<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; security vulnerabilities</title>
	<atom:link href="http://www.ghacks.net/tag/security-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 23 Nov 2009 14:06:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Expect A Massive Patch Day Tomorrow</title>
		<link>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/</link>
		<comments>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 10:28:02 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe reader]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=17188</guid>
		<description><![CDATA[Tomorrow is a day that could force many system administrators into overtime as both Microsoft and Adobe plan to release security patches for several of their products. Microsoft alone plans to release 13 security patches and updates for various Microsoft operating system, Microsoft Office and other Microsoft products. The patch day is also the first [...]]]></description>
			<content:encoded><![CDATA[<p>Tomorrow is a day that could force many system administrators into overtime as both Microsoft and Adobe plan to release security patches for several of their products. Microsoft alone <a href="http://www.microsoft.com/technet/security/Bulletin/MS09-oct.mspx">plans</a> to release 13 security patches and updates for various Microsoft operating system, Microsoft Office and other Microsoft products. The patch day is also the first to include a critical security patch for Microsoft&#8217;s upcoming operating system <a href="http://windows7news.com/">Windows 7</a>. </p>
<p>Adobe on the other hand <a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">plans</a> to release security patches for its popular PDF reader Adobe Reader that are also rated critical. The updates will all be released tomorrow and system administrators will certainly their hands full updating the computer systems that run the software and operating systems.</p>
<p><span id="more-17188"></span>A closer look at the Microsoft Patch Day reveals eight critical security vulnerabilities and five important vulnerabilities that will get fixed with the patches that are released tomorrow. The majority of vulnerabilities affects the Windows operating system but it does also include one critical Internet Explorer vulnerability. </p>
<p>System administrators and Windows users are encouraged to visit the two websites linked above for further information. These websites will also contain the links to patch the security vulnerabilities. Windows users can also use Windows Update, Microsoft Update or Automatic Updates to update their operating system.</p>

	Tags: <a href="http://www.ghacks.net/tag/adobe/" title="adobe" rel="tag">adobe</a>, <a href="http://www.ghacks.net/tag/adobe-reader/" title="adobe reader" rel="tag">adobe reader</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/patch-day/" title="patch day" rel="tag">patch day</a>, <a href="http://www.ghacks.net/tag/patches/" title="patches" rel="tag">patches</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/04/15/windows-vista-sp1-all-languages-released/" title="Windows Vista SP1 all languages released (April 15, 2008)">Windows Vista SP1 all languages released</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/04/13/windows-update-fix/" title="Windows Update Fix (April 13, 2009)">Windows Update Fix</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/10/12/expect-a-massive-patch-day-tomorrow/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Patches for June 2009</title>
		<link>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</link>
		<comments>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 22:45:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[office patches]]></category>
		<category><![CDATA[office update]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</guid>
		<description><![CDATA[Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office.
The easiest way to download and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> and Microsoft Office.</p>
<p>The easiest way to download and install the patches is by pointing the Internet Explorer web browser to <a href="http://update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&#038;&#038;thankspage=5">Microsoft Update</a> which will automatically detect and install the available patches for the computer system. Other possibilities include downloading the security patches from <a href="http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&#038;freetext=security%20update">Microsoft Download Center</a> from where they are available as well.</p>
<p><span id="more-13419"></span>Six vulnerabilities have been rated as critical, three as important and one as moderate. Critical security vulnerabilities can usually be exploited for remote code execution meaning it is essential to fix these vulnerabilities quickly. You can follow the links below for additional information about each vulnerability.</p>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=151361">MS09-018</a> &#8211; Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150860">MS09-019</a> &#8211; Cumulative Security Update for Internet Explorer (969897)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=150568">MS09-020</a> &#8211; Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=147294">MS09-021</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=141786">MS09-022</a> &#8211; Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=143550">MS09-023</a> &#8211; Vulnerability in Windows Search Could Allow Information Disclosure (963093)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=128104">MS09-024</a> &#8211; Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150248">MS09-025</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=150174">MS09-026</a> &#8211; Vulnerability in RPC Could Allow Elevation of Privilege (970238)</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=147416">MS09-027</a> &#8211; Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)</li>
</ul>

	Tags: <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/office-patches/" title="office patches" rel="tag">office patches</a>, <a href="http://www.ghacks.net/tag/office-update/" title="office update" rel="tag">office update</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/" title="Microsoft updates two critical security patches (April 24, 2008)">Microsoft updates two critical security patches</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/09/09/microsoft-security-patches-september-2009/" title="Microsoft Security Patches September 2009 (September 9, 2009)">Microsoft Security Patches September 2009</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Java Security Update Released</title>
		<link>http://www.ghacks.net/2008/12/07/java-security-update-released/</link>
		<comments>http://www.ghacks.net/2008/12/07/java-security-update-released/#comments</comments>
		<pubDate>Sun, 07 Dec 2008 17:33:08 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java ra]]></category>
		<category><![CDATA[java security]]></category>
		<category><![CDATA[java update]]></category>
		<category><![CDATA[java vulnerability]]></category>
		<category><![CDATA[jre update]]></category>
		<category><![CDATA[security vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8794</guid>
		<description><![CDATA[Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.
A total of 13 security vulnerabilities are fixed by the Java update. Attackers can [...]]]></description>
			<content:encoded><![CDATA[<p>Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.</p>
<p>A total of 13 security vulnerabilities are fixed by the Java update. Attackers can use those vulnerabilities for various attacks on a computer system that can lead to privilege escalations.</p>
<p>Probably the easiest way to uninstall old versions of Java and to install the latest secure update is by using the third party software <a href="http://raproducts.org/">Java RA</a>. Java RA can uninstall old versions of Java. Users should download the latest <a href="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jre-6u11-oth-JPR@CDS-CDS_Developer">JRE</a> directly from Sun and install it on their systems. Java Ra should be run after the installation as it will remove all old versions of Java while keeping the latest version installed.</p>
<p><span id="more-8794"></span><strong>List of vulnerabilities:</strong></p>
<ul>
<li>The Java Runtime Environment Creates Temporary Files That Have “Guessable” File Names </li>
<li>Java Runtime Environment (JRE) Buffer Overflow Vulnerabilities in Processing Image Files and Fonts </li>
<p>May
<li>Allow Applets or Java Web Start Applications to Elevate Their Privileges </li>
<li>Multiple Security Vulnerabilities in Java Web Start and Java Plug-in May Allow Privilege Escalation </li>
<li>The Java Runtime Environment (JRE) “Java Update” Mechanism Does Not Check the Digital Signature of the JRE that it Downloads </li>
<li>A Buffer Overflow Vulnerability in the Java Runtime Environment (JRE) May Allow Privileges to be Escalated </li>
<li>A Security Vulnerability in the Java Runtime Environment (JRE) Related to Deserializing Calendar Objects May Allow Privileges to be Escalated </li>
<li>The Java Runtime Environment UTF-8 Decoder May Allow Multiple Representations of UTF-8 Input </li>
<li>Security Vulnerability in Java Runtime Environment May Allow Applets to List the Contents of the Current User’s Home Directory </li>
<li>Security Vulnerability in the Java Runtime Environment With Processing RSA Public Keys </li>
<li>A Security Vulnerability in Java Runtime Environment (JRE) With Authenticating Users Through Kerberos May Lead to a Denial of Service (DoS) </li>
<li>Security Vulnerabilities in the Java Runtime Environment (JRE) JAX-WS and JAXB Packages may Allow Privileges to be Escalated </li>
<li>A Security Vulnerability in Java Runtime Environment (JRE) With Parsing of Zip Files May Allow Reading of Arbitrary Memory Locations </li>
<li>A Security Vulnerability in the Java Runtime Environment may Allow Code Loaded From the Local Filesystem to Access LocalHost </li>
</ul>
<p>Users who cannot install the Java update immediately should disable Java for the time being to protect their computer system from the exploits.</p>

	Tags: <a href="http://www.ghacks.net/tag/java/" title="java" rel="tag">java</a>, <a href="http://www.ghacks.net/tag/java-ra/" title="java ra" rel="tag">java ra</a>, <a href="http://www.ghacks.net/tag/java-security/" title="java security" rel="tag">java security</a>, <a href="http://www.ghacks.net/tag/java-update/" title="java update" rel="tag">java update</a>, <a href="http://www.ghacks.net/tag/java-vulnerability/" title="java vulnerability" rel="tag">java vulnerability</a>, <a href="http://www.ghacks.net/tag/jre-update/" title="jre update" rel="tag">jre update</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/09/update-java-and-remove-old-java-versions-from-your-system/" title="Update Java and remove old Java versions from your system (April 9, 2008)">Update Java and remove old Java versions from your system</a> (10)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/10/29/turn-your-mobile-phone-into-a-pc-remote-control/" title="Turn Your Mobile Phone Into A PC Remote Control (October 29, 2008)">Turn Your Mobile Phone Into A PC Remote Control</a> (22)</li>
	<li><a href="http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/" title="Secure Wordpress with the first Wordpress Worm (August 2, 2007)">Secure Wordpress with the first Wordpress Worm</a> (7)</li>
	<li><a href="http://www.ghacks.net/2009/02/05/photo-collage/" title="Photo Collage (February 5, 2009)">Photo Collage</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/07/java-security-update-released/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday November 08</title>
		<link>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/</link>
		<comments>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 13:55:43 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[microsoft security bulletin]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8233</guid>
		<description><![CDATA[Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins MS08-069 and MS08-068 patched two vulnerability with the status critical and important.
The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code execution [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins <a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069</a> and <a href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">MS08-068</a> patched two vulnerability with the status critical and important.</p>
<p>The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code execution in Microsoft Server Message Block (SMB) Protocol.</p>
<p>Both security vulnerabilities can be fixed by using Windows Update or by downloading the security updates directly from the Microsoft Download website by following the two links given above in this article.</p>
<p><span id="more-8233"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/microsoft-security/" title="microsoft security" rel="tag">microsoft security</a>, <a href="http://www.ghacks.net/tag/microsoft-security-bulletin/" title="microsoft security bulletin" rel="tag">microsoft security bulletin</a>, <a href="http://www.ghacks.net/tag/patch-tuesday/" title="patch tuesday" rel="tag">patch tuesday</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/" title="Microsoft Security Patches July 2009 (July 15, 2009)">Microsoft Security Patches July 2009</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/" title="Microsoft Patch Tuesday December 08 (December 10, 2008)">Microsoft Patch Tuesday December 08</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/" title="Microsoft releases two security patches for Windows (January 9, 2008)">Microsoft releases two security patches for Windows</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</title>
		<link>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 08:38:16 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[office security]]></category>
		<category><![CDATA[patch day]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7632</guid>
		<description><![CDATA[It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not [...]]]></description>
			<content:encoded><![CDATA[<p>It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not releasing them because they release them in one package on one day.</p>
<p>Microsoft released a batch of eleven security patches for various operating systems and products yesterday which are available by visiting Windows Update or Microsoft Technet which contains in depths information about the affected products and the security vulnerabilities.</p>
<p>The patches fix four critical, six important and 1 moderate security vulnerability:</p>
<p><span id="more-7632"></span>	</p>
<ul>
<li>Vulnerability in Active Directory Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128125">957280</a>)</li>
<li>Cumulative Security Update for Internet Explorer (<a href="http://go.microsoft.com/fwlink/?LinkID=128060">956390</a>)</li>
<li>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=125712">956695</a>)</li>
<li>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=124653">956416</a>)</li>
</ul>
<ul>
<li>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=125709">956803</a>)</li>
<li>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=121738">954211</a>)</li>
<li>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=120829">953155</a>)</li>
<li>Vulnerability in SMB Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkID=127994">957095</a>)</li>
<li>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (<a href="http://go.microsoft.com/fwlink/?LinkId=128103">956841</a>)</li>
<li>Vulnerability in Message Queuing Could Allow Remote Code Execution (<a href="http://go.microsoft.com/fwlink/?LinkId=128102">951071</a>)</li>
</ul>
<ul>
<li>Vulnerability in Microsoft Office Could Allow Information Disclosure (<a href="http://go.microsoft.com/fwlink/?LinkId=128145">957699</a>)</li>
</ul>
<p>It is highly recommended to update the products as soon as possible to protect the system from this attacks.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/office/" title="office" rel="tag">office</a>, <a href="http://www.ghacks.net/tag/office-security/" title="office security" rel="tag">office security</a>, <a href="http://www.ghacks.net/tag/patch-day/" title="patch day" rel="tag">patch day</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/11/29/watch-three-webcasts-get-vista-and-office-for-free/" title="Watch three webcasts get vista and office for free (November 29, 2006)">Watch three webcasts get vista and office for free</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Updates May 2008</title>
		<link>http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/</link>
		<comments>http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/#comments</comments>
		<pubDate>Fri, 16 May 2008 09:54:29 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft-office]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patch]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=4150</guid>
		<description><![CDATA[Microsoft released four security updates for various applications and operating systems that they produce. Three of the four updates are regarded as critical while one has a moderate risk level. To break it up further: Two patches are updating Microsoft Office 2000, Office XP, Office 2003 and Office 2007, one Windows XP, Windows 2000 and [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released four security updates for various applications and operating systems that they produce. Three of the four updates are regarded as critical while one has a moderate risk level. To break it up further: Two patches are updating Microsoft Office 2000, Office XP, Office 2003 and Office 2007, one Windows XP, Windows 2000 and Windows Server 2003 and the last one applications that use the Microsoft Malware Protection Engine which includes Windows Live Care and <a href="http://www.ghacks.net/2009/05/29/windows-defender/">Windows Defender</a>.</p>
<p>Use the following links to open the Security Bulletins directly: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution [<a href="http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx">link</a>], Vulnerability in Microsoft Publisher Could Allow Remote Code Execution [<a href="http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx">link</a>], Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution [<a href="http://www.microsoft.com/technet/security/Bulletin/ms08-028.mspx">link</a>] and Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service [<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-029.mspx">link</a>].</p>
<p>It is as always advised to update the system as soon as possible. The first two patches have to be applied to users of Microsoft Office, the third by almost everyone and the fourth by users who use Microsoft Malware protection applications.</p>
<p><span id="more-4150"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-office/" title="microsoft-office" rel="tag">microsoft-office</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patch/" title="windows patch" rel="tag">windows patch</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/08/26/windows-xp-wga-to-mimic-that-of-windows-vista/" title="Windows XP WGA To Mimic That Of Windows Vista (August 26, 2008)">Windows XP WGA To Mimic That Of Windows Vista</a> (18)</li>
	<li><a href="http://www.ghacks.net/2008/04/16/windows-xp-sp3-release-date-announced/" title="Windows XP SP3 Release Date announced (April 16, 2008)">Windows XP SP3 Release Date announced</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft updates two critical security patches</title>
		<link>http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/</link>
		<comments>http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/#comments</comments>
		<pubDate>Thu, 24 Apr 2008 09:02:16 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[ie patch]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[net framework]]></category>
		<category><![CDATA[net patch]]></category>
		<category><![CDATA[security vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3903</guid>
		<description><![CDATA[It feels like I&#8217;m updating my computer every day in the last weeks. Microsoft issued yet another two security patches for Internet Explorer and the .net framework that can be downloaded from Microsoft Security Bulletin MS07-040 &#8211; Critical and Microsoft Security Bulletin MS08-024 &#8211; Critical. Both security patches are updated to patches that had been [...]]]></description>
			<content:encoded><![CDATA[<p>It feels like I&#8217;m updating my computer every day in the last weeks. Microsoft issued yet another two security patches for <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> and the .net framework that can be downloaded from Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx">MS07-040</a> &#8211; Critical and Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms08-024.mspx">MS08-024</a> &#8211; Critical. Both security patches are updated to patches that had been released before, one of them just a few weeks ago.</p>
<p>The Cumulative Security Update for Internet Explorer patches Internet Explorer 6 and newer versions of Internet Explorer. If the user visits a specially prepared website an attacker can gain the same rights on the Windows system as the user who is currently logged into the system. While this does not affect other browsers and to a lesser extent users who do not use administrative accounts it is still recommended to update the software immediately.</p>
<p>The Vulnerabilities in .NET Framework Could Allow Remote Code Execution patch fixes three security vulnerabilities. Two of them allow remote code execution and one information disclosure. It is again advised to update the system immediately to fix those security holes.</p>
<p><span id="more-3903"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/ie-patch/" title="ie patch" rel="tag">ie patch</a>, <a href="http://www.ghacks.net/tag/internet-explorer/" title="internet-explorer" rel="tag">internet-explorer</a>, <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/net-framework/" title="net framework" rel="tag">net framework</a>, <a href="http://www.ghacks.net/tag/net-patch/" title="net patch" rel="tag">net patch</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/06/13/windows-malicious-software-removal-tool-observations/" title="Windows Malicious Software Removal Tool Observations (June 13, 2006)">Windows Malicious Software Removal Tool Observations</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/08/01/why-cannot-i-uninstall-the-microsoft-net-framework/" title="Why Can&#8217;t I Uninstall the Microsoft .net Framework? (August 1, 2008)">Why Can&#8217;t I Uninstall the Microsoft .net Framework?</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/01/11/what-is-connecting-to-the-internet/" title="What is connecting to the Internet (January 11, 2008)">What is connecting to the Internet</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Windows Vulnerability Scanner</title>
		<link>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/</link>
		<comments>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 18:35:38 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows vulnerability scanner]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3846</guid>
		<description><![CDATA[Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be [...]]]></description>
			<content:encoded><![CDATA[<p>Windows is probably the operating system that is attacked the most, some say because it has the largest user base, some say because it is simply insecure. Whatever it is Windows users should do whatever they can to protect their system and patch all possible known security vulnerabilities to make sure their system won&#8217;t be added to one of the botnets out there.</p>
<p>I <a href="http://www.pspl.com/download/winvulscan.htm">discovered</a> a software Windows Vulnerability Scanner at <a href="http://www.techmalaya.com/2008/04/18/proland-windows-vulnerability-scanner/">Tech Malaya</a> which scans a Windows NT system, that is Windows 2000, Windows XP, Windows 2003 Server or Windows Vista for security vulnerabilities. It seems to use information from the Microsoft Knowledgebase exclusively and one would assume that a system that downloaded all Windows Updates recently reveal no vulnerabilities. I let the software scan my system and it did find six critical and one important security vulnerability that had not been patched yet.</p>
<p>I&#8217;m not sure how this can be but was glad that the application revealed the information to me. It lists the vulnerabilities and provides links to the Microsoft website that contains information about it. </p>
<p><span id="more-3846"></span><a href='http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner.jpg'><img src="http://www.ghacks.net/wp-content/uploads/2008/04/windows_vulnerability_scanner-300x218.jpg" alt="windows vulnerability scanner" title="windows vulnerability scanner" width="300" height="218" class="alignnone size-medium wp-image-3847" /></a></p>
<p>The Knowledgebase article at Microsoft contains a link to the download of the security patch and I did install all the patches one after the other.  An improvement would have been if the software would automatically download the patches and install them on the system, or at least those that the user selects. If you have not been to Windows Update for a while I suggest you start there and scan the system again afterwards which should fix most of the security vulnerabilities found during the first scan.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-vulnerability-scanner/" title="windows vulnerability scanner" rel="tag">windows vulnerability scanner</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/" title="Microsoft Security Updates May 2008 (May 16, 2008)">Microsoft Security Updates May 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/" title="Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities (October 15, 2008)">Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Patches April 2008</title>
		<link>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/</link>
		<comments>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/#comments</comments>
		<pubDate>Tue, 08 Apr 2008 19:34:07 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft-office]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows-vista]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3759</guid>
		<description><![CDATA[Microsoft have released their Security Bulletin Summary for April 2008 today which contains information and download links to eight patches for various Microsoft operating systems and applications like Microsoft Office and Microsoft Internet Explorer. Five of the eight security patches are patching critical vulnerabilities while three patch important ones. The update is recommended for every [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft have released their Security Bulletin Summary for <a href="http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx">April 2008</a> today which contains information and download links to eight patches for various Microsoft operating systems and applications like Microsoft Office and Microsoft <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a>. Five of the eight security patches are patching critical vulnerabilities while three patch important ones. The update is recommended for every user that uses Windows and or Microsoft Office.</p>
<p>All critical vulnerabilities which affect Microsoft Windows, Microsoft Office and Internet Explorer allow Remote Code Execution. The easiest way to patch these security vulnerabilities is by visiting the Windows Update website with Internet Explorer and let a script check the available updates for your system. Please note that you will be asked if you want to install Service Pack 3 Refresh 2 for Windows XP if you use that operating system. My advise would be to not install this version yet and wait for the release version.</p>
<p>All security updates will be displayed and are selected for immediate download and installation. You could follow the link above which leads to the Microsoft website that explains the vulnerabilities and leads to downloads of the patches. This means that you have to make sure to pick the correct downloads for your operating system and software.</p>
<p><span id="more-3759"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/microsoft-office/" title="microsoft-office" rel="tag">microsoft-office</a>, <a href="http://www.ghacks.net/tag/patch-tuesday/" title="patch tuesday" rel="tag">patch tuesday</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-vista/" title="windows-vista" rel="tag">windows-vista</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/" title="Microsoft Security Updates May 2008 (May 16, 2008)">Microsoft Security Updates May 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/" title="Microsoft releases two security patches for Windows (January 9, 2008)">Microsoft releases two security patches for Windows</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/" title="Microsoft Patch Tuesday November 08 (November 12, 2008)">Microsoft Patch Tuesday November 08</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/08/26/windows-xp-wga-to-mimic-that-of-windows-vista/" title="Windows XP WGA To Mimic That Of Windows Vista (August 26, 2008)">Windows XP WGA To Mimic That Of Windows Vista</a> (18)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft releases two security patches for Windows</title>
		<link>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/</link>
		<comments>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 13:23:46 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft-windows]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows-vista]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/</guid>
		<description><![CDATA[Microsoft is releasing collected security patches each month for their Windows operating systems. I'm not a fan of this approach because I would feel safer and securer if they would release patches as soon as they would be ready to be released which would secure computers and reduce the time that someone could exploit these security vulnerabilities.]]></description>
			<content:encoded><![CDATA[<p>Microsoft is releasing collected security patches each month for their Windows operating systems. I&#8217;m not a fan of this approach because I would feel safer and securer if they would release patches as soon as they would be ready to be released which would secure computers and reduce the time that someone could exploit these security vulnerabilities.</p>
<p>Two security patches have been released this month, they are the <a href="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx">critical</a> Microsoft Security Bulletin MS08-001 and the <a href="http://www.microsoft.com/technet/security/bulletin/ms08-002.mspx">important</a> Microsoft Security Bulletin MS08-002. The critical patch fixes vulnerabilities in Windows TCP/IP that could allow remote code execution while the important patch deals with a vulnerability in LSASS that could allow local elevation of privilege.</p>
<p>Both patches are available through Windows Updates but also as single downloads. Several operating systems need to be patched including Windows Vista (only the critical), Windows 2000 and Windows XP. Downloads are available if you follow the links above.</p>
<p><span id="more-2797"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-windows/" title="microsoft-windows" rel="tag">microsoft-windows</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-vista/" title="windows-vista" rel="tag">windows-vista</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2007/12/12/microsoft-releases-security-updates-for-xp-and-vista/" title="Microsoft releases security updates for XP and Vista (December 12, 2007)">Microsoft releases security updates for XP and Vista</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/01/29/wpf-performance-fix-for-windows-vista-and-xp/" title="WPF Performance Fix for Windows Vista and XP (January 29, 2008)">WPF Performance Fix for Windows Vista and XP</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/08/26/windows-xp-wga-to-mimic-that-of-windows-vista/" title="Windows XP WGA To Mimic That Of Windows Vista (August 26, 2008)">Windows XP WGA To Mimic That Of Windows Vista</a> (18)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft releases security updates for XP and Vista</title>
		<link>http://www.ghacks.net/2007/12/12/microsoft-releases-security-updates-for-xp-and-vista/</link>
		<comments>http://www.ghacks.net/2007/12/12/microsoft-releases-security-updates-for-xp-and-vista/#comments</comments>
		<pubDate>Wed, 12 Dec 2007 12:40:10 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[windows updates]]></category>
		<category><![CDATA[windows-vista]]></category>
		<category><![CDATA[windows-xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/12/12/microsoft-releases-security-updates-for-xp-and-vista/</guid>
		<description><![CDATA[Once in a month Microsoft releases their so called Security Bulletins in which they announce security updates for several of their operating systems and other products. The current Security Bulletin for December lists seven vulnerabilities that have been fixed including three critical and four important ones.]]></description>
			<content:encoded><![CDATA[<p>Once in a month Microsoft releases their so called Security Bulletins in which they announce security updates for several of their operating systems and other products. The current Security Bulletin for December lists seven vulnerabilities that have been fixed including three critical and four important ones.</p>
<p>Every user should head out immediately and use either Windows Updates or browse the Microsoft website manually to download the security patches. I have added the download links to all security patches at the end of the article to make things easier for you.</p>
<p>A quick glance at the security vulnerabilities revealed that five patches have to be downloaded for both Windows XP and Windows Vista. Take a look at the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms07-dec.mspx">overview</a> site if you are using a different operating system to find out what has been patched for it.</p>
<p><span id="more-2504"></span><strong>Windows Vista:</strong></p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-063.mspx">Microsoft Security Bulletin MS07-063</a> – Important (Vulnerability in SMBv2 Could Allow Remote Code Execution (942624))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/MS07-064.mspx">Microsoft Security Bulletin MS07-064</a> – Critical (Vulnerabilities in DirectX Could Allow Remote Code Execution (941568))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/MS07-066.mspx">Microsoft Security Bulletin MS07-066</a> – Important (Vulnerability in Windows Kernel Could Allow Elevation of Privilege (943078))</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-068.mspx">Microsoft Security Bulletin MS07-068</a> &#8211; Critical (Vulnerability in Windows Media File Format Could Allow Remote Code Execution (941569 and 944275))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-069.mspx">Microsoft Security Bulletin MS07-069</a> &#8211; Critical (Cumulative Security Update for Internet Explorer (942615))</p>
<p><strong>Windows XP:</strong></p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/MS07-064.mspx">Microsoft Security Bulletin MS07-064</a> – Critical (Vulnerabilities in DirectX Could Allow Remote Code Execution (941568))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-065.mspx">Microsoft Security Bulletin MS07-065</a> – Important (Vulnerability in Message Queuing Could Allow Remote Code Execution (937894))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/MS07-067.mspx">Microsoft Security Bulletin MS07-067</a> – Important (Vulnerability in Macrovision Driver Could Allow Local Elevation of Privilege (944653))</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-068.mspx">Microsoft Security Bulletin MS07-068</a> &#8211; Critical (Vulnerability in Windows Media File Format Could Allow Remote Code Execution (941569 and 944275))</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-069.mspx">Microsoft Security Bulletin MS07-069</a> &#8211; Critical (Cumulative Security Update for Internet Explorer (942615))</p>

	Tags: <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-updates/" title="windows updates" rel="tag">windows updates</a>, <a href="http://www.ghacks.net/tag/windows-vista/" title="windows-vista" rel="tag">windows-vista</a>, <a href="http://www.ghacks.net/tag/windows-xp/" title="windows-xp" rel="tag">windows-xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/07/20/windows-updates-downloader/" title="Windows Updates Downloader (July 20, 2008)">Windows Updates Downloader</a> (6)</li>
	<li><a href="http://www.ghacks.net/2007/10/15/restart-your-computer-to-finish-installing-important-updates/" title="Restart your computer to finish installing important updates (October 15, 2007)">Restart your computer to finish installing important updates</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/" title="Microsoft releases two security patches for Windows (January 9, 2008)">Microsoft releases two security patches for Windows</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/12/12/microsoft-releases-security-updates-for-xp-and-vista/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure Wordpress with the first Wordpress Worm</title>
		<link>http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/</link>
		<comments>http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/#comments</comments>
		<pubDate>Thu, 02 Aug 2007 15:57:18 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[wordpress bugs]]></category>
		<category><![CDATA[wordpress exploits]]></category>
		<category><![CDATA[wordpress patch]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/</guid>
		<description><![CDATA[Did you know that the latest version of Wordpress contains at least seven security vulnerabilities that could compromise your blog ? If you use Wordpress you should make sure that to fix them as soon as possible. The easiest way to fix them right now is to use the first Wordpress worm - which is a good one - to fix all seven vulnerabilities for you.]]></description>
			<content:encoded><![CDATA[<p>Did you know that the latest version of Wordpress contains at least <a href="http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/">seven</a> security vulnerabilities that could compromise your blog ? If you use Wordpress you should make sure that to fix them as soon as possible. The easiest way to fix them right now is to use the first Wordpress worm &#8211; which is a good one &#8211; to fix all seven vulnerabilities for you.</p>
<p>The process requires some faith that the <a href="http://mybeni.rootzilla.de/mybeNi/2007/this_is_the_first_weblog_xss_worm/">xss worm</a> is really fixing the vulnerabilities but the application itself is easy. About the faith: I have not read negative reviews so far and the worm has been released two days ago which should be enough time for some experts to complain about it.</p>
<p>If you want to secure your blog you simply write a comment on your own blog while you are logged in as the administrator linking to http://mybeni.rootzilla.de/mybeNi/ ; Click on that link from your admin panel afterwards which will lead to the site.</p>
<p><span id="more-1825"></span>The first page explains what will be done and only if you actively click on &#8220;Secure my Blog&#8221; the vulnerability scan will be started. It will check three Wordpress files for the vulnerabilities and offer to fix them if the vulnerability is found. </p>
<p>The vulnerabilities can only be fixed if the files are writable so make sure they are. An alternative would be to copy the code that will be inserted and add it manually in the files. The complete code of the file is shown and the addition is highlighted. </p>
<p>I suggest to run the worm a second time to make sure that your blog is safe and that the fixes have been applied.</p>

	Tags: <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.ghacks.net/tag/wordpress-bugs/" title="wordpress bugs" rel="tag">wordpress bugs</a>, <a href="http://www.ghacks.net/tag/wordpress-exploits/" title="wordpress exploits" rel="tag">wordpress exploits</a>, <a href="http://www.ghacks.net/tag/wordpress-patch/" title="wordpress patch" rel="tag">wordpress patch</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2007/12/01/wordpress-incorrect-password/" title="Wordpress Incorrect Password (December 1, 2007)">Wordpress Incorrect Password</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/02/11/wordpress-271-update/" title="Wordpress 2.7.1 Update (February 11, 2009)">Wordpress 2.7.1 Update</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/04/24/microsoft-updates-two-critical-security-patches/" title="Microsoft updates two critical security patches (April 24, 2008)">Microsoft updates two critical security patches</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/05/16/microsoft-security-updates-may-2008/" title="Microsoft Security Updates May 2008 (May 16, 2008)">Microsoft Security Updates May 2008</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
