed vulnerabilities in Host Integration Server. The vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the Host Integration Server ports should be blocked from the Internet.</li><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg" alt="windows updates" title="windows updates" width="579" height="382" class="alignnone size-full wp-image-51405" /></a></p><p>Windows users can update their operating system by installing the security patches via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> or <a
href="http://www.microsoft.com/download/en/default.aspx">Microsoft's</a> Download Center with Windows Update being the better option if the patches do not have to be installed on multiple computer systems.</p><p>Updates are already live and available via Windows Update. Additional information are <a
href="http://blogs.technet.com/b/msrc/">available at</a> Microsoft's Security Response Center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/feed/</wfw:commentRss> <slash:comments>4</slash:comments> <enclosure
url="http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft Patch Day August 2011 Overview</title><link>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/</link> <comments>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/#comments</comments> <pubDate>Wed, 10 Aug 2011 06:47:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=48837</guid> <description><![CDATA[Microsoft yesterday evening released this month&#8217;s security patches for their software products. The 13 security bulletins fix security related issues in Microsoft products such as the Windows operating system, Microsoft Office, the .Net Framework and Internet Explorer. Two of the security bulletins have received a critical severity rating, the highest possible rating while nine have [...]]]></description> <content:encoded><![CDATA[<p>Microsoft yesterday evening released this month&#8217;s security patches for their software products. The 13 security bulletins fix security related issues in Microsoft products such as the Windows operating system, Microsoft Office, the .Net Framework and Internet Explorer. Two of the security bulletins have received a critical severity rating, the highest possible rating while nine have received an important rating and two a moderate one. Please note that this is the maximum severity rating, the rating may be lower for specific products.</p><p>All in all, the bulletins address 22 vulnerabilities in Microsoft products. The two critical updates address issues in Internet Explorer and DNS Server.</p><p>Microsoft has <a
href="http://blogs.technet.com/b/msrc/">released</a> deployment priorities and the severity and exploitability index. (click on the images for full size)</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/bulletin-deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/bulletin-deployment-priority-600x337.png" alt="bulletin-deployment-priority" title="bulletin-deployment-priority" width="600" height="337" class="alignnone size-medium wp-image-48839" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/severity-exploitability-index-600x337.png" alt="severity-exploitability-index" title="severity-exploitability-index" width="600" height="337" class="alignnone size-medium wp-image-48840" /></a></p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx">MS11-057</a> &#8211; Cumulative Security Update for Internet Explorer (2559049) &#8211; This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-058.mspx">MS11-058</a> &#8211; Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485) &#8211; This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker registers a domain, creates an NAPTR DNS resource record, and then sends a specially crafted NAPTR query to the target DNS server. Servers that do not have the DNS role enabled are not at risk.</li></ul><p>The bulletins that fix important issues.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-059.mspx">MS11-059</a> &#8211; Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate Excel file (such as a .xlsx file) that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-060.mspx">MS11-060</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-061.mspx">MS11-061</a> &#8211; Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250) &#8211; This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 prevents this attack for its users when browsing to a Remote Desktop Web Access server in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 is not enabled by default in the Intranet Zone.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-062.mspx">MS11-062</a> &#8211; Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454) &#8211;<br
/> This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.</p><p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability and take complete control over the affected system. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-063.mspx">MS11-063</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680) &#8211;<br
/> This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-064.mspx">MS11-064</a> &#8211; Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow denial of service if an attacker sends a sequence of specially crafted Internet Control Message Protocol (ICMP) messages to a target system or sends a specially crafted URL request to a server that is serving Web content and has the URL-based Quality of Service (QoS) feature enabled.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-065.mspx">MS11-065</a> &#8211; Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222) &#8211; This security update resolves a privately reported vulnerability in the Remote Desktop Protocol. The vulnerability could allow denial of service if an affected system received a sequence of specially crafted RDP packets. Microsoft has also received reports of limited, targeted attacks attempting to exploit this vulnerability. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-066.mspx">MS11-066</a> &#8211; Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943) &#8211; This security update resolves a privately reported vulnerability in ASP.NET Chart controls. The vulnerability could allow information disclosure if an attacker sent a specially crafted GET request to an affected server hosting the Chart controls. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker&#8217;s user rights directly, but it could be used to retrieve information that could be used to further compromise the affected system. Only web applications using Microsoft Chart Control are affected by this issue. Default installations of the .NET Framework are not affected.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-067.mspx">MS11-067</a> &#8211; Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230) &#8211; This security update resolves a privately reported vulnerability in Microsoft Report Viewer. The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.</li></ul><p>And finally the moderate bulletins.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-068.mspx">MS11-068</a> &#8211; Vulnerability in Windows Kernel Could Allow Denial of Service (2556532) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user visits a network share (or visits a Web site that points to a network share) containing a specially crafted file. In all cases, however, an attacker would have no way to force a user to visit such a network share or Web site. Instead, an attacker would have to convince a user to do so, typically by getting the user to click a link in an e-mail message or Instant Messenger message.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-069.mspx">MS11-069</a> &#8211; Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)  &#8211; This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow information disclosure if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</li></ul><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/windows-updates.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/windows-updates.png" alt="windows-updates" title="windows-updates" width="574" height="270" class="alignnone size-full wp-image-48841" /></a></p><p>The updates are as usually available via Windows Update and Microsoft&#8217;s Download Center (even though I would not recommend using this at this time as it is a mess).</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Adobe Patch Day Brings Fixes For Flash, Shockwave And Adobe Reader</title><link>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/</link> <comments>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/#comments</comments> <pubDate>Wed, 15 Jun 2011 07:42:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[companies]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[patch day]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46489</guid> <description><![CDATA[Microsoft had a huge patch day yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software. Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after teaming up with Microsoft to coordinate security releases.. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft had a huge <a
href="http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/">patch day</a> yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software.</p><p>Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after <a
href="http://www.ghacks.net/2010/07/29/adobe-microsoft-to-team-up-on-vulnerability-sharing/">teaming up with Microsoft</a> to coordinate security releases.. Of the five, three may be affecting end users as they address vulnerabilities in Adobe Reader and Acrobat, Shockwave Player and Flash Player. All three have received a maximum severity rating of critical, the highest possible rating.</p><p>The bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-16.html">APSB11-16</a> describes a critical vulnerability in Adobe Reader X 10.0.3 and earlier on Windows, and Adobe Reader X 10.0.3 and earlier on Macintosh, as well as earlier versions of Adobe Reader 9 and 8, and Adobe Acrobat 9 and 8. The vulnerability could be exploited by attackers to crash the application to take control of the computer system Adobe Reader X is running on.</p><p>Adobe recommends to update the software product to the latest available version. For Adobe Reader X that would mean to update to version 10.1, for users of Adobe Reader 9.4.4 and earlier to update to version 9.4.5.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/adobe-reader-x.png" alt="adobe-reader-x" title="adobe-reader-x" width="600" height="449" class="alignnone size-full wp-image-46493" /></p><p>Adobe Reader and Acrobat users can check for updates in the program interface. This is done via Help > Check for Updates. Updates can also be downloaded from the following locations.</p><ul><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.">Adobe Reader Windows</a></li><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.">Adobe Reader Macintosh</a></li></ul><p>You can also check out <a
href="http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/">Adobe Reader X Offline Installers</a></p><p>Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-17.html">APSB11-17</a> describes vulnerabilities in Adobe Shockwave Player 11.5.9.620 and earlier on the Windows and Macintosh platform. Attackers who successfully exploit the vulnerabilities could run malicious code on the computer system. Adobe recommends to update Shockwave Player to version 11.6.0.626 to protect the system from possible exploits.</p><p>Windows and Mac users who run Shockwave Player on their system can download the latest version <a
href="http://get.adobe.com/shockwave/">at the official</a> download site.</p><p>Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-18.html">APSB11-18</a> finally describes a vulnerability in Adobe Flash Player that affects Adobe Flash Player 10.3.181.23 and earlier on Windows, Macintosh, Linux and Solaris, as well as Flash Player 10.3.185.23 and earlier for Android.</p><p>The vulnerability could be exploited to cause a crash which could allow the attacker to gain control over the affected system. Adobe has confirmed reports that the vulnerability is exploited in the wild in the form of targeted attacks on specifically prepared websites.</p><p>Adobe recommends to update Flash Player to Adobe Flash Player 10.3.181.26 on desktop operating systems. Android users will receive a patch before week&#8217;s end.</p><p>Users can verify their installed version of Flash Player by visiting the <a
href="http://www.adobe.com/products/flash/about/">About Flash Player</a> page at Adobe.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/flash-player-version.png" alt="flash player version" title="flash player version" width="600" height="512" class="alignnone size-full wp-image-46490" /></p><p>Adobe lists the latest version for all supported operating systems on the page, so that users only need to compare their installed version with the latest available version to see if they need to update.</p><p>The latest versions can be downloaded from <a
href="http://get.adobe.com/flashplayer/">Adobe&#8217;s Flash Player Download Center</a>.  Users who do not want to use the download manager can check out this guide D<a
href="http://www.ghacks.net/2010/02/27/download-adobe-flash-without-adobe-download-manager/">ownload Adobe Flash Without Adobe Download Manager</a>.</p><p>Google Chrome users can check for updates in Chrome to get the latest version. This is done by clicking on the wrench icon and selecting About Google Chrome.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Patch Day June 2011 Overview</title><link>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/</link> <comments>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/#comments</comments> <pubDate>Tue, 14 Jun 2011 17:33:37 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46476</guid> <description><![CDATA[Microsoft has released a total of 16 security bulletins on this month&#8217;s patch day. Patch day refers to the second Tuesday of each month on which Microsoft will release security patches. This month&#8217;s patch day consists of many different patches. Nine of the 16 bulletins have a maximum severity rating of critical, the highest possible [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released a total of 16 security bulletins on this month&#8217;s patch day. Patch day refers to the second Tuesday of each month on which Microsoft will release security patches. This month&#8217;s patch day consists of many different patches. Nine of the 16 bulletins have a maximum severity rating of critical, the highest possible rating, the remaining 7 bulletins a rating of important.</p><p>Highest possible means that at least one operating system or application has received that rating. It happens that all programs receive the same rating, but it is often not the case.</p><p>When you look at affected software programs you will notice that the majority of bulletins resolve issues under Microsoft Windows. Other Microsoft software affected includes Microsoft Internet Explorer, Microsoft Office or the Microsoft .Net Framework.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/windows-updates-june-2011.png" alt="windows updates june 2011" title="windows updates june 2011" width="596" height="281" class="alignnone size-full wp-image-46477" /></p><p>Detailed bulletin information have not been released at this point. Windows users can however check for updates to download and install the security patches right away. This is done via Start Menu > All Programs > Windows Update.</p><p>I will update this guide as soon as more information become available.</p><p>Update: The June security bulletins have been posted.</p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-038.mspx">MS11-038</a> &#8211; Vulnerability in OLE Automation Could Allow Remote Code Execution (2476490)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-039.mspx">MS11-039</a> &#8211; Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2514842)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-040.mspx">MS11-040</a> &#8211; Vulnerability in Threat Management Gateway Firewall Client Could Allow Remote Code Execution (2520426)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-041.mspx">MS11-041</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2525694)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-042.mspx">MS11-042</a> &#8211; Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-043.mspx">MS11-043</a> &#8211; Vulnerability in SMB Client Could Allow Remote Code Execution (2536276)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-044.mspx">MS11-044</a> &#8211; Vulnerability in .NET Framework Could Allow Remote Code Execution (2538814)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-050.mspx">MS11-050</a> &#8211; Cumulative Security Update for Internet Explorer (2530548)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-052.mspx">MS11-052</a> &#8211; Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2544521)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-037.mspx">MS11-037</a> &#8211; Vulnerability in MHTML Could Allow Information Disclosure (2544893)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-045.mspx">MS11-045</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-046.mspx">MS11-046</a> &#8211; Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2503665)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-047.mspx">MS11-047</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2525835)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-048.mspx">MS11-048</a> &#8211; Vulnerability in SMB Server Could Allow Denial of Service (2536275)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-049.mspx">MS11-049</a> &#8211; Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-051.mspx">MS11-051</a> &#8211; Vulnerability in Active Directory Certificate Services Web Enrollment Could Allow Elevation of Privilege (2518295)</li></ul><p>You get an overview of all patches on the security bulletin summary page <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-jun.mspx">over at</a> Microsoft. It lists for instance the individual severity level of all affected operating systems and applications. Patches do not seem to have been posted yet on Microsoft Download Center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Microsoft May 2011 Patch Day Overview</title><link>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/</link> <comments>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/#comments</comments> <pubDate>Tue, 10 May 2011 20:34:53 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44985</guid> <description><![CDATA[Microsoft has released two security bulletins on this month&#8217;s patch day. Every second Tuesday of a month is so called patch day at Microsoft where a number of security related updates are released. One of the security bulletin addresses securities in Microsoft Windows, the other in Microsoft Office. If you look at the maximum severity [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released two security bulletins on this month&#8217;s patch day. Every second Tuesday of a month is so called patch day at Microsoft where a number of security related updates are released. One of the security bulletin addresses securities in Microsoft Windows, the other in Microsoft Office.</p><p>If you look at the maximum severity rating you notice that the Windows vulnerabilities have received a severity rating of critical, the highest possible rating. The Office bulletin on the other hand received a rating of important, the second highest rating.</p><p>Microsoft Security Bulletin MS11-035 offers detailed information about the Windows vulnerability. It affects only Windows Server products, from Windows Server 2003 to Windows Server 2008 R2. Not affected are all client operating systems of Microsoft.</p><p>If you look at Microsoft Security Bulletin MS11-036 you notice that Office XP, 2003 and 2007 are affected on Windows. Furthermore affected are Microsoft Office 2004 and 2008 for Mac, the Open XML File Format Converter for Mac and the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2.</p><p>Why is not Office 2010 affected by the vulnerability? Because Office File Validation mitigates the risk of the vulnerability.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-035.mspx">MS11-035</a> &#8211; Vulnerability in WINS Could Allow Remote Code Execution (2524426) &#8211; This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system. Only customers who manually installed this component are affected by this issue.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-036.mspx">MS11-036</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1269 and CVE-2011-1270.</li></ul><p>Additional information on both vulnerabilities are available at the <a
href="http://blogs.technet.com/b/msrc/archive/2011/05/10/may-2011-security-bulletin-release.aspx">MSRC</a> Technet Blog.</p><p>The patches are available via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> or the <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">Microsoft Download Center</a>. The May Security Release ISO image is <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f134d93b-dd1e-401a-a214-343f99b77350&#038;pf=true">available</a> there as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/10/microsoft-may-2011-patch-day-overview/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Microsoft April 2011 Patch Day Overview</title><link>http://www.ghacks.net/2011/04/13/microsoft-april-2011-patch-day-overview/</link> <comments>http://www.ghacks.net/2011/04/13/microsoft-april-2011-patch-day-overview/#comments</comments> <pubDate>Wed, 13 Apr 2011 10:00:45 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43861</guid> <description><![CDATA[Yesterday&#8217;s monthly patch day was a big one, with 17 patches fixing a total of 64 security issues in Microsoft products. Affected applications include Microsoft Windows, Microsoft Office and Internet Explorer. If you look closer you notice that nine of the 17 patches have a maximum severity rating of critical, the highest possible rating. The [...]]]></description> <content:encoded><![CDATA[<p>Yesterday&#8217;s monthly patch day was a big one, with 17 patches fixing a total of 64 security issues in Microsoft products. Affected applications include Microsoft Windows, Microsoft Office and Internet Explorer. If you look closer you notice that nine of the 17 patches have a maximum severity rating of critical, the highest possible rating. The remaining patches have a rating of important.</p><p>When you look at the number of critical vulnerabilities of each individual operating system you will notice that Windows Vista leads the pack with nine critical security vulnerabilities followed by Windows 7 with eight and Windows XP with seven.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/windows-update.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/windows-update-550x390.png" alt="windows update" title="windows update" width="550" height="390" class="alignnone size-medium wp-image-43862" /></a></p><p>The security patches protect the system against remote code execution, information disclosure and elevation of privileges.</p><p>You find information about each individual security bulletin, their severity rating and impact <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx">over at the</a> Microsoft Security Bulletin Summary for April 2011.</p><p>Another interesting read is the risk assessment of April&#8217;s security updates. Microsoft is aware that some issues are already exploited, while others are likely to be exploited in the coming 30 days.</p><p><a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Updates</a> are as usually available on various channels. Most Windows users are probably using automatic updates to install the new patches. Those who do not can check manually for updates or <a
href="http://www.microsoft.com/downloads/en/resultsForCategory.aspx?nr=50&#038;sortOrder=Descending&#038;sortCriteria=Date&#038;period=33&#038;stype=ss_nd&#038;sterm=All+Categories&#038;pf=true&#038;displaylang=en&#038;categoryid=7">visit the</a> Microsoft Download Center to download the patches individually. Another option is to download the April Security Release ISO <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=55a462c8-7ef8-4cf0-974d-3babbfcf69c5&#038;pf=true">which contains</a> all Windows patches released in April.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/13/microsoft-april-2011-patch-day-overview/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>Microsoft March 2011 Patch Day Overview</title><link>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/</link> <comments>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/#comments</comments> <pubDate>Wed, 09 Mar 2011 09:05:54 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42277</guid> <description><![CDATA[Microsoft has released new security patches on yesterday&#8217;s Patch Day that address vulnerabilities in various Microsoft products including Microsoft Windows and Microsoft Office. The updates that have been released are already available via Windows Update and the Microsoft Download Center. One of the vulnerabilities has a maximum severity rating of critical, the highest possible. The [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released new security patches on yesterday&#8217;s Patch Day that address vulnerabilities in various Microsoft products including Microsoft Windows and Microsoft Office. The updates that have been released are already available via Windows Update and the Microsoft Download Center.</p><p>One of the vulnerabilities has a maximum severity rating of critical, the highest possible. The two remaining vulnerabilities are rated as important.</p><p>A critical vulnerability has been discovered in Windows Media that could be exploited for remote code execution. The vulnerability has been rated as critical for all Microsoft client operating systems, from Windows XP to Windows 7. Windows Server 2008 R2 is the only server product affected, the vulnerability received a rating of important here.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-severity.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-severity-550x309.png" alt="march 2011 patch day severity" title="march 2011 patch day severity" width="550" height="309" class="alignnone size-medium wp-image-42278" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-deployment-550x309.png" alt="march 2011 patch day deployment" title="march 2011 patch day deployment" width="550" height="309" class="alignnone size-medium wp-image-42279" /></a></p><p>Below are links to each security bulletin. The Bulletins offer information about the affected products, severity rating and non-affected software.</p><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-015.mspx">MS11-015</a> &#8211; Vulnerabilities in Windows Media Could Allow Remote Code Execution (2510030) &#8211; This security update resolves one publicly disclosed vulnerability in DirectShow and one privately reported vulnerability in Windows Media Player and Windows Media Center. The more severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Digital Video Recording (.dvr-ms) file. In all cases, a user cannot be forced to open the file; for an attack to be successful, a user must be convinced to do so.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-017.mspx">MS11-017</a> &#8211; Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2508062) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user opens a legitimate Remote Desktop configuration (.rdp) file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-016.mspx">MS11-016</a> &#8211; Vulnerability in Microsoft Groove Could Allow Remote Code Execution (2494047) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Groove that could allow remote code execution if a user opens a legitimate Groove-related file that is located in the same network directory as a specially crafted library file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><p>Users can update their Windows operating system and Microsoft Office via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a>, the <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">Microsoft Download Center</a> or by downloading the <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=ab55654c-c685-4316-93fc-e3a80cccac71&#038;pf=true">March 2011</a> Security Release ISO image.</p><p>In other news, Microsoft is still working on a fix for the MHTML-related vulnerability that was discovered in January. Additional information are available at the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>Microsoft Security Bulletin Overview February 2011</title><link>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/</link> <comments>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/#comments</comments> <pubDate>Tue, 08 Feb 2011 18:17:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39715</guid> <description><![CDATA[Microsoft has just enabled downloads for today&#8217;s security patches on Windows Update. Today&#8217;s Patch Day brings 12 security bulletins that fix vulnerabilities of various severity affecting the Microsoft Windows operating system, Internet Explorer and Microsoft Office. Three of the vulnerabilities have a maximum severity rating of critical, the highest possible rating. The remaining 11 have [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just enabled downloads for today&#8217;s security patches on Windows Update. Today&#8217;s Patch Day brings 12 security bulletins that fix vulnerabilities of various severity affecting the Microsoft Windows operating system, Internet Explorer and Microsoft Office. Three of the vulnerabilities have a maximum severity rating of critical, the highest possible rating. The remaining 11 have a maximum severity rating of imporant.</p><p>Windows users can check for the updates by opening Windows Update which is linked from the Windows start menu. There it is possible to check for new updates which needs to be done if the PC has been running for some time today.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/02/windows-update.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/02/windows-update-550x253.jpg" alt="windows update" title="windows update" width="550" height="253" class="alignnone size-medium wp-image-39716" /></a></p><p>The <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">security bulletin summary</a> for February 2011 offers in depth information about the updates and the affected applications.</p><p>All individual security bulletins are listed and linked below as well.</p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx">MS11-003</a> &#8211; Cumulative Security Update for Internet Explorer (2482017) &#8211; This security update resolves two privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user opens a legitimate HTML file that loads a specially crafted library file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-006.mspx">MS11-006</a> &#8211; Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185) &#8211; This security update resolves a publicly disclosed vulnerability in the Windows Shell graphics processor. The vulnerability could allow remote code execution if a user views a specially crafted thumbnail image. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-007.mspx">MS11-007</a> &#8211; Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376) &#8211; This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow remote code execution if a user views content rendered in a specially crafted CFF font. In all cases, an attacker would have no way to force users to view the specially crafted content. Instead, an attacker would have to convince users to visit a Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-004.mspx">MS11-004</a> &#8211; Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution (2489256) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Internet Information Services (IIS) FTP Service. The vulnerability could allow remote code execution if an FTP server receives a specially crafted FTP command. FTP Service is not installed by default on IIS.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-005.mspx">MS11-005</a> &#8211; Vulnerability in Active Directory Could Allow Denial of Service (2478953) &#8211; This security update resolves a publicly disclosed vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sent a specially crafted packet to an affected Active Directory server. The attacker must have valid local administrator privileges on the domain-joined computer in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-008.mspx">MS11-008</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-009.mspx">MS11-009</a> &#8211; Vulnerability in JScript and VBScript Scripting Engines Could Allow Information Disclosure (2475792) &#8211; This security update resolves a privately reported vulnerability in the JScript and VBScript scripting engines. The vulnerability could allow information disclosure if a user visited a specially crafted Web site. An attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-010.mspx">MS11-010</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2476687) &#8211; This security update resolves a privately reported vulnerability in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003. The vulnerability could allow elevation of privilege if an attacker logs on to a user&#8217;s system and starts a specially crafted application that continues running after the attacker logs off in order to obtain the logon credentials of subsequent users. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-011.mspx">MS11-011</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-012.mspx">MS11-012</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-013.mspx">MS11-013</a> &#8211; Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930) &#8211; This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege if a local, authenticated attacker installs a malicious service on a domain-joined computer.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-014.mspx">MS11-014</a> &#8211; Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960) &#8211; This security update resolves a privately reported vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows XP and Windows Server 2003.<p>The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li></ul><p>The updates can also be downloaded directly and individually <a
href="http://www.microsoft.com/downloads/en/default.aspx">from the</a> Microsoft Download Center. Check out our detailed <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> guide for additional information and tips.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Security Bulletin December 2010</title><link>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/</link> <comments>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/#comments</comments> <pubDate>Wed, 15 Dec 2010 08:49:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37961</guid> <description><![CDATA[Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer. When we look at the severity rating of those vulnerabilities we notice that two of [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer.</p><p>When we look at the severity rating of those vulnerabilities we notice that two of the bulletins have a maximum severity rating of critical while the remaining ones a rating of important with the exception of one that has been rated as moderate.</p><p>Maximum severity rating means that at least one Microsoft product is affect this way by the vulnerability. The critical vulnerability MS10-090 affects Internet Explorer 6 to Internet Explorer 8 and is critical on all Microsoft operating systems. Vulnerability MS10-091 on the other hand is critical on Windows Vista and Windows 7 but not on Windows XP, something that we do not see very often thanks to improved security of the two operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority-550x309.png" alt="deployment priority" title="deployment priority" width="550" height="309" class="alignnone size-medium wp-image-37962" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index-550x309.png" alt="severity exploitability index" title="severity exploitability index" width="550" height="309" class="alignnone size-medium wp-image-37963" /></a></p><p>The updates are already available via Windows Update and the <a
href="http://www.microsoft.com/downloads/en/default.aspx">Microsoft Download Center</a>.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-090.mspx">MS10-090</a> &#8211; Cumulative Security Update for Internet Explorer (2416400) &#8211; This security update resolves four privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-091.mspx">MS10-091</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199) &#8211; This security update resolves several privately reported vulnerabilities in the Windows Open Type Font (OTF) driver that could allow remote code execution. An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a> &#8211; Vulnerability in Task Scheduler Could Allow Elevation of Privilege (2305420) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Task Scheduler. The vulnerability could allow elevation of privilege if an attacker logged on to an affected system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-093.mspx">MS10-093</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Movie Maker file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx">MS10-094</a> &#8211; Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Media Encoder. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-095.mspx">MS10-095</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2385678) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file type such as .eml and .rss (Windows Live Mail) or .wpost (Microsoft Live Writer) located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx">MS10-096</a> &#8211; Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Address Book. The vulnerability could allow remote code execution if a user opens a Windows Address Book file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx">MS10-097</a> &#8211; Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105) &#8211;  This security update resolves a publicly disclosed vulnerability in the Internet Connection Signup Wizard of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-098.mspx">MS10-098</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) &#8211; This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-099.mspx">MS10-099</a> &#8211; Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591) &#8211; This security update addresses a privately reported vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx">MS10-100</a> &#8211; Vulnerability in Consent User Interface Could Allow Elevation of Privilege (2442962) &#8211; This security update resolves a privately reported vulnerability in the Consent User Interface (UI). The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application on an affected system. An attacker must have valid logon credentials and the SeImpersonatePrivilege and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-101.mspx">MS10-101</a> &#8211; Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559) &#8211; This security update resolves a privately reported vulnerability in the Netlogon RPC Service on affected versions of Windows Server that are configured to serve as domain controllers. The vulnerability could allow denial of service if an attacker sends a specially crafted RPC packet to the Netlogon RPC Service interface on an affected system. An attacker requires administrator privileges on a machine that is joined to the same domain as the affected domain controller in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-102.mspx">MS10-102</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2345316) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx">MS10-103</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292970) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-104.mspx">MS10-104</a> &#8211; Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution (2455005) &#8211; This security update resolves a privately reported vulnerability in Microsoft SharePoint. The vulnerability could allow remote code execution in the security context of a guest user if an attacker sent a specially crafted SOAP request to the Document Conversions Launcher Service in a SharePoint server environment that is using the Document Conversions Load Balancer Service. By default, the Document Conversions Load Balancer Service and Document Conversions Launcher Service are not enabled in Microsoft Office SharePoint Server 2007.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx">MS10-105</a> &#8211; Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-106.mspx">MS10-106</a> &#8211; Vulnerability in Microsoft Exchange Server Could Allow Denial of Service (2407132) &#8211; This security update resolves a privately reported vulnerability in Microsoft Exchange Server. The vulnerability could allow denial of service if an authenticated attacker sent a specially crafted network message to a computer running the Exchange service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li></ul><p>Additional information are available at the <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-dec.mspx">security bulletin summary</a> and the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Bulletin November 2010</title><link>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/</link> <comments>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/#comments</comments> <pubDate>Wed, 10 Nov 2010 08:33:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[forefront]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36710</guid> <description><![CDATA[Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity rating of critical, the other two bulletins an important rating. Lets take a closer look at the bulletins.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-087.mspx">MS10-087</a> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930) &#8211; This security update resolves one publicly disclosed vulnerability and four privately reported vulnerabilities in Microsoft Office. The most severe vulnerability could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-088.mspx">MS10-088</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-089.mspx">MS10-089</a> &#8211; Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074) &#8211; This security update resolves four privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow elevation of privilege if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li></ul><p>The security patches are as usually available via Windows Update, Microsoft Update and <a
href="http://www.microsoft.com/downloads/en/default.aspx">direct</a> download. Office and Forefront users should patch the security vulnerabilities as soon as possible, everyone else can relax this month and wait for things to come. (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-nov.mspx">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Bulletins October 2010</title><link>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/</link> <comments>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/#comments</comments> <pubDate>Tue, 12 Oct 2010 20:52:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35831</guid> <description><![CDATA[Every second Tuesday in a month is patch day over at Microsoft. What does it mean? Microsoft pushes out all security patches of a month on that day to all users of their Windows operating systems and other applications like Microsoft Office. Only highly critical vulnerabilities receive out of band security patches. This month&#8217;s patch [...]]]></description> <content:encoded><![CDATA[<p>Every second Tuesday in a month is patch day over at Microsoft. What does it mean? Microsoft pushes out all security patches of a month on that day to all users of their Windows operating systems and other applications like Microsoft Office. Only highly critical vulnerabilities receive out of band security patches.</p><p>This month&#8217;s patch day is huge. While it is not the largest in history, it addresses the impressive amount of 49 vulnerabilities affecting Windows, Internet Explorer, Microsoft Office and the .net framework.</p><blockquote><p>Looking at the number and type of updates this month, we have a fairly standard number of bulletins affecting products like Windows and Office. This month we also have a few bulletins originating from product groups that we don&#8217;t see on a regular basis. For example, SharePoint, the Microsoft Foundation Class (MFC) Library (which is an application framework for programming in Windows), and the .NET Framework. It&#8217;s worth noting that only six of the 49 total vulnerabilities being addressed have a critical rating. Further, three of the bulletins account for 34 of the total vulnerabilities. (<a
href="http://blogs.technet.com/b/msrc/archive/2010/10/11/october-2010-security-bulletin-release.aspx">via</a>)</p></blockquote><p><strong>Deployment Priority</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/10/Deployment-Priority1.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/10/Deployment-Priority1-500x281.png" alt="Deployment Priority" title="Deployment Priority" width="500" height="281" class="alignnone size-medium wp-image-35833" /></a></p><p><strong>Severity and Exploitability</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/10/Severity-Exploitability.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/10/Severity-Exploitability-500x281.png" alt="Severity Exploitability" title="Severity Exploitability" width="500" height="281" class="alignnone size-medium wp-image-35834" /></a></p><p>Four of the vulnerabilities have a maximum severity rating of critical, 10 of important and the remaining 2 of moderate.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-071.mspx">MS10-071</a> &#8211; Cumulative Security Update for Internet Explorer (2360131) &#8211; This security update resolves seven privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-075.mspx">MS10-075</a> &#8211; Vulnerability in Media Player Network Sharing Service Could Allow Remote Code Execution (2281679) &#8211; This security update resolves a privately reported vulnerability in the Microsoft Windows Media Player network sharing service. The vulnerability could allow remote code execution if an attacker sent a specially crafted RTSP packet to an affected system. However, Internet access to home media is disabled by default. In this default configuration, the vulnerability can be exploited only by an attacker within the same subnet.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-076.mspx">MS10-076</a> &#8211; Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (982132) &#8211; This security update resolves a privately reported vulnerability in a Microsoft Windows component, the Embedded OpenType (EOT) Font Engine. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-077.mspx">MS10-077</a> &#8211; Vulnerability in .NET Framework Could Allow Remote Code Execution (2160841) &#8211; This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-072.mspx">MS10-072</a> &#8211; Vulnerabilities in SafeHTML Could Allow Information Disclosure (2412048) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft SharePoint and Windows SharePoint Services. The vulnerabilities could allow information disclosure if an attacker submits specially crafted script to a target site using SafeHTML.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-073.mspx">MS10-073</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (981957) &#8211; This security update resolves several publicly disclosed vulnerabilities in the Windows kernel-mode drivers. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application.<p>An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-078.mspx">MS10-078</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Format Driver Could Allow Elevation of Privilege (2279986) &#8211; This security update resolves two privately reported vulnerabilities in the Windows OpenType Font (OTF) format driver. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerabilities could allow elevation of privilege if a user views content rendered in a specially crafted OpenType font. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-079.mspx">MS10-079</a> &#8211; Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) &#8211; This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-080.mspx">MS10-080</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211) &#8211; This security update resolves thirteen privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file or a specially crafted Lotus 1-2-3 file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-081.mspx">MS10-081</a> &#8211; Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (2296011) &#8211; This security update resolves a privately reported vulnerability in the Windows common control library. The vulnerability could allow remote code execution if a user visited a specially crafted Web page. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-082.mspx">MS10-082</a> &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (2378111) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-083.mspx">MS10-083</a> &#8211; Vulnerability in COM Validation in Windows Shell and WordPad Could Allow Remote Code Execution (2405882) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted file using WordPad or selects or opens a shortcut file that is on a network or WebDAV share. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-084.mspx">MS10-084</a> &#8211; Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs specially crafted code that sends an LPC message to the local LRPC Server. The message could then allow an authenticated user to access resources that are running in the context of the NetworkService account. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-085.mspx">MS10-085</a> &#8211; Vulnerability in SChannel Could Allow Denial of Service (2207566) &#8211; This security update resolves a privately reported vulnerability in the Secure Channel (SChannel) security package in Windows. The vulnerability could allow denial of service if an affected Internet Information Services (IIS) server hosting a Secure Sockets Layer (SSL)-enabled Web site received a specially crafted packet message. By default, IIS is not configured to host SSL Web sites.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-074.mspx">MS10-074</a> &#8211; Vulnerability in Microsoft Foundation Classes Could Allow Remote Code Execution (2387149) &#8211; This security update resolves a publicly disclosed vulnerability in the Microsoft Foundation Class (MFC) Library. The vulnerability could allow remote code execution if a user is logged on with administrative user rights and opens an application built with the MFC Library. An attacker who successfully exploited this vulnerability could obtain the same permissions as the currently logged-on user. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-086.mspx">MS10-086</a> &#8211; Vulnerability in Windows Shared Cluster Disks Could Allow Tampering (2294255) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 R2 when used as a shared failover cluster. The vulnerability could allow data tampering on the administrative shares of failover cluster disks. By default, Windows Server 2008 R2 servers are not affected by this vulnerability. This vulnerability only applies to the cluster disks used in a failover cluster.</li></ul><p>The patches are as usual available via Windows Update and <a
href="http://www.microsoft.com/downloads/en/resultsForCategory.aspx?nr=50&#038;sortOrder=Descending&#038;sortCriteria=Date&#038;period=30&#038;stype=ss_nd&#038;sterm=All+Categories">Microsoft Download</a>. Microsoft has furthermore <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=07c7c176-a801-4868-8f53-c8b1aebb2b11">released</a> the October 2010 Security Release ISO Image containing all references security patches and Knowledgebase articles.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/12/microsoft-security-bulletins-october-2010/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Security Updates May 2010</title><link>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/</link> <comments>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/#comments</comments> <pubDate>Wed, 12 May 2010 10:35:14 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft security updates]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=25381</guid> <description><![CDATA[The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic. The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications. [...]]]></description> <content:encoded><![CDATA[<p>The Microsoft security updates for May 2010 are now available for download and installation. Microsoft has released a total of two security bulletins that fix vulnerabilities in Microsoft Windows, Microsoft Office and Microsoft Visual Basic.</p><p>The maximum severity rating has been set to critical. The critical rating applies only to some operating systems and applications.</p><p>Both vulnerabilities can be exploited to execute code remotely on affected operating systems and applications.</p><p><span
id="more-25381"></span><ul><li>MS10-030 &#8211; Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-030.mspx">978542</a>) &#8211; This security update resolves a privately reported vulnerability in Outlook Express, Windows Mail, and Windows Live Mail. The vulnerability could allow remote code execution if a user visits a malicious e-mail server. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li>MS10-031 &#8211; Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-031.mspx">978213</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Visual Basic for Applications. The vulnerability could allow remote code execution if a host application opens and passes a specially crafted file to the Visual Basic for Applications runtime. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>The security patches can be downloaded via Windows Update, Microsoft Update and the individual security bulletin pages.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/05/12/microsoft-security-updates-may-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates February 2010</title><link>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/</link> <comments>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/#comments</comments> <pubDate>Wed, 10 Feb 2010 14:48:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22954</guid> <description><![CDATA[Microsoft has released a total of 14 security updates on yesterday&#8217;s patch day. The updates are, as usual, for several Microsoft software products including the Microsoft Windows operating system and Microsoft Office. Five of the updates have received a critical rating by Microsoft, the highest security rating. Seven were ranked as important which is the [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released a total of 14 security updates on yesterday&#8217;s patch day. The updates are, as usual, for several Microsoft software products including the Microsoft Windows operating system and Microsoft Office.</p><p>Five of the updates have received a critical rating by Microsoft, the highest security rating. Seven were ranked as important which is the second highest rating and one as moderate. The security ratings can vary depending on the operating system and Office version used.</p><p>Microsoft Windows 7 users for instance will notice that the security updates have all received an important rating for their operating system while Windows 2000 or Windows XP users will notice that their operating systems have received the largest amount of critical ratings.</p><p><span
id="more-22954"></span></p><ul><li>Microsoft Security Bulletin MS10-006 &#8211; Critical &#8211; Vulnerabilities in SMB Client Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">978251</a>) &#8211; his security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a malicious SMB server.<br
/> This security update is rated Critical for Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows 7, and Windows Server 2008 R2, and is rated Important for Windows Vista and Windows Server 2008.</li><li>Microsoft Security Bulletin MS10-007 &#8211; Critical &#8211; Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx">975713</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not impacted by this security update. The vulnerability could allow remote code execution if an application, such as a Web browser, passes specially crafted data to the ShellExecute API function through the Windows Shell Handler.<br
/> This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003</li><li>Microsoft Security Bulletin MS10-008 &#8211; Critical &#8211; Cumulative Security Update of ActiveX Kill Bits (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx">978262</a>) &#8211; his security update addresses a privately reported vulnerability for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000 and Windows XP, Important for all supported editions of Windows Vista and Windows 7, Moderate for all supported editions of Windows Server 2003, and Low for all supported editions of Windows Server 2008 and Windows Server 2008 R2.</li><li>Microsoft Security Bulletin MS10-009 &#8211; Critical &#8211; Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx">974145</a>) &#8211; his security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.<br
/> This security update is rated Critical for Windows Vista and Windows Server 2008.</li><li>Microsoft Security Bulletin MS10-013 &#8211; Critical &#8211; Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-013.mspx">977935</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft DirectShow. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Critical for all supported editions of Microsoft Windows except for all supported Itanium-based editions of Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2, for which this security update is rated Important.</li><li>Microsoft Security Bulletin MS10-003 &#8211; Important &#8211; Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-003.mspx">978214</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Important for all supported editions of Microsoft Office XP and Microsoft Office 2004 for Mac.</li><li>Microsoft Security Bulletin MS10-004 &#8211; Important &#8211;  Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx">975416</a>) &#8211; This security update resolves six privately reported vulnerabilities in Microsoft Office PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Important for supported editions of Microsoft Office PowerPoint 2002 and Microsoft Office PowerPoint 2003, and Microsoft Office 2004 for Mac</li><li>Microsoft Security Bulletin MS10-010 &#8211; Important &#8211; Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-010.mspx">977894</a>) &#8211; his security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.<br
/> This security update is rated Important for all supported x64-based editions of Windows Server 2008 and Windows Server 2008 R2</li><li>Microsoft Security Bulletin MS10-011 &#8211; Important &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx">978037</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not affected. The vulnerability could allow elevation of privilege if an attacker logs on to the system and starts a specially crafted application designed to continue running after the attacker logs out. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.</li><li>Microsoft Security Bulletin MS10-012 &#8211; Important &#8211; Vulnerabilities in SMB Server Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx">971468</a>) &#8211; This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.<br
/> This security update is rated Important for all supported editions of Microsoft Windows.</li><li>Microsoft Security Bulletin MS10-014 &#8211; Important &#8211; Vulnerability in Kerberos Could Allow Denial of Service (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-014.mspx">977290</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a specially crafted ticket renewal request is sent to the Windows Kerberos domain from an authenticated user on a trusted non-Windows Kerberos realm. The denial of service could persist until the domain controller is restarted.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008</li><li>Microsoft Security Bulletin MS10-015 &#8211; Important &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">977165</a>) &#8211; his security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on to the system and then ran a specially crafted application. To exploit either vulnerability, an attacker must have valid logon credentials and be able to log on locally. The vulnerabilities could not be exploited remotely or by anonymous users.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 for 32-bit Systems.</li><li>Microsoft Security Bulletin MS10-005 &#8211; Moderate &#8211; Vulnerability in Microsoft Paint Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-005.mspx">978706</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Paint. The vulnerability could allow remote code execution if a user viewed a specially crafted JPEG image file using Microsoft Paint. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Moderate for Microsoft Windows 2000, Windows XP, and Windows Server 2003</li></ul><p>Updates can be downloaded and installed the usual ways. This includes through Windows Update, Microsoft Update, downloading the updates individually or downloading the security CD for February 2010 which will is provided by Microsoft after every patch day.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Expect A Massive Patch Day Tomorrow</title><link>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/</link> <comments>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/#comments</comments> <pubDate>Mon, 12 Oct 2009 10:28:02 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patches]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17188</guid> <description><![CDATA[Tomorrow is a day that could force many system administrators into overtime as both Microsoft and Adobe plan to release security patches for several of their products. Microsoft alone plans to release 13 security patches and updates for various Microsoft operating system, Microsoft Office and other Microsoft products. The patch day is also the first [...]]]></description> <content:encoded><![CDATA[<p>Tomorrow is a day that could force many system administrators into overtime as both Microsoft and Adobe plan to release security patches for several of their products. Microsoft alone <a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-oct.mspx">plans</a> to release 13 security patches and updates for various Microsoft operating system, Microsoft Office and other Microsoft products. The patch day is also the first to include a critical security patch for Microsoft&#8217;s upcoming operating system Windows 7.</p><p>Adobe on the other hand <a
href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">plans</a> to release security patches for its popular PDF reader Adobe Reader that are also rated critical. The updates will all be released tomorrow and system administrators will certainly their hands full updating the computer systems that run the software and operating systems.</p><p><span
id="more-17188"></span>A closer look at the Microsoft Patch Day reveals eight critical security vulnerabilities and five important vulnerabilities that will get fixed with the patches that are released tomorrow. The majority of vulnerabilities affects the Windows operating system but it does also include one critical Internet Explorer vulnerability.</p><p>System administrators and Windows users are encouraged to visit the two websites linked above for further information. These websites will also contain the links to patch the security vulnerabilities. Windows users can also use Windows Update, Microsoft Update or Automatic Updates to update their operating system.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Patch Day March 2009</title><link>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/</link> <comments>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/#comments</comments> <pubDate>Tue, 10 Mar 2009 17:26:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[remote code execution]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[spoofing]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows vulnerabilities]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=11081</guid> <description><![CDATA[Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including [...]]]></description> <content:encoded><![CDATA[<p>Just a few minutes ago the patches for this month&#8217;s patch day have been uploaded to Windows Update and Microsoft Update. Users are encouraged to update their Microsoft operating system as soon as possible to close the recently discovered security vulnerabilities. Among the affected operating systems are practically all Microsoft operating systems since and including Windows 2000. This means the popular operating systems Windows XP and Vista are affected as well as Windows Server 2003 and 2008.</p><p>One security vulnerability has a critical rating for all affected operating systems while the other two are rated important by Microsoft&#8217;s security research team.</p><p>Details about the Security Bulletins can be found by following these links: Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-006.mspx">MS09-006</a>, <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-007.mspx">MS09-007</a> or <a
href="http://www.microsoft.com/technet/security/bulletin/MS09-008.mspx">MS09-008</a>. Another possibility is to <a
href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx">access</a> the Security Bulletin Summary at Microsoft Technet.</p><p>The vulnerabilities fix one remote code execution vulnerability and two spoofing vulnerabilities on the affected Windows operating systems:</p><ul><li>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution</li><li>Vulnerability in SChannel Could Allow Spoofing</li><li>Vulnerabilities in DNS and WINS Server Could Allow Spoofing</li></ul><p><span
id="more-11081"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</title><link>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/</link> <comments>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/#comments</comments> <pubDate>Wed, 15 Oct 2008 08:38:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[office]]></category> <category><![CDATA[office security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7632</guid> <description><![CDATA[It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not [...]]]></description> <content:encoded><![CDATA[<p>It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not releasing them because they release them in one package on one day.</p><p>Microsoft released a batch of eleven security patches for various operating systems and products yesterday which are available by visiting Windows Update or Microsoft Technet which contains in depths information about the affected products and the security vulnerabilities.</p><p>The patches fix four critical, six important and 1 moderate security vulnerability:</p><p><span
id="more-7632"></span></p><ul><li>Vulnerability in Active Directory Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-060.mspx">957280</a>)</li><li>Cumulative Security Update for Internet Explorer (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-058.mspx">956390</a>)</li><li>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-059.mspx">956695</a>)</li><li>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx">956416</a>)</li></ul><ul><li>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-066.mspx">956803</a>)</li><li>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-061.mspx">954211</a>)</li><li>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-062.mspx">953155</a>)</li><li>Vulnerability in SMB Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-063.mspx">957095</a>)</li><li>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-064.mspx">956841</a>)</li><li>Vulnerability in Message Queuing Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-065.mspx">951071</a>)</li></ul><ul><li>Vulnerability in Microsoft Office Could Allow Information Disclosure (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-056.mspx">957699</a>)</li></ul><p>It is highly recommended to update the products as soon as possible to protect the system from this attacks.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
