<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; windows patches</title> <atom:link href="http://www.ghacks.net/tag/windows-patches/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Microsoft Patch Day November 2011 Overview</title><link>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/</link> <comments>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/#comments</comments> <pubDate>Tue, 08 Nov 2011 18:42:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52475</guid> <description><![CDATA[Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating. In this case, [...]]]></description> <content:encoded><![CDATA[<p>Today Microsoft has released security updates exclusively for Microsoft Windows operating systems. Of the four bulletins released today, one has received the maximum severity rating of critical while the other three have received one of important. Maximum severity means that at least one Microsoft operating system has received the critical vulnerability rating.</p><p>In this case, the critical rating applies to all operating systems that Microsoft supplies with security patches. This includes the client operating systems Windows XP, Vista and Windows 7 as well as the server operating systems Windows Server 2008 and 2008 R2.</p><p>Here are two graphs visualizing the severity and exploitability index and the bulletin deployment priority.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-bulletin-deployment-600x337.png" alt="november2011 bulletin deployment" title="november2011 bulletin deployment" width="600" height="337" class="alignnone size-medium wp-image-52476" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/november2011-severity-600x337.png" alt="november2011 severity" title="november2011 severity" width="600" height="337" class="alignnone size-medium wp-image-52477" /></a></p><p>Here is the list of security bulletins released in November 2011 by Microsoft.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-083">MS11-083</a> &#8211; Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-085">MS11-085</a> &#8211; Vulnerability in Windows Mail and Windows Meeting Space Could Allow Remote Code Execution (2620704) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .eml or .wcinv file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Mail or Windows Meeting Space could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .eml or .wcinv file) from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-086">MS11-086</a> &#8211; Vulnerability in Active Directory Could Allow Elevation of Privilege (2630837) &#8211; This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow elevation of privilege if Active Directory is configured to use LDAP over SSL (LDAPS) and an attacker acquires a revoked certificate that is associated with a valid domain account and then uses that revoked certificate to authenticate to the Active Directory domain. By default, Active Directory is not configured to use LDAP over SSL.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-084">MS11-084</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Denial of Service (2617657) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user opens a specially crafted TrueType font file as an e-mail attachment or navigates to a network share or WebDAV location containing a specially crafted TrueType font file. For an attack to be successful, a user must visit the untrusted remote file system location or WebDAV share containing the specially crafted TrueType font file, or open the file as an e-mail attachment. In all cases, however, an attacker would have no way to force users to perform these actions. Instead, an attacker would have to persuade users to do so, typically by getting them to click a link in an e-mail message or Instant Messenger message.</li></ul><p>Microsoft has published a video in which Jerry Bryant discusses this month&#8217;s bulletins (Silverlight required).</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=3619b004-8dd9-40f0-ae88-2d0be504684b,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><p>Additional information about this month's security bulletins are available on the Technet Blog <a
href="http://blogs.technet.com/b/msrc/">page</a> and the Microsoft Security bulletin <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-nov">Summary</a> for November 2011.</p><p>The updates are already available on Windows Update. Users who have started their computer earlier today may need to run a manual update check in Windows Update.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/windows-updates.jpg" alt="windows updates" title="windows updates" width="567" height="275" class="alignnone size-full wp-image-52478" /></a></p><p>The updates will also be available <a
href="http://www.microsoft.com/download/en/default.aspx">shortly</a> at Microsoft's Download center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/08/microsoft-patch-day-november-2011-overview/feed/</wfw:commentRss> <slash:comments>3</slash:comments> <enclosure
url="http://content4.catalog.video.msn.com/e2/ds/fdf9929c-c9e7-480c-aa13-ea4155cefb8b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft Patch Day October 2011 Overview</title><link>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/</link> <comments>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/#comments</comments> <pubDate>Tue, 11 Oct 2011 17:32:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=51391</guid> <description><![CDATA[Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest [...]]]></description> <content:encoded><![CDATA[<p>Microsoft releases Windows updates on the second Tuesday of the month. A total of eight different security bulletins have been released today by Microsoft. They update the operating system Microsoft Windows and other Microsoft products such as the .NET Framework, Microsoft Silverlight and Internet Explorer. Two of the eight bulletins have been given the highest possible severity rating critical, the remaining six one of important. Maximum severity means that there is at least one product affected by that vulnerability impact.</p><p>You find information about each security bulletin below. Please follow the links for information about affected operating systems and Microsoft applications. You find a summary of all security bulletins <a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-oct">here</a>.</p><p>Here are the Bulletin Deployment Priority and Severity and Exploitability Index screenshots for October 2011:</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/bulletin-deployment-priority-october-2011-600x337.jpg" alt="bulletin deployment priority october 2011" title="bulletin deployment priority october 2011" width="600" height="337" class="alignnone size-medium wp-image-51408" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/severity-exploitability-index-october-2011-600x337.png" alt="severity exploitability index october 2011" title="severity exploitability index october 2011" width="600" height="337" class="alignnone size-medium wp-image-51409" /></a></p><p>And a video in which Jerry Bryant discusses this month&#8217;s bulletins:</p><div
style="width:480px;height:270px" ><object
type="application/x-silverlight-2" data="data:application/x-silverlight-2," width="480" height="270" ><param
name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param
name="initParams" value="Culture=en-us,Uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=fa386fac-a875-4fba-9c77-1fef766bbb2d,Mode=Player" /><param
name="enableHtmlAccess" value="true" /><param
name="allowHtmlPopupwindow" value="true" /><param
name="background" value="#FF000000" /><param
name="minRuntimeVersion" value="4.0.50401.0" /><param
name="autoUpgrade" value="true" /><div><a
href="http://go.microsoft.com/fwlink/?LinkID=149156" style="text-decoration: none;" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-US&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'"><img
src="http://img.microsoft.com/showcase/Content/img/resx/en-US/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none"/></a></div><div
style='margin-top: -80px; text-align: center;'><a
style='text-align: center; color: #7db0d2; text-decoration: none; font-size: 80%; font-family: "Segoe UI", Segoe, Tahoma, Verdana, sans-serif;' href='http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4'>View this video as a WMV</a></div><p><noscript><div><img
alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No"/></div><p></noscript></object></div><p><script type="text/javascript">document.write("<script type='text/javascript' src='" + (window.location.protocol) + "//c.microsoft.com/ms.js'><\/script>");</script></p><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-078">MS11-078</a> - Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930) -<br
/> This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-081">MS11-081</a> - Cumulative Security Update for Internet Explorer (2586448) - This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-075">MS11-075</a> - Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699) - This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, the Microsoft Active Accessibility component could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-076">MS11-076</a> - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926) - This security update resolves a publicly disclosed vulnerability in Windows Media Center. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Media Center could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-077">MS11-077</a> - Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053) - This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment. For a remote attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the specially crafted font file, or open the file as an e-mail attachment.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-079">MS11-079</a> - Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641) - This security update resolves five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's Web site.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-080">MS11-080</a> - Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) - This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user's system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-082">MS11-082</a> - Vulnerabilities in Host Integration Server Could Allow Denial of Service (2607670) - This security update resolves two publicly disclosed vulnerabilities in Host Integration Server. The vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the Host Integration Server ports should be blocked from the Internet.</li><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/windows-updates.jpg" alt="windows updates" title="windows updates" width="579" height="382" class="alignnone size-full wp-image-51405" /></a></p><p>Windows users can update their operating system by installing the security patches via <a
href="http://www.ghacks.net/2010/12/20/microsoft-windows-update-overview-all-you-need-to-know/">Windows Update</a> or <a
href="http://www.microsoft.com/download/en/default.aspx">Microsoft's</a> Download Center with Windows Update being the better option if the patches do not have to be installed on multiple computer systems.</p><p>Updates are already live and available via Windows Update. Additional information are <a
href="http://blogs.technet.com/b/msrc/">available at</a> Microsoft's Security Response Center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/10/11/microsoft-patch-day-october-2011-overview/feed/</wfw:commentRss> <slash:comments>4</slash:comments> <enclosure
url="http://content1.catalog.video.msn.com/e2/ds/d8c46a81-5247-42b5-9c5d-dd930a38f93b.mp4" length="0" type="video/mp4" /> </item> <item><title>Microsoft Patch Day June 2011 Overview</title><link>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/</link> <comments>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/#comments</comments> <pubDate>Tue, 14 Jun 2011 17:33:37 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46476</guid> <description><![CDATA[Microsoft has released a total of 16 security bulletins on this month&#8217;s patch day. Patch day refers to the second Tuesday of each month on which Microsoft will release security patches. This month&#8217;s patch day consists of many different patches. Nine of the 16 bulletins have a maximum severity rating of critical, the highest possible [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released a total of 16 security bulletins on this month&#8217;s patch day. Patch day refers to the second Tuesday of each month on which Microsoft will release security patches. This month&#8217;s patch day consists of many different patches. Nine of the 16 bulletins have a maximum severity rating of critical, the highest possible rating, the remaining 7 bulletins a rating of important.</p><p>Highest possible means that at least one operating system or application has received that rating. It happens that all programs receive the same rating, but it is often not the case.</p><p>When you look at affected software programs you will notice that the majority of bulletins resolve issues under Microsoft Windows. Other Microsoft software affected includes Microsoft Internet Explorer, Microsoft Office or the Microsoft .Net Framework.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/windows-updates-june-2011.png" alt="windows updates june 2011" title="windows updates june 2011" width="596" height="281" class="alignnone size-full wp-image-46477" /></p><p>Detailed bulletin information have not been released at this point. Windows users can however check for updates to download and install the security patches right away. This is done via Start Menu > All Programs > Windows Update.</p><p>I will update this guide as soon as more information become available.</p><p>Update: The June security bulletins have been posted.</p><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-038.mspx">MS11-038</a> &#8211; Vulnerability in OLE Automation Could Allow Remote Code Execution (2476490)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-039.mspx">MS11-039</a> &#8211; Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2514842)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-040.mspx">MS11-040</a> &#8211; Vulnerability in Threat Management Gateway Firewall Client Could Allow Remote Code Execution (2520426)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-041.mspx">MS11-041</a> &#8211; Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2525694)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-042.mspx">MS11-042</a> &#8211; Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-043.mspx">MS11-043</a> &#8211; Vulnerability in SMB Client Could Allow Remote Code Execution (2536276)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-044.mspx">MS11-044</a> &#8211; Vulnerability in .NET Framework Could Allow Remote Code Execution (2538814)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-050.mspx">MS11-050</a> &#8211; Cumulative Security Update for Internet Explorer (2530548)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-052.mspx">MS11-052</a> &#8211; Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2544521)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-037.mspx">MS11-037</a> &#8211; Vulnerability in MHTML Could Allow Information Disclosure (2544893)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-045.mspx">MS11-045</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-046.mspx">MS11-046</a> &#8211; Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2503665)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS11-047.mspx">MS11-047</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2525835)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-048.mspx">MS11-048</a> &#8211; Vulnerability in SMB Server Could Allow Denial of Service (2536275)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS11-049.mspx">MS11-049</a> &#8211; Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms11-051.mspx">MS11-051</a> &#8211; Vulnerability in Active Directory Certificate Services Web Enrollment Could Allow Elevation of Privilege (2518295)</li></ul><p>You get an overview of all patches on the security bulletin summary page <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-jun.mspx">over at</a> Microsoft. It lists for instance the individual severity level of all affected operating systems and applications. Patches do not seem to have been posted yet on Microsoft Download Center.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft Security Bulletin December 2010</title><link>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/</link> <comments>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/#comments</comments> <pubDate>Wed, 15 Dec 2010 08:49:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37961</guid> <description><![CDATA[Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer. When we look at the severity rating of those vulnerabilities we notice that two of [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released the last set of planned security bulletins for the year 2010 yesterday. A total of 17 security bulletins have been released that patch vulnerabilities in Microsoft products like the Windows operating system, Microsoft Office or Internet Explorer.</p><p>When we look at the severity rating of those vulnerabilities we notice that two of the bulletins have a maximum severity rating of critical while the remaining ones a rating of important with the exception of one that has been rated as moderate.</p><p>Maximum severity rating means that at least one Microsoft product is affect this way by the vulnerability. The critical vulnerability MS10-090 affects Internet Explorer 6 to Internet Explorer 8 and is critical on all Microsoft operating systems. Vulnerability MS10-091 on the other hand is critical on Windows Vista and Windows 7 but not on Windows XP, something that we do not see very often thanks to improved security of the two operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/deployment-priority-550x309.png" alt="deployment priority" title="deployment priority" width="550" height="309" class="alignnone size-medium wp-image-37962" /></a></p><p><a
href="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/severity-exploitability-index-550x309.png" alt="severity exploitability index" title="severity exploitability index" width="550" height="309" class="alignnone size-medium wp-image-37963" /></a></p><p>The updates are already available via Windows Update and the <a
href="http://www.microsoft.com/downloads/en/default.aspx">Microsoft Download Center</a>.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-090.mspx">MS10-090</a> &#8211; Cumulative Security Update for Internet Explorer (2416400) &#8211; This security update resolves four privately reported vulnerabilities and three publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-091.mspx">MS10-091</a> &#8211; Vulnerabilities in the OpenType Font (OTF) Driver Could Allow Remote Code Execution (2296199) &#8211; This security update resolves several privately reported vulnerabilities in the Windows Open Type Font (OTF) driver that could allow remote code execution. An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a> &#8211; Vulnerability in Task Scheduler Could Allow Elevation of Privilege (2305420) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Task Scheduler. The vulnerability could allow elevation of privilege if an attacker logged on to an affected system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-093.mspx">MS10-093</a> &#8211; Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (2424434) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Movie Maker. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Movie Maker file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-094.mspx">MS10-094</a> &#8211; Vulnerability in Windows Media Encoder Could Allow Remote Code Execution (2447961) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Media Encoder. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate Windows Media Profile (.prx) file that is located in the same network directory as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-095.mspx">MS10-095</a> &#8211; Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2385678) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file type such as .eml and .rss (Windows Live Mail) or .wpost (Microsoft Live Writer) located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-096.mspx">MS10-096</a> &#8211; Vulnerability in Windows Address Book Could Allow Remote Code Execution (2423089) &#8211; This security update resolves a publicly disclosed vulnerability in Windows Address Book. The vulnerability could allow remote code execution if a user opens a Windows Address Book file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-097.mspx">MS10-097</a> &#8211; Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105) &#8211;  This security update resolves a publicly disclosed vulnerability in the Internet Connection Signup Wizard of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow remote code execution if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-098.mspx">MS10-098</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2436673) &#8211; This security update resolves one publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-099.mspx">MS10-099</a> &#8211; Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591) &#8211; This security update addresses a privately reported vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/MS10-100.mspx">MS10-100</a> &#8211; Vulnerability in Consent User Interface Could Allow Elevation of Privilege (2442962) &#8211; This security update resolves a privately reported vulnerability in the Consent User Interface (UI). The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application on an affected system. An attacker must have valid logon credentials and the SeImpersonatePrivilege and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-101.mspx">MS10-101</a> &#8211; Vulnerability in Windows Netlogon Service Could Allow Denial of Service (2207559) &#8211; This security update resolves a privately reported vulnerability in the Netlogon RPC Service on affected versions of Windows Server that are configured to serve as domain controllers. The vulnerability could allow denial of service if an attacker sends a specially crafted RPC packet to the Netlogon RPC Service interface on an affected system. An attacker requires administrator privileges on a machine that is joined to the same domain as the affected domain controller in order to exploit this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-102.mspx">MS10-102</a> &#8211; Vulnerability in Hyper-V Could Allow Denial of Service (2345316) &#8211; This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx">MS10-103</a> &#8211; Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2292970) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-104.mspx">MS10-104</a> &#8211; Vulnerability in Microsoft SharePoint Could Allow Remote Code Execution (2455005) &#8211; This security update resolves a privately reported vulnerability in Microsoft SharePoint. The vulnerability could allow remote code execution in the security context of a guest user if an attacker sent a specially crafted SOAP request to the Document Conversions Launcher Service in a SharePoint server environment that is using the Document Conversions Load Balancer Service. By default, the Document Conversions Load Balancer Service and Document Conversions Launcher Service are not enabled in Microsoft Office SharePoint Server 2007.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx">MS10-105</a> &#8211; Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) &#8211; This security update resolves seven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using Microsoft Office. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-106.mspx">MS10-106</a> &#8211; Vulnerability in Microsoft Exchange Server Could Allow Denial of Service (2407132) &#8211; This security update resolves a privately reported vulnerability in Microsoft Exchange Server. The vulnerability could allow denial of service if an authenticated attacker sent a specially crafted network message to a computer running the Exchange service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li></ul><p>Additional information are available at the <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-dec.mspx">security bulletin summary</a> and the <a
href="http://blogs.technet.com/b/msrc/">Microsoft Security Response Center</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/15/microsoft-security-bulletin-december-2010/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Updates June 2010</title><link>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/</link> <comments>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/#comments</comments> <pubDate>Tue, 08 Jun 2010 18:41:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26349</guid> <description><![CDATA[Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of 34 30 different security vulnerabilities. The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released security updates for their operating systems and applications. The June 2010 patch day consists of 10 security bulletins that fix a total of <del
datetime="2010-06-08T20:06:40+00:00">34</del> 30 different security vulnerabilities.</p><p>The updates are already available via Windows Update but can also be downloaded from the Microsoft website in case they need to be deployed on computer systems without Internet connection.</p><p><span
id="more-26349"></span><div
id="attachment_26350" class="wp-caption alignnone" style="width: 509px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/06/windows_update-499x248.png" alt="windows update" title="windows update" width="499" height="248" class="size-medium wp-image-26350" /><p
class="wp-caption-text">windows update</p></div></p><p>The severity rating differs depending on the operating system and software version installed. Three security bulletins have a maximum security rating of critical, the most severe one, while the remaining seven are all rated as important.</p><p>Vulnerabilities affect various Windows operating systems from Windows 2000 to Windows 7, Microsoft Office, Internet Explorer, Microsoft Server and the Microsoft .net Framework.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS10-033.mspx">MS10-033</a> &#8211; Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (980195) &#8211; This security update addresses two privately reported vulnerabilities for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Vista, and Windows 7, and Moderate for all supported editions of Windows Server 2003, Windows Server2008, and Windows Server 2008 R2.<p>The vulnerabilities could allow remote code execution if a user views a specially crafted Web page that instantiates a specific ActiveX control with Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> &#8211; Cumulative Security Update for Internet Explorer (982381) &#8211; This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> &#8211; Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559) &#8211;<br
/> This security update resolves two publicly disclosed vulnerabilities and one privately reported vulnerability in the Windows kernel-mode drivers. The vulnerabilities could allow elevation of privilege if a user views content rendered in a specially crafted TrueType font.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> &#8211; Vulnerability in COM Validation in Microsoft Office Could Allow Remote Code Execution (983235) &#8211; This security update resolves a privately reported vulnerability in COM validation in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel, Word, Visio, Publisher, or PowerPoint file with an affected version of Microsoft Office. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful a user must open an attachment that is sent in an e-mail message.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-037.mspx">MS10-037</a> &#8211; Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Elevation of Privilege (980218) &#8211; This security update resolves a privately reported vulnerability in the Windows OpenType Compact Font Format (CFF) driver. The vulnerability could allow elevation of privilege if a user views content rendered in a specially crafted CFF font. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx">MS10-038</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) &#8211; This security update resolves fourteen privately reported vulnerabilities in Microsoft Office. The more severe vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> &#8211; Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2028554) &#8211; This security update resolves one publicly disclosed and two privately reported vulnerabilities in Microsoft SharePoint. The most severe vulnerability could allow elevation of privilege if an attacker convinced a user of a targeted SharePoint site to click on a specially crafted link.</li><li>MS10-040 &#8211; Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666) &#8211; This security update resolves a privately reported vulnerability in Internet Information Services (IIS). The vulnerability could allow remote code execution if a user received a specially crafted HTTP request. An attacker who successfully exploited this vulnerability could take complete control of an affected system.</li><li> <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx">MS10-041</a> &#8211; Vulnerability in Microsoft .NET Framework Could Allow Tampering (981343) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft .NET Framework. The vulnerability could allow data tampering in signed XML content without being detected. In custom applications, the security impact depends on how the signed content is used in the specific application. Scenarios in which signed XML messages are transmitted over a secure channel (such as SSL) are not affected by this vulnerability.</li></ul><p>It is advised to install the security patches immediately to protect the PC from exploits that are targeting unpatched computer systems. Additional information are provided by the <a
href="http://blogs.technet.com/b/srd/">Security Research &#038; Defense</a> team which offers additional information that are helpful for system administrators and advanced users.</p><p>Lastly there is the <a
href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx">security bulletin</a> overview which lists all relevant information.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/microsoft-security-updates-june-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>AutoPatcher Adds Windows 7 Support</title><link>http://www.ghacks.net/2010/03/08/autopatcher-adds-windows-7-support/</link> <comments>http://www.ghacks.net/2010/03/08/autopatcher-adds-windows-7-support/#comments</comments> <pubDate>Mon, 08 Mar 2010 09:17:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[autopatcher]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[service packs]]></category> <category><![CDATA[windows 7]]></category> <category><![CDATA[windows 7 patch]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23561</guid> <description><![CDATA[AutoPatcher was one of the first software based services that allowed Windows users to download all released service packs and patches for their operating system and Microsoft Office. The service had been in deer troubles in the past thanks to an disagreement with Microsoft. They did come back from that and have changed the way [...]]]></description> <content:encoded><![CDATA[<p>AutoPatcher was one of the first software based services that allowed Windows users to download all released service packs and patches for their operating system and Microsoft Office. The service had been in deer troubles in the past thanks to an disagreement with Microsoft. They did come back from that and have changed the way AutoPatcher operates.</p><p>AutoPatcher is offered as a portable program that can be executed after unpacking the download file. It will then display a list of all available release packages that can be downloaded to the local computer system.</p><p>Available for selection are the core program files. operating system patches for Windows XP, Windows Server 2003 and Windows Vista, Microsoft Office XP, 2003 and 2007, the Microsoft .net Framework, DirectX, Java runtime and Adobe Reader. Most release packages are offered in all languages while some only in specific languages.</p><p><span
id="more-23561"></span><img
src="http://www.ghacks.net/wp-content/uploads/2010/03/autopatcher_windows7-421x500.jpg" alt="" title="autopatcher windows 7" width="421" height="500" class="alignnone size-medium wp-image-23562" /></p><p>Windows 7 was integrated in the latest release of AutoPatcher. AutoPatcher only supports 32-bit operating systems right now which means that the Windows 7 patches are also only offered for the 32-bit version of the operating system.</p><p>The main benefit of using AutoPatcher is that it will download all patches that have been released to the local computer system with the option to install them afterwards. This means that the patches can be installed while the computer is offline. It also means that the patches can be distributed to other computer systems to patch those as well.</p><p><a
href="http://www.autopatcher.com/">AutoPatcher</a> can be downloaded from the developer&#8217;s website, it should run on all Microsoft operating systems including 64-bit editions.</p><p><strong>Update:</strong> AutoPatcher development continues. Support for the first Windows 7 Service Pack has been added to the operating system updater recently. The site itself has seen change though, as it now redirects to a forum where download links and instructions are posted now.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/08/autopatcher-adds-windows-7-support/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Updates February 2010</title><link>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/</link> <comments>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/#comments</comments> <pubDate>Wed, 10 Feb 2010 14:48:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22954</guid> <description><![CDATA[Microsoft has released a total of 14 security updates on yesterday&#8217;s patch day. The updates are, as usual, for several Microsoft software products including the Microsoft Windows operating system and Microsoft Office. Five of the updates have received a critical rating by Microsoft, the highest security rating. Seven were ranked as important which is the [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has released a total of 14 security updates on yesterday&#8217;s patch day. The updates are, as usual, for several Microsoft software products including the Microsoft Windows operating system and Microsoft Office.</p><p>Five of the updates have received a critical rating by Microsoft, the highest security rating. Seven were ranked as important which is the second highest rating and one as moderate. The security ratings can vary depending on the operating system and Office version used.</p><p>Microsoft Windows 7 users for instance will notice that the security updates have all received an important rating for their operating system while Windows 2000 or Windows XP users will notice that their operating systems have received the largest amount of critical ratings.</p><p><span
id="more-22954"></span></p><ul><li>Microsoft Security Bulletin MS10-006 &#8211; Critical &#8211; Vulnerabilities in SMB Client Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">978251</a>) &#8211; his security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit these vulnerabilities, an attacker must convince the user to initiate an SMB connection to a malicious SMB server.<br
/> This security update is rated Critical for Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows 7, and Windows Server 2008 R2, and is rated Important for Windows Vista and Windows Server 2008.</li><li>Microsoft Security Bulletin MS10-007 &#8211; Critical &#8211; Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx">975713</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not impacted by this security update. The vulnerability could allow remote code execution if an application, such as a Web browser, passes specially crafted data to the ShellExecute API function through the Windows Shell Handler.<br
/> This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003</li><li>Microsoft Security Bulletin MS10-008 &#8211; Critical &#8211; Cumulative Security Update of ActiveX Kill Bits (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx">978262</a>) &#8211; his security update addresses a privately reported vulnerability for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000 and Windows XP, Important for all supported editions of Windows Vista and Windows 7, Moderate for all supported editions of Windows Server 2003, and Low for all supported editions of Windows Server 2008 and Windows Server 2008 R2.</li><li>Microsoft Security Bulletin MS10-009 &#8211; Critical &#8211; Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx">974145</a>) &#8211; his security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.<br
/> This security update is rated Critical for Windows Vista and Windows Server 2008.</li><li>Microsoft Security Bulletin MS10-013 &#8211; Critical &#8211; Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-013.mspx">977935</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft DirectShow. The vulnerability could allow remote code execution if a user opened a specially crafted AVI file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Critical for all supported editions of Microsoft Windows except for all supported Itanium-based editions of Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2, for which this security update is rated Important.</li><li>Microsoft Security Bulletin MS10-003 &#8211; Important &#8211; Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-003.mspx">978214</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Important for all supported editions of Microsoft Office XP and Microsoft Office 2004 for Mac.</li><li>Microsoft Security Bulletin MS10-004 &#8211; Important &#8211;  Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx">975416</a>) &#8211; This security update resolves six privately reported vulnerabilities in Microsoft Office PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Important for supported editions of Microsoft Office PowerPoint 2002 and Microsoft Office PowerPoint 2003, and Microsoft Office 2004 for Mac</li><li>Microsoft Security Bulletin MS10-010 &#8211; Important &#8211; Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-010.mspx">977894</a>) &#8211; his security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a malformed sequence of machine instructions is run by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to log on locally into a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.<br
/> This security update is rated Important for all supported x64-based editions of Windows Server 2008 and Windows Server 2008 R2</li><li>Microsoft Security Bulletin MS10-011 &#8211; Important &#8211; Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx">978037</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000, Windows XP, and Windows Server 2003. Other versions of Windows are not affected. The vulnerability could allow elevation of privilege if an attacker logs on to the system and starts a specially crafted application designed to continue running after the attacker logs out. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.</li><li>Microsoft Security Bulletin MS10-012 &#8211; Important &#8211; Vulnerabilities in SMB Server Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx">971468</a>) &#8211; This security update resolves several privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit these vulnerabilities.<br
/> This security update is rated Important for all supported editions of Microsoft Windows.</li><li>Microsoft Security Bulletin MS10-014 &#8211; Important &#8211; Vulnerability in Kerberos Could Allow Denial of Service (<a
href="http://www.microsoft.com/technet/security/bulletin/MS10-014.mspx">977290</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a specially crafted ticket renewal request is sent to the Windows Kerberos domain from an authenticated user on a trusted non-Windows Kerberos realm. The denial of service could persist until the domain controller is restarted.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008</li><li>Microsoft Security Bulletin MS10-015 &#8211; Important &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">977165</a>) &#8211; his security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logged on to the system and then ran a specially crafted application. To exploit either vulnerability, an attacker must have valid logon credentials and be able to log on locally. The vulnerabilities could not be exploited remotely or by anonymous users.<br
/> This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 for 32-bit Systems.</li><li>Microsoft Security Bulletin MS10-005 &#8211; Moderate &#8211; Vulnerability in Microsoft Paint Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms10-005.mspx">978706</a>) &#8211; This security update resolves a privately reported vulnerability in Microsoft Paint. The vulnerability could allow remote code execution if a user viewed a specially crafted JPEG image file using Microsoft Paint. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<br
/> This security update is rated Moderate for Microsoft Windows 2000, Windows XP, and Windows Server 2003</li></ul><p>Updates can be downloaded and installed the usual ways. This includes through Windows Update, Microsoft Update, downloading the updates individually or downloading the security CD for February 2010 which will is provided by Microsoft after every patch day.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/10/microsoft-security-updates-february-2010/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Security Updates October 2009 Online</title><link>http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/</link> <comments>http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/#comments</comments> <pubDate>Tue, 13 Oct 2009 17:29:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft updates]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17232</guid> <description><![CDATA[Microsoft has published all security patches for today&#8217;s Patch Day a few minutes ago. The patches are available via Windows Update, Microsoft Update and the individual security bulletins that describe the nature of each security patch in detail. Windows users are encouraged to update their operating system and software programs as soon as possible to [...]]]></description> <content:encoded><![CDATA[<p>Microsoft has published all security patches for today&#8217;s Patch Day a few minutes ago. The patches are available via Windows Update, Microsoft Update and the individual security bulletins that describe the nature of each security patch in detail. Windows users are encouraged to update their operating system and software programs as soon as possible to block attacks from malicious software that could exploit the security vulnerabilities.</p><p>Microsoft has released the following security patches (with a link pointing to the security bulletin containing additional information, deployment guidelines and download opportunities):</p><p><span
id="more-17232"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx">MS09-050</a> Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517) (Critical) &#8211; This security update resolves one publicly disclosed and two privately reported vulnerabilities in Server Message Block Version 2 (SMBv2). The most severe of the vulnerabilities could allow remote code execution if an attacker sent a specially crafted SMB packet to a computer running the Server service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate from outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-051.mspx">MS09-051</a> Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682) (Critical) &#8211; This security update resolves two privately reported vulnerabilities in Windows Media Runtime. The vulnerabilities could allow remote code execution if a user opened a specially crafted media file or received specially crafted streaming content from a Web site or any application that delivers Web content. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-052.mspx">MS09-052</a> Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112) (Critical) &#8211; This security update resolves a privately reported vulnerability in Windows Media Player. The vulnerability could allow remote code execution if a specially crafted ASF file is played using Windows Media Player 6.4. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx">MS09-054</a> Cumulative Security Update for Internet Explorer (974455) (Critical) &#8211; This security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-055.mspx">MS09-055</a> Cumulative Security Update of ActiveX Kill Bits (973525) (Critical) &#8211; This security update addresses a privately reported vulnerability that is common to multiple ActiveX controls and is currently being exploited. The vulnerability that affects ActiveX controls that were compiled using the vulnerable version of the Microsoft Active Template Library (ATL) could allow remote code execution if a user views a specially crafted Web page with Internet Explorer, instantiating the ActiveX control. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-060.mspx">MS09-060</a> Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965) (Critical) &#8211; This security update resolves several privately reported vulnerabilities in ActiveX Controls for Microsoft that were compiled with a vulnerable version of Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-061.mspx">MS09-061</a> Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378) (Critical) &#8211; This security update resolves three privately reported vulnerabilities in Microsoft .NET Framework and Microsoft Silverlight. The vulnerabilities could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications, or if an attacker succeeds in persuading a user to run a specially crafted Microsoft .NET application. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerabilities could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and executing it, as could be the case in a Web hosting scenario. Microsoft .NET applications, Silverlight applications, XBAPs and ASP.NET pages that are not malicious are not at risk of being compromised because of this vulnerability.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-062.mspx">MS09-062</a> Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488) (Critical)- This security update resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-053.mspx">MS09-053</a> Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254) (Important) &#8211; This security update resolves two publicly disclosed vulnerabilities in the FTP Service in Microsoft Internet Information Services (IIS) 5.0, Microsoft Internet Information Services (IIS) 5.1, Microsoft Internet Information Services (IIS) 6.0, and Microsoft Internet Information Services (IIS) 7.0. On IIS 7.0, only FTP Service 6.0 is affected. The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx">MS09-056</a> Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571) (Important) &#8211; This security update resolves two publicly disclosed vulnerabilities in Microsoft Windows. The vulnerabilities could allow spoofing if an attacker gains access to the certificate used by the end user for authentication.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-057.mspx">MS09-057</a> Vulnerability in Indexing Service Could Allow Remote Code Execution (969059) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker set up a malicious Web page that invokes the Indexing Service through a call to its ActiveX component. This call could include a malicious URL and exploit the vulnerability, granting the attacker access to the client system with the privileges of the user browsing the Web page. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-058.mspx">MS09-058</a> Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486) (Important) &#8211; This security update resolves several privately reported vulnerabilities in the Windows kernel. The most severe of the vulnerabilities could allow elevation of privilege if an attacker logged on to the system and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit any of these vulnerabilities. The vulnerabilities could not be exploited remotely or by anonymous users.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-059.mspx">MS09-059</a> Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467) (Important) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker sent a maliciously crafted packet during the NTLM authentication process.</li></ul><p>Adobe will also release security patches later today for critical vulnerabilities in Acrobat Reader.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/13/microsoft-security-updates-october-2009-online/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Security Patches July 2009</title><link>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/</link> <comments>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/#comments</comments> <pubDate>Wed, 15 Jul 2009 11:49:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security patches]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[security patches]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14410</guid> <description><![CDATA[Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft.jpg" alt="microsoft" title="microsoft" width="156" height="125" class="alignleft size-full wp-image-12026" />Microsoft has released the Security Bulletin Summary for July 2009 which contains security patches for several Microsoft products. Six security patches are provided by Microsoft this time that include three rated critical and three rated important. Affected programs are Microsoft Windows, Microsoft Office, Microsoft ISA Server, Virtual PC and Virtual Server. Affected operating systems are pretty much all from Windows 2000 onwards although the severity rating varies depending on the operating system.</p><p>Critical ratings for Windows XP or Windows Server 2003 are usually important or moderate ratings for Windows Vista or Windows Server 2008 thanks to the increased security in those operating systems. Downloads are already available from various official sources including Automatic Updates, Windows Update or Microsoft Update.</p><p><span
id="more-14410"></span><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx">MS09-028</a> &#8211; Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371) &#8211; This security update resolves two privately reported vulnerabilities in the Microsoft Windows component, Embedded OpenType (EOT) Font Engine. The vulnerabilities could allow remote code execution. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system remotely. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-029.mspx">MS09-029</a> &#8211; Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) &#8211; This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-030.mspx">MS09-030</a> &#8211; Cumulative Security Update of ActiveX Kill Bits (973346) &#8211; This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability in Microsoft Video ActiveX Control could allow remote code execution if a user views a specially crafted Web page with Internet Explorer, instantiating the ActiveX control. This ActiveX control was never intended to be instantiated in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-031.mspx">MS09-031</a> &#8211; Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856) &#8211; This security update resolves a privately reported vulnerability in Microsoft Virtual PC and Microsoft Virtual Server. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected guest operating system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032</a> -Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953) &#8211; This security update resolves a privately reported vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2006. The vulnerability could allow elevation of privilege if an attacker successfully impersonates an administrative user account for an ISA server that is configured for Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation.</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-033.mspx">MS09-033</a> &#8211; Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516) &#8211; This security update resolves a privately reported vulnerability in Microsoft Office Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li></ul><p>It is recommended to install the Microsoft Security Patches as soon as possible to close the security vulnerabilities.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/15/microsoft-security-patches-july-2009/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Microsoft Security Patches for June 2009</title><link>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</link> <comments>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/#comments</comments> <pubDate>Tue, 09 Jun 2009 22:45:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[office patches]]></category> <category><![CDATA[office update]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/</guid> <description><![CDATA[Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office. The easiest way to download [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />Microsoft has released the security bulletin summary for June 2009 which details this month&#8217;s software and system updates. A total of ten security bulletins have been released this month which patch vulnerabilities in a variety of Microsoft products including various Microsoft Windows operating systems, Microsoft Internet Explorer and Microsoft Office.</p><p>The easiest way to download and install the patches is by pointing the Internet Explorer web browser to <a
href="http://update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&#038;&#038;thankspage=5">Microsoft Update</a> which will automatically detect and install the available patches for the computer system. Other possibilities include downloading the security patches from <a
href="http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&#038;freetext=security%20update">Microsoft Download Center</a> from where they are available as well.</p><p><span
id="more-13419"></span>Six vulnerabilities have been rated as critical, three as important and one as moderate. Critical security vulnerabilities can usually be exploited for remote code execution meaning it is essential to fix these vulnerabilities quickly. You can follow the links below for additional information about each vulnerability.</p><ul><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx">MS09-018</a> &#8211; Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx">MS09-019</a> &#8211; Cumulative Security Update for Internet Explorer (969897)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx">MS09-020</a> &#8211; Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-021.mspx">MS09-021</a> &#8211; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx">MS09-022</a> &#8211; Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx">MS09-023</a> &#8211; Vulnerability in Windows Search Could Allow Information Disclosure (963093)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/MS09-024.mspx">MS09-024</a> &#8211; Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx">MS09-025</a> &#8211; Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx">MS09-026</a> &#8211; Vulnerability in RPC Could Allow Elevation of Privilege (970238)</li><li><a
href="http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx">MS09-027</a> &#8211; Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/feed/</wfw:commentRss> <slash:comments>12</slash:comments> </item> <item><title>Microsoft Patch Tuesday December 08</title><link>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/</link> <comments>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/#comments</comments> <pubDate>Wed, 10 Dec 2008 21:06:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patchday]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8835</guid> <description><![CDATA[Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important. The easiest way to install the patches is by downloading and installing the security patches at Windows Update [...]]]></description> <content:encoded><![CDATA[<p>Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.</p><p>The easiest way to install the patches is by downloading and installing the security patches at <a
href="http://www.update.microsoft.com/windowsupdate/v6/thanks.aspx?ln=en&amp;&amp;thankspage=5">Windows Update</a> which provides access to all security updates even for users who run a non legit version of Windows.</p><p>Microsoft did also release a new version of the Windows Malicious Software Removal Tool which is now able to detect two new families of malware (Win32/FakeXPA and Win32/Yektel)</p><p><span
id="more-8835"></span><ul><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx">MS08-070</a>: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx">MS08-071</a>: Vulnerabilities in GDI Could Allow Remote Code Execution (956802) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx">MS08-072</a>: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx">MS08-073</a>: Cumulative Security Update for Internet Explorer (958215) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx">MS08-074</a>: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx">MS08-075</a>: Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349) which is rated &#8220;Critical&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx">MS08-076</a>: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807) which is rated &#8220;Important&#8221;</li><li><a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-077.mspx">MS08-077</a>: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175) which is rated &#8220;Important&#8221;</li></ul><p>Windows users should install the updates as soon as possible to secure their computer system.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft Patch Tuesday November 08</title><link>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/</link> <comments>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/#comments</comments> <pubDate>Wed, 12 Nov 2008 13:55:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft security bulletin]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8233</guid> <description><![CDATA[Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins MS08-069 and MS08-068 patched two vulnerability with the status critical and important. The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code [...]]]></description> <content:encoded><![CDATA[<p>Microsoft released only two patches for their products on this November&#8217;s Patch Tuesday. The Microsoft Security Bulletins <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069</a> and <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">MS08-068</a> patched two vulnerability with the status critical and important.</p><p>The vulnerability rated as critical could allow remote code execution in the in Microsoft XML Core Services while the vulnerability rated important could allow remote code execution in Microsoft Server Message Block (SMB) Protocol.</p><p>Both security vulnerabilities can be fixed by using Windows Update or by downloading the security updates directly from the Microsoft Download website by following the two links given above in this article.</p><p><span
id="more-8233"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft October 2008 Patch Day Patches 11 Security Vulnerabilities</title><link>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/</link> <comments>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/#comments</comments> <pubDate>Wed, 15 Oct 2008 08:38:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[office]]></category> <category><![CDATA[office security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7632</guid> <description><![CDATA[It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not [...]]]></description> <content:encoded><![CDATA[<p>It was always a mystery to me why Microsoft released security patches on one day only considering that an unpatched security vulnerability could be exploited easily in that time. The impression with all the announcements regarding the patches a week or so earlier is that Microsoft has (some of) the patches ready but is not releasing them because they release them in one package on one day.</p><p>Microsoft released a batch of eleven security patches for various operating systems and products yesterday which are available by visiting Windows Update or Microsoft Technet which contains in depths information about the affected products and the security vulnerabilities.</p><p>The patches fix four critical, six important and 1 moderate security vulnerability:</p><p><span
id="more-7632"></span></p><ul><li>Vulnerability in Active Directory Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-060.mspx">957280</a>)</li><li>Cumulative Security Update for Internet Explorer (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-058.mspx">956390</a>)</li><li>Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-059.mspx">956695</a>)</li><li>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx">956416</a>)</li></ul><ul><li>Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-066.mspx">956803</a>)</li><li>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/Bulletin/MS08-061.mspx">954211</a>)</li><li>Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-062.mspx">953155</a>)</li><li>Vulnerability in SMB Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-063.mspx">957095</a>)</li><li>Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-064.mspx">956841</a>)</li><li>Vulnerability in Message Queuing Could Allow Remote Code Execution (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-065.mspx">951071</a>)</li></ul><ul><li>Vulnerability in Microsoft Office Could Allow Information Disclosure (<a
href="http://www.microsoft.com/technet/security/bulletin/ms08-056.mspx">957699</a>)</li></ul><p>It is highly recommended to update the products as soon as possible to protect the system from this attacks.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/10/15/microsoft-october-2008-patch-day-patches-11-security-vulnerabilities/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Create A List Of All Installed Windows Hotfixes</title><link>http://www.ghacks.net/2008/09/08/create-a-list-of-all-installed-windows-hotfixes/</link> <comments>http://www.ghacks.net/2008/09/08/create-a-list-of-all-installed-windows-hotfixes/#comments</comments> <pubDate>Mon, 08 Sep 2008 12:51:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[batch command]]></category> <category><![CDATA[knowledgebase]]></category> <category><![CDATA[microsoft-windows]]></category> <category><![CDATA[windows hotfixes]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows tips]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=6863</guid> <description><![CDATA[Windows hotfixes usually solve errors and problems after installing them. It happened in the past however that they did produce additional errors that could bring a computer system to a standstill. It is therefor handy to produce a list of all installed Windows Hotfixes in the way that they have been installed on a computer [...]]]></description> <content:encoded><![CDATA[<p>Windows hotfixes usually solve errors and problems after installing them. It happened in the past however that they did produce additional errors that could bring a computer system to a standstill. It is therefor handy to produce a list of all installed Windows Hotfixes in the way that they have been installed on a computer system.</p><p>This can be achieved with a small batch file that will create a list of all installed Windows hotfixes and the date and time that they have been installed on the system. The information is taken directly from the KBxxxxxx.log files that are created for each individual hotfix that is installed in Windows.</p><p>Those log files are located in the Windows directory and it would take some time to check them manually to build the list. Here is a screenshot of the output which is saved in a text document in the root directory of the main hard drive.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2008/09/knowledgebase.jpg" alt="knowledgebase" title="knowledgebase" width="427" height="203" class="alignnone size-medium wp-image-6864" /></p><p>The code which has to be added in one line is the following:</p><p><code>dir %windir%\*.log /o:d | findstr /i /r /c:q......\.log /c:kb......\.log /c:q......uninst\.log /c:kb......uninst\.log > %systemdrive%\hotfixes.log</code></p><p>Some of you might prefer a direct download, just download the <a
href='http://www.ghacks.net/wp-content/uploads/2008/09/knowledgebase.zip'>knowledgebase</a> file and unpack it to the computer system. It contains the same code that is shown above.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/09/08/create-a-list-of-all-installed-windows-hotfixes/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Download All Updates For Windows From Microsoft</title><link>http://www.ghacks.net/2008/08/18/download-all-updates-for-windows-from-microsoft/</link> <comments>http://www.ghacks.net/2008/08/18/download-all-updates-for-windows-from-microsoft/#comments</comments> <pubDate>Mon, 18 Aug 2008 15:57:28 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[updates]]></category> <category><![CDATA[updates for windows]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=6265</guid> <description><![CDATA[Users who want to update their Windows operating system can use the automatic updates feature to download updates for Windows automatically, visit the Windows Update website in Internet Explorer or use one of the several Windows Updates downloaders like Autopatcher or Windows Updates Downloader. A third possibility came to light recently with the introduction of [...]]]></description> <content:encoded><![CDATA[<p>Users who want to update their Windows operating system can use the automatic updates feature to download updates for Windows automatically, visit the Windows Update website in Internet Explorer or use one of the several Windows Updates downloaders like <a
href="http://www.ghacks.net/2008/03/24/autopatcher-updater-104/">Autopatcher</a> or <a
href="http://www.ghacks.net/2008/07/20/windows-updates-downloader/">Windows Updates Downloader</a>.</p><p>A third possibility came to light recently with the introduction of the <a
href="http://test.catalog.update.microsoft.com/v7/site/">Windows Update Catalog</a>. Like the Windows Updates website the Windows Update Catalog only loads properly in Internet Explorer. It does offer however a nice and convenient way of downloading all updates for Windows in one go from the official Microsoft server.</p><p>The website features a search form that searches the entire Windows database of patches, updates and applications. Entering a generic name like Windows XP returns more than 1000 results which means that it makes sense to reduce the results by narrowing down the search.</p><p><span
id="more-6265"></span><img
src="http://www.ghacks.net/wp-content/uploads/2008/08/updates_for_windows.jpg" alt="updates for windows" title="updates for windows" width="394" height="99" class="alignnone size-medium wp-image-6266" /></p><p>Instead of searching for Windows XP a user could search for Windows XP Security Updates or Windows XP KB. Items can be added to the basket from where they can be downloaded at once. The updates will be stored in a selected folder from where they can be installed.</p><p>The Windows Update Catalog offers an enhancement by introducing the basket which makes it possible to add all files to it before downloading them in one go. This is a great way of downloading all updates for Windows in short time.</p><p>It is missing a few features like filtering search results by operating system or language which would greatly reduce the hits and time spent on the site.</p><p><strong>Update</strong>: The website is more for the professional user who know exactly what they are looking for. The easiest way to work your way through the site is to know the unique patch numbers to display them directly and without noise in the interface.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/08/18/download-all-updates-for-windows-from-microsoft/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Microsoft Security Patches April 2008</title><link>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/</link> <comments>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/#comments</comments> <pubDate>Tue, 08 Apr 2008 19:34:07 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft patches]]></category> <category><![CDATA[microsoft-office]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-vista]]></category> <category><![CDATA[windows-xp]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=3759</guid> <description><![CDATA[Microsoft have released their Security Bulletin Summary for April 2008 today which contains information and download links to eight patches for various Microsoft operating systems and applications like Microsoft Office and Microsoft Internet Explorer. Five of the eight security patches are patching critical vulnerabilities while three patch important ones. The update is recommended for every [...]]]></description> <content:encoded><![CDATA[<p>Microsoft have released their Security Bulletin Summary for <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx">April 2008</a> today which contains information and download links to eight patches for various Microsoft operating systems and applications like Microsoft Office and Microsoft Internet Explorer. Five of the eight security patches are patching critical vulnerabilities while three patch important ones. The update is recommended for every user that uses Windows and or Microsoft Office.</p><p>All critical vulnerabilities which affect Microsoft Windows, Microsoft Office and Internet Explorer allow Remote Code Execution. The easiest way to patch these security vulnerabilities is by visiting the Windows Update website with Internet Explorer and let a script check the available updates for your system. Please note that you will be asked if you want to install Service Pack 3 Refresh 2 for Windows XP if you use that operating system. My advise would be to not install this version yet and wait for the release version.</p><p>All security updates will be displayed and are selected for immediate download and installation. You could follow the link above which leads to the Microsoft website that explains the vulnerabilities and leads to downloads of the patches. This means that you have to make sure to pick the correct downloads for your operating system and software.</p><p><span
id="more-3759"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Microsoft releases two security patches for Windows</title><link>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/</link> <comments>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/#comments</comments> <pubDate>Wed, 09 Jan 2008 13:23:46 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[microsoft-windows]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows-vista]]></category> <category><![CDATA[windows-xp]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/</guid> <description><![CDATA[Microsoft is releasing collected security patches each month for their Windows operating systems. I'm not a fan of this approach because I would feel safer and securer if they would release patches as soon as they would be ready to be released which would secure computers and reduce the time that someone could exploit these security vulnerabilities.]]></description> <content:encoded><![CDATA[<p>Microsoft is releasing collected security patches each month for their Windows operating systems. I&#8217;m not a fan of this approach because I would feel safer and securer if they would release patches as soon as they would be ready to be released which would secure computers and reduce the time that someone could exploit these security vulnerabilities.</p><p>Two security patches have been released this month, they are the <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx">critical</a> Microsoft Security Bulletin MS08-001 and the <a
href="http://www.microsoft.com/technet/security/bulletin/ms08-002.mspx">important</a> Microsoft Security Bulletin MS08-002. The critical patch fixes vulnerabilities in Windows TCP/IP that could allow remote code execution while the important patch deals with a vulnerability in LSASS that could allow local elevation of privilege.</p><p>Both patches are available through Windows Updates but also as single downloads. Several operating systems need to be patched including Windows Vista (only the critical), Windows 2000 and Windows XP. Downloads are available if you follow the links above.</p><p><span
id="more-2797"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/01/09/microsoft-releases-two-security-patches-for-windows/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>List all installed Windows Updates</title><link>http://www.ghacks.net/2007/10/01/list-all-installed-windows-updates/</link> <comments>http://www.ghacks.net/2007/10/01/list-all-installed-windows-updates/#comments</comments> <pubDate>Mon, 01 Oct 2007 10:50:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Tools]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[knowledge base]]></category> <category><![CDATA[nirsoft]]></category> <category><![CDATA[windows patches]]></category> <category><![CDATA[windows updates]]></category> <category><![CDATA[winupdatelist]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2007/10/01/list-all-installed-windows-updates/</guid> <description><![CDATA[It sometimes might be a good idea to get a list of all installed Windows Updates on your system for administration or security purposes. WinUpdatesList is a sweet small software from one of my favorite developers NirSoft. The software lists all installed Windows Updates on your system detailing all updated files on your system.]]></description> <content:encoded><![CDATA[<p>It sometimes might be a good idea to get a list of all installed Windows Updates on your system for administration or security purposes. WinUpdatesList is a sweet small software from one of my favorite developers NirSoft. The software lists all installed Windows Updates on your system detailing all updated files on your system.</p><p>Besides listing all updated files the tool offers links to the Microsoft website detailing information about the update that has been installed. This is great to verify what the update fixed. All the information can be exported as text, html or xml files.</p><p>You can run the software on all Windows operating systems starting with Windows 98 except Windows Vista. WinUpdatesList can also be used to gather the updates from a second installation of Windows XP / 2000 or from a remote computer.</p><p><span
id="more-2072"></span>To get these information you use the following two commands:</p><p>Another operating system on the same computer: (replace e:\winnt with the drive and dir)</p><p><code>wul.exe /another e:\winnt</code></p><p>Using the software to get the list from a remote computer: (replace 192.168.0.10 with the IP of the remote computer)</p><p><code>wul.exe /remote \\192.168.0.10</code></p><p><strong><br
/> Read More:</strong></p><p><a
href="http://www.nirsoft.net/utils/wul.html">Win Updates List</a></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2007/10/01/list-all-installed-windows-updates/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
