<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; security bulletins</title> <atom:link href="http://www.ghacks.net/tag/security-bulletins/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Security Updates April 2010</title><link>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/</link> <comments>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/#comments</comments> <pubDate>Tue, 13 Apr 2010 17:24:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[security bulletins]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows updates]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24511</guid> <description><![CDATA[Microsoft has just added the security updates for April 2010 to Windows Update from where every Windows user can download and install them on their operating system. A total of eleven security bulletins have been released that update the Windows operating system as well as other Microsoft software like Microsoft Office. The updates fix security [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has just added the security updates for April 2010 to Windows Update from where every Windows user can download and install them on their operating system.</p><p>A total of eleven security bulletins have been released that update the Windows operating system as well as other Microsoft software like Microsoft Office.</p><p>The updates fix security vulnerabilities in Microsoft applications and it is generally recommended to update the operating systems and applications as soon as possible to close the security holes and protect the systems from malicious attacks exploiting these vulnerabilities.</p><p>Five of the vulnerabilities have received a critical rating, the highest and most severe rating that vulnerabilities can get.</p><p><span
id="more-24511"></span><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010WindowsBulletins.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010WindowsBulletins-500x281.png" alt="April2010WindowsBulletins" title="April2010WindowsBulletins" width="500" height="281" class="alignnone size-medium wp-image-24513" /></a><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010RiskImpact.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010RiskImpact-500x281.png" alt="April2010RiskImpact" title="April2010RiskImpact" width="500" height="281" class="alignnone size-medium wp-image-24514" /></a><a
href="http://www.ghacks.net/wp-content/uploads/2010/04/April2010DeploymentPriority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/04/April2010DeploymentPriority-500x281.png" alt="April2010DeploymentPriority" title="April2010DeploymentPriority" width="500" height="281" class="alignnone size-medium wp-image-24515" /></a></p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-019.mspx">MS10-019</a> &#8211; Vulnerabilities in Windows Could Allow Remote Code Execution (981210) &#8211; This security update resolves two privately reported vulnerabilities in Windows Authenticode Verification that could allow remote code execution. An attacker who successfully exploited either vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx">MS10-020</a> &#8211; Vulnerabilities in SMB Client Could Allow Remote Code Execution (980232) &#8211; This security update resolves one publicly disclosed and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a specially crafted SMB server.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-025.mspx">MS10-025</a> &#8211; Vulnerability in Microsoft Windows Media Services Could Allow Remote Code Execution (980858) &#8211; This security update resolves a privately reported vulnerability in Windows Media Services running on Microsoft Windows 2000 Server. The vulnerability could allow remote code execution if an attacker sent a specially crafted transport information packet to a Microsoft Windows 2000 Server system running Windows Media Services. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate from outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. On Microsoft Windows 2000 Server, Windows Media Services is an optional component and is not installed by default.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-026.mspx">MS10-026</a> &#8211; Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (977816) &#8211;<br
/> This security update resolves a privately reported vulnerability in Microsoft MPEG Layer-3 audio codecs. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file containing an MPEG Layer-3 audio stream. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-027.mspx">MS10-027</a> &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (979402) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if Windows Media Player opened specially crafted media content hosted on a malicious Web site. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx">MS10-021</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (979683) &#8211; This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-022.mspx">MS10-022</a> &#8211; Vulnerability in VBScript Could Allow Remote Code Execution (981169) &#8211; This security update resolves a publicly disclosed vulnerability in VBScript on Microsoft Windows that could allow remote code execution. This security update is rated Important for Microsoft Windows 2000, Windows XP, and Windows Server 2003. On Windows Server 2008, Windows Vista, Windows 7, and Windows Server 2008 R2, the vulnerable code is not exploitable, however, as the code is present, this update is provided as a defense-in-depth measure and has no severity rating.<p>The vulnerability could allow remote code execution if a malicious Web site displayed a specially crafted dialog box on a Web page and a user pressed the F1 key, causing the Windows Help System to be started with a Windows Help File provided by the attacker. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx">MS10-023</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (981160)  &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx">MS10-024</a> &#8211; Vulnerabilities in Microsoft Exchange and Windows SMTP Service Could Allow Denial of Service (981832) &#8211; This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Exchange and Windows SMTP Service. The more severe of these vulnerabilities could allow denial of service if an attacker sent a specially crafted DNS response to a computer running the SMTP service. By default, the SMTP component is not installed on Windows Server 2003, Windows Server 2003 x64 Edition, or Windows XP Professional x64 Edition.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-028.mspx">MS10-028</a> &#8211; Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (980094) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-029.mspx">MS10-029</a> &#8211; Vulnerabilities in Windows ISATAP Component Could Allow Spoofing (978338) &#8211; This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Moderate for Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. Windows 7 and Windows Server 2008 R2 are not vulnerable because these operating systems include the feature deployed by this security update.<p>This vulnerability could allow an attacker to spoof an IPv4 address so that it may bypass filtering devices that rely on the source IPv4 address. The security update addresses the vulnerability by changing the manner in which the Windows TCP/IP stack checks the source IPv6 address in a tunneled ISATAP packet.</li></ul><p>The security updates can be downloaded by following the links listed above or by launching Windows Update or Microsoft Update to download and install them automatically on the computer system.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/feed/</wfw:commentRss> <slash:comments>18</slash:comments> </item> <item><title>Windows Security Updates September 2008</title><link>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/</link> <comments>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/#comments</comments> <pubDate>Tue, 09 Sep 2008 22:19:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[security bulletins]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=6893</guid> <description><![CDATA[Microsoft has released four Microsoft Security Bulletins for September 2008. All updates are rated critical and it is recommended to update the computer system running Windows operating systems or Microsoft software as soon as possible. The updates are available for pretty much every Windows operating system from Windows XP to Windows Server 2008. The easiest [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released four Microsoft Security Bulletins for September 2008. All updates are rated critical and it is recommended to update the computer system running Windows operating systems or Microsoft software as soon as possible.</p><p>The updates are available for pretty much every Windows operating system from Windows XP to Windows Server 2008. The easiest way to download the security updates is to use the official <a
href="http://update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&amp;&amp;thankspage=5">Windows Update</a> server from Microsoft, Automatic Updates or direct downloads from the <a
href="http://www.microsoft.com/downloads/en/results.aspx?DisplayLang=en&amp;nr=20&amp;freetext=security+update&amp;sortCriteria=date">Microsoft Download Center</a>.</p><p>Below are the names of the Microsoft Security Bulletin and the links to the Microsoft Security Bulletin website.</p><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-052.mspx">MS08-052</a> – Critical &#8211; Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-053.mspx">MS08-053</a> – Critical &#8211; Vulnerability in Windows Media Encoder 9 Could Allow Remote Code Execution (954156)</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/ms08-054.mspx">MS08-054</a> – Critical &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (954154)</li><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-055.mspx">MS08-055</a> – Critical &#8211; Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047)</li></ul><p><span
id="more-6893"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Security Updates for June 2008</title><link>http://www.ghacks.net/2008/06/11/microsoft-security-updates-for-june-2008/</link> <comments>http://www.ghacks.net/2008/06/11/microsoft-security-updates-for-june-2008/#comments</comments> <pubDate>Wed, 11 Jun 2008 08:27:41 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[security bulletins]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=4939</guid> <description><![CDATA[Microsoft finally released the Security Bulletin for June 2008 that contains links to seven updates for various Microsoft products. The bulletin lists three critical, three important and one moderate update with only various versions and editions of Microsoft Windows being affected. The updates are available through various means, most users will probably prefer to download [...]]]></description> <content:encoded><![CDATA[<p>Microsoft finally released <a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-jun.mspx">the</a> Security Bulletin for June 2008 that contains links to seven updates for various Microsoft products. The bulletin lists three critical, three important and one moderate update with only various versions and editions of Microsoft Windows being affected. The updates are available through various means, most users will probably prefer to download them from Windows Update.</p><p>Here is the list of updates that have been released. The easiest way to update them is by simply visiting Windows Update. If you want more control about the update process I suggest you follow the links below or use the <a
href="http://www.ghacks.net/2008/03/24/autopatcher-updater-104/">Autopatcher Updater</a> to download and install the updates.</p><p><span
id="more-4939"></span><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-030.mspx">MS08-030</a> (Critical)<br
/> <strong>Description:</strong> Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376)<br
/> <strong>Impact:</strong> Remote Code Execution</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-031.mspx">MS08-031</a> (Critical)<br
/> <strong>Description:</strong> Cumulative Security Update for Internet Explorer (950759)<br
/> <strong>Impact:</strong> Remote Code Execution</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-033.mspx">MS08-033</a> (Critical)<br
/> <strong>Description:</strong> Vulnerabilities in DirectX Could Allow Remote Code Execution (951698)<br
/> <strong>Impact:</strong> Remote Code Execution</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-034.mspx">MS08-034</a> (Important)<br
/> <strong>Description:</strong> Vulnerability in WINS Could Allow Elevation of Privilege (948745)<br
/> <strong>Impact:</strong> Elevation of Privilege</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-030.mspx">MS08-035</a> (Important)<br
/> <strong>Description:</strong> Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)<br
/> <strong>Impact:</strong> Denial of Service</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-035.mspx">MS08-036</a> (Important)<br
/> <strong>Description:</strong> Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376)<br
/> <strong>Impact:</strong> Denial of Service</p><p><strong>Bulletin:</strong> Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-032.mspx">MS08-032</a> (Moderate)<br
/> <strong>Description:</strong> Cumulative Security Update of ActiveX Kill Bits (950760)<br
/> <strong>Impact:</strong> Remote Code Execution</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/06/11/microsoft-security-updates-for-june-2008/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
