<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; security bulletin</title> <atom:link href="http://www.ghacks.net/tag/security-bulletin/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Releases First 2012 Security Update</title><link>http://www.ghacks.net/2012/01/10/microsoft-releases-first-2012-security-update/</link> <comments>http://www.ghacks.net/2012/01/10/microsoft-releases-first-2012-security-update/#comments</comments> <pubDate>Tue, 10 Jan 2012 18:18:00 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=55638</guid> <description><![CDATA[Microsoft today has released seven security related bulletins that fix issues in the Windows operating system and in Microsoft&#8217;s Developer Tools. One bulletin has received the maximum severity rating of critical, the highest available rating, while the remaining six bulletins have all received a rating of important, the third highest rating. It is interesting to [...]]]></description> <content:encoded><![CDATA[<p>Microsoft today has released seven security related bulletins that fix issues in the Windows operating system and in Microsoft&#8217;s Developer Tools. One bulletin has received the maximum severity rating of critical, the highest available rating, while the remaining six bulletins have all received a rating of important, the third highest rating.</p><p>It is interesting to note that the severity rating of the first bulletin is critical on Windows XP and Vista, while only important on Windows 7 and Windows Server 2008 R2. When you look at all bulletins you will notice that Windows XP is affected by all, Vista by five and Windows 7 by four of the vulnerabilities addressed in the bulletins.</p><p>The Security Bulletins have just <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan">been posted</a> on Microsoft&#8217;s Technet website. Here is this month&#8217;s summary with links to each security bulletin.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004">MS12-004</a> &#8211; Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-001">MS12-001</a> &#8211; Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-002">MS12-002</a> &#8211; Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-003">MS12-003</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) &#8211; This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. All supported editions of Windows 7 and Windows Server 2008 R2 are not affected by this vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-005">MS12-005</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-006">MS12-006</a> &#8211; Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) &#8211; This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-007">MS12-007</a> &#8211; Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) &#8211; This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker&#8217;s user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.</li></ul><p>The updates are already available on <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a>. The easiest way to open the updating tool is to click on the start menu orb and select Windows Update from the program listing there.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/windows-update-january-2012.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/windows-update-january-2012.jpg" alt="windows update january 2012" title="windows update january 2012" width="575" height="270" class="alignnone size-full wp-image-55642" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/updates-january-2012.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/updates-january-2012.jpg" alt="updates january 2012" title="updates january 2012" width="591" height="283" class="alignnone size-full wp-image-55643" /></a></p><p>Windows users who do not want to or can&#8217;t use Windows Updates can download the updates from Microsoft&#8217;s Download Center beginning later today. Microsoft as usual will release an ISO image with all security updates of the month for easier distribution.</p><p><strong>Update:</strong> The severity and exploitability index and bulletin deployment information have been <a
href="http://blogs.technet.com/b/msrc/archive/2012/01/10/january-2012-security-bulletins-released.aspx">posted</a>.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/4048.20120110_Severity_and_XI.png"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/4048.20120110_Severity_and_XI-600x337.png" alt="Severity and Exploitability Index" title="Severity and Exploitability Index" width="600" height="337" class="alignnone size-medium wp-image-55650" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/4527.20120110_Deployment_Priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/4527.20120110_Deployment_Priority-600x337.png" alt="Bulletin Deployment Priority" title="Bulletin Deployment Priority" width="600" height="337" class="alignnone size-medium wp-image-55651" /></a></p><p>The next security updates will be released on February 14, 2012.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2012/01/10/microsoft-releases-first-2012-security-update/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Microsoft .Net Framework Security Update Released</title><link>http://www.ghacks.net/2011/12/30/microsoft-net-framework-security-update-released/</link> <comments>http://www.ghacks.net/2011/12/30/microsoft-net-framework-security-update-released/#comments</comments> <pubDate>Fri, 30 Dec 2011 17:49:38 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[net framework]]></category> <category><![CDATA[security bulletin]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=55068</guid> <description><![CDATA[Microsoft has released an out-of-band security update for the Windows operating system that fixes a number of security vulnerabilities in the Microsoft .NET Framework. The vulnerability affects all 32-bit and 64-bit versions of Windows that receive security updates, and the following versions of the Microsoft .NET Framework: Microsoft .Net Framework 1.1, 2.0, 3.5 Service Pack [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released an out-of-band security update for the Windows operating system that fixes a number of security vulnerabilities in the Microsoft .NET Framework. The vulnerability affects all 32-bit and 64-bit versions of Windows that receive security updates, and the following versions of the Microsoft .NET Framework: Microsoft .Net Framework 1.1, 2.0, 3.5 Service Pack 1 and 4.</p><p>At least one of the vulnerabilities has received the maximum severity rating of critical, the highest possible rating, on all affected operating systems and .Net versions. Microsoft notes that the most severe vulnerability could allow elevation of privileges &#8220;if an unauthenticated attacker sends a specially crafted web request to&#8221; a target site. Attackers who successfully exploit the issue can &#8220;take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands&#8221;.</p><p>Security updates are already listed on Windows Update. Windows users who have only installed the Microsoft .Net Framework 4.0 Client Profile may only see important in Windows Update instead of critical ones. That is because ASP.Net, the component that is affected by the critical vulnerability, is not included in this version of the framework.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/net-framework-vulnerability.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/net-framework-vulnerability.jpg" alt="net framework vulnerability" title="net framework vulnerability" width="590" height="137" class="alignnone size-full wp-image-55069" /></a></p><p>Most Windows users have configured automatic updates. Users who do not use automatic updates or Windows Update may download the patches <a
href="http://catalog.update.microsoft.com/v7/site/Search.aspx?q=MS11-100">from the</a> Microsoft Update Catalog site instead. Please note that you can only open the site in Internet Explorer and not in other browsers.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/microsoft-update-catalog.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/microsoft-update-catalog-600x378.jpg" alt="microsoft update catalog" title="microsoft update catalog" width="600" height="378" class="alignnone size-medium wp-image-55070" /></a></p><p>Microsoft&#8217;s Download Center is currently not listing the security updates. It is however likely that they will appear on the site in the next days.</p><p>A restart of the computer is not required after applying the patches. The patches will merely stop related services during patches before they are restarted.</p><p>Additional information about the security vulnerability are available <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx">on the</a> Microsoft Security Bulletin page. This bulletin raises the count to 100 bulletins that have been released by the Redmond company in 2011.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/12/30/microsoft-net-framework-security-update-released/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>Microsoft Releases Security Patches for December 2011</title><link>http://www.ghacks.net/2011/12/14/microsoft-releases-security-patches-for-december-2011/</link> <comments>http://www.ghacks.net/2011/12/14/microsoft-releases-security-patches-for-december-2011/#comments</comments> <pubDate>Wed, 14 Dec 2011 10:23:59 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=54360</guid> <description><![CDATA[Yesterday&#8217;s Patch Tuesday brought 13 security bulletins fixing a total of 19 different vulnerabilities affecting Microsoft products. The majority of security patches have been released for Microsoft&#8217;s Windows operating system and Microsoft Office, with a cumulative security update released for Internet Explorer as well. The updates are already available on Windows Update and via the [...]]]></description> <content:encoded><![CDATA[<p>Yesterday&#8217;s Patch Tuesday brought 13 security bulletins fixing a total of 19 different vulnerabilities affecting Microsoft products. The majority of security patches have been released for Microsoft&#8217;s Windows operating system and Microsoft Office, with a cumulative security update released for Internet Explorer as well.</p><p>The updates are already available on Windows Update and <a
href="http://www.microsoft.com/download/en/default.aspx">via the</a> Microsoft Download Center for users who prefer to download them separately. A DVD Iso image has <a
href="http://www.microsoft.com/download/en/details.aspx?id=28485">also been</a> released with December&#8217;s security updates.</p><p>Microsoft recommends to focus the attention on the MS11-092 – Windows Media and MS11-087 – Windows critical updates before installing the remaining patches. The bulletin deployment priority table, and severity and exploitability index provide further assistance.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/bulletin-deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/bulletin-deployment-priority-600x337.png" alt="bulletin deployment priority" title="bulletin deployment priority" width="600" height="337" class="alignnone size-medium wp-image-54361" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/severity-exploitability-index-600x337.png" alt="severity exploitability index" title="severity exploitability index" width="600" height="337" class="alignnone size-medium wp-image-54362" /></a></p><p>Here is a list of all bulletins released in December 2011 by Microsoft.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-087">MS11-087</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted document or visits a malicious Web page that embeds TrueType font files.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-090">MS11-090</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (2618451) &#8211; This security update resolves a privately reported vulnerability in Microsoft software. The vulnerability could allow remote code execution if a user views a specially crafted Web page that uses a specific binary behavior in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-092">MS11-092</a> &#8211; Vulnerability in Windows Media Could Allow Remote Code Execution (2648048) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player and Windows Media Center. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Digital Video Recording (.dvr-ms) file. In all cases, a user cannot be forced to open the file; for an attack to be successful, a user must be convinced to do so.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-088">MS11-088</a> &#8211; Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Privilege (2652016) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user performed specific actions on a system where an affected version of the Microsoft Pinyin (MSPY) Input Method Editor (IME) for Simplified Chinese is installed. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights. Only implementations of Microsoft Pinyin IME 2010 are affected by this vulnerability. Other versions of Simplified Chinese IME and other implementations of IME are not affected.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-089/">MS11-089</a> &#8211; Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-091/">MS11-091</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2607702) &#8211; This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-093">MS11-093</a> &#8211; Vulnerability in OLE Could Allow Remote Code Execution (2624667) &#8211; This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-094/">MS11-094</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of the vulnerabilities could take complete control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-095">MS11-095</a> &#8211; Vulnerability in Active Directory Could Allow Remote Code Execution (2640045) &#8211; This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-096">MS11-096</a> &#8211; Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-3403.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-097">MS11-097</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-098">MS11-098</a> &#8211; Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-099">MS11-099</a> &#8211; Cumulative Security Update for Internet Explorer (2618444) &#8211; This security update resolves three privately reported vulnerabilities in Internet Explorer. The most severe vulnerability could allow remote code execution if a user opens a legitimate HyperText Markup Language (HTML) file that is located in the same directory as a specially crafted dynamic link library (DLL) file.</li></ul><p>The next upcoming scheduled security update will be on the 10th of January 2012.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/12/14/microsoft-releases-security-patches-for-december-2011/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Microsoft Patch Day November 2011 Overview</title><link>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/</link> <comments>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/#comments</comments> <pubDate>Tue, 08 Nov 2011 18:42:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52475</guid> <description><![CDATA[Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating. In this case, [...]]]></description> <content:encoded><![CDATA[<p>Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating.</p><p>In this case, the critical rating applies to all operating systems that Microsoft supplies with security patches. This includes the client operating systems Windows XP, Vista and Windows 7 as well as the server operating systems Windows Server 2008 and 2008 R2.</p><p>Here are two graphs visualizing the severity and exploitability index and the bulletin deployment priority.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment-600x337.png" alt="november2011 bulletin deployment" title="november2011 bulletin deployment" width="600" height="337" class="alignnone size-medium wp-image-52476" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity-600x337.png" alt="november2011 severity" title="november2011 severity" width="600" height="337" class="alignnone size-medium wp-image-52477" /></a></p><p>Here is the list of security bulletins released in November 2011 by Microsoft.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-083">MS11-083</a> &#8211; Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-085">MS11-085</a> &#8211; Vulnerability in Windows Mail and Windows Meeting Space Could Allow Remote Code Execution (2620704) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .eml or .wcinv file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Mail or Windows Meeting Space could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .eml or .wcinv file) from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-086">MS11-086</a> &#8211; Vulnerability in Active Directory Could Allow Elevation of Privilege (2630837) &#8211; This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow elevation of privilege if Active Directory is configured to use LDAP over SSL (LDAPS) and an attacker acquires a revoked certificate that is associated with a valid domain account and then uses that revoked certificate to authenticate to the Active Directory domain. By default, Active Directory is not configured to use LDAP over SSL.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-084">MS11-084</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Denial of Service (2617657) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user opens a specially crafted TrueType font file as an e-mail attachment or navigates to a network share or WebDAV location containing a specially crafted TrueType font file. For an attack to be successful, a user must visit the untrusted remote file system location or WebDAV share containing the specially crafted TrueType font file, or open the file as an e-mail attachment. In all cases, however, an attacker would have no way to force users to perform these actions. Instead, an attacker would have to persuade users to do so, typically by getting them to click a link in an e-mail message or Instant Messenger message.</li></ul><p>Microsoft has published a video in which Jerry Bryant discusses this month&#8217;s bulletins (Silverlight required).</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><p>Additional information about this month's security bulletins are available on the Technet Blog <a
href="http://blogs.technet.com/b/msrc/">page</a> and the Microsoft Security bulletin <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-nov">Summary</a> for November 2011.</p><p>The updates are already available on Windows Update. Users who have started their computer earlier today may need to run a manual update check in Windows Update.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg" alt="windows updates" title="windows updates" width="567" height="275" class="alignnone size-full wp-image-52478" /></a></p><p>The updates will also be available <a
href="http://www.microsoft.com/download/en/default.aspx">shortly</a> at Microsoft's Download center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/feed/</wfw:commentRss> <slash:comments>3</slash:comments> <enclosure
url="http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft Patch Day October 2011 Overview</title><link>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/</link> <comments>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/#comments</comments> <pubDate>Tue, 11 Oct 2011 17:32:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=51391</guid> <description><![CDATA[Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest [...]]]></description> <content:encoded><![CDATA[<p>Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest possible severity rating critical, the remaining six one of important. Maximum severity means that there is at least one product affected by that vulnerability impact.</p><p>You find information about each security bulletin below. Please follow the links for information about affected operating systems and Microsoft applications. You find a summary of all security bulletins <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-oct">here</a>.</p><p>Here are the Bulletin Deployment Priority and Severity and Exploitability Index screenshots for October 2011:</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011-600x337.jpg" alt="bulletin deployment priority october 2011" title="bulletin deployment priority october 2011" width="600" height="337" class="alignnone size-medium wp-image-51408" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011-600x337.png" alt="severity exploitability index october 2011" title="severity exploitability index october 2011" width="600" height="337" class="alignnone size-medium wp-image-51409" /></a></p><p>And a video in which Jerry Bryant discusses this month&#8217;s bulletins:</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-078">MS11-078</a> - Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930) -<br
/> This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-081">MS11-081</a> - Cumulative Security Update for Internet Explorer (2586448) - This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-075">MS11-075</a> - Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699) - This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, the Microsoft Active Accessibility component could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-076">MS11-076</a> - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926) - This security update resolves a publicly disclosed vulnerability in Windows Media Center. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Media Center could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-077">MS11-077</a> - Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053) - This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment. For a remote attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the specially crafted font file, or open the file as an e-mail attachment.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-079">MS11-079</a> - Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641) - This security update resolves five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-080">MS11-080</a> - Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-082">MS11-082</a> - Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670) - This security update resolves two publicly disclosed vulnerabilities in Host Integration Server. The vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the Host Integration Server ports should be blocked from the Internet.</li><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg" alt="windows updates" title="windows updates" width="579" height="382" class="alignnone size-full wp-image-51405" /></a></p><p>Windows users can update their operating system by installing the security patches via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> or <a
href="http://www.microsoft.com/download/en/default.aspx">Microsoft's</a> Download Center with Windows Update being the better option if the patches do not have to be installed on multiple computer systems.</p><p>Updates are already live and available via Windows Update. Additional information are <a
href="http://blogs.technet.com/b/msrc/">available at</a> Microsoft's Security Response Center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/feed/</wfw:commentRss> <slash:comments>4</slash:comments> <enclosure
url="http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft, Adobe Ready Security Updates</title><link>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/</link> <comments>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/#comments</comments> <pubDate>Tue, 13 Sep 2011 18:34:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe update]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=50399</guid> <description><![CDATA[It is the second Tuesday of the month again and this means security patch day at Microsoft and Adobe. Adobe has just released a security bulletin for Adobe Reader and Acrobat that fix several critical vulnerabilities in versions of the pdf software. Vulnerabilities affect Adobe Reader X and earlier versions for Windows and Macintosh, Adobe [...]]]></description> <content:encoded><![CDATA[<p>It is the second Tuesday of the month again and this means security patch day at Microsoft and Adobe. Adobe has just released a security bulletin for Adobe Reader and Acrobat that fix several critical vulnerabilities in versions of the pdf software.</p><p>Vulnerabilities affect Adobe Reader X and earlier versions for Windows and Macintosh, Adobe Reader 9.4.2 and earlier for Unix, and Adobe Acrobat 10.1 and earlier for Windows and Macintosh.</p><p>Adobe as usually recommends to update Adobe Reader to the new version released today. This is Adobe Reader 10.1.1 for Windows and Macintosh, and Adobe Raeder 9.4.5 for Unix, as well as Adobe Acrobat 10.1.1 for Windows and Macintosh.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-24.html">offers</a> vulnerability details and download links for all Adobe Reader and Acrobat updates.</p><p>Microsoft today has released five security bulletins that affect Microsoft Windows, Microsoft Server Software and Microsoft Office. The maximum severity of all five bulletins is Important, the second highest rating available.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/09/windows-updates.png" alt="windows-updates" title="windows-updates" width="592" height="329" class="alignnone size-full wp-image-50410" /></p><p>Windows Update is already picking up the updates online. Windows users can check for updates in their operating system to download and install the patches right now.</p><p>You find summaries for all five bulletins below. Follow the link for detailed descriptions of each security bulletin.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-070">MS11-070</a> &#8211; Vulnerability in WINS Could Allow Elevation of Privilege (2571621) &#8211; This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow elevation of privilege if a user received a specially crafted WINS replication packet on an affected system running the WINS service. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-071">MS11-071</a> &#8211; Vulnerability in Windows Components Could Allow Remote Code Execution (2570947) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate rich text format file (.rtf), text file (.txt), or Word document (.doc) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-072">MS11-072</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1986 and CVE-2011-1987.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-073">MS11-073</a> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file or if a user opens a legitimate Office file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited either of the vulnerabilities could gain the same user rights as the logged on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-074">MS11-074</a> &#8211; Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858) &#8211; This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft SharePoint and Windows SharePoint Services. The most severe vulnerabilities could allow elevation of privilege if a user clicked on a specially crafted URL or visited a specially crafted Web site. For the most severe vulnerabilities, Internet Explorer 8 and Internet Explorer 9 users browsing to a SharePoint site in the Internet Zone are at a reduced risk because, by default, the XSS Filter in Internet Explorer 8 and Internet Explorer 9 helps to block the attacks in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9, however, is not enabled by default in the Intranet Zone.</li></ul><p>You find deployment priority information and the severity index <a
href="http://blogs.technet.com/b/msrc/archive/2011/09/13/more-on-diginotar-certificates-and-september-bulletins.aspx">at the</a> Technet blog.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Security Updates August 2011</title><link>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/</link> <comments>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/#comments</comments> <pubDate>Wed, 10 Aug 2011 12:35:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player update]]></category> <category><![CDATA[security bulletin]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=48865</guid> <description><![CDATA[Adobe has synced their security release schedule with that of Microsoft. It is therefor not surprising that the company announced yesterday the availability of security updates for several of their products. Security updates were released for Adobe Shockwave Player, Flash Media Server, Adobe Flash Player, Adobe Photoshop CS5 and RoboHelp. All security issues have received [...]]]></description> <content:encoded><![CDATA[<p>Adobe has synced their security release schedule with that of Microsoft. It is therefor not surprising that the company announced yesterday the availability of security updates for several of their products. Security updates were released for Adobe Shockwave Player, Flash Media Server, Adobe Flash Player, Adobe Photoshop CS5 and RoboHelp.</p><p>All security issues have received the maximum severity rating of critical, with the exception of the one for RoboHelp which received one of important instead.</p><p>The Flash Player update fixes several critical vulnerabilities in all Adobe Flash Player versions for Windows, Macintosh, Linux, Solaris and Android. Versions that are affected by the vulnerability are Flash Player 1.0.3.181.36 and earlier on all supported systems (Android 10.3.185.25 and earlier).</p><p>A successful exploit of a vulnerability could cause a crash and the successful taking control of the system in the process.</p><p>Adobe recommends that all users update Adobe Flash Player as soon as possible to protect their operating system and data from exploits.</p><p>The latest version of Adobe Flash Player can be downloaded <a
href="http://get.adobe.com/flashplayer/">from</a> Adobe&#8217;s Download Center or in the case of Android from the Android Marketplace.</p><p>Windows users can furthermore use the Flash Player Settings Manager that is part of the Windows Control Panel to check for updates. Here it is furthermore possible to check the Flash Player version that is installed on the system. The path is Control Panel > Flash Player (32-bit) > Advanced. Users with a 64-bit version of Flash Player installed need to change the 32-bit to 64-bit in the path.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/adobe-flash-player-settings-manager.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/adobe-flash-player-settings-manager.png" alt="adobe-flash-player-settings-manager" title="adobe-flash-player-settings-manager" width="475" height="430" class="alignnone size-full wp-image-48867" /></a></p><p>Additional information <a
href="http://www.adobe.com/support/security/bulletins/apsb11-21.html">about the</a> Flash Player vulnerabilities are available on Adobe&#8217;s security bulletin page.</p><p>Google Chrome users, who do not have Flash installed separately, have received an update by now that has updated their internal version of Flash to the latest version.</p><p>Happy updating everyone.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Patch Day August 2011 Overview</title><link>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/</link> <comments>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/#comments</comments> <pubDate>Wed, 10 Aug 2011 06:47:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=48837</guid> <description><![CDATA[Microsoft yesterday evening released this month&#8217;s security patches for their software products. The 13 security bulletins fix security related issues in Microsoft products such as the Windows operating system, Microsoft Office, the .Net Framework and Internet Explorer. Two of the security bulletins have received a critical severity rating, the highest possible rating while nine have [...]]]></description> <content:encoded><![CDATA[<p>Microsoft yesterday evening released this month&#8217;s security patches for their software products. The 13 security bulletins fix security related issues in Microsoft products such as the Windows operating system, Microsoft Office, the .Net Framework and Internet Explorer. Two of the security bulletins have received a critical severity rating, the highest possible rating while nine have received an important rating and two a moderate one. Please note that this is the maximum severity rating, the rating may be lower for specific products.</p><p>All in all, the bulletins address 22 vulnerabilities in Microsoft products. The two critical updates address issues in Internet Explorer and DNS Server.</p><p>Microsoft has <a
href="http://blogs.technet.com/b/msrc/">released</a> deployment priorities and the severity and exploitability index. (click on the images for full size)</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/bulletin-deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/bulletin-deployment-priority-600x337.png" alt="bulletin-deployment-priority" title="bulletin-deployment-priority" width="600" height="337" class="alignnone size-medium wp-image-48839" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/severity-exploitability-index-600x337.png" alt="severity-exploitability-index" title="severity-exploitability-index" width="600" height="337" class="alignnone size-medium wp-image-48840" /></a></p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx">MS11-057</a> &#8211; Cumulative Security Update for Internet Explorer (2559049) &#8211; This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-058.mspx">MS11-058</a> &#8211; Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485) &#8211; This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker registers a domain, creates an NAPTR DNS resource record, and then sends a specially crafted NAPTR query to the target DNS server. Servers that do not have the DNS role enabled are not at risk.</li></ul><p>The bulletins that fix important issues.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-059.mspx">MS11-059</a> &#8211; Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate Excel file (such as a .xlsx file) that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-060.mspx">MS11-060</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-061.mspx">MS11-061</a> &#8211; Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250) &#8211; This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 prevents this attack for its users when browsing to a Remote Desktop Web Access server in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 is not enabled by default in the Intranet Zone.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-062.mspx">MS11-062</a> &#8211; Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454) &#8211;<br
/> This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.</p><p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability and take complete control over the affected system. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-063.mspx">MS11-063</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680) &#8211;<br
/> This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-064.mspx">MS11-064</a> &#8211; Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow denial of service if an attacker sends a sequence of specially crafted Internet Control Message Protocol (ICMP) messages to a target system or sends a specially crafted URL request to a server that is serving Web content and has the URL-based Quality of Service (QoS) feature enabled.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-065.mspx">MS11-065</a> &#8211; Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222) &#8211; This security update resolves a privately reported vulnerability in the Remote Desktop Protocol. The vulnerability could allow denial of service if an affected system received a sequence of specially crafted RDP packets. Microsoft has also received reports of limited, targeted attacks attempting to exploit this vulnerability. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-066.mspx">MS11-066</a> &#8211; Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943) &#8211; This security update resolves a privately reported vulnerability in ASP.NET Chart controls. The vulnerability could allow information disclosure if an attacker sent a specially crafted GET request to an affected server hosting the Chart controls. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker&#8217;s user rights directly, but it could be used to retrieve information that could be used to further compromise the affected system. Only web applications using Microsoft Chart Control are affected by this issue. Default installations of the .NET Framework are not affected.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-067.mspx">MS11-067</a> &#8211; Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230) &#8211; This security update resolves a privately reported vulnerability in Microsoft Report Viewer. The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.</li></ul><p>And finally the moderate bulletins.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-068.mspx">MS11-068</a> &#8211; Vulnerability in Windows Kernel Could Allow Denial of Service (2556532) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user visits a network share (or visits a Web site that points to a network share) containing a specially crafted file. In all cases, however, an attacker would have no way to force a user to visit such a network share or Web site. Instead, an attacker would have to convince a user to do so, typically by getting the user to click a link in an e-mail message or Instant Messenger message.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-069.mspx">MS11-069</a> &#8211; Vulnerability in .NET Framework Could Allow Information Disclosure (2567951)  &#8211; This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow information disclosure if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</li></ul><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/windows-updates.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/windows-updates.png" alt="windows-updates" title="windows-updates" width="574" height="270" class="alignnone size-full wp-image-48841" /></a></p><p>The updates are as usually available via Windows Update and Microsoft&#8217;s Download Center (even though I would not recommend using this at this time as it is a mess).</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/08/10/microsoft-patch-day-august-2011-overview/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Microsoft Security Patches for July 2011</title><link>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/</link> <comments>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/#comments</comments> <pubDate>Tue, 12 Jul 2011 20:25:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft download center]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47740</guid> <description><![CDATA[It is the second Tuesday of the month which means it is patch day over at Microsoft. The Redmond based company has released a total of four security bulletins that month. One bulletin has received a maximum severity rating of critical, while the three others one of important. The critical vulnerability addresses a issue in [...]]]></description> <content:encoded><![CDATA[<p>It is the second Tuesday of the month which means it is patch day over at Microsoft. The Redmond based company has released a total of four security bulletins that month. One bulletin has received a maximum severity rating of critical, while the three others one of important. The critical vulnerability addresses a issue in the Bluetooth stack that could allow remote code execution. Affected are only Microsoft Windows Vista and Windows 7, and not Windows XP or earlier operating systems.</p><p>Two of the three remaining vulnerabilities address issues in the Windows operating system as well. Security bulletin MS11-054 describes a vulnerability in Windows Kernel-Mode drivers that could allow elevation of privileges, while bulletin MS11-056 a vulnerability in the Windows Client and Server run-time subsystem.</p><p>All supported Microsoft client and server operating systems are affected by the two security vulnerabilities. The last issue is a vulnerability in Microsoft Visio.</p><p>Here is an overview of all four security bulletins with links to their pages at the Microsoft Technet website.</p><ul><li> <a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-053.mspx">MS11-053</a> &#8211; Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-054.mspx">MS11-054</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-056.mspx">MS11-056</a> &#8211; Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-055.mspx">MS11-055</a> &#8211; Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847)</li></ul><p>The patches are as usual already available via Windows Update, Microsoft Update and via the Microsoft Download Center. The monthly exploit mitigation guide at the Technet Security blog provides additional information about the vulnerabilities and deployment strategies.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/07/7367.201107-severity-xi.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/7367.201107-severity-xi-600x337.png" alt="" title="7367.201107-severity-xi" width="600" height="337" class="alignnone size-medium wp-image-47741" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/07/7418.201107-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/7418.201107-deployment-600x337.png" alt="" title="7418.201107-deployment" width="600" height="337" class="alignnone size-medium wp-image-47742" /></a></p><p>Probably the easiest way to deploy the security updates to a single system is via Windows Update.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/windows-update.png" alt="windows update" title="windows update" width="575" height="280" class="alignnone size-full wp-image-47743" /></p><p>Just click on Start > All Programs > Windows Update to open the update screen. You may need to click on Check for updates on the left sidebar if your computer has been up for some time and the updates are not displayed directly in the main window.</p><p>Have you updated your system yet? Am I the only user who feels that Microsoft&#8217;s Download Center is not usable at all at the moment?</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/07/12/microsoft-security-patches-for-july-2011/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft March 2011 Patch Day Overview</title><link>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/</link> <comments>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/#comments</comments> <pubDate>Wed, 09 Mar 2011 09:05:54 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42277</guid> <description><![CDATA[Microsoft has released new security patches on yesterday&#8217;s Patch Day that address vulnerabilities in various Microsoft products including Microsoft Windows and Microsoft Office. The updates that have been released are already available via Windows Update and the Microsoft Download Center. One of the vulnerabilities has a maximum severity rating of critical, the highest possible. The [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released new security patches on yesterday&#8217;s Patch Day that address vulnerabilities in various Microsoft products including Microsoft Windows and Microsoft Office. The updates that have been released are already available via Windows Update and the Microsoft Download Center.</p><p>One of the vulnerabilities has a maximum severity rating of critical, the highest possible. The two remaining vulnerabilities are rated as important.</p><p>A critical vulnerability has been discovered in Windows Media that could be exploited for remote code execution. The vulnerability has been rated as critical for all Microsoft client operating systems, from Windows XP to Windows 7. Windows Server 2008 R2 is the only server product affected, the vulnerability received a rating of important here.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-severity.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-severity-550x309.png" alt="march 2011 patch day severity" title="march 2011 patch day severity" width="550" height="309" class="alignnone size-medium wp-image-42278" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/march-2011-patch-day-deployment-550x309.png" alt="march 2011 patch day deployment" title="march 2011 patch day deployment" width="550" height="309" class="alignnone size-medium wp-image-42279" /></a></p><p>Below are links to each security bulletin. The Bulletins offer information about the affected products, severity rating and non-affected software.</p><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-015.mspx">MS11-015</a> &#8211; Vulnerabilities in Windows Media Could Allow Remote Code Execution (2510030) &#8211; This security update resolves one publicly disclosed vulnerability in DirectShow and one privately reported vulnerability in Windows Media Player and Windows Media Center. The more severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Digital Video Recording (.dvr-ms) file. In all cases, a user cannot be forced to open the file; for an attack to be successful, a user must be convinced to do so.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-017.mspx">MS11-017</a> &#8211; Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2508062) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user opens a legitimate Remote Desktop configuration (.rdp) file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-016.mspx">MS11-016</a> &#8211; Vulnerability in Microsoft Groove Could Allow Remote Code Execution (2494047) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Groove that could allow remote code execution if a user opens a legitimate Groove-related file that is located in the same network directory as a specially crafted library file. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><p>Users can update their Windows operating system and Microsoft Office via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a>, the <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">Microsoft Download Center</a> or by downloading the <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=ab55654c-c685-4316-93fc-e3a80cccac71&#038;pf=true">March 2011</a> Security Release ISO image.</p><p>In other news, Microsoft is still working on a fix for the MHTML-related vulnerability that was discovered in January. Additional information are available at the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/09/microsoft-march-2011-patch-day-overview/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>Microsoft Security Bulletin Overview February 2011</title><link>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/</link> <comments>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/#comments</comments> <pubDate>Tue, 08 Feb 2011 18:17:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39715</guid> <description><![CDATA[Microsoft has just enabled downloads for today&#8217;s security patches on Windows Update. Today&#8217;s Patch Day brings 12 security bulletins that fix vulnerabilities of various severity affecting the Microsoft Windows operating system, Internet Explorer and Microsoft Office. Three of the vulnerabilities have a maximum severity rating of critical, the highest possible rating. The remaining 11 have [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just enabled downloads for today&#8217;s security patches on Windows Update. Today&#8217;s Patch Day brings 12 security bulletins that fix vulnerabilities of various severity affecting the Microsoft Windows operating system, Internet Explorer and Microsoft Office. Three of the vulnerabilities have a maximum severity rating of critical, the highest possible rating. The remaining 11 have a maximum severity rating of imporant.</p><p>Windows users can check for the updates by opening Windows Update which is linked from the Windows start menu. There it is possible to check for new updates which needs to be done if the PC has been running for some time today.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/02/windows-update.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/02/windows-update-550x253.jpg" alt="windows update" title="windows update" width="550" height="253" class="alignnone size-medium wp-image-39716" /></a></p><p>The <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">security bulletin summary</a> for February 2011 offers in depth information about the updates and the affected applications.</p><p>All individual security bulletins are listed and linked below as well.</p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx">MS11-003</a> &#8211; Cumulative Security Update for Internet Explorer (2482017) &#8211; This security update resolves two privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user opens a legitimate HTML file that loads a specially crafted library file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-006.mspx">MS11-006</a> &#8211; Vulnerability in Windows Shell Graphics Processing Could Allow Remote Code Execution (2483185) &#8211; This security update resolves a publicly disclosed vulnerability in the Windows Shell graphics processor. The vulnerability could allow remote code execution if a user views a specially crafted thumbnail image. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-007.mspx">MS11-007</a> &#8211; Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2485376) &#8211; This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow remote code execution if a user views content rendered in a specially crafted CFF font. In all cases, an attacker would have no way to force users to view the specially crafted content. Instead, an attacker would have to convince users to visit a Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-004.mspx">MS11-004</a> &#8211; Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution (2489256) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Internet Information Services (IIS) FTP Service. The vulnerability could allow remote code execution if an FTP server receives a specially crafted FTP command. FTP Service is not installed by default on IIS.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-005.mspx">MS11-005</a> &#8211; Vulnerability in Active Directory Could Allow Denial of Service (2478953) &#8211; This security update resolves a publicly disclosed vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sent a specially crafted packet to an affected Active Directory server. The attacker must have valid local administrator privileges on the domain-joined computer in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-008.mspx">MS11-008</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-009.mspx">MS11-009</a> &#8211; Vulnerability in JScript and VBScript Scripting Engines Could Allow Information Disclosure (2475792) &#8211; This security update resolves a privately reported vulnerability in the JScript and VBScript scripting engines. The vulnerability could allow information disclosure if a user visited a specially crafted Web site. An attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-010.mspx">MS11-010</a> &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2476687) &#8211; This security update resolves a privately reported vulnerability in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003. The vulnerability could allow elevation of privilege if an attacker logs on to a user&#8217;s system and starts a specially crafted application that continues running after the attacker logs off in order to obtain the logon credentials of subsequent users. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-011.mspx">MS11-011</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2393802) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-012.mspx">MS11-012</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2479628) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-013.mspx">MS11-013</a> &#8211; Vulnerabilities in Kerberos Could Allow Elevation of Privilege (2496930) &#8211; This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege if a local, authenticated attacker installs a malicious service on a domain-joined computer.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-014.mspx">MS11-014</a> &#8211; Vulnerability in Local Security Authority Subsystem Service Could Allow Local Elevation of Privilege (2478960) &#8211; This security update resolves a privately reported vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows XP and Windows Server 2003.<p>The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li></ul><p>The updates can also be downloaded directly and individually <a
href="http://www.microsoft.com/downloads/en/default.aspx">from the</a> Microsoft Download Center. Check out our detailed <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> guide for additional information and tips.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/08/microsoft-security-bulletin-overview-february-2011-2/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Bulletin Overview January 2011</title><link>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/</link> <comments>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/#comments</comments> <pubDate>Tue, 11 Jan 2011 23:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=38900</guid> <description><![CDATA[The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>The second Tuesday of a month is Microsoft&#8217;s patch day where the software company releases security patches and fixes for its products. The first patch day of the year 2011 brings two security bulletins that patch vulnerabilities in the Windows operating system. MS11-002 patches vulnerabilities in Microsoft Data Access Components that could allow remote code execution. The maximum severity rating of the vulnerability is critical, the highest possible rating.</p><p>A closer look at the security vulnerability reveals that is is rated critical for all 32-bit and 64-bit Windows client operating systems from Windows XP to Windows 7. The same vulnerability is rated as important for all server based operating systems.</p><p>The second vulnerability, MS11-001, has a maximum severity rating of important. It fixes a vulnerability in the Windows Backup Manager that could allow remote code execution. The vulnerability affects only the Windows Vista operating system.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-002.mspx">MS11-002</a> &#8211; Vulnerabilities in Microsoft Data Access Components Could Allow Remote Code Execution (2451910) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Data Access Components. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS11-001.mspx">MS11-001</a> &#8211; Vulnerability in Windows Backup Manager Could Allow Remote Code Execution (2478935) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Backup Manager. The vulnerability could allow remote code execution if a user opens a legitimate Windows Backup Manager file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the legitimate file from that location, which in turn could cause Windows Backup Manager to load the specially crafted library file.</li></ul><p><strong>Severity and Exploitability Index</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6011.sev-exp-1101-550x309.png" alt="" title="6011.sev-exp-1101" width="550" height="309" class="alignnone size-medium wp-image-38901" /></a></p><p><strong>Bulletin Deployment Priority</strong></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/01/6153.deploy_2D00_1101-550x309.png" alt="6153.deploy_2D00_1101" title="6153.deploy_2D00_1101" width="550" height="309" class="alignnone size-medium wp-image-38902" /></a></p><p>The images have been taken from the <a
href="http://blogs.technet.com/b/msrc/archive/2011/01/11/january-2011-security-bulletins.aspx">Technet</a> announcement which offers further information about the vulnerabilities and patch deployment.</p><p>Windows users are advised to apply the patches as soon as possible to protect their system from possible exploits. The patches can be applied directly via Windows Update or <a
href="http://www.microsoft.com/downloads/en/default.aspx?pf=true">directly from</a> Microsoft Download.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Bulletin December 2010</title><link>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/</link> <comments>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/#comments</comments> <pubDate>Wed, 15 Dec 2010 08:49:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37961</guid> <description><![CDATA[Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer. When we look at the severity rating of those vulnerabilities we notice that two of [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer.</p><p>When we look at the severity rating of those vulnerabilities we notice that two of the bulletins have a maximum severity rating of critical while the remaining ones a rating of important with the exception of one that has been rated as moderate.</p><p>Maximum severity rating means that at least one Microsoft product is affect this way by the vulnerability. The critical vulnerability MS10-090 affects Internet Explorer 6 to Internet Explorer 8 and is critical on all Microsoft operating systems. Vulnerability MS10-091 on the other hand is critical on Windows Vista and Windows 7 but not on Windows XP, something that we do not see very often thanks to improved security of the two operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority-550x309.png" alt="deployment priority" title="deployment priority" width="550" height="309" class="alignnone size-medium wp-image-37962" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index-550x309.png" alt="severity exploitability index" title="severity exploitability index" width="550" height="309" class="alignnone size-medium wp-image-37963" /></a></p><p>The updates are already available via Windows Update and the <a
href="http://www.microsoft.com/downloads/en/default.aspx">Microsoft Download Center</a>.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-090.mspx">MS10-090</a> &#8211; Cumulative Security Update for Internet Explorer (2416400) &#8211; This security update resolves four privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-091.mspx">MS10-091</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199) &#8211; This security update resolves several privately reported vulnerabilities in the Windows Open Type Font (OTF) driver that could allow remote code execution. An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a> &#8211; Vulnerability in Task Scheduler Could Allow Elevation of Privilege (2305420) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Task Scheduler. The vulnerability could allow elevation of privilege if an attacker logged on to an affected system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-093.mspx">MS10-093</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Movie Maker file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx">MS10-094</a> &#8211; Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Media Encoder. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-095.mspx">MS10-095</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2385678) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file type such as .eml and .rss (Windows Live Mail) or .wpost (Microsoft Live Writer) located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx">MS10-096</a> &#8211; Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Address Book. The vulnerability could allow remote code execution if a user opens a Windows Address Book file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx">MS10-097</a> &#8211; Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105) &#8211;  This security update resolves a publicly disclosed vulnerability in the Internet Connection Signup Wizard of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-098.mspx">MS10-098</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) &#8211; This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-099.mspx">MS10-099</a> &#8211; Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591) &#8211; This security update addresses a privately reported vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx">MS10-100</a> &#8211; Vulnerability in Consent User Interface Could Allow Elevation of Privilege (2442962) &#8211; This security update resolves a privately reported vulnerability in the Consent User Interface (UI). The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application on an affected system. An attacker must have valid logon credentials and the SeImpersonatePrivilege and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-101.mspx">MS10-101</a> &#8211; Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559) &#8211; This security update resolves a privately reported vulnerability in the Netlogon RPC Service on affected versions of Windows Server that are configured to serve as domain controllers. The vulnerability could allow denial of service if an attacker sends a specially crafted RPC packet to the Netlogon RPC Service interface on an affected system. An attacker requires administrator privileges on a machine that is joined to the same domain as the affected domain controller in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-102.mspx">MS10-102</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2345316) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx">MS10-103</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292970) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-104.mspx">MS10-104</a> &#8211; Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution (2455005) &#8211; This security update resolves a privately reported vulnerability in Microsoft SharePoint. The vulnerability could allow remote code execution in the security context of a guest user if an attacker sent a specially crafted SOAP request to the Document Conversions Launcher Service in a SharePoint server environment that is using the Document Conversions Load Balancer Service. By default, the Document Conversions Load Balancer Service and Document Conversions Launcher Service are not enabled in Microsoft Office SharePoint Server 2007.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx">MS10-105</a> &#8211; Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-106.mspx">MS10-106</a> &#8211; Vulnerability in Microsoft Exchange Server Could Allow Denial of Service (2407132) &#8211; This security update resolves a privately reported vulnerability in Microsoft Exchange Server. The vulnerability could allow denial of service if an authenticated attacker sent a specially crafted network message to a computer running the Exchange service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li></ul><p>Additional information are available at the <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-dec.mspx">security bulletin summary</a> and the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Bulletin November 2010</title><link>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/</link> <comments>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/#comments</comments> <pubDate>Wed, 10 Nov 2010 08:33:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[forefront]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36710</guid> <description><![CDATA[Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released information and patches of this month&#8217;s patch day. It is promising that there is no patch for Windows in this month&#8217;s patch day. The three bulletins that have been released fix security issues in Microsoft Office and Microsoft forefront United Access Gateway. One of the MS Offices bulletins has a maximum severity rating of critical, the other two bulletins an important rating. Lets take a closer look at the bulletins.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-087.mspx">MS10-087</a> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930) &#8211; This security update resolves one publicly disclosed vulnerability and four privately reported vulnerabilities in Microsoft Office. The most severe vulnerability could allow remote code execution if a user opens or previews a specially crafted RTF e-mail message. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-088.mspx">MS10-088</a> &#8211; Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-089.mspx">MS10-089</a> &#8211; Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074) &#8211; This security update resolves four privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow elevation of privilege if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</li></ul><p>The security patches are as usually available via Windows Update, Microsoft Update and <a
href="http://www.microsoft.com/downloads/en/default.aspx">direct</a> download. Office and Forefront users should patch the security vulnerabilities as soon as possible, everyone else can relax this month and wait for things to come. (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-nov.mspx">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/10/microsoft-security-bulletin-november-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Releases September Security Patches</title><link>http://www.ghacks.net/2010/09/14/microsoft-releases-september-security-patches/</link> <comments>http://www.ghacks.net/2010/09/14/microsoft-releases-september-security-patches/#comments</comments> <pubDate>Tue, 14 Sep 2010 20:44:46 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=34436</guid> <description><![CDATA[Microsoft has released this month&#8217;s security patches for their operating systems and applications. The patches and updates are already available via Windows Update and Microsoft Download, and it is recommended to update the operating system as soon as possible to protect it from exploits targeting those vulnerabilities. A total of nine bulletins has been released [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released this month&#8217;s security patches for their operating systems and applications. The patches and updates are already available via Windows Update and Microsoft Download, and it is recommended to update the operating system as soon as possible to protect it from exploits targeting those vulnerabilities.</p><p>A total of nine bulletins has been released by Microsoft of which four have received a maximum vulnerability impact rating of critical, the highest possible rating. As usual, not all operating systems and applications are affected with the same severity. Microsoft&#8217;s latest desktop operating system Windows 7 for instance is either not affected by the critical vulnerabilities, or with a lower severity of important.</p><div
id="attachment_34437" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/windows-updates.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/windows-updates-500x241.png" alt="windows updates" title="windows updates" width="500" height="241" class="size-medium wp-image-34437" /></a><p
class="wp-caption-text">windows updates</p></div><p>Below are the vulnerability summaries for all nine bulletins that have been released by Microsoft in September 2010:</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-061.mspx">MS10-061</a> &#8211; Vulnerability in Print Spooler Service Could Allow Remote Code Execution (2347290) &#8211; This security update resolves a publicly disclosed vulnerability in the Print Spooler service. The vulnerability could allow remote code execution if an attacker sends a specially crafted print request to a vulnerable system that has a print spooler interface exposed over RPC. By default, printers are not shared on any currently supported Windows operating system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-062.mspx">MS10-062</a> &#8211; Vulnerability in MPEG-4 Codec Could Allow Remote Code Execution (975558) &#8211; This security update resolves a privately reported vulnerability in MPEG-4 codec. The vulnerability could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx">MS10-063</a> &#8211; Vulnerability in Unicode Scripts Processor Could Allow Remote Code Execution (2320113) &#8211; This security update resolves a privately reported vulnerability in the Unicode Scripts Processor. The vulnerability could allow remote code execution if a user viewed a specially crafted document or Web page with an application that supports embedded OpenType fonts. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-064.mspx">MS10-064</a> &#8211; Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (2315011) &#8211; This security update resolves a privately reported vulnerability. The vulnerability could allow remote code execution if a user opened or previewed a specially crafted e-mail message using an affected version of Microsoft Outlook that is connected to an Exchange server with Online Mode. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx">MS10-065</a> &#8211; Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution (2267960) &#8211; This security update resolves two privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Information Services (IIS). The most severe of these vulnerabilities could allow remote code execution if a client sends a specially crafted HTTP request to the server. An attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-066.mspx">MS10-066</a> &#8211; Vulnerability in Remote Procedure Call Could Allow Remote Code Execution (982802) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if an attacker sent a specially crafted RPC response to a client-initiated RPC request. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker must convince the user to initiate an RPC connection to a malicious server under the attacker&#8217;s control. An attacker could not remotely exploit this vulnerability without user interaction.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-067.mspx">MS10-067</a> &#8211; Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2259922) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opened a specially crafted file using WordPad. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-068.mspx">MS10-068</a> &#8211; Vulnerability in Local Security Authority Subsystem Service Could Allow Elevation of Privilege (983539) &#8211; This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow elevation of privilege if an authenticated attacker sent specially crafted Lightweight Directory Access Protocol (LDAP) messages to a listening LSASS server. In order to successfully exploit this vulnerability, an attacker must have a member account within the target Windows domain. However, the attacker does not need to have a workstation joined to the Windows domain.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-069.mspx">MS10-069</a> &#8211; Vulnerability in Windows Client/Server Runtime Subsystem Could Allow Elevation of Privilege (2121546) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logged on to an affected system that is configured with a Chinese, Japanese, or Korean system locale. An attacker who successfully exploited this vulnerability could then install programs; view, change, or delete data; or create new accounts with full user rights.</li></ul><p>Microsoft&#8217;s <a
href="http://blogs.technet.com/b/msrc/archive/2010/09/13/september-2010-security-bulletin-release.aspx">Jerry Bryant</a> has posted graphs for the deployment priority and severity exportability index in a blog post.</p><div
id="attachment_34438" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/severity-explotability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/severity-explotability-index-500x281.png" alt="severity explotability index" title="severity explotability index" width="500" height="281" class="size-medium wp-image-34438" /></a><p
class="wp-caption-text">severity exportability index</p></div><div
id="attachment_34439" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/09/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/09/deployment-priority-500x281.png" alt="deployment priority" title="deployment priority" width="500" height="281" class="size-medium wp-image-34439" /></a><p
class="wp-caption-text">deployment priority</p></div><p>Happy patching everyone.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/14/microsoft-releases-september-security-patches/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Microsoft Out Of Band Security Update Released</title><link>http://www.ghacks.net/2010/08/02/microsoft-out-of-band-security-update-released/</link> <comments>http://www.ghacks.net/2010/08/02/microsoft-out-of-band-security-update-released/#comments</comments> <pubDate>Mon, 02 Aug 2010 21:48:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patch]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=30109</guid> <description><![CDATA[Microsoft as expected has just released an out of band security update for the Windows operating system that fixes a critical security vulnerable. The vulnerability affects all Microsoft operating systems that have been released in the past years, including Windows XP, Windows Vista, Windows 7, and the Windows Server product line. The severity of the [...]]]></description> <content:encoded><![CDATA[<p>Microsoft as <a
href="http://www.ghacks.net/2010/07/31/except-out-of-band-windows-security-release-on-august-2/">expected</a> has just released an out of band security update for the Windows operating system that fixes a critical security vulnerable. The vulnerability affects all Microsoft operating systems that have been released in the past years, including Windows XP, Windows Vista, Windows 7, and the Windows Server product line.</p><p>The severity of the issue and the fact that the security vulnerability was already exploited actively made the out of band release a necessity.</p><p><span
id="more-30109"></span><br
/><blockquote>This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p></blockquote><div
id="attachment_30110" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/08/windows-security-update.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/08/windows-security-update-500x204.png" alt="windows security update" title="windows security update" width="500" height="204" class="size-medium wp-image-30110" /></a><p
class="wp-caption-text">windows security update</p></div><p>The patch is available via Windows Update, or <a
href="http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&#038;freetext=security%20update">via</a> Microsoft Download. Windows users are encouraged to download and install the patch as soon as possible to protect their operating system from attacks exploiting the issue.</p><p><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx">Additional</a> information about the issue, deployment of the patch and vulnerability information are available at the Microsoft Security Bulletin.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/08/02/microsoft-out-of-band-security-update-released/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Microsoft Security Updates June 2010</title><link>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/</link> <comments>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/#comments</comments> <pubDate>Tue, 08 Jun 2010 18:41:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26349</guid> <description><![CDATA[Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of 34 30 different security vulnerabilities. The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of <del
datetime="2010-06-08T20:06:40+00:00">34</del> 30 different security vulnerabilities.</p><p>The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed on computer systems without Internet connection.</p><p><span
id="more-26349"></span><div
id="attachment_26350" class="wp-caption alignnone" style="width: 509px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/06/windows_update-499x248.png" alt="windows update" title="windows update" width="499" height="248" class="size-medium wp-image-26350" /><p
class="wp-caption-text">windows update</p></div></p><p>The severity rating differs depending on the operating system and software version installed. Three security bulletins have a maximum security rating of critical, the most severe one, while the remaining seven are all rated as important.</p><p>Vulnerabilities affect various Windows operating systems from Windows 2000 to Windows 7, Microsoft Office, Internet Explorer, Microsoft Server and the Microsoft .net Framework.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx">MS10-033</a> &#8211; Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (980195) &#8211; This security update addresses two privately reported vulnerabilities for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Vista, and Windows 7, and Moderate for all supported editions of Windows Server 2003, Windows Server2008, and Windows Server 2008 R2.<p>The vulnerabilities could allow remote code execution if a user views a specially crafted Web page that instantiates a specific ActiveX control with Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> &#8211; Cumulative Security Update for Internet Explorer (982381) &#8211; This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559) &#8211;<br
/> This security update resolves two publicly disclosed vulnerabilities and one privately reported vulnerability in the Windows kernel-mode drivers. The vulnerabilities could allow elevation of privilege if a user views content rendered in a specially crafted TrueType font.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> &#8211; Vulnerability in COM Validation in Microsoft Office Could Allow Remote Code Execution (983235) &#8211; This security update resolves a privately reported vulnerability in COM validation in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel, Word, Visio, Publisher, or PowerPoint file with an affected version of Microsoft Office. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful a user must open an attachment that is sent in an e-mail message.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-037.mspx">MS10-037</a> &#8211; Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Elevation of Privilege (980218) &#8211; This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow elevation of privilege if a user views content rendered in a specially crafted CFF font. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx">MS10-038</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) &#8211; This security update resolves fourteen privately reported vulnerabilities in Microsoft Office. The more severe vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> &#8211; Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2028554) &#8211; This security update resolves one publicly disclosed and two privately reported vulnerabilities in Microsoft SharePoint. The most severe vulnerability could allow elevation of privilege if an attacker convinced a user of a targeted SharePoint site to click on a specially crafted link.</li><li>MS10-040 &#8211; Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666) &#8211; This security update resolves a privately reported vulnerability in Internet Information Services (IIS). The vulnerability could allow remote code execution if a user received a specially crafted HTTP request. An attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx">MS10-041</a> &#8211; Vulnerability in Microsoft .NET Framework Could Allow Tampering (981343) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft .NET Framework. The vulnerability could allow data tampering in signed XML content without being detected. In custom applications, the security impact depends on how the signed content is used in the specific application. Scenarios in which signed XML messages are transmitted over a secure channel (such as SSL) are not affected by this vulnerability.</li></ul><p>It is advised to install the security patches immediately to protect the PC from exploits that are targeting unpatched computer systems. Additional information are provided by the <a
href="http://blogs.technet.com/b/srd/">Security Research &#038; Defense</a> team which offers additional information that are helpful for system administrators and advanced users.</p><p>Lastly there is the <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx">security bulletin</a> overview which lists all relevant information.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Internet Explorer Patch Released: Update Now</title><link>http://www.ghacks.net/2010/03/31/internet-explorer-patch-released-update-now/</link> <comments>http://www.ghacks.net/2010/03/31/internet-explorer-patch-released-update-now/#comments</comments> <pubDate>Wed, 31 Mar 2010 10:19:12 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Internet Explorer]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[internet explorer 8]]></category> <category><![CDATA[internet explorer patch]]></category> <category><![CDATA[internet explorer security]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[security bulletin]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24072</guid> <description><![CDATA[Microsoft has released an out-of-band security patch for Internet Explorer which fixes a security vulnerability that has been actively exploited on the Internet. The patch has caused some confusion as reported by Ed Bott since the the security vulnerability that caused the emergency update to be released is only affecting Internet Explorer 6 or IE7. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released an out-of-band security patch for Internet Explorer which fixes a security vulnerability that has been actively exploited on the Internet. The patch has caused some confusion as reported by <a
href="http://www.zdnet.com/blog/bott/yes-ie8-users-you-need-that-new-security-update/1921">Ed Bott</a> since the the security vulnerability that caused the emergency update to be released is only affecting Internet Explorer 6 or IE7.</p><p>The patch that Microsoft has released is however a cumulative update with patches that will fix Internet Explorer 8 security vulnerabilities as well.</p><p>The information posted by Microsoft reads:</p><blockquote><p>MS10-018 resolves Security Advisory 981374, addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is unaffected by the vulnerability addressed in the advisory</p></blockquote><p><span
id="more-24072"></span>MS10-018 is a cumulative update with the patch for Security Advisory 981374 being one of the patches included in the release. This basically means that Internet Explorer 8 is unaffected by that one vulnerability but affected by others that are included in the cumulative update as well. This is confirmed by the affected and unaffected software listing on the security bulletin page which lists the severity as critical for Internet Explorer 8 as well.</p><p>Windows users should install the update as soon as possible to protect their computer system from possible exploits. The update is also <a
href="http://www.microsoft.com/security/updates/bulletins/201003_oob.aspx">available</a> at the Microsoft Download site.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/31/internet-explorer-patch-released-update-now/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Patches July 2009</title><link>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/</link> <comments>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/#comments</comments> <pubDate>Wed, 15 Jul 2009 11:49:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14410</guid> <description><![CDATA[Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are pretty much all from Windows 2000 onwards although the severity rating varies depending on the operating system.</p><p>Critical ratings for Windows XP or Windows Server 2003 are usually important or moderate ratings for Windows Vista or Windows Server 2008 thanks to the increased security in those operating systems. Downloads are already available from various official sources including Automatic Updates, Windows Update or Microsoft Update.</p><p><span
id="more-14410"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx">MS09-028</a> &#8211; Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371) &#8211; This security update resolves two privately reported vulnerabilities in the Microsoft Windows component, Embedded OpenType (EOT) Font Engine. The vulnerabilities could allow remote code execution. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-029.mspx">MS09-029</a> &#8211; Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) &#8211; This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx">MS09-030</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (973346) &#8211; This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability in Microsoft Video ActiveX Control could allow remote code execution if a user views a specially crafted Web page with Internet Explorer, instantiating the ActiveX control. This ActiveX control was never intended to be instantiated in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-031.mspx">MS09-031</a> &#8211; Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856) &#8211; This security update resolves a privately reported vulnerability in Microsoft Virtual PC and Microsoft Virtual Server. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected guest operating system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032</a> -Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953) &#8211; This security update resolves a privately reported vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2006. The vulnerability could allow elevation of privilege if an attacker successfully impersonates an administrative user account for an ISA server that is configured for Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-033.mspx">MS09-033</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>It is recommended to install the Microsoft Security Patches as soon as possible to close the security vulnerabilities.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Bulletin May 2009</title><link>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/</link> <comments>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/#comments</comments> <pubDate>Wed, 13 May 2009 14:05:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security bulleting]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security vulnerability]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/</guid> <description><![CDATA[Microsoft has released the Security Bulletin for May 2009 which contains one Microsoft Office PowerPoint vulnerability which affects various editions of Microsoft Office but also the Microsoft Office PowerPoint Viewer and Microsoft Office Compatibility Pack. Affected are Microsoft Office PowerPoint editions in Microsoft Office 2000, Office XP, Office 2003 and Microsoft Office 2007. The security [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_office.jpg" alt="microsoft office" title="microsoft office" width="128" height="105" class="alignleft size-full wp-image-12120" />Microsoft has released the Security Bulletin for May 2009 which contains one Microsoft Office PowerPoint vulnerability which affects various editions of Microsoft Office but also the Microsoft Office PowerPoint Viewer and Microsoft Office Compatibility Pack. Affected are Microsoft Office PowerPoint editions in Microsoft Office 2000, Office XP, Office 2003 and Microsoft Office 2007. The security update is rated as critical for Microsoft Office 2000 editions and important for all other affected editions of Microsoft Office and software programs by Microsoft.</p><p><span
id="more-12792"></span><br
/><blockquote>This security update resolves a publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p></blockquote><p>The security update is available on Windows Update and Microsoft Update. Additional information and links can be found at the <a
href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">Security Bulletin</a> that has been created for the security vulnerability. Users of affected software programs are encouraged to perform the security update as soon as possible.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
