<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; security patches</title>
	<atom:link href="http://www.ghacks.net/tag/security-patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Wed, 25 Nov 2009 11:56:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Security Patches September 2009</title>
		<link>http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/</link>
		<comments>http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 22:17:42 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft-windows]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=16146</guid>
		<description><![CDATA[Microsoft has released the security patches for September 2009 which fix browser and web based attacks in various Microsoft programs and operating systems. All security patches have a critical or important security rating and are users who work with these software programs or operating systems should update them as soon as possible to protect their [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/09/windows_software.jpg" alt="windows software" title="windows software" width="128" height="128" class="alignleft size-full wp-image-16120" />Microsoft has released the security patches for September 2009 which fix browser and web based attacks in various Microsoft programs and operating systems. All security patches have a critical or important security rating and are users who work with these software programs or operating systems should update them as soon as possible to protect their system from these attacks.</p>
<p>Microsoft has released two charts that show the severity and exploitable index and the deployment priority. The former interesting for all users while the latter probably only for network administrators.</p>
<p><span id="more-16146"></span>
<ul>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx">MS09-045</a> &#8211; Critical &#8211; Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961) &#8211; This security update resolves a privately reported vulnerability in the JScript scripting engine that could allow remote code execution if a user opened a specially crafted file or visited a specially crafted Web site and invoked a malformed script. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-046.mspx">MS09-046</a> &#8211; Critical &#8211; Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844) &#8211; This security update resolves a privately reported vulnerability in the DHTML Editing Component ActiveX control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx">MS09-047</a> &#8211; Critical &#8211; Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812) &#8211; This security update resolves two privately reported vulnerabilities in Windows Media Format. Either vulnerability could allow remote code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx">MS09-048</a> &#8211; Critical &#8211; Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723) &#8211; This security update resolves several privately reported vulnerabilities in Transmission Control Protocol/Internet Protocol (TCP/IP) processing. The vulnerabilities could allow remote code execution if an attacker sent specially crafted TCP/IP packets over the network to a computer with a listening service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-049.mspx">MS09-049</a> &#8211; Critical &#8211; Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution (970710) &#8211; This security update resolves a privately reported vulnerability in Wireless LAN AutoConfig Service. The vulnerability could allow remote code execution if a client or server with a wireless network interface enabled receives specially crafted wireless frames. Systems without a wireless card enabled are not at risk from this vulnerability.</li>
</ul>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/09/severity_and_exploitability_index-500x281.PNG" alt="severity and exploitability index" title="severity and exploitability index" width="500" height="281" class="alignnone size-medium wp-image-16147" /></p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/09/deployment_priority-500x281.PNG" alt="deployment priority" title="deployment priority" width="500" height="281" class="alignnone size-medium wp-image-16148" /></p>
<p>The patches can be download and applied by visiting the pages that are linked above or by using any of the update options that are provided by Microsoft operating systems including Windows Update, Automatic Updates or Microsoft Updates. Additional <a href="http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx">information</a> can be found at the Microsoft Technet page.</p>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/microsoft-windows/" title="microsoft-windows" rel="tag">microsoft-windows</a>, <a href="http://www.ghacks.net/tag/security-patches/" title="security patches" rel="tag">security patches</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/" title="Windows Security Updates September 2008 (September 10, 2008)">Windows Security Updates September 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2006/11/17/block-windows-update-from-automatic-updating-to-ie7/" title="Block windows update from automatic updating to IE7 (November 17, 2006)">Block windows update from automatic updating to IE7</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/04/15/windows-vista-sp1-all-languages-released/" title="Windows Vista SP1 all languages released (April 15, 2008)">Windows Vista SP1 all languages released</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/03/05/windows-vista-service-pack-2-rc-download/" title="Windows Vista Service Pack 2 RC Download (March 5, 2009)">Windows Vista Service Pack 2 RC Download</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Patches July 2009</title>
		<link>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/</link>
		<comments>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 11:49:35 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[microsoft security patches]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[windows patches]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14410</guid>
		<description><![CDATA[Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are pretty much all from Windows 2000 onwards although the severity rating varies depending on the operating system. </p>
<p>Critical ratings for Windows XP or Windows Server 2003 are usually important or moderate ratings for Windows Vista or Windows Server 2008 thanks to the increased security in those operating systems. Downloads are already available from various official sources including Automatic Updates, Windows Update or Microsoft Update. </p>
<p><span id="more-14410"></span>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=152887">MS09-028</a> &#8211; Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371) &#8211; This security update resolves two privately reported vulnerabilities in the Microsoft Windows component, Embedded OpenType (EOT) Font Engine. The vulnerabilities could allow remote code execution. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=139788">MS09-029</a> &#8211; Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) &#8211; This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=147424">MS09-030</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (973346) &#8211; This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability in Microsoft Video ActiveX Control could allow remote code execution if a user views a specially crafted Web page with <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a>, instantiating the ActiveX control. This ActiveX control was never intended to be instantiated in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=154993">MS09-031</a> &#8211; Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856) &#8211; This security update resolves a privately reported vulnerability in Microsoft Virtual PC and Microsoft Virtual Server. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected guest operating system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=157386">MS09-032</a> -Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953) &#8211; This security update resolves a privately reported vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2006. The vulnerability could allow elevation of privilege if an attacker successfully impersonates an administrative user account for an ISA server that is configured for Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation.</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=153891">MS09-033</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
</ul>
<p>It is recommended to install the Microsoft Security Patches as soon as possible to close the security vulnerabilities.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/microsoft-security-patches/" title="microsoft security patches" rel="tag">microsoft security patches</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/security-patches/" title="security patches" rel="tag">security patches</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/" title="Microsoft Patch Tuesday November 08 (November 12, 2008)">Microsoft Patch Tuesday November 08</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/" title="Microsoft Security Patches September 2009 (September 9, 2009)">Microsoft Security Patches September 2009</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/" title="Microsoft Patch Tuesday December 08 (December 10, 2008)">Microsoft Patch Tuesday December 08</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Windows Security Updates September 2008</title>
		<link>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/</link>
		<comments>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 22:19:32 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft updates]]></category>
		<category><![CDATA[security bulletins]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6893</guid>
		<description><![CDATA[Microsoft has released four Microsoft Security Bulletins for September 2008. All updates are rated critical and it is recommended to update the computer system running Windows operating systems or Microsoft software as soon as possible.
The updates are available for pretty much every Windows operating system from Windows XP to Windows Server 2008. The easiest way [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released four Microsoft Security Bulletins for September 2008. All updates are rated critical and it is recommended to update the computer system running Windows operating systems or Microsoft software as soon as possible.</p>
<p>The updates are available for pretty much every Windows operating system from Windows XP to Windows Server 2008. The easiest way to download the security updates is to use the official <a href="http://go.microsoft.com/fwlink/?LinkId=21130">Windows Update</a> server from Microsoft, Automatic Updates or direct downloads from the <a href="http://www.microsoft.com/downloads/results.aspx?DisplayLang=en&#038;nr=20&#038;freetext=security+update&#038;sortCriteria=date">Microsoft Download Center</a>.</p>
<p>Below are the names of the Microsoft Security Bulletin and the links to the Microsoft Security Bulletin website.</p>
<ul>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms08-052.mspx">MS08-052</a> – Critical &#8211; Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms08-053.mspx">MS08-053</a> – Critical &#8211; Vulnerability in Windows Media Encoder 9 Could Allow Remote Code Execution (954156)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/Bulletin/ms08-054.mspx">MS08-054</a> – Critical &#8211; Vulnerability in Windows Media Player Could Allow Remote Code Execution (954154)</li>
<li>Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms08-055.mspx">MS08-055</a> – Critical &#8211; Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047)</li>
</ul>
<p><span id="more-6893"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-updates/" title="microsoft updates" rel="tag">microsoft updates</a>, <a href="http://www.ghacks.net/tag/security-bulletins/" title="security bulletins" rel="tag">security bulletins</a>, <a href="http://www.ghacks.net/tag/security-patches/" title="security patches" rel="tag">security patches</a>, <a href="http://www.ghacks.net/tag/security-updates/" title="security updates" rel="tag">security updates</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/06/11/microsoft-security-updates-for-june-2008/" title="Microsoft Security Updates for June 2008 (June 11, 2008)">Microsoft Security Updates for June 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/10/steps-to-take-before-you-install-windows-xp-service-pack-3/" title="Steps to take before you install Windows XP Service Pack 3 (May 10, 2008)">Steps to take before you install Windows XP Service Pack 3</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/01/27/project-dakota-full-windows-xp-update-cd/" title="Project Dakota Full Windows XP Update CD (January 27, 2008)">Project Dakota Full Windows XP Update CD</a> (7)</li>
	<li><a href="http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/" title="Microsoft Security Updates October 2009 Online (October 13, 2009)">Microsoft Security Updates October 2009 Online</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/09/10/windows-security-updates-september-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
