<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; ActiveX</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/activex/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Wed, 28 Jul 2010 16:31:39 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>June 2010 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 08 Jun 2010 13:47:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3336719</guid>
		<description><![CDATA[<p>Hi everyone,</p>
<p>Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these bulletins get our maximum severity rating of Critical. The rest are rated Important. However, we encourage customers to test and deploy all applicable security updates as soon as possible. </p>
<p>The three Critical bulletins get our highest deployment priority this month. Those are:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx">MS10-033</a> is a remote code execution vulnerability in both Quartz.dll and Asycfilt.dll and is rated Critical on all supported versions of Windows. Specially crafted media files could trigger the vulnerability when a user visits a web page or opens a malicious file. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> is a cumulative update for ActiveX Kill Bits and is Critical on Windows 2000, XP, Vista, and Windows 7. There are two Microsoft controls we are applying Kill Bits for. Those are the Internet Explorer 8 Developer Tools control, and the Data Analyzer ActiveX control. The latter control is not installed by default. In addition, there are Kill Bits for four third-party controls. Please review the bulletin for additional details. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> is a cumulative update for Internet Explorer. Of the six vulnerabilities addressed in the bulletin, only one, an information disclosure vulnerability, is publicly known. This issue was identified in <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Security Advisory 980088</a>. We remain unaware of any active attacks against this vulnerability.</li>
</ul>
<p>In the video below, Adrian Stone and I go in to some detail on the three priority bulletins and explain why each should be at the top of your list to install:</p>
<table cellpadding="2" border="0" style="width: 550px">
<tbody>
<tr>
<td>





</td>
<td><span style="font-family: 'Segoe UI','sans-serif';font-size: 12.5pt"><span>
<p><span style="font-size: x-small">More listening and viewing options:</span></p>
<ul type="disc">
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv" title="Windows Media Video (WMV)"><span style="font-size: x-small">Windows Media Video (WMV)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wma" title="Windows Media Audio (WMA)"><span style="font-size: x-small">Windows Media Audio (WMA)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp4" title="iPod Video (MP4)"><span style="font-size: x-small">iPod Video (MP4)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp3" title="MP3 Audio"><span style="font-size: x-small">MP3 Audio</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_2MB_edge.wmv" title="High Quality WMV (2.5 Mbps)"><span style="font-size: x-small">High Quality WMV (2.5 Mbps)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_Zune_edge.wmv" title="Zune Video (WMV)"><span style="font-size: x-small">Zune Video (WMV)</span></a></li>
</ul>
</span></span></td>
</tr>
</tbody>
</table>
<p>Also, included below is the aggregate risk and impact slide for June. Note that we do not typically give an Exploitability Index rating for ActiveX Kill Bits but as stated, this update should be a high priority. </p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4532.June-2010-Severity-and-Exploitability-Index.png" border="0" /></p>
<p>Here is our overall deployment priority information:</p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8780.June-2010-Deployment-Priority.png" border="0" /></p>
<p>There are additional subtleties with specific bulletins that I want to discuss here to eliminate potential confusion:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> is an elevation of privilege issue in the affected Microsoft products. There is a potential remote vector if applications fail to properly request the length of the buffer when calling the affected API. All Microsoft applications make this call properly but there may be applications out there that do not. Regardless, installing this update addresses the issue for all vectors. See our <a href="http://blogs.technet.com/srd">Security Research &#38; Defense (SRD) blog</a> for more details on this one.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> is a COM validation update. The issue could result in an attack through ActiveX in Office applications. This is not a new attack vector but the underlying vulnerability is and the bulletin addresses it. For additional clarification, I want to point out that Office XP does not have the architecture needed for the update. However, for customers running Office XP on Windows XP or newer operating systems, we have made a shim available that protects against the vulnerability. The shim can be installed via a Microsoft FixIt which can be downloaded from <a href="http://support.microsoft.com/kb/983235">KB983235</a>.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> is a SharePoint related update, closing out <a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">Security Advisory 983438</a> which addressed an elevation of privilege vulnerability. We are not currently aware of any attacks against this issue. </li>
</ul>
<p>As usual, our SRD team has written several blog posts that go in to details on some of this month's bulletins and I encourage customers to review those for additional insight: <a href="http://blogs.technet.com/b/srd">http://blogs.technet.com/b/srd</a>. </p>
<p>If you have questions about the June bulletins, please attend our public webcast tomorrow which I will be hosting with Adrian Stone from the MSRC. We will go in to additional details on each bulletin and along with a room full of subject matter experts attempt to address all of your questions. Here's how to register:</p>
<p>When: Wednesday June 10, 2010 at 11:00 a.m. PDT (UTC -7)<br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226</a></p>
<p>I hope you can join us then.</p>
<p>Thanks!</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
<p>Follow us on Twitter: <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3336719" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>
<p>Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these bulletins get our maximum severity rating of Critical. The rest are rated Important. However, we encourage customers to test and deploy all applicable security updates as soon as possible. </p>
<p>The three Critical bulletins get our highest deployment priority this month. Those are:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx">MS10-033</a> is a remote code execution vulnerability in both Quartz.dll and Asycfilt.dll and is rated Critical on all supported versions of Windows. Specially crafted media files could trigger the vulnerability when a user visits a web page or opens a malicious file. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> is a cumulative update for ActiveX Kill Bits and is Critical on Windows 2000, XP, Vista, and Windows 7. There are two Microsoft controls we are applying Kill Bits for. Those are the Internet Explorer 8 Developer Tools control, and the Data Analyzer ActiveX control. The latter control is not installed by default. In addition, there are Kill Bits for four third-party controls. Please review the bulletin for additional details. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> is a cumulative update for Internet Explorer. Of the six vulnerabilities addressed in the bulletin, only one, an information disclosure vulnerability, is publicly known. This issue was identified in <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Security Advisory 980088</a>. We remain unaware of any active attacks against this vulnerability.</li>
</ul>
<p>In the video below, Adrian Stone and I go in to some detail on the three priority bulletins and explain why each should be at the top of your list to install:</p>
<table cellpadding="2" border="0" style="width: 550px;">
<tbody>
<tr>
<td>
<object type="application/x-silverlight-2" height="240" width="320" data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAIAAASIQAAzhgAABQAAAAjADAAMABGAEYARgBGAEYARgAAAAAAAAAAAAAAAAAAAHQAAABoAHQAdABwADoALwAvAGUAZABnAGUALgB0AGUAYwBoAG4AZQB0AC4AYwBvAG0ALwBBAHAAcABfAFQAaABlAG0AZQBzAC8AZABlAGYAYQB1AGwAdAAvAHYAcAAwADkAXwAwADYAXwAyADIALgB4AGEAcAAAADwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC8AQAAbQA9AGgAdAB0AHAAOgAvAC8AZQBjAG4ALgBjAGgAYQBuAG4AZQBsADkALgBtAHMAZABuAC4AYwBvAG0ALwBvADkALwBlAGQAZwBlAC8AOAAvADEALwAwAC8ANQAvADIALwBtAHMAcgBjAGoAdQBuADIAMAAxADAAYgBvAHYAZQByAF8AZQBkAGcAZQAuAHcAbQB2ACwAYQB1AHQAbwBzAHQAYQByAHQAPQBmAGEAbABzAGUALABhAHUAdABvAGgAaQBkAGUAPQB0AHIAdQBlACwAcwBoAG8AdwBlAG0AYgBlAGQAPQB0AHIAdQBlACwAIAB0AGgAdQBtAGIAbgBhAGkAbAA9AGgAdAB0AHAAOgAvAC8AZQBjAG4ALgBjAGgAYQBuAG4AZQBsADkALgBtAHMAZABuAC4AYwBvAG0ALwBvADkALwBlAGQAZwBlAC8AOAAvADEALwAwAC8ANQAvADIALwBtAHMAcgBjAGoAdQBuADIAMAAxADAAYgBvAHYAZQByAF8AMwAyADAAXwBlAGQAZwBlAC4AcABuAGcALAAgAHAAbwBzAHQAaQBkAD0AMgA1ADAAMQA4AAAAAAAAAAAAAAABAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA">
<param value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" name="source" />
<param value="m=http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_320_edge.png, postid=25018" name="initParams" />
<param value="#00FFFFFF" name="background" />
</object>
</td>
<td><span style="font-family: 'Segoe UI','sans-serif'; font-size: 12.5pt; mso-fareast-font-family: 'Times New Roman';"><o :p><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-latin;"><o :p>
<p><span style="font-size: x-small;">More listening and viewing options:</span></p>
<ul type="disc">
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv" title="Windows Media Video (WMV)"><span style="font-size: x-small;">Windows Media Video (WMV)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wma" title="Windows Media Audio (WMA)"><span style="font-size: x-small;">Windows Media Audio (WMA)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp4" title="iPod Video (MP4)"><span style="font-size: x-small;">iPod Video (MP4)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp3" title="MP3 Audio"><span style="font-size: x-small;">MP3 Audio</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_2MB_edge.wmv" title="High Quality WMV (2.5 Mbps)"><span style="font-size: x-small;">High Quality WMV (2.5 Mbps)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_Zune_edge.wmv" title="Zune Video (WMV)"><span style="font-size: x-small;">Zune Video (WMV)</span></a></li>
</ul>
</o></span></o></span></td>
</tr>
</tbody>
</table>
<p>Also, included below is the aggregate risk and impact slide for June. Note that we do not typically give an Exploitability Index rating for ActiveX Kill Bits but as stated, this update should be a high priority. </p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4532.June-2010-Severity-and-Exploitability-Index.png" border="0" /></p>
<p>Here is our overall deployment priority information:</p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8780.June-2010-Deployment-Priority.png" border="0" /></p>
<p>There are additional subtleties with specific bulletins that I want to discuss here to eliminate potential confusion:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> is an elevation of privilege issue in the affected Microsoft products. There is a potential remote vector if applications fail to properly request the length of the buffer when calling the affected API. All Microsoft applications make this call properly but there may be applications out there that do not. Regardless, installing this update addresses the issue for all vectors. See our <a href="http://blogs.technet.com/srd">Security Research &amp; Defense (SRD) blog</a> for more details on this one.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> is a COM validation update. The issue could result in an attack through ActiveX in Office applications. This is not a new attack vector but the underlying vulnerability is and the bulletin addresses it. For additional clarification, I want to point out that Office XP does not have the architecture needed for the update. However, for customers running Office XP on Windows XP or newer operating systems, we have made a shim available that protects against the vulnerability. The shim can be installed via a Microsoft FixIt which can be downloaded from <a href="http://support.microsoft.com/kb/983235">KB983235</a>.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> is a SharePoint related update, closing out <a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">Security Advisory 983438</a> which addressed an elevation of privilege vulnerability. We are not currently aware of any attacks against this issue. </li>
</ul>
<p>As usual, our SRD team has written several blog posts that go in to details on some of this month's bulletins and I encourage customers to review those for additional insight: <a href="http://blogs.technet.com/b/srd">http://blogs.technet.com/b/srd</a>. </p>
<p>If you have questions about the June bulletins, please attend our public webcast tomorrow which I will be hosting with Adrian Stone from the MSRC. We will go in to additional details on each bulletin and along with a room full of subject matter experts attempt to address all of your questions. Here's how to register:</p>
<p>When: Wednesday June 10, 2010 at 11:00 a.m. PDT (UTC -7)<br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226</a></p>
<p>I hope you can join us then.</p>
<p>Thanks!</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
<p>Follow us on Twitter: <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3336719" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Components-PostAttachments/00-03-33-67-19/June-2010-Security-Bulletin-Release-Information.ppt" length="1698816" type="application/vnd.ms-powerpoint" />
		</item>
		<item>
		<title>February 2010 Security Bulletin Release</title>
		<link>http://blogs.technet.com/msrc/archive/2010/02/09/february-2010-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2010/02/09/february-2010-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 09 Feb 2010 18:28:58 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Mitigations]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311638</guid>
		<description><![CDATA[<p>MSRC Bulletin Release Blog Post</p>  <p>Hi everyone,</p>  <p>As mentioned in our ANS blog post last week, today we are releasing 13 bulletins addressing 26 vulnerabilities. 11 bulletins affect Windows and 2 affect older versions of Microsoft Office. </p>  <p>In the post on Thursday, we mentioned that bulletins in the ANS listed as 1, 2, 3, and 6 were going to top our deployment priority list this month. We have also added <a href="http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx">MS10-015</a> (#12) to that list. It addresses <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx">Security Advisory 979682</a>. We are aware of publicly available Proof-of-Concept code for this issue, but are not aware of any active attacks at this time. Here is the mapping from the bulletin numbers in the ANS to the released bulletin ID’s: </p>  <p>   <table border="1" cellspacing="0" cellpadding="0"><tbody>       <tr>         <td valign="top" width="151">ANS Bulletin Number </td>          <td valign="top" width="274">Actual Bulletin Number </td>       </tr>        <tr>         <td valign="top" width="151">1 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-006.mspx">MS10-006</a> </td>       </tr>        <tr>         <td valign="top" width="151">2 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a> </td>       </tr>        <tr>         <td valign="top" width="151">3 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a> </td>       </tr>        <tr>         <td valign="top" width="151">4 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx">MS10-009</a> </td>       </tr>        <tr>         <td valign="top" width="151">5 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx">MS10-012</a> </td>       </tr>        <tr>         <td valign="top" width="151">6 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a> </td>       </tr>        <tr>         <td valign="top" width="151">7 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-003.mspx">MS10-003</a> </td>       </tr>        <tr>         <td valign="top" width="151">8 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx">MS10-004</a> </td>       </tr>        <tr>         <td valign="top" width="151">9 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-010.mspx">MS10-010</a> </td>       </tr>        <tr>         <td valign="top" width="151">10 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx">MS10-011</a> </td>       </tr>        <tr>         <td valign="top" width="151">11 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx">MS10-014</a> </td>       </tr>        <tr>         <td valign="top" width="151">12 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">MS10-015</a> </td>       </tr>        <tr>         <td valign="top" width="151">13 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-005.mspx">MS10-005</a> </td>       </tr>     </tbody></table> </p>  <p>As always, it is recommended that customers deploy all security updates as soon as possible. Of the bulletins released this month, customers should prioritize and deploy <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">MS10-006</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a>, and <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">MS10-015</a>, given Critical severity ratings and/or Exploitability Index ratings of 1 (“Consistent Exploit Code Likely”).</p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a>, which addresses a Critical vulnerability in DirectShow, should be at the top of your list for testing and deployment. This issue is Critical on all supported versions of Windows except Itanium based server products and has an Exploitability Index rating of 1. To exploit the vulnerability, an attacker could host a malicious AVI file on a website and convince a user to visit the site, or send the file via email and convince the a user to open it. </p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">MS10-006</a> is also Critical on all versions of Windows, except Windows Vista and Windows Server 2008, and addresses 2 vulnerabilities in SMB Client. One of the vulnerabilities has an Exploitability Index rating of 1. In the simplest scenario, a system connecting to a network file share is an SMB Client. The issue occurs during the client/server negotiation phase of the connection. In order to exploit this issue, an attacker would need to host a malicious server and convince a client system to connect to it. An attacker could also try to perform a man-in-the-middle attack by responding to SMB requests from clients. From our analysis of this issue, we expect attempts to exploit it would be more likely to result in a Denial of Service than in Remote Code Execution.</p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a> addresses a Critical vulnerability in Windows Shell Handler that affects Windows 2000, Windows XP, and Windows Server 2003. The attack vector is through a specially crafted link that appears to the ShellExecute API to be a valid link. This issue has not been publicly exposed but we give it an Exploitability Index rating of 1, so we urge customers on affected platforms to install it as soon as possible. </p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a> is the last one I will give some additional detail on. This is a cumulative update for ActiveX Killbits and is also Critical. You will notice in our Severity &#38; Exploitability Index chart that we did not give this an Exploitability rating. That is because a Killbit is not an update that addresses the underlying vulnerability. It is a registry setting that keeps the vulnerable ActiveX control from running in Internet Explorer. We will give these an Exploitability rating of 1 if we are aware of active exploitation but in this case, we are not.</p>  <p>You can find more detailed information about these bulletins in several blog posts by our Security Research &#38; Defense team at <a href="http://blogs.technet.com/srd">http://blogs.technet.com/srd</a>. </p>  <p>With that, here are the Severity and Exploitability Index and Deployment Priority slides: </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3311615/original.aspx" target="_blank"><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3311615/original.aspx" width="500" /></a></p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3311613/original.aspx" target="_blank"><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3311613/original.aspx" width="500" /></a></p>  <p>In the following video, Adrian Stone and I talk a little more about this month’s top priority bulletins:</p>  <table border="0" cellspacing="0" cellpadding="2" width="606"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="354">More listening and viewing options:          <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.mp3">MP3 Audio</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>I would also encourage you to attend out public webcast tomorrow where we will go in to detail on all 13 bulletins. Here is the registration information:</p>  <p>Date: Wednesday, Feb 10    <br />Time: 11:00 a.m. PST (UTC -8)     <br />Registration: <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032427679">http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032427679</a></p>  <p>Hope you can join us!</p>  <p>Jerry Bryant    <br />Sr. Security Communications Manager – Lead </p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3311638" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>MSRC Bulletin Release Blog Post</p>  <p>Hi everyone,</p>  <p>As mentioned in our ANS blog post last week, today we are releasing 13 bulletins addressing 26 vulnerabilities. 11 bulletins affect Windows and 2 affect older versions of Microsoft Office. </p>  <p>In the post on Thursday, we mentioned that bulletins in the ANS listed as 1, 2, 3, and 6 were going to top our deployment priority list this month. We have also added <a href="http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx">MS10-015</a> (#12) to that list. It addresses <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx">Security Advisory 979682</a>. We are aware of publicly available Proof-of-Concept code for this issue, but are not aware of any active attacks at this time. Here is the mapping from the bulletin numbers in the ANS to the released bulletin ID’s: </p>  <p>   <table border="1" cellspacing="0" cellpadding="0"><tbody>       <tr>         <td valign="top" width="151">ANS Bulletin Number </td>          <td valign="top" width="274">Actual Bulletin Number </td>       </tr>        <tr>         <td valign="top" width="151">1 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-006.mspx">MS10-006</a> </td>       </tr>        <tr>         <td valign="top" width="151">2 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a> </td>       </tr>        <tr>         <td valign="top" width="151">3 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a> </td>       </tr>        <tr>         <td valign="top" width="151">4 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx">MS10-009</a> </td>       </tr>        <tr>         <td valign="top" width="151">5 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx">MS10-012</a> </td>       </tr>        <tr>         <td valign="top" width="151">6 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a> </td>       </tr>        <tr>         <td valign="top" width="151">7 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-003.mspx">MS10-003</a> </td>       </tr>        <tr>         <td valign="top" width="151">8 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx">MS10-004</a> </td>       </tr>        <tr>         <td valign="top" width="151">9 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-010.mspx">MS10-010</a> </td>       </tr>        <tr>         <td valign="top" width="151">10 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx">MS10-011</a> </td>       </tr>        <tr>         <td valign="top" width="151">11 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx">MS10-014</a> </td>       </tr>        <tr>         <td valign="top" width="151">12 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">MS10-015</a> </td>       </tr>        <tr>         <td valign="top" width="151">13 </td>          <td valign="top" width="274"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-005.mspx">MS10-005</a> </td>       </tr>     </tbody></table> </p>  <p>As always, it is recommended that customers deploy all security updates as soon as possible. Of the bulletins released this month, customers should prioritize and deploy <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">MS10-006</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a>, <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a>, and <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">MS10-015</a>, given Critical severity ratings and/or Exploitability Index ratings of 1 (“Consistent Exploit Code Likely”).</p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a>, which addresses a Critical vulnerability in DirectShow, should be at the top of your list for testing and deployment. This issue is Critical on all supported versions of Windows except Itanium based server products and has an Exploitability Index rating of 1. To exploit the vulnerability, an attacker could host a malicious AVI file on a website and convince a user to visit the site, or send the file via email and convince the a user to open it. </p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">MS10-006</a> is also Critical on all versions of Windows, except Windows Vista and Windows Server 2008, and addresses 2 vulnerabilities in SMB Client. One of the vulnerabilities has an Exploitability Index rating of 1. In the simplest scenario, a system connecting to a network file share is an SMB Client. The issue occurs during the client/server negotiation phase of the connection. In order to exploit this issue, an attacker would need to host a malicious server and convince a client system to connect to it. An attacker could also try to perform a man-in-the-middle attack by responding to SMB requests from clients. From our analysis of this issue, we expect attempts to exploit it would be more likely to result in a Denial of Service than in Remote Code Execution.</p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a> addresses a Critical vulnerability in Windows Shell Handler that affects Windows 2000, Windows XP, and Windows Server 2003. The attack vector is through a specially crafted link that appears to the ShellExecute API to be a valid link. This issue has not been publicly exposed but we give it an Exploitability Index rating of 1, so we urge customers on affected platforms to install it as soon as possible. </p>  <p><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a> is the last one I will give some additional detail on. This is a cumulative update for ActiveX Killbits and is also Critical. You will notice in our Severity &amp; Exploitability Index chart that we did not give this an Exploitability rating. That is because a Killbit is not an update that addresses the underlying vulnerability. It is a registry setting that keeps the vulnerable ActiveX control from running in Internet Explorer. We will give these an Exploitability rating of 1 if we are aware of active exploitation but in this case, we are not.</p>  <p>You can find more detailed information about these bulletins in several blog posts by our Security Research &amp; Defense team at <a href="http://blogs.technet.com/srd">http://blogs.technet.com/srd</a>. </p>  <p>With that, here are the Severity and Exploitability Index and Deployment Priority slides: </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3311615/original.aspx" ><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3311615/original.aspx" width="500" /></a></p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3311613/original.aspx" ><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3311613/original.aspx" width="500" /></a></p>  <p>In the following video, Adrian Stone and I talk a little more about this month’s top priority bulletins:</p>  <table border="0" cellspacing="0" cellpadding="2" width="606"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /> <param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_320_edge.png, postid=17191" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="354">More listening and viewing options:          <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_edge.mp3">MP3 Audio</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/9/1/7/1/msrcfebovb10_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>I would also encourage you to attend out public webcast tomorrow where we will go in to detail on all 13 bulletins. Here is the registration information:</p>  <p>Date: Wednesday, Feb 10    <br />Time: 11:00 a.m. PST (UTC -8)     <br />Registration: <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032427679">http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032427679</a></p>  <p>Hope you can join us!</p>  <p>Jerry Bryant    <br />Sr. Security Communications Manager – Lead </p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3311638" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2010/02/09/february-2010-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2009 Security Bulletin Release</title>
		<link>http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 13 Oct 2009 17:05:34 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Malicious Software Removal Tool (MSRT)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Responsible Disclosure]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3286576</guid>
		<description><![CDATA[<p>Summary of Microsoft’s Security Bulletin Release for October 2009</p>  <p>This month, we released <a href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx">13 new bulletins</a> which address 33 vulnerabilities in Windows, Internet Explorer and Microsoft Office. Since we published this information in our advance notification (ANS) last Thursday, we have been asked “is this the most bulletins Microsoft has ever released”? The short answer to that question is yes. However, we have, on several occasions, released between 10 and 12 bulletins so this is business as usual. All of our updates go through extensive quality testing and when they reach the bar for broad distribution, we schedule them for release. </p>  <p>As we noted in the ANS last week, two of the updates address open Security Advisories. <a href="http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx">MS09-050</a> addresses the SMBv2 issue in <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">Security Advisory 975497</a> and <a href="http://www.microsoft.com/technet/security/bulletin/ms09-053.mspx">MS09-053</a> addresses the IIS issue discussed in <a href="http://www.microsoft.com/technet/security/advisory/975191.mspx">Security Advisory 975191</a>. </p>  <p>Another issue being addressed this month that has received some public attention has to do with security certificates used for authentication. The vulnerabilities being addressed by Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx">MS09-056</a> could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. We are aware that a rogue certificate was distributed in a public forum but we are not aware of any attempts to use this to attack users. </p>  <p>Below is the severity summary and exploitability index for the 13 new bulletins. We also refer to this as the overall risk and impact summary. As you can see, eight of the bulletins have a rating of Critical. Of those eight, six have an exploitability index rating of 1, which means we believe it is highly likely that we will see exploit code in the wild within the first 30 days from the date of release. </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" target="_blank"><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" width="500" /></a></p>  <p>To help with deployment planning, we started publishing our guidance (beginning last month) on which bulletins should be considered first for deployment. Obviously one size does not fit all and each customer will need to consider their own unique situations in addition to this guidance. Our approach is to take a combination of the severity, the exploitability index rating, the range of products affected, and potential mitigations to group these in to a priority 1, 2 or 3. Our <a href="http://blogs.technet.com/srd">Security Research &#38; Defense</a> team, who represent some of the best security researchers in the world, play a key role in this every month as well. </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" target="_blank"><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" width="500" /></a></p>  <p>Most of this month’s updates require a restart, so please refer to the bulletins when you’re planning your deployment to ensure you’re fully protected. We want to specifically note that MS09-050 requires a restart but will not prompt you to do so if you install the update manually. </p>  <p>As we do every month, Adrian Stone and I provide a high-level overview of this month’s bulletin release in the following video:</p>  <table border="0" cellspacing="0" cellpadding="2" width="554"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="302">Other listening and viewing options:          <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp3">MP3 Audio</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>This month we are also re-releasing <a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069, vulnerability in Microsoft XML Core Services could allow remote code execution (955218)</a> to add detection for Windows 7 and Windows Server 2008 R2. This component does not ship with these platforms but many applications install it in order to use its functionality.</p>  <p>Finally, you may also notice a change in the severity rating since the advance notification for several versions of Windows in the .NET bulletin (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx">MS09-061</a>). We have elevated the severity of these products from Important to Critical. We do not typically make changes after the advance notification goes out but during our ongoing investigation to protect customers, we determined that this was the appropriate rating for these products when certain versions of the .NET Framework are installed on them. </p>  <p>We encourage all customers to join us tomorrow when Adrian and I will go in to detail on each bulletin and, along with a room full of subject matter experts, answer all of your questions live. So if you can, please join us at 11:00 a.m. PDT (UTC -7). You can register for the webcast at <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&#38;culture=en-US">this link</a>.</p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>Update – Resource links:</p>  <ul>   <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx" target="_blank">Assessing the risk of the October security bulletins</a> – Security Research &#38; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx" target="_blank">MS09-051: A note on the affected platforms</a> – Security Research &#38; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx" target="_blank">MS09-050: Exploit timeline for SMB2 RCE vulnerability</a> – Security Research &#38; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx" target="_blank">MS09-054: Extra info on the attack surface for the IE security bulletin</a> – Security Research &#38; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx" target="_blank">MS09-061: More information about the .NET security bulletin</a> – Security Research &#38; Defense blog </li>    <li><a href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx" target="_blank">Scanti-ly Clad – Another Rogue Stripped by MSRT</a> – Microsoft Malware Protection Center blog </li> </ul>  <p>Update (10/13) Changed the number of vulnerabilities addressed to 33 from 34. CVE-2009-2493 was counted in both MS09-055 and MS09-060. </p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3286576" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Summary of Microsoft’s Security Bulletin Release for October 2009</p>  <p>This month, we released <a href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx">13 new bulletins</a> which address 33 vulnerabilities in Windows, Internet Explorer and Microsoft Office. Since we published this information in our advance notification (ANS) last Thursday, we have been asked “is this the most bulletins Microsoft has ever released”? The short answer to that question is yes. However, we have, on several occasions, released between 10 and 12 bulletins so this is business as usual. All of our updates go through extensive quality testing and when they reach the bar for broad distribution, we schedule them for release. </p>  <p>As we noted in the ANS last week, two of the updates address open Security Advisories. <a href="http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx">MS09-050</a> addresses the SMBv2 issue in <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">Security Advisory 975497</a> and <a href="http://www.microsoft.com/technet/security/bulletin/ms09-053.mspx">MS09-053</a> addresses the IIS issue discussed in <a href="http://www.microsoft.com/technet/security/advisory/975191.mspx">Security Advisory 975191</a>. </p>  <p>Another issue being addressed this month that has received some public attention has to do with security certificates used for authentication. The vulnerabilities being addressed by Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx">MS09-056</a> could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. We are aware that a rogue certificate was distributed in a public forum but we are not aware of any attempts to use this to attack users. </p>  <p>Below is the severity summary and exploitability index for the 13 new bulletins. We also refer to this as the overall risk and impact summary. As you can see, eight of the bulletins have a rating of Critical. Of those eight, six have an exploitability index rating of 1, which means we believe it is highly likely that we will see exploit code in the wild within the first 30 days from the date of release. </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" ><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" width="500" /></a></p>  <p>To help with deployment planning, we started publishing our guidance (beginning last month) on which bulletins should be considered first for deployment. Obviously one size does not fit all and each customer will need to consider their own unique situations in addition to this guidance. Our approach is to take a combination of the severity, the exploitability index rating, the range of products affected, and potential mitigations to group these in to a priority 1, 2 or 3. Our <a href="http://blogs.technet.com/srd">Security Research &amp; Defense</a> team, who represent some of the best security researchers in the world, play a key role in this every month as well. </p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" ><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" width="500" /></a></p>  <p>Most of this month’s updates require a restart, so please refer to the bulletins when you’re planning your deployment to ensure you’re fully protected. We want to specifically note that MS09-050 requires a restart but will not prompt you to do so if you install the update manually. </p>  <p>As we do every month, Adrian Stone and I provide a high-level overview of this month’s bulletin release in the following video:</p>  <table border="0" cellspacing="0" cellpadding="2" width="554"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /> <param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_320_edge.png, postid=11402" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="302">Other listening and viewing options:          <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp3">MP3 Audio</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>This month we are also re-releasing <a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">MS08-069, vulnerability in Microsoft XML Core Services could allow remote code execution (955218)</a> to add detection for Windows 7 and Windows Server 2008 R2. This component does not ship with these platforms but many applications install it in order to use its functionality.</p>  <p>Finally, you may also notice a change in the severity rating since the advance notification for several versions of Windows in the .NET bulletin (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx">MS09-061</a>). We have elevated the severity of these products from Important to Critical. We do not typically make changes after the advance notification goes out but during our ongoing investigation to protect customers, we determined that this was the appropriate rating for these products when certain versions of the .NET Framework are installed on them. </p>  <p>We encourage all customers to join us tomorrow when Adrian and I will go in to detail on each bulletin and, along with a room full of subject matter experts, answer all of your questions live. So if you can, please join us at 11:00 a.m. PDT (UTC -7). You can register for the webcast at <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;culture=en-US">this link</a>.</p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>Update – Resource links:</p>  <ul>   <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx" >Assessing the risk of the October security bulletins</a> – Security Research &amp; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx" >MS09-051: A note on the affected platforms</a> – Security Research &amp; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx" >MS09-050: Exploit timeline for SMB2 RCE vulnerability</a> – Security Research &amp; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx" >MS09-054: Extra info on the attack surface for the IE security bulletin</a> – Security Research &amp; Defense blog </li>    <li><a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx" >MS09-061: More information about the .NET security bulletin</a> – Security Research &amp; Defense blog </li>    <li><a href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx" >Scanti-ly Clad – Another Rogue Stripped by MSRT</a> – Microsoft Malware Protection Center blog </li> </ul>  <p>Update (10/13) Changed the number of vulnerabilities addressed to 33 from 34. CVE-2009-2493 was counted in both MS09-055 and MS09-060. </p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3286576" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2009 Security Bulletin Webcast Video and Customer Q and A</title>
		<link>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx#comments</comments>
		<pubDate>Fri, 14 Aug 2009 23:42:53 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Defense-in-depth]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Mitigations]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q&A]]></category>
		<category><![CDATA[Security Update Webcast Q&amp]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273699</guid>
		<description><![CDATA[<p>As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).</p>  <p>It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a>: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a <a href="http://support.microsoft.com/fixit#tab0">Microsoft Fix it</a> solution) to customers while we worked towards an update for the underlying issue. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)</a>: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx">MS09-034 – Cumulative Security Update for Internet Explorer (972260)</a>: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)</a>: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this <a href="http://go.microsoft.com/?linkid=9674481">MSDN article</a>. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)</a>: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. </li>    <li><a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. </li> </ul>  <p>To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.</p>  <p>Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx%20">Q&#38;A here&#62;&#62;</a>.</p>  <p>Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&#38;A session:</p>  <table border="0" cellspacing="0" cellpadding="2" width="541"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="289">More viewing and listening options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3">MP3 Audio</a></li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&#38;culture=en-US">Click here to register &#62;&#62;</a>.</p>  <p>Finally, please visit our <a href="http://blogs.technet.com/srd">Security Research &#38; Defense blog</a> where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new <a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx">blog aggregator</a> useful for getting a consolidated view of all of our Trustworthy Computing blogs. </p>  <p>Thanks, </p>  <p>Jerry Bryant </p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).</p>  <p>It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a>: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a <a href="http://support.microsoft.com/fixit#tab0">Microsoft Fix it</a> solution) to customers while we worked towards an update for the underlying issue. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)</a>: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx">MS09-034 – Cumulative Security Update for Internet Explorer (972260)</a>: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)</a>: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this <a href="http://go.microsoft.com/?linkid=9674481">MSDN article</a>. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)</a>: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. </li>    <li><a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. </li> </ul>  <p>To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.</p>  <p>Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx%20">Q&amp;A here&gt;&gt;</a>.</p>  <p>Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&amp;A session:</p>  <table border="0" cellspacing="0" cellpadding="2" width="541"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png, postid=5067" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="289">More viewing and listening options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3">MP3 Audio</a></li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;culture=en-US">Click here to register &gt;&gt;</a>.</p>  <p>Finally, please visit our <a href="http://blogs.technet.com/srd">Security Research &amp; Defense blog</a> where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new <a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx">blog aggregator</a> useful for getting a consolidated view of all of our Trustworthy Computing blogs. </p>  <p>Thanks, </p>  <p>Jerry Bryant </p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2009 Bulletin Release</title>
		<link>http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 11 Aug 2009 20:00:36 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Defense-in-depth]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272463</guid>
		<description><![CDATA[<p>Summary of Microsoft’s Security Bulletin Release for August 2009</p>  <p>Hi everyone,</p>  <p>This month, we released nine security bulletins. Five of those are rated Critical and four have an aggregate severity rating of Important. Of the nine updates, eight affect Windows and the last one affects Office Web Components (OWC). It is also important to note that five of the six critical updates also have an Exploitability Index rating of “1” which means that we could expect there to be consistent, reliable code in the wild seeking to exploit one or more of these vulnerabilities within the first 30 days from release. The chart below shows the aggregate severity summary and exploitability index ratings for all nine bulletins. This overview chart should guide you in prioritizing this month’s updates in order to protect your systems efficiently and effectively.</p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" target="_blank"><img src="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" width="500" border="0" /></a></p>  <p>Of particular note in this release is <a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037</a> which is an update for Microsoft Active Template Library (ATL). Among the five updates in this bulletin is a binary level update for the Microsoft Video ActiveX Control. As you may recall, we originally released <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a> on July 6 in response to an active attack against this component and subsequently released Security Bulletin <a href="http://go.microsoft.com/fwlink/?LinkId=157386">MS09-032</a> to supply an official kill bit update (rather than the temporary Microsoft Fix it supplied with the advisory). All of the included vulnerabilities were privately reported, have a critical severity and are rated “1” on our exploitability index. We encourage you to deploy this update as soon as possible. We will be updating <a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a> to include a reference to this bulletin as it relates to ATL. </p>  <p>Another of the updates I would like to draw your attention to is <a href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx">MS09-043</a>, which addresses the Office Web Components vulnerability discussed in <a href="http://www.microsoft.com/technet/security/advisory/973472.mspx">Security Advisory 973472</a>. We strongly encourage customers to review and deploy this bulletin if applicable given that we have seen exploitation in the wild. Even though this update addresses an ActiveX control issue, it is unrelated to the ATL issue we discuss in <a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>. </p>  <p>If you are running a WINS server on either Windows 2000 or Windows Server 2003 then I would also call your attention to <a href="http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx">MS09-039</a> as this one has the potential for an un-authenticated, self-replicating attack across the network. Installing the update will protect your systems should any attacks be developed to exploit the vulnerabilities addressed in this update but at this time, we are not aware of any exploit code in the wild.</p>  <p>In the video below, Adrian Stone and I provide an overview of this month’s release and discuss the updates above in a little more detail. For even greater detail on all nine bulletins, please join us tomorrow, August 12 at 11:00 a.m. (UTC-7) for our monthly bulletin webcast where we will also address your questions concerning these updates. <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&#38;EventCategory=4&#38;culture=en-US&#38;CountryCode=US">Click HERE to register &#62;&#62;</a></p>  <table cellspacing="0" cellpadding="2" width="544" border="0"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="292">More viewing and listening options:          <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_large_edge.png">Large Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_small_edge.png">Small Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp3">MP3 Audio</a> </li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/0/0/5/msrcaug09itov_s_edge.wmv">Streaming WMV (512kbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>We are also re-releasing two bulletins this month:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-029.mspx">MS09-029</a> to address a print spooler issue on various Windows platforms that could cause the print spooler to stop responding in certain scenarios. Please see <a href="http://support.microsoft.com/kb/961371">Knowledge Base article 961371</a> for details. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035</a> to offer new updates for Visual Studio 2005 SP1, Visual Studio 2008 and Visual Studio 2008 SP1. The new security updates are for developers who use Visual Studio to create components and controls for mobile applications using ATL for Smart Devices. All Visual Studio developers should install these new updates so that they can use Visual Studio to create components and controls that are not vulnerable to the reported issues. For more information on this known issue, see <a href="http://support.microsoft.com/kb/969706">Knowledge Base Article 969706</a>. </li> </ul>  <p>To close this month’s blog post, I would encourage systems administrators and application developers to read through <a href="http://www.microsoft.com/technet/security/advisory/973811.mspx">Security Advisory 973811</a> which was also released today. This is a non-security update that enables new protection technology that can be used to enhance the protection of credentials when authenticating network connections. </p>  <p>As always, please check the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> for additional technical information on these updates and we hope to see you at the webcast tomorrow.</p>  <p>Thanks,</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3272463" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Summary of Microsoft’s Security Bulletin Release for August 2009</p>  <p>Hi everyone,</p>  <p>This month, we released nine security bulletins. Five of those are rated Critical and four have an aggregate severity rating of Important. Of the nine updates, eight affect Windows and the last one affects Office Web Components (OWC). It is also important to note that five of the six critical updates also have an Exploitability Index rating of “1” which means that we could expect there to be consistent, reliable code in the wild seeking to exploit one or more of these vulnerabilities within the first 30 days from release. The chart below shows the aggregate severity summary and exploitability index ratings for all nine bulletins. This overview chart should guide you in prioritizing this month’s updates in order to protect your systems efficiently and effectively.</p>  <p><a href="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" ><img src="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" width="500" border="0" /></a></p>  <p>Of particular note in this release is <a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037</a> which is an update for Microsoft Active Template Library (ATL). Among the five updates in this bulletin is a binary level update for the Microsoft Video ActiveX Control. As you may recall, we originally released <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a> on July 6 in response to an active attack against this component and subsequently released Security Bulletin <a href="http://go.microsoft.com/fwlink/?LinkId=157386">MS09-032</a> to supply an official kill bit update (rather than the temporary Microsoft Fix it supplied with the advisory). All of the included vulnerabilities were privately reported, have a critical severity and are rated “1” on our exploitability index. We encourage you to deploy this update as soon as possible. We will be updating <a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a> to include a reference to this bulletin as it relates to ATL. </p>  <p>Another of the updates I would like to draw your attention to is <a href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx">MS09-043</a>, which addresses the Office Web Components vulnerability discussed in <a href="http://www.microsoft.com/technet/security/advisory/973472.mspx">Security Advisory 973472</a>. We strongly encourage customers to review and deploy this bulletin if applicable given that we have seen exploitation in the wild. Even though this update addresses an ActiveX control issue, it is unrelated to the ATL issue we discuss in <a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>. </p>  <p>If you are running a WINS server on either Windows 2000 or Windows Server 2003 then I would also call your attention to <a href="http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx">MS09-039</a> as this one has the potential for an un-authenticated, self-replicating attack across the network. Installing the update will protect your systems should any attacks be developed to exploit the vulnerabilities addressed in this update but at this time, we are not aware of any exploit code in the wild.</p>  <p>In the video below, Adrian Stone and I provide an overview of this month’s release and discuss the updates above in a little more detail. For even greater detail on all nine bulletins, please join us tomorrow, August 12 at 11:00 a.m. (UTC-7) for our monthly bulletin webcast where we will also address your questions concerning these updates. <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US">Click HERE to register &gt;&gt;</a></p>  <table cellspacing="0" cellpadding="2" width="544" border="0"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/0/0/5/msrcaug09itov_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_large_edge.png, postid=5003" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="292">More viewing and listening options:          <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_large_edge.png">Large Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_small_edge.png">Small Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp3">MP3 Audio</a> </li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/0/0/5/msrcaug09itov_s_edge.wmv">Streaming WMV (512kbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>We are also re-releasing two bulletins this month:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-029.mspx">MS09-029</a> to address a print spooler issue on various Windows platforms that could cause the print spooler to stop responding in certain scenarios. Please see <a href="http://support.microsoft.com/kb/961371">Knowledge Base article 961371</a> for details. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035</a> to offer new updates for Visual Studio 2005 SP1, Visual Studio 2008 and Visual Studio 2008 SP1. The new security updates are for developers who use Visual Studio to create components and controls for mobile applications using ATL for Smart Devices. All Visual Studio developers should install these new updates so that they can use Visual Studio to create components and controls that are not vulnerable to the reported issues. For more information on this known issue, see <a href="http://support.microsoft.com/kb/969706">Knowledge Base Article 969706</a>. </li> </ul>  <p>To close this month’s blog post, I would encourage systems administrators and application developers to read through <a href="http://www.microsoft.com/technet/security/advisory/973811.mspx">Security Advisory 973811</a> which was also released today. This is a non-security update that enables new protection technology that can be used to enhance the protection of credentials when authenticating network connections. </p>  <p>As always, please check the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> for additional technical information on these updates and we hope to see you at the webcast tomorrow.</p>  <p>Thanks,</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3272463" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Bulletin Webcast Video, Questions and Answers – July 2009</title>
		<link>http://blogs.technet.com/msrc/archive/2009/07/15/security-bulletin-webcast-video-questions-and-answers-july-2009.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/07/15/security-bulletin-webcast-video-questions-and-answers-july-2009.aspx#comments</comments>
		<pubDate>Thu, 16 Jul 2009 07:34:14 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[amp]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q & A]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3265126</guid>
		<description><![CDATA[<p>Today Adrian Stone and I conducted the security bulletin webcast for June covering the six bulletins we released yesterday and <a href="http://www.microsoft.com/technet/security/advisory/973472.mspx" target="_blank">Security Advisory 973472</a> (vulnerability in Office Web Components). </p>  <p>There were several questions about <a href="http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx" target="_blank">MS09-028</a> and <a href="http://www.microsoft.com/technet/security/bulletin/MS09-032.mspx" target="_blank">MS09-032</a>. These security updates addressed two open security advisories (<a href="http://www.microsoft.com/technet/security/advisory/971778.mspx" target="_blank">971778</a> and <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank">972890</a> respectively). One common question was “if I installed the Fix it workaround in the advisory, do I need to uninstall it before installing the update in the bulletin?”. The answer to that question is no, you can install the security update right on top of the Fix it workaround. </p>  <p>Another area where we were asked for clarification was if the cumulative security update of ActiveX Kill Bits contained the kill bit for the OWC advisory (973472). Good question. The kill bit provided in the advisory is not part of MS09-032. The issue discussed in the advisory is still under investigation and when that is complete, we will take appropriate action to protect customers. Meanwhile, we encourage all customers to evaluate and apply the workaround as quickly as possible. </p>  <p>With that, <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-july-2009.aspx" target="_blank"><strong>here is the complete list of questions and answers</strong></a> and I invite you to view the video below from today’s webcast.</p>  <table cellspacing="0" cellpadding="2" width="544" border="0"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="292">More viewing and listening options:         <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.mp3">MP3 Audio</a></li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/8/4/3/msrcjul09webcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please join us <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&#38;EventCategory=4&#38;culture=en-US&#38;CountryCode=US" target="_blank">August 12th for our next regularly scheduled webcast</a> following the August bulletin release where we will again have a room full of subject matter experts to answer all of your questions. </p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3265126" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Today Adrian Stone and I conducted the security bulletin webcast for June covering the six bulletins we released yesterday and <a href="http://www.microsoft.com/technet/security/advisory/973472.mspx" >Security Advisory 973472</a> (vulnerability in Office Web Components). </p>  <p>There were several questions about <a href="http://www.microsoft.com/technet/security/bulletin/MS09-028.mspx" >MS09-028</a> and <a href="http://www.microsoft.com/technet/security/bulletin/MS09-032.mspx" >MS09-032</a>. These security updates addressed two open security advisories (<a href="http://www.microsoft.com/technet/security/advisory/971778.mspx" >971778</a> and <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" >972890</a> respectively). One common question was “if I installed the Fix it workaround in the advisory, do I need to uninstall it before installing the update in the bulletin?”. The answer to that question is no, you can install the security update right on top of the Fix it workaround. </p>  <p>Another area where we were asked for clarification was if the cumulative security update of ActiveX Kill Bits contained the kill bit for the OWC advisory (973472). Good question. The kill bit provided in the advisory is not part of MS09-032. The issue discussed in the advisory is still under investigation and when that is complete, we will take appropriate action to protect customers. Meanwhile, we encourage all customers to evaluate and apply the workaround as quickly as possible. </p>  <p>With that, <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-july-2009.aspx" ><strong>here is the complete list of questions and answers</strong></a> and I invite you to view the video below from today’s webcast.</p>  <table cellspacing="0" cellpadding="2" width="544" border="0"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/8/4/3/msrcjul09webcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_large_edge.png, postid=3483" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="292">More viewing and listening options:         <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_edge.mp3">MP3 Audio</a></li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/8/4/3/msrcjul09webcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/8/4/3/msrcjul09webcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please join us <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US" >August 12th for our next regularly scheduled webcast</a> following the August bulletin release where we will again have a room full of subject matter experts to answer all of your questions. </p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3265126" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/07/15/security-bulletin-webcast-video-questions-and-answers-july-2009.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Advisory 973472 Released</title>
		<link>http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx#comments</comments>
		<pubDate>Mon, 13 Jul 2009 12:18:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Microsoft Active Protections Program (MAPP)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Workarounds]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3263403</guid>
		<description><![CDATA[<p class="Bulletin"><span>Hi Everyone,</span></p>
<p class="Bulletin"><span>&#160;</span></p>
<p class="Bulletin"><span>This is Dave Forstrom, group manager for our security response communications team.<span>&#160; </span>We have just posted Microsoft Security Advisory 973472, which highlights a vulnerability in Microsoft Office Web Components. </span><span>Specifically, the vulnerability exists in the Spreadsheet ActiveX control and while we’ve only seen limited attacks, if exploited successfully, an attacker could gain the same user rights as the local user.</span></p>
<p class="Bulletin"><span>&#160;</span></p>
<p class="Bulletin"><span>Products affected are Microsoft Office XP Service Pack 3, Microsoft Office 2003 Service Pack 3, </span><span>Microsoft Office XP Web Components Service Pack 3, Microsoft Office Web Components 2003 Service Pack 3, Microsoft Office 2003 Web Components for the <span>&#160;</span>2007 Microsoft Office system Service Pack 1, Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Microsoft Internet Security and Acceleration Server 2006 Service Pack 1, Microsoft Office Small Business Accounting 2006.</span><span></span></p>
<p class="Bulletin"><span>&#160;</span></p>
<p class="MsoNormal"><span><font face="Calibri"></font><font size="3">We’re currently investigating the issue as part of our </font><a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" target="_blank"><span><font color="#0000ff" size="3">Software Security Incident Response Process (SSIRP)</font></span></a></span><span><font size="3"></font><font face="Calibri">&#160;and working to develop a security update.<span>&#160; </span>This update will be released once it reaches an appropriate level of quality for broad distribution.</font></span></p>
<p class="MsoNormal"><span><font face="Calibri" size="3">&#160;</font></span></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>Additionally, we </span>are actively working with partners in our </font><a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"><font face="Calibri" color="#0000ff" size="3">Microsoft Active Protections Program (MAPP)</font></a><font face="Calibri" size="3"> as well as the </font><a href="http://www.microsoft.com/security/msra/default.mspx" target="_blank"><span><font face="Calibri" color="#0000ff" size="3">Microsoft Security Response Alliance (MSRA)</font></span></a><font size="3"></font><font face="Calibri"><span> </span>to share information that they can use to provide broader protections to customers.</font></p>
<p class="MsoNormal"><span><font face="Calibri" size="3">&#160;</font></span></p>
<p class="MsoNormal"><span><font face="Calibri" size="3">Although the Microsoft Office Web Components ActiveX control has been deprecated for some time now, we still recommend customers implement the workarounds as provided in the Advisory. This can be done either manually, using the instructions in the <b>Workaround</b> section, or automatically, using the solution found in </font></span><a href="http://support.microsoft.com/kb/973472"><span><font face="Calibri" color="#0000ff" size="3">Microsoft Knowledge Base Article 973472</font></span></a><span><font size="3"></font><font face="Calibri">.</font></span></p>
<p class="MsoNormal"><span><font face="Calibri" size="3">&#160;</font></span></p>
<p class="MsoNormal"><font face="Calibri" size="3">For more technical details on the Advisory, please see what our colleagues have written over on the </font><a href="http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx"><font face="Calibri" color="#0000ff" size="3">Security Research &#38; Defense blog</font></a><font face="Calibri" size="3">.</font></p>
<p class="MsoNormal"><font face="Calibri" size="3">&#160;</font></p>
<p class="MsoNormal"><font face="Calibri" size="3">As always, be sure to check back here on the MSRC blog or in the Advisory for any additional information or updates that develop.</font></p>
<p class="MsoNormal"><font face="Calibri" size="3">&#160;</font></p>
<p class="MsoNormal"><font face="Calibri" size="3">Thanks,</font></p>
<p class="MsoNormal"><font face="Calibri" size="3">Dave</font></p>
<p class="Bulletin"><span>&#160;</span></p>
<p class="Bulletin"><span>&#160;</span></p>
<p class="MsoNormal"><span lang="EN"><font face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights*</font></span><span lang="EN"></span></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3263403" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold">Hi Everyone,< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p></o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p>&nbsp;</o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold">This is Dave Forstrom, group manager for our security response communications team.<span style="mso-spacerun: yes">&nbsp; </span>We have just posted Microsoft Security Advisory 973472, which highlights a vulnerability in Microsoft Office Web Components. </span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold">Specifically, the vulnerability exists in the Spreadsheet ActiveX control and while we’ve only seen limited attacks, if exploited successfully, an attacker could gain the same user rights as the local user.<o :p></o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p>&nbsp;</o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold">Products affected are Microsoft Office XP Service Pack 3, Microsoft Office 2003 Service Pack 3, </span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold">Microsoft Office XP Web Components Service Pack 3, Microsoft Office Web Components 2003 Service Pack 3, Microsoft Office 2003 Web Components for the <span style="mso-spacerun: yes">&nbsp;</span>2007 Microsoft Office system Service Pack 1, Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Microsoft Internet Security and Acceleration Server 2006 Service Pack 1, Microsoft Office Small Business Accounting 2006.</span><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p></o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p>&nbsp;</o></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"><font face=Calibri></font><font size=3>We’re currently investigating the issue as part of our </font><a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" ><span style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"><font color=#0000ff size=3>Software Security Incident Response Process (SSIRP)</font></span></a></span><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"><font size=3></font><font face=Calibri>&nbsp;and working to develop a security update.<span style="mso-spacerun: yes">&nbsp; </span>This update will be released once it reaches an appropriate level of quality for broad distribution.<o :p></o></font></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o :p><font face=Calibri size=3>&nbsp;</font></o></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><font size=3></font><font face=Calibri><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri">Additionally, we </span>are actively working with partners in our </font><a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"><font face=Calibri color=#0000ff size=3>Microsoft Active Protections Program (MAPP)</font></a><font face=Calibri size=3> as well as the </font><a href="http://www.microsoft.com/security/msra/default.mspx"  mce_href="http://www.microsoft.com/security/msra/default.mspx"><span style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"><font face=Calibri color=#0000ff size=3>Microsoft Security Response Alliance (MSRA)</font></span></a><font size=3></font><font face=Calibri><span style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"> </span>to share information that they can use to provide broader protections to customers.</font></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><o :p><font face=Calibri size=3>&nbsp;</font></o></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face=Calibri size=3>Although the Microsoft Office Web Components ActiveX control has been deprecated for some time now, we still recommend customers implement the workarounds as provided in the Advisory. This can be done either manually, using the instructions in the <b>Workaround</b> section, or automatically, using the solution found in </font></span><a href="http://support.microsoft.com/kb/973472" mce_href="http://support.microsoft.com/kb/973472"><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font face=Calibri color=#0000ff size=3>Microsoft Knowledge Base Article 973472</font></span></a><span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><font size=3></font><font face=Calibri>.<o :p></o></font></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"><o :p><font face=Calibri size=3>&nbsp;</font></o></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><font face=Calibri size=3>For more technical details on the Advisory, please see what our colleagues have written over on the </font><a href="http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx"><font face=Calibri color=#0000ff size=3>Security Research &amp; Defense blog</font></a><font face=Calibri size=3>.</font></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><o :p><font face=Calibri size=3>&nbsp;</font></o></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><font face=Calibri size=3>As always, be sure to check back here on the MSRC blog or in the Advisory for any additional information or updates that develop.</font></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><o :p><font face=Calibri size=3>&nbsp;</font></o></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><font face=Calibri size=3>Thanks,</font></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><font face=Calibri size=3>Dave</font></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p>&nbsp;</o></span></p>
<p class=Bulletin style="MARGIN: 0in 0in 0pt"><span style="FONT-WEIGHT: normal; FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"><o :p>&nbsp;</o></span></p>
<p class=MsoNormal style="MARGIN: 0in 0in 0pt; LINE-HEIGHT: normal"><span lang=EN style="FONT-SIZE: 12pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN"><font face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights*</font></span><span lang=EN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"><o :p></o></span></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3263403" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Questions about Timing and Microsoft Security Advisory 972890</title>
		<link>http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx#comments</comments>
		<pubDate>Thu, 09 Jul 2009 21:27:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3262556</guid>
		<description><![CDATA[<p class="MsoNormal"><font size="3"></font><font face="Calibri">Hi everyone, Mike Reavey here.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">You’ve probably seen in Jerry’s </font><a href="http://blogs.technet.com/msrc/archive/2009/07/08/july-2009-advance-notification.aspx" target="_blank"><font size="3" face="Calibri">Advance Notification</font></a><font size="3" face="Calibri"> posting today announcing that we’re on track to release an update to address the issue discussed in </font><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank"><font size="3" face="Calibri">Microsoft Security Advisory 972890</font></a><font size="3"></font><font face="Calibri">.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">We’ve gotten some questions from customers about when we got the first report of this vulnerability and how long the investigation has taken relative to the outbreak of attacks against this vulnerability.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Before I go into the details, the key thing I want customers to understand is that this is an issue that was responsibly reported to us and we have been driving in our standard process towards a security update. While in the middle of that process, attackers found this same vulnerability and began attacks against it. We were far enough in the process that we could provide information that customers can use to protect themselves in the interim while we complete that investigation and deliver a security update that you can deploy broadly with confidence. Like Jerry said, we’re targeting next Tuesday to release this update. <span>&#160;</span></font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">In terms of timeline, we received the original report from Ryan Smith and Alex Wheeler with </font><a href="http://www.iss.net/" target="_blank"><font size="3" face="Calibri">IBM ISS X-Force</font></a><font size="3" face="Calibri"> in the early Spring of 2008. The CVE number assigned to this, </font><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015" target="_blank"><font size="3" face="Calibri">CVE-2008-0015</font></a><font size="3"></font><font face="Calibri">, can make it look older but that’s because IBM (like Microsoft) gets CVE numbers in large blocks and assigned them sequentially to issues.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Once we got the report, we started an investigation and confirmed that this ActiveX control that ships with Windows did expose an exploitable vulnerability that could be exploited by malicious websites.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">We always aim to be thorough in our investigations.<span>&#160; </span>For any issue that is reported to us, we strive to address not only the vulnerabilities brought to us but also to find any similar or related issues to ensure the update provides as comprehensive security as possible. And once we confirmed that issue we expanded our investigation to be thorough.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">In the case of this particular issue, part of our investigation showed other interfaces were vulnerable, in this ActiveX Control, not only the one seen used in attacks. </font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Another thing our investigation showed is that there was no known use for these interfaces in Internet Explorer. In fact, as part of our security work on Vista, these interfaces had been disabled in Internet Explorer.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Based on that, our engineering teams felt the best approach to protect customers would be to prevent these any interfaces with no know use in Internet Explorer (45 in total), from loading in Internet Explorer in earlier versions of Windows.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">However, disabling or removing functionality is a more radical step than updating code to address an unchecked buffer, for example. When we disable or remove functionality, we have to engage in even more research and testing than usual, to ensure that we can take this step and not cause more harm than good by inadvertently “breaking” applications. For something like this, we have to ensure not only our applications but also major third-party applications are not hurt by this. Otherwise, if our update “breaks” a major application, customers won’t deploy the update but the bad guys will have information about the vulnerability that they can use to attack it.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">We were far enough along in our process that we felt comfortable taking this information from our investigation and giving it to customers so they could take immediate action to protect themselves while we finish our security update. To make it even easier for customers to protect themselves, we also implemented the “FixIt” that automatically implements the killbits.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Customers who have already implemented the killbits manually or through the FixIt workaround won’t need to implement next week’s security update, though we recommend that you apply the update to ensure that reporting accurately shows that the systems are fully protected.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">We’re on track to release the security update next Tuesday. But if you haven’t implemented the killbits already, we recommend that you go ahead and do that to protect yourself against the attacks.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">I hope this helps answer any questions you might have.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Thanks.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">Mike</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights*</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3262556" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Hi everyone, Mike Reavey here.< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>You’ve probably seen in Jerry’s </font><a href="http://blogs.technet.com/msrc/archive/2009/07/08/july-2009-advance-notification.aspx"  mce_href="http://blogs.technet.com/msrc/archive/2009/07/08/july-2009-advance-notification.aspx"><font size=3 face=Calibri>Advance Notification</font></a><font size=3 face=Calibri> posting today announcing that we’re on track to release an update to address the issue discussed in </font><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"  mce_href="http://www.microsoft.com/technet/security/advisory/972890.mspx"><font size=3 face=Calibri>Microsoft Security Advisory 972890</font></a><font size=3></font><font face=Calibri>.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>We’ve gotten some questions from customers about when we got the first report of this vulnerability and how long the investigation has taken relative to the outbreak of attacks against this vulnerability.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Before I go into the details, the key thing I want customers to understand is that this is an issue that was responsibly reported to us and we have been driving in our standard process towards a security update. While in the middle of that process, attackers found this same vulnerability and began attacks against it. We were far enough in the process that we could provide information that customers can use to protect themselves in the interim while we complete that investigation and deliver a security update that you can deploy broadly with confidence. Like Jerry said, we’re targeting next Tuesday to release this update. <span style="mso-spacerun: yes">&nbsp;</span><o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>In terms of timeline, we received the original report from Ryan Smith and Alex Wheeler with </font><a href="http://www.iss.net/"  mce_href="http://www.iss.net/"><font size=3 face=Calibri>IBM ISS X-Force</font></a><font size=3 face=Calibri> in the early Spring of 2008. The CVE number assigned to this, </font><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015"  mce_href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015"><font size=3 face=Calibri>CVE-2008-0015</font></a><font size=3></font><font face=Calibri>, can make it look older but that’s because IBM (like Microsoft) gets CVE numbers in large blocks and assigned them sequentially to issues.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Once we got the report, we started an investigation and confirmed that this ActiveX control that ships with Windows did expose an exploitable vulnerability that could be exploited by malicious websites.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>We always aim to be thorough in our investigations.<span style="mso-spacerun: yes">&nbsp; </span>For any issue that is reported to us, we strive to address not only the vulnerabilities brought to us but also to find any similar or related issues to ensure the update provides as comprehensive security as possible. And once we confirmed that issue we expanded our investigation to be thorough.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>In the case of this particular issue, part of our investigation showed other interfaces were vulnerable, in this ActiveX Control, not only the one seen used in attacks. <o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Another thing our investigation showed is that there was no known use for these interfaces in Internet Explorer. In fact, as part of our security work on Vista, these interfaces had been disabled in Internet Explorer.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Based on that, our engineering teams felt the best approach to protect customers would be to prevent these any interfaces with no know use in Internet Explorer (45 in total), from loading in Internet Explorer in earlier versions of Windows.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>However, disabling or removing functionality is a more radical step than updating code to address an unchecked buffer, for example. When we disable or remove functionality, we have to engage in even more research and testing than usual, to ensure that we can take this step and not cause more harm than good by inadvertently “breaking” applications. For something like this, we have to ensure not only our applications but also major third-party applications are not hurt by this. Otherwise, if our update “breaks” a major application, customers won’t deploy the update but the bad guys will have information about the vulnerability that they can use to attack it.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>We were far enough along in our process that we felt comfortable taking this information from our investigation and giving it to customers so they could take immediate action to protect themselves while we finish our security update. To make it even easier for customers to protect themselves, we also implemented the “FixIt” that automatically implements the killbits.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Customers who have already implemented the killbits manually or through the FixIt workaround won’t need to implement next week’s security update, though we recommend that you apply the update to ensure that reporting accurately shows that the systems are fully protected.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>We’re on track to release the security update next Tuesday. But if you haven’t implemented the killbits already, we recommend that you go ahead and do that to protect yourself against the attacks.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>I hope this helps answer any questions you might have.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Thanks.<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>Mike<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights*<o :p></o></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3262556" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/07/09/questions-about-timing-and-microsoft-security-advisory-972890.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Advisory 972890 Released</title>
		<link>http://blogs.technet.com/msrc/archive/2009/07/06/microsoft-security-advisory-972890-released.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/07/06/microsoft-security-advisory-972890-released.aspx#comments</comments>
		<pubDate>Mon, 06 Jul 2009 15:59:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Microsoft Active Protections Program (MAPP)]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3261596</guid>
		<description><![CDATA[<p class="MsoNormal"><font size="3" face="Calibri">I wanted to let you know that we have just posted <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank">Microsoft Security Advisory 972890</a> that discusses new, limited attacks against a Microsoft Video ActiveX Control affecting Windows XP and Windows Server 2003.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">Specifically, we’re aware of a code execution vulnerability within this control that can enable an attacker to run code as the logged-on user if they browse to a malicious site.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">We have an investigation into this issue under way as part of our <a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspxsponding.aspx" target="_blank">Software Security Incident Response Process (SSIRP)</a> and are working to develop a security update to address the issue. </font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">In the meantime, our investigation has shown that there are no by-design uses for this ActiveX Control within Internet Explorer.<span>&#160; </span>Therefore, we’re recommending that all customers go ahead and implement the workaround outlined in the Security Advisory: setting all killbits associated with this particular control. While Windows Vista and Windows Server 2008 customers are not affected by this vulnerability, we are recommending that they also set these killbits as a defense-in-depth measure. Once that killbit is set, any attempt by malicious websites to exploit the vulnerability would not succeed. </font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">As we did with <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx" target="_blank">Microsoft Security Advisory 971778</a>, we are providing a way to automatically implement the workaround. Once again, go to the KB article for the advisory and follow the instructions under “Fix It For Me”.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">My colleagues have posted some more details in the <a href="http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx" target="_blank">Security Research and Defense blog</a> as well.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">We are also actively working with partners in the <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx" target="_blank">Microsoft Active Protections Program (MAPP)</a> and the <a href="http://www.microsoft.com/security/msra/default.mspx" target="_blank">Microsoft Security Response Alliance (MSRA)</a> program to provide information that they can use to provide broader protections to customers. </font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">As always, we’ll provide more information as we have it through our <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank">advisory</a>, the <a href="http://blogs.technet.com/msrc">MSRC weblog</a> or both.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">Thanks</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>&#160;</span>Christopher Budd</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights*</font></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3261596" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>I wanted to let you know that we have just posted <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"  mce_href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Microsoft Security Advisory 972890</a> that discusses new, limited attacks against a Microsoft Video ActiveX Control affecting Windows XP and Windows Server 2003.</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal>< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>Specifically, we’re aware of a code execution vulnerability within this control that can enable an attacker to run code as the logged-on user if they browse to a malicious site.</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>We have an investigation into this issue under way as part of our <a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspxsponding.aspx"  mce_href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspxsponding.aspx">Software Security Incident Response Process (SSIRP)</a> and are working to develop a security update to address the issue. </font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>In the meantime, our investigation has shown that there are no by-design uses for this ActiveX Control within Internet Explorer.<span style="mso-spacerun: yes">&nbsp; </span>Therefore, we’re recommending that all customers go ahead and implement the workaround outlined in the Security Advisory: setting all killbits associated with this particular control. While Windows Vista and Windows Server 2008 customers are not affected by this vulnerability, we are recommending that they also set these killbits as a defense-in-depth measure. Once that killbit is set, any attempt by malicious websites to exploit the vulnerability would not succeed. </font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>As we did with <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx"  mce_href="http://www.microsoft.com/technet/security/advisory/971778.mspx">Microsoft Security Advisory 971778</a>, we are providing a way to automatically implement the workaround. Once again, go to the KB article for the advisory and follow the instructions under “Fix It For Me”.</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>My colleagues have posted some more details in the <a href="http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx"  mce_href="http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx">Security Research and Defense blog</a> as well.</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>We are also actively working with partners in the <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx"  mce_href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx">Microsoft Active Protections Program (MAPP)</a> and the <a href="http://www.microsoft.com/security/msra/default.mspx"  mce_href="http://www.microsoft.com/security/msra/default.mspx">Microsoft Security Response Alliance (MSRA)</a> program to provide information that they can use to provide broader protections to customers. </font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>As always, we’ll provide more information as we have it through our <a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"  mce_href="http://www.microsoft.com/technet/security/advisory/972890.mspx">advisory</a>, the <a href="http://blogs.technet.com/msrc" mce_href="http://blogs.technet.com/msrc">MSRC weblog</a> or both.</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>Thanks</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="mso-spacerun: yes">&nbsp;</span>Christopher Budd</font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights*</font></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3261596" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/07/06/microsoft-security-advisory-972890-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2009 Bulletin Release</title>
		<link>http://blogs.technet.com/msrc/archive/2009/06/09/june-2009-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/06/09/june-2009-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 09 Jun 2009 17:29:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252605</guid>
		<description><![CDATA[<p>Summary of Microsoft’s monthly security bulletin release for June 2009.</p>  <p>Today we released <a href="http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx">10 new security bulletins</a>. 6 of those affect Windows with two rated as critical, three rated as important and one as moderate. The remaining four all have an aggregate rating of critical and affect Internet Explorer, Microsoft Office Word, Microsoft Office Excel and Microsoft Works Converters. </p>  <p>In addition to these new bulletins, we are releasing the remaining updates for <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> which now includes updates for Microsoft Office for Mac (versions 2004 and 2008) and Microsoft Works 8.5 and 9.0. You may recall that we released this bulletin last month with updates only for versions of PowerPoint that run on Windows. Please refer to <a href="http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx">last month’s bulletin blog post</a> for more information.</p>  <p>This month we are also releasing two security advisories. The first advisory, <a href="http://www.microsoft.com/technet/security/advisory/969898.mspx">969898</a>, is for a new set of ActiveX kill bits. The list of kill bits in this rollup includes an update for Microsoft Visual Basic 6.0 SP6, and ActiveX controls developed by <a href="http://go.microsoft.com/fwlink/?LinkId=150864">Microgaming</a>, <a href="http://go.microsoft.com/fwlink/?LinkId=150865">eBay</a>, and <a href="http://go.microsoft.com/fwlink/?LinkId=150866">HP</a> (click the company names to view their security release for these kill bits). </p>  <p>The second advisory, <a href="http://www.microsoft.com/technet/security/advisory/971888.mspx">971888</a>, is providing a non-security update for DNS devolution. While this is a non-security update, it changes the security configuration of systems it is applied to and that is why we are releasing it with an advisory. This advisory is also related to the WPAD issue for which we originally released Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/945731.mspx">945731</a> and subsequently Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-008.mspx">MS09-008</a>. With the release of this new advisory, we are closing out Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/945731.mspx">945731</a>. Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971888.mspx">971888</a> and the <a href="http://support.microsoft.com/default.aspx/kb/971888">associated KB</a> article go in to detail on DNS devolution and how the update changes the configuration. If you have any follow up questions, our <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032395225">live webcast</a> tomorrow would be a great place to ask them. </p>  <p>Concerning open advisories going in to this month, with the release of <a href="http://www.microsoft.com/technet/security/bulletin/ms09-020.mspx">MS09-020</a>, Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971492.mspx">971492</a>, which discusses an issue with Internet Information Services, specifically in WebDAV, is now closed. And, as we noted in our <a href="http://blogs.technet.com/msrc/archive/2009/06/04/june-2009-advance-notification.aspx">Advance Notification (ANS) blog post</a> last week, we do not yet have an update ready for the DirectShow vulnerability discussed in Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx">971778</a>. Our security teams are working hard on this issue but the update has to meet the right quality bar before we can release it. We continue to monitor the threat landscape through our Software Security Incident Response Process (SSIRP), and will provide updates to the advisory if needed. We continue to encourage customers to review the mitigations and workarounds in the advisory and check out the “Fix It For Me” solution in <a href="http://support.microsoft.com/default.aspx/kb/971778">Knowledgebase Article 971778</a>. Additionally, please refer to these blog posts for more information on this issue:</p>  <ul>   <li><a href="http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx">New vulnerability in quartz.dll Quicktime parsing</a> </li>    <li><a href="http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx">Microsoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released</a> </li> </ul>  <p>On the Anti-Malware front, the Microsoft Malware Protection Center (MMPC) has added one new malware family: <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/InternetAntivirus">Win32/InternetAntivirus</a> which is a fake online scanner that leads to a rogue downloader. For details, please refer to the <a href="http://blogs.technet.com/mmpc">MMPC Blog</a>.</p>  <p>In the video below, Adrian Stone from the Microsoft Security Response Center (MSRC) and I go in to a little more detail on issues customers should be thinking about when considering the deployment of this month’s updates.</p>  <table cellspacing="0" cellpadding="2" width="547" border="0"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="295">More viewing and listening options:          <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_large_edge.png">Large Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_small_edge.png">Small Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.mp3">MP3 Audio</a> </li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/1/3/2/3/MSRCJuneITProOV_s_edge.wmv">Streaming WMV (512kbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>This month’s release addresses 31 total vulnerabilities with 15 rated as “1” on our Exploitability Index, meaning there is a high likelihood that reliable exploit code may be developed in the next 30 days. </p>  <p>Some of these vulnerabilities are already publicly known. For example, <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1532">CVE-2009-1532</a> addresses the first IE 8 vulnerability. This vulnerability in a pre-release version of IE 8 was first revealed in March 2009 at CanSecWest in the Pwn2Own contest. In the final release, a mitigation was put in to place to protect against ASLR+DEP .NET bypass used in the contest, so right now, there is no known way to attack this issue in the default configuration of IE 8 on Windows Vista (<a href="http://blogs.technet.com/srd/archive/2009/03/23/released-build-of-internet-explorer-8-blocks-dowd-sotirov-aslr-dep-net-bypass.aspx">see the write up in our Security Research &#38; Defense blog for details</a>). Regardless, <a href="http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx">MS09-019</a> addresses the underlying vulnerability which is rated as Critical on Windows XP and Windows Vista but due to IE 8’s built in mitigations, it only rates as a “3” for Windows Vista on the Exploitability Index while Windows XP is rated as “1”. </p>  <p>The IE 8 vulnerability does not affect Windows 7 RC (build 7100) but does affect Windows 7 Beta. Updates for beta versions of Windows 7 will be available via <a href="http://support.microsoft.com/kb/969897" target="_blank">KB969897</a>.</p>  <p>Customers running Windows 2000 domains should pay particular attention to <a href="http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx">MS09-018</a> as <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1138">CVE-2009-1138</a> affects Windows 2000 domain controllers and LDAP server. This is a remote code execution vulnerability that is reachable over the network. While this vulnerability was privately disclosed, we give it a “1” on the Exploitability Index.Finally, the three Office related updates (Excel, Word and Works Converters) all have an aggregate severity rating of Critical due to the Office 2000 platform. All other affected platforms are rated as Important. If you are still on the Office 2000 platform, please note that it reaches the end of its <a href="http://support.microsoft.com/lifecycle/?p1=2484">product lifecycle</a> on July 14, 2009. That is the last day we would release security updates for Office 2000 if there are any to release at that time. </p>  <p>As always, check the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> for additional technical information on these updates.&#160; If you have questions or would like more information about this month’s release, please plan to attend our regularly scheduled security bulletin webcast tomorrow, Wednesday, June 10, 2009, at 11:00 a.m. PDT (UTC –7). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032395225">Click HERE to register</a>.&#160; </p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p>  <p>May 10, 2009: Updated to correct third party ActiveX control company names.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3252605" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Summary of Microsoft’s monthly security bulletin release for June 2009.</p>  <p>Today we released <a href="http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx">10 new security bulletins</a>. 6 of those affect Windows with two rated as critical, three rated as important and one as moderate. The remaining four all have an aggregate rating of critical and affect Internet Explorer, Microsoft Office Word, Microsoft Office Excel and Microsoft Works Converters. </p>  <p>In addition to these new bulletins, we are releasing the remaining updates for <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> which now includes updates for Microsoft Office for Mac (versions 2004 and 2008) and Microsoft Works 8.5 and 9.0. You may recall that we released this bulletin last month with updates only for versions of PowerPoint that run on Windows. Please refer to <a href="http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx">last month’s bulletin blog post</a> for more information.</p>  <p>This month we are also releasing two security advisories. The first advisory, <a href="http://www.microsoft.com/technet/security/advisory/969898.mspx">969898</a>, is for a new set of ActiveX kill bits. The list of kill bits in this rollup includes an update for Microsoft Visual Basic 6.0 SP6, and ActiveX controls developed by <a href="http://go.microsoft.com/fwlink/?LinkId=150864">Microgaming</a>, <a href="http://go.microsoft.com/fwlink/?LinkId=150865">eBay</a>, and <a href="http://go.microsoft.com/fwlink/?LinkId=150866">HP</a> (click the company names to view their security release for these kill bits). </p>  <p>The second advisory, <a href="http://www.microsoft.com/technet/security/advisory/971888.mspx">971888</a>, is providing a non-security update for DNS devolution. While this is a non-security update, it changes the security configuration of systems it is applied to and that is why we are releasing it with an advisory. This advisory is also related to the WPAD issue for which we originally released Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/945731.mspx">945731</a> and subsequently Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms09-008.mspx">MS09-008</a>. With the release of this new advisory, we are closing out Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/945731.mspx">945731</a>. Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971888.mspx">971888</a> and the <a href="http://support.microsoft.com/default.aspx/kb/971888">associated KB</a> article go in to detail on DNS devolution and how the update changes the configuration. If you have any follow up questions, our <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032395225">live webcast</a> tomorrow would be a great place to ask them. </p>  <p>Concerning open advisories going in to this month, with the release of <a href="http://www.microsoft.com/technet/security/bulletin/ms09-020.mspx">MS09-020</a>, Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971492.mspx">971492</a>, which discusses an issue with Internet Information Services, specifically in WebDAV, is now closed. And, as we noted in our <a href="http://blogs.technet.com/msrc/archive/2009/06/04/june-2009-advance-notification.aspx">Advance Notification (ANS) blog post</a> last week, we do not yet have an update ready for the DirectShow vulnerability discussed in Security Advisory <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx">971778</a>. Our security teams are working hard on this issue but the update has to meet the right quality bar before we can release it. We continue to monitor the threat landscape through our Software Security Incident Response Process (SSIRP), and will provide updates to the advisory if needed. We continue to encourage customers to review the mitigations and workarounds in the advisory and check out the “Fix It For Me” solution in <a href="http://support.microsoft.com/default.aspx/kb/971778">Knowledgebase Article 971778</a>. Additionally, please refer to these blog posts for more information on this issue:</p>  <ul>   <li><a href="http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx">New vulnerability in quartz.dll Quicktime parsing</a> </li>    <li><a href="http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx">Microsoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released</a> </li> </ul>  <p>On the Anti-Malware front, the Microsoft Malware Protection Center (MMPC) has added one new malware family: <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/InternetAntivirus">Win32/InternetAntivirus</a> which is a fake online scanner that leads to a rogue downloader. For details, please refer to the <a href="http://blogs.technet.com/mmpc">MMPC Blog</a>.</p>  <p>In the video below, Adrian Stone from the Microsoft Security Response Center (MSRC) and I go in to a little more detail on issues customers should be thinking about when considering the deployment of this month’s updates.</p>  <table cellspacing="0" cellpadding="2" width="547" border="0"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_04_23.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/1/3/2/3/MSRCJuneITProOV_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_large_edge.png, postid=3231" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="295">More viewing and listening options:          <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.wmv">Windows Media Video (WMV)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.wma">Windows Media Audio (WMA)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_large_edge.png">Large Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_small_edge.png">Small Preview Image (PNG)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.mp4">iPod Video (MP4)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_edge.mp3">MP3 Audio</a> </li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/1/3/2/3/MSRCJuneITProOV_s_edge.wmv">Streaming WMV (512kbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a> </li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/1/3/2/3/MSRCJuneITProOV_Zune_edge.wmv">Zune Video (WMV)</a> </li>         </ul>       </td>     </tr>   </tbody></table>  <p>This month’s release addresses 31 total vulnerabilities with 15 rated as “1” on our Exploitability Index, meaning there is a high likelihood that reliable exploit code may be developed in the next 30 days. </p>  <p>Some of these vulnerabilities are already publicly known. For example, <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1532">CVE-2009-1532</a> addresses the first IE 8 vulnerability. This vulnerability in a pre-release version of IE 8 was first revealed in March 2009 at CanSecWest in the Pwn2Own contest. In the final release, a mitigation was put in to place to protect against ASLR+DEP .NET bypass used in the contest, so right now, there is no known way to attack this issue in the default configuration of IE 8 on Windows Vista (<a href="http://blogs.technet.com/srd/archive/2009/03/23/released-build-of-internet-explorer-8-blocks-dowd-sotirov-aslr-dep-net-bypass.aspx">see the write up in our Security Research &amp; Defense blog for details</a>). Regardless, <a href="http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx">MS09-019</a> addresses the underlying vulnerability which is rated as Critical on Windows XP and Windows Vista but due to IE 8’s built in mitigations, it only rates as a “3” for Windows Vista on the Exploitability Index while Windows XP is rated as “1”. </p>  <p>The IE 8 vulnerability does not affect Windows 7 RC (build 7100) but does affect Windows 7 Beta. Updates for beta versions of Windows 7 will be available via <a href="http://support.microsoft.com/kb/969897" >KB969897</a>.</p>  <p>Customers running Windows 2000 domains should pay particular attention to <a href="http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx">MS09-018</a> as <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1138">CVE-2009-1138</a> affects Windows 2000 domain controllers and LDAP server. This is a remote code execution vulnerability that is reachable over the network. While this vulnerability was privately disclosed, we give it a “1” on the Exploitability Index.Finally, the three Office related updates (Excel, Word and Works Converters) all have an aggregate severity rating of Critical due to the Office 2000 platform. All other affected platforms are rated as Important. If you are still on the Office 2000 platform, please note that it reaches the end of its <a href="http://support.microsoft.com/lifecycle/?p1=2484">product lifecycle</a> on July 14, 2009. That is the last day we would release security updates for Office 2000 if there are any to release at that time. </p>  <p>As always, check the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> for additional technical information on these updates.&#160; If you have questions or would like more information about this month’s release, please plan to attend our regularly scheduled security bulletin webcast tomorrow, Wednesday, June 10, 2009, at 11:00 a.m. PDT (UTC –7). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032395225">Click HERE to register</a>.&#160; </p>  <p>Thanks!</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p>  <p>May 10, 2009: Updated to correct third party ActiveX control company names.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3252605" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/06/09/june-2009-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
