<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Internet Explorer (IE)</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/internet-explorer-ie/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 09 Sep 2010 16:45:00 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>June 2010 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 08 Jun 2010 13:47:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3336719</guid>
		<description><![CDATA[<p>Hi everyone,</p>
<p>Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these bulletins get our maximum severity rating of Critical. The rest are rated Important. However, we encourage customers to test and deploy all applicable security updates as soon as possible. </p>
<p>The three Critical bulletins get our highest deployment priority this month. Those are:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx">MS10-033</a> is a remote code execution vulnerability in both Quartz.dll and Asycfilt.dll and is rated Critical on all supported versions of Windows. Specially crafted media files could trigger the vulnerability when a user visits a web page or opens a malicious file. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> is a cumulative update for ActiveX Kill Bits and is Critical on Windows 2000, XP, Vista, and Windows 7. There are two Microsoft controls we are applying Kill Bits for. Those are the Internet Explorer 8 Developer Tools control, and the Data Analyzer ActiveX control. The latter control is not installed by default. In addition, there are Kill Bits for four third-party controls. Please review the bulletin for additional details. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> is a cumulative update for Internet Explorer. Of the six vulnerabilities addressed in the bulletin, only one, an information disclosure vulnerability, is publicly known. This issue was identified in <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Security Advisory 980088</a>. We remain unaware of any active attacks against this vulnerability.</li>
</ul>
<p>In the video below, Adrian Stone and I go in to some detail on the three priority bulletins and explain why each should be at the top of your list to install:</p>
<table cellpadding="2" border="0" style="width: 550px">
<tbody>
<tr>
<td>





</td>
<td><span style="font-family: 'Segoe UI','sans-serif';font-size: 12.5pt"><span>
<p><span style="font-size: x-small">More listening and viewing options:</span></p>
<ul type="disc">
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv" title="Windows Media Video (WMV)"><span style="font-size: x-small">Windows Media Video (WMV)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wma" title="Windows Media Audio (WMA)"><span style="font-size: x-small">Windows Media Audio (WMA)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp4" title="iPod Video (MP4)"><span style="font-size: x-small">iPod Video (MP4)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp3" title="MP3 Audio"><span style="font-size: x-small">MP3 Audio</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_2MB_edge.wmv" title="High Quality WMV (2.5 Mbps)"><span style="font-size: x-small">High Quality WMV (2.5 Mbps)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_Zune_edge.wmv" title="Zune Video (WMV)"><span style="font-size: x-small">Zune Video (WMV)</span></a></li>
</ul>
</span></span></td>
</tr>
</tbody>
</table>
<p>Also, included below is the aggregate risk and impact slide for June. Note that we do not typically give an Exploitability Index rating for ActiveX Kill Bits but as stated, this update should be a high priority. </p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4532.June-2010-Severity-and-Exploitability-Index.png" border="0" /></p>
<p>Here is our overall deployment priority information:</p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8780.June-2010-Deployment-Priority.png" border="0" /></p>
<p>There are additional subtleties with specific bulletins that I want to discuss here to eliminate potential confusion:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> is an elevation of privilege issue in the affected Microsoft products. There is a potential remote vector if applications fail to properly request the length of the buffer when calling the affected API. All Microsoft applications make this call properly but there may be applications out there that do not. Regardless, installing this update addresses the issue for all vectors. See our <a href="http://blogs.technet.com/srd">Security Research &#38; Defense (SRD) blog</a> for more details on this one.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> is a COM validation update. The issue could result in an attack through ActiveX in Office applications. This is not a new attack vector but the underlying vulnerability is and the bulletin addresses it. For additional clarification, I want to point out that Office XP does not have the architecture needed for the update. However, for customers running Office XP on Windows XP or newer operating systems, we have made a shim available that protects against the vulnerability. The shim can be installed via a Microsoft FixIt which can be downloaded from <a href="http://support.microsoft.com/kb/983235">KB983235</a>.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> is a SharePoint related update, closing out <a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">Security Advisory 983438</a> which addressed an elevation of privilege vulnerability. We are not currently aware of any attacks against this issue. </li>
</ul>
<p>As usual, our SRD team has written several blog posts that go in to details on some of this month's bulletins and I encourage customers to review those for additional insight: <a href="http://blogs.technet.com/b/srd">http://blogs.technet.com/b/srd</a>. </p>
<p>If you have questions about the June bulletins, please attend our public webcast tomorrow which I will be hosting with Adrian Stone from the MSRC. We will go in to additional details on each bulletin and along with a room full of subject matter experts attempt to address all of your questions. Here's how to register:</p>
<p>When: Wednesday June 10, 2010 at 11:00 a.m. PDT (UTC -7)<br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226</a></p>
<p>I hope you can join us then.</p>
<p>Thanks!</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
<p>Follow us on Twitter: <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3336719" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>
<p>Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these bulletins get our maximum severity rating of Critical. The rest are rated Important. However, we encourage customers to test and deploy all applicable security updates as soon as possible. </p>
<p>The three Critical bulletins get our highest deployment priority this month. Those are:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx">MS10-033</a> is a remote code execution vulnerability in both Quartz.dll and Asycfilt.dll and is rated Critical on all supported versions of Windows. Specially crafted media files could trigger the vulnerability when a user visits a web page or opens a malicious file. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx">MS10-034</a> is a cumulative update for ActiveX Kill Bits and is Critical on Windows 2000, XP, Vista, and Windows 7. There are two Microsoft controls we are applying Kill Bits for. Those are the Internet Explorer 8 Developer Tools control, and the Data Analyzer ActiveX control. The latter control is not installed by default. In addition, there are Kill Bits for four third-party controls. Please review the bulletin for additional details. </li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx">MS10-035</a> is a cumulative update for Internet Explorer. Of the six vulnerabilities addressed in the bulletin, only one, an information disclosure vulnerability, is publicly known. This issue was identified in <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">Security Advisory 980088</a>. We remain unaware of any active attacks against this vulnerability.</li>
</ul>
<p>In the video below, Adrian Stone and I go in to some detail on the three priority bulletins and explain why each should be at the top of your list to install:</p>
<table cellpadding="2" border="0" style="width: 550px;">
<tbody>
<tr>
<td>
<object type="application/x-silverlight-2" height="240" width="320" data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAIAAASIQAAzhgAABQAAAAjADAAMABGAEYARgBGAEYARgAAAAAAAAAAAAAAAAAAAHQAAABoAHQAdABwADoALwAvAGUAZABnAGUALgB0AGUAYwBoAG4AZQB0AC4AYwBvAG0ALwBBAHAAcABfAFQAaABlAG0AZQBzAC8AZABlAGYAYQB1AGwAdAAvAHYAcAAwADkAXwAwADYAXwAyADIALgB4AGEAcAAAADwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC8AQAAbQA9AGgAdAB0AHAAOgAvAC8AZQBjAG4ALgBjAGgAYQBuAG4AZQBsADkALgBtAHMAZABuAC4AYwBvAG0ALwBvADkALwBlAGQAZwBlAC8AOAAvADEALwAwAC8ANQAvADIALwBtAHMAcgBjAGoAdQBuADIAMAAxADAAYgBvAHYAZQByAF8AZQBkAGcAZQAuAHcAbQB2ACwAYQB1AHQAbwBzAHQAYQByAHQAPQBmAGEAbABzAGUALABhAHUAdABvAGgAaQBkAGUAPQB0AHIAdQBlACwAcwBoAG8AdwBlAG0AYgBlAGQAPQB0AHIAdQBlACwAIAB0AGgAdQBtAGIAbgBhAGkAbAA9AGgAdAB0AHAAOgAvAC8AZQBjAG4ALgBjAGgAYQBuAG4AZQBsADkALgBtAHMAZABuAC4AYwBvAG0ALwBvADkALwBlAGQAZwBlAC8AOAAvADEALwAwAC8ANQAvADIALwBtAHMAcgBjAGoAdQBuADIAMAAxADAAYgBvAHYAZQByAF8AMwAyADAAXwBlAGQAZwBlAC4AcABuAGcALAAgAHAAbwBzAHQAaQBkAD0AMgA1ADAAMQA4AAAAAAAAAAAAAAABAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA">
<param value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" name="source" />
<param value="m=http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_320_edge.png, postid=25018" name="initParams" />
<param value="#00FFFFFF" name="background" />
</object>
</td>
<td><span style="font-family: 'Segoe UI','sans-serif'; font-size: 12.5pt; mso-fareast-font-family: 'Times New Roman';"><o :p><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-latin;"><o :p>
<p><span style="font-size: x-small;">More listening and viewing options:</span></p>
<ul type="disc">
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wmv" title="Windows Media Video (WMV)"><span style="font-size: x-small;">Windows Media Video (WMV)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.wma" title="Windows Media Audio (WMA)"><span style="font-size: x-small;">Windows Media Audio (WMA)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp4" title="iPod Video (MP4)"><span style="font-size: x-small;">iPod Video (MP4)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_edge.mp3" title="MP3 Audio"><span style="font-size: x-small;">MP3 Audio</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_2MB_edge.wmv" title="High Quality WMV (2.5 Mbps)"><span style="font-size: x-small;">High Quality WMV (2.5 Mbps)</span></a></li>
<li><a href="http://ecn.channel9.msdn.com/o9/edge/8/1/0/5/2/msrcjun2010bover_Zune_edge.wmv" title="Zune Video (WMV)"><span style="font-size: x-small;">Zune Video (WMV)</span></a></li>
</ul>
</o></span></o></span></td>
</tr>
</tbody>
</table>
<p>Also, included below is the aggregate risk and impact slide for June. Note that we do not typically give an Exploitability Index rating for ActiveX Kill Bits but as stated, this update should be a high priority. </p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4532.June-2010-Severity-and-Exploitability-Index.png" border="0" /></p>
<p>Here is our overall deployment priority information:</p>
<p><img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8780.June-2010-Deployment-Priority.png" border="0" /></p>
<p>There are additional subtleties with specific bulletins that I want to discuss here to eliminate potential confusion:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx">MS10-032</a> is an elevation of privilege issue in the affected Microsoft products. There is a potential remote vector if applications fail to properly request the length of the buffer when calling the affected API. All Microsoft applications make this call properly but there may be applications out there that do not. Regardless, installing this update addresses the issue for all vectors. See our <a href="http://blogs.technet.com/srd">Security Research &amp; Defense (SRD) blog</a> for more details on this one.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx">MS10-036</a> is a COM validation update. The issue could result in an attack through ActiveX in Office applications. This is not a new attack vector but the underlying vulnerability is and the bulletin addresses it. For additional clarification, I want to point out that Office XP does not have the architecture needed for the update. However, for customers running Office XP on Windows XP or newer operating systems, we have made a shim available that protects against the vulnerability. The shim can be installed via a Microsoft FixIt which can be downloaded from <a href="http://support.microsoft.com/kb/983235">KB983235</a>.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx">MS10-039</a> is a SharePoint related update, closing out <a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">Security Advisory 983438</a> which addressed an elevation of privilege vulnerability. We are not currently aware of any attacks against this issue. </li>
</ul>
<p>As usual, our SRD team has written several blog posts that go in to details on some of this month's bulletins and I encourage customers to review those for additional insight: <a href="http://blogs.technet.com/b/srd">http://blogs.technet.com/b/srd</a>. </p>
<p>If you have questions about the June bulletins, please attend our public webcast tomorrow which I will be hosting with Adrian Stone from the MSRC. We will go in to additional details on each bulletin and along with a room full of subject matter experts attempt to address all of your questions. Here's how to register:</p>
<p>When: Wednesday June 10, 2010 at 11:00 a.m. PDT (UTC -7)<br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032395226</a></p>
<p>I hope you can join us then.</p>
<p>Thanks!</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
<p>Follow us on Twitter: <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3336719" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/06/08/june-2010-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Components-PostAttachments/00-03-33-67-19/June-2010-Security-Bulletin-Release-Information.ppt" length="1698816" type="application/vnd.ms-powerpoint" />
		</item>
		<item>
		<title>June 2010 Security Bulletin Advance Notification</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/06/03/june-2010-security-bulletin-advance-notification.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/06/03/june-2010-security-bulletin-advance-notification.aspx#comments</comments>
		<pubDate>Thu, 03 Jun 2010 17:01:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3335584</guid>
		<description><![CDATA[<p class="MsoNormal"><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #333333">Hi everyone,</span></span></span></p>
<p class="MsoNormal"><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #333333"></span></span></span><span style="color: #333333"><span style="font-family: Calibri;font-size: small">Today we published our </span></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx"><span><span style="font-family: Calibri;color: #000077;font-size: small">advance notification</span></span></a><span style="color: #333333"><span style="font-family: Calibri"><span style="font-size: small"> for the June security bulletin release, scheduled for release next Tuesday, June 8. This month&#8217;s release includes ten bulletins addressing 34 vulnerabilities.</span></span></span></p>
<ul>
<li>
<div class="MsoListParagraphCxSpFirst"><span style="color: #333333"><span style="font-family: Calibri;font-size: small">Six of the bulletins affect Windows; of those, two carry a Critical </span></span><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><span><span style="font-family: Calibri;color: #000077;font-size: small">severity rating</span></span></a><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #333333"> and four are rated Important. </span><span style="color: #333333"></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpMiddle"><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #333333">Two bulletins, both with a severity rating of Important, affect Microsoft Office. </span><span style="color: #333333"></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpMiddle"><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #333333">One bulletin, again with a severity rating of Important, affects both Windows and Office. <span>&#160;</span></span><span style="color: #333333"></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpLast"><span style="color: #333333"><span style="font-family: Calibri"><span style="font-size: small">One bulletin, with a severity rating of Critical, affects Internet Explorer.</span></span></span></div>
</li>
</ul>
<p class="MsoNormal"><span style="color: #333333"><span style="font-family: Calibri"><span style="font-size: small">As ever, we recommend that customers prepare for the testing and deployment of these bulletins as soon as possible. </span></span></span></p>
<p class="MsoNormal"><span style="color: #333333"><span style="font-family: Calibri"><span style="font-size: small">We will also be acting on two Security Advisories this month.</span></span></span></p>
<ul>
<li>
<div class="MsoListParagraphCxSpFirst"><span style="color: #333333"><span style="font-family: Calibri;font-size: small">We are closing Security Advisory 983438 (</span></span><a href="http://www.microsoft.com/technet/security/advisory/983438.mspx"><span style="color: #000077"><span style="font-family: Calibri"><span style="font-size: small"><span>Vuln</span><span>erability in Microsoft SharePoint Could Allow Elevation of Privilege</span></span></span></span></a><span><span style="font-family: Calibri"><span style="font-size: small">) with the June bulletins. </span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpLast"><span style="color: #333333"><span style="font-family: Calibri;font-size: small">We are also addressing Security Advisory 980088 (</span></span><a href="http://www.microsoft.com/technet/security/advisory/980088.mspx"><span><span style="font-family: Calibri;color: #000077;font-size: small">Vulnerability in Internet Explorer Could Allow Information Disclosure</span></span></a><span><span style="font-size: small"><span style="font-family: Calibri">). </span></span></span></div>
</li>
</ul>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333">Please join Adrian Stone and me for a public webcast on Wednesday next week where we will go into detail about the bulletins and answer questions live on the air. Register at the link below:</span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span><span style="color: #333333"><span style="font-family: Calibri;font-size: small">Date: Wednesday June 9<br />Time: 11:00 a.m. PDT (UTC &#8211;7) <br />Registration: </span></span><a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427727"><span><span style="font-family: Calibri;color: #000077;font-size: small">https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427727</span></span></a></p>
<p class="MsoNormal">&#160;</p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333">Finally, we remind Windows 2000 and Windows XP SP2 customers once again that all support for these platforms will end after July 13, 2010 &#8211; that is, next month. Customers should upgrade to either a supported operating system or the latest service pack in order to keep receiving necessary security updates. </span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333">Thanks,</span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #333333"></span></span></span><span style="color: #333333"><span style="font-size: small"><span style="font-family: Calibri">Jerry Bryant<br />Group Manager, Response Communications</span></span></span></p>
<p class="MsoNormal"><span style="color: #333333"><span style="font-size: small"><span style="font-family: Calibri"></span></span></span></p>
<p class="MsoNormal"><span style="color: #333333"><span style="font-size: small"><span style="font-family: Calibri"></span></span></span><span style="color: #333333"><span style="font-family: Calibri;font-size: small">Follow us on Twitter: </span></span><a href="http://twitter.com/msftsecresponse"><span style="color: blue"><span style="font-family: Calibri;font-size: small">@MSFTSecResponse</span></span></a><span style="color: #333333"></span></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3335584" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Hi everyone,</span></span></span></p>
<p class="MsoNormal"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; font-size: small;">Today we published our </span></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; color: #000077; font-size: small;">advance notification</span></span></a><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri;"><span style="font-size: small;"> for the June security bulletin release, scheduled for release next Tuesday, June 8. This month&rsquo;s release includes ten bulletins addressing 34 vulnerabilities.<o :p></o></span></span></span></p>
<ul>
<li>
<div class="MsoListParagraphCxSpFirst"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; font-size: small;">Six of the bulletins affect Windows; of those, two carry a Critical </span></span><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; color: #000077; font-size: small;">severity rating</span></span></a><span style="font-family: Calibri;"><span style="font-size: small;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"> and four are rated Important. </span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><o :p></o></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpMiddle"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Two bulletins, both with a severity rating of Important, affect Microsoft Office. </span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><o :p></o></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpMiddle"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">One bulletin, again with a severity rating of Important, affects both Windows and Office. <span style="mso-spacerun: yes;">&nbsp;</span></span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><o :p></o></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpLast"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri;"><span style="font-size: small;">One bulletin, with a severity rating of Critical, affects Internet Explorer.<o :p></o></span></span></span></div>
</li>
</ul>
<p class="MsoNormal"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri;"><span style="font-size: small;">As ever, we recommend that customers prepare for the testing and deployment of these bulletins as soon as possible. <o :p></o></span></span></span></p>
<p class="MsoNormal"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri;"><span style="font-size: small;">We will also be acting on two Security Advisories this month.<o :p></o></span></span></span></p>
<ul>
<li>
<div class="MsoListParagraphCxSpFirst"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; font-size: small;">We are closing Security Advisory 983438 (</span></span><a href="http://www.microsoft.com/technet/security/advisory/983438.mspx"><span style="color: #000077;"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Vuln</span><span style="mso-bidi-font-weight: bold;">erability in Microsoft SharePoint Could Allow Elevation of Privilege</span></span></span></span></a><span style="mso-bidi-font-weight: bold;"><span style="font-family: Calibri;"><span style="font-size: small;">) with the June bulletins. <o :p></o></span></span></span></div>
</li>
<li>
<div class="MsoListParagraphCxSpLast"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; font-size: small;">We are also addressing Security Advisory 980088 (</span></span><a href="http://www.microsoft.com/technet/security/advisory/980088.mspx"><span style="mso-bidi-font-weight: bold;"><span style="font-family: Calibri; color: #000077; font-size: small;">Vulnerability in Internet Explorer Could Allow Information Disclosure</span></span></a><span style="mso-bidi-font-weight: bold;"><span style="font-size: small;"><span style="font-family: Calibri;">). <o :p></o></span></span></span></div>
</li>
</ul>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Please join Adrian Stone and me for a public webcast on Wednesday next week where we will go into detail about the bulletins and answer questions live on the air. Register at the link below:</span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; font-size: small;">Date: Wednesday June 9<br />Time: 11:00 a.m. PDT (UTC &ndash;7) <br />Registration: </span></span><a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427727"><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"><span style="font-family: Calibri; color: #000077; font-size: small;">https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427727</span></span></a></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Finally, we remind Windows 2000 and Windows XP SP2 customers once again that all support for these platforms will end after July 13, 2010 &ndash; that is, next month. Customers should upgrade to either a supported operating system or the latest service pack in order to keep receiving necessary security updates. </span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;">Thanks,</span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span></p>
<p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Calibri;"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"></span></span></span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: Calibri;">Jerry Bryant<br />Group Manager, Response Communications</span></span></span></p>
<p class="MsoNormal"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: Calibri;"></span></span></span></p>
<p class="MsoNormal"><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><span style="font-size: small;"><span style="font-family: Calibri;"></span></span></span><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Calibri; font-size: small;">Follow us on Twitter: </span></span><a href="http://twitter.com/msftsecresponse"><span style="color: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Calibri; font-size: small;">@MSFTSecResponse</span></span></a><span style="color: #333333; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman';"><o :p></o></span></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3335584" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/06/03/june-2010-security-bulletin-advance-notification.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guidance on Internet Explorer XSS Filter</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/04/19/guidance-on-internet-explorer-xss-filter.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/04/19/guidance-on-internet-explorer-xss-filter.aspx#comments</comments>
		<pubDate>Tue, 20 Apr 2010 03:29:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Defense-in-depth]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Risk Assessment]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3326538</guid>
		<description><![CDATA[<span lang="EN"><font size="3" face="Calibri"></font></span><span>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>The XSS Filter related Blackhat EU presentation discussed a vulnerability that was previously disclosed and addressed in the January security update to Internet Explorer</span><span> (</span></font><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><font color="#0000ff" size="3" face="Calibri">MS10-002</font></a><font size="3"></font><font face="Calibri"><span>). </span><span>This attack scenario involved modified HTTP responses, enabling XSS on sites that would not otherwise be vulnerable.&#160; </span></font></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>An additional update to</span><span> </span></font><a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><font color="#0000ff" size="3" face="Calibri">the IE XSS Filter</font></a><font size="3"></font><font face="Calibri"><span> </span><span>is currently scheduled for release in June.&#160;This change will address a SCRIPT tag attack scenario described in the Blackhat EU presentation. <span>This issue manifests when malicious script can “break out” from within a construct that is already within an existing script block.<span>&#160; </span>While the issue identified and addressed in </span></span><span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><font color="#0000ff">MS10-002</font></a> </span><span>was identified to exist on high-profile web sites, thus far real-world examples of the SCRIPT tag neutering attack scenario have been hard to come by.<b></b></span></font></p>
<p class="MsoNormal"><a name="_GoBack"></a><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>Like many security issues – take</span><span> <a href="http://blogs.msdn.com/ie/archive/2010/03/05/ie8-smartscreen-filter-protecting-users-at-internet-scale.aspx"><font color="#0000ff">malware</font></a> </span><span>as an example – attack vectors are always a moving target.<span>&#160; </span>The role of the browser maker is to do everything we can to keep people safe without them having to do a lot of extra work.<span>&#160; </span></span></font></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">In the case of the Internet Explorer XSS Filter, researchers found scenarios that are generally applicable across XSS filtering technologies in all currently shipping browsers with this technology built-in.<span>&#160; </span>In January (</font></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><span><font color="#0000ff" size="3" face="Calibri">MS10-002</font></span></a><span><font size="3" face="Calibri">) and again in March<span>&#160; </span>(</font></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx"><span><font size="3" face="Calibri">MS10-018</font></span></a><span><font size="3"></font><font face="Calibri">), we took steps to mitigate this threat class and we’ll take the next major step in the June timeframe.<span>&#160; </span>Overall we maintain that it’s important to use a browser with an XSS Filter, as the benefits of protection from a large class of attacks outweigh the potential risks from vulnerabilities in most cases.<span>&#160; </span></font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">We look forward to continuing to improve the Internet Explorer XSS Filter going forward to address new attack scenarios and the evolving threat landscape.</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">David Ross</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">MSRC Engineering</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">&#160;</font></span></p>
<p class="MsoNormal"><span lang="EN"><font size="3" face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights*</font></span><span></span></p>
<p class="MsoNormal"></p></span>&#160;<div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3326538" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<span style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN" lang=EN><font size=3 face=Calibri></font></span><span style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi">< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="COLOR: black; mso-themecolor: text1">The XSS Filter related Blackhat EU presentation discussed a vulnerability that was previously disclosed and addressed in the January security update to Internet Explorer</span><span style="COLOR: #1f497d"> (</span></font><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><font color=#0000ff size=3 face=Calibri>MS10-002</font></a><font size=3></font><font face=Calibri><span style="COLOR: #1f497d">). </span><span style="COLOR: black; mso-themecolor: text1">This attack scenario involved modified HTTP responses, enabling XSS on sites that would not otherwise be vulnerable.&nbsp; <o :p></o></span></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-themecolor: text1"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="COLOR: black; mso-themecolor: text1">An additional update to</span><span style="COLOR: #1f497d"> </span></font><a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><font color=#0000ff size=3 face=Calibri>the IE XSS Filter</font></a><font size=3></font><font face=Calibri><span style="COLOR: #1f497d"> </span><span style="COLOR: black; mso-themecolor: text1">is currently scheduled for release in June.&nbsp;This change will address a SCRIPT tag attack scenario described in the Blackhat EU presentation. <span style="mso-bidi-font-weight: bold">This issue manifests when malicious script can “break out” from within a construct that is already within an existing script block.<span style="mso-spacerun: yes">&nbsp; </span>While the issue identified and addressed in </span></span><span style="COLOR: #1f497d; mso-bidi-font-weight: bold"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><font color=#0000ff>MS10-002</font></a> </span><span style="COLOR: black; mso-bidi-font-weight: bold; mso-themecolor: text1">was identified to exist on high-profile web sites, thus far real-world examples of the SCRIPT tag neutering attack scenario have been hard to come by.<b><o :p></o></b></span></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><a name=_GoBack></a><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi">Like many security issues – take</span><span style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: dark2; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"> <a href="http://blogs.msdn.com/ie/archive/2010/03/05/ie8-smartscreen-filter-protecting-users-at-internet-scale.aspx"><font color=#0000ff>malware</font></a> </span><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi">as an example – attack vectors are always a moving target.<span style="mso-spacerun: yes">&nbsp; </span>The role of the browser maker is to do everything we can to keep people safe without them having to do a lot of extra work.<span style="mso-spacerun: yes">&nbsp; </span><o :p></o></span></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3 face=Calibri>In the case of the Internet Explorer XSS Filter, researchers found scenarios that are generally applicable across XSS filtering technologies in all currently shipping browsers with this technology built-in.<span style="mso-spacerun: yes">&nbsp; </span>In January (</font></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx"><span style="mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font color=#0000ff size=3 face=Calibri>MS10-002</font></span></a><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3 face=Calibri>) and again in March<span style="mso-spacerun: yes">&nbsp; </span>(</font></span><a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx"><span style="mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3 face=Calibri>MS10-018</font></span></a><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3></font><font face=Calibri>), we took steps to mitigate this threat class and we’ll take the next major step in the June timeframe.<span style="mso-spacerun: yes">&nbsp; </span>Overall we maintain that it’s important to use a browser with an XSS Filter, as the benefits of protection from a large class of attacks outweigh the potential risks from vulnerabilities in most cases.<span style="mso-spacerun: yes">&nbsp; </span><o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3></font><font face=Calibri>We look forward to continuing to improve the Internet Explorer XSS Filter going forward to address new attack scenarios and the evolving threat landscape.<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3></font><font face=Calibri>David Ross<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><font size=3></font><font face=Calibri>MSRC Engineering<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p><font size=3 face=Calibri>&nbsp;</font></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN" lang=EN><font size=3 face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights*</font></span><span style="COLOR: black; mso-bidi-font-family: 'Times New Roman'; mso-themecolor: text1; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"><o :p></o></span></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal></p></o></span>&nbsp;<div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3326538" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/04/19/guidance-on-internet-explorer-xss-filter.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March Out-of-Band Security Bulletin Webcast</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/04/05/march-out-of-band-security-bulletin-webcast.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/04/05/march-out-of-band-security-bulletin-webcast.aspx#comments</comments>
		<pubDate>Mon, 05 Apr 2010 16:14:07 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q & A]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Webcast Q&A]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3323198</guid>
		<description><![CDATA[<p>Hi everyone,</p>  <p>Last week Adrian Stone and I conducted a webcast to cover the Internet Explorer out-of-band security bulletin release. We only spent a short period of timing on the presentation and then spent the rest of the time answering customer questions which you can <a href="http://blogs.technet.com/msrc/pages/out-of-band-security-bulletin-webcast-q-a-march-30-2010.aspx">read here</a>.</p>  <p>There were some interesting questions and hopefully those who attended came away with a better understanding about how to better protect themselves from emerging threats. One resource we referred customers to several times is a new blog post by the Microsoft Malware Protection Center (MMPC) where they chart attacks against CVE2010-0806 by local:</p>  <p><a href="http://blogs.technet.com/mmpc/archive/2010/03/30/active-exploitation-of-cve-2010-0806.aspx">http://blogs.technet.com/mmpc/archive/2010/03/30/active-exploitation-of-cve-2010-0806.aspx</a></p>  <p>To be clear, this data comes from attempted exploits of the vulnerability against customers who are protected by Microsoft security products such as Microsoft Security Essentials and Microsoft Forefront Client Security, etc. In these cases, the exploit failed because mitigating signatures are in place (see article for details). One of the questions we got in the webcast was:</p>  <p><i>“If my malware protection is updated and covers this vulnerability, am I covered throughout the normal update cycle?”</i></p>  <p>This would only be true for known exploits and not the vulnerability itself. Once we find a new exploit, the MMPC can develop and deploy a signature for it. Applying the update addresses the vulnerability itself and is why we recommend that as the priority in addition to upgrading to the latest version of Internet Explorer (IE8) if you have not done so already.</p>  <table border="0" cellspacing="0" cellpadding="2" width="582"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="330">More listening and viewing options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.mp3">MP3 Audio</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Our next regularly scheduled bulletin release is Tuesday April 13, so that means we will be conducting another public webcast on April 14. We invite you to attend that webcast and bring any questions you have regarding the April release and we will try to answer them all live on the air. Here is the registration information:</p>  <p>Date: Wednesday April 14   <br />Time: 11:00 a.m. PDT (UTC –8)    <br />Registration: <a title="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721" href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721">https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721</a></p>  <p>Thanks!</p>  <p>Jerry Bryant   <br />Group Manager, Response Communications</p>  <p>Follow us on Twitter: <a href="http://twitter.com/msftsecresponse">@MSFTSecResponse</a></p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3323198" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>  <p>Last week Adrian Stone and I conducted a webcast to cover the Internet Explorer out-of-band security bulletin release. We only spent a short period of timing on the presentation and then spent the rest of the time answering customer questions which you can <a href="http://blogs.technet.com/msrc/pages/out-of-band-security-bulletin-webcast-q-a-march-30-2010.aspx">read here</a>.</p>  <p>There were some interesting questions and hopefully those who attended came away with a better understanding about how to better protect themselves from emerging threats. One resource we referred customers to several times is a new blog post by the Microsoft Malware Protection Center (MMPC) where they chart attacks against CVE2010-0806 by local:</p>  <p><a href="http://blogs.technet.com/mmpc/archive/2010/03/30/active-exploitation-of-cve-2010-0806.aspx">http://blogs.technet.com/mmpc/archive/2010/03/30/active-exploitation-of-cve-2010-0806.aspx</a></p>  <p>To be clear, this data comes from attempted exploits of the vulnerability against customers who are protected by Microsoft security products such as Microsoft Security Essentials and Microsoft Forefront Client Security, etc. In these cases, the exploit failed because mitigating signatures are in place (see article for details). One of the questions we got in the webcast was:</p>  <p><i>“If my malware protection is updated and covers this vulnerability, am I covered throughout the normal update cycle?”</i></p>  <p>This would only be true for known exploits and not the vulnerability itself. Once we find a new exploit, the MMPC can develop and deploy a signature for it. Applying the update addresses the vulnerability itself and is why we recommend that as the priority in addition to upgrading to the latest version of Internet Explorer (IE8) if you have not done so already.</p>  <table border="0" cellspacing="0" cellpadding="2" width="582"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /> <param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_320_edge.png, postid=21100" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="330">More listening and viewing options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_edge.mp3">MP3 Audio</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/0/0/1/1/2/msrcmaroob2_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Our next regularly scheduled bulletin release is Tuesday April 13, so that means we will be conducting another public webcast on April 14. We invite you to attend that webcast and bring any questions you have regarding the April release and we will try to answer them all live on the air. Here is the registration information:</p>  <p>Date: Wednesday April 14   <br />Time: 11:00 a.m. PDT (UTC –8)    <br />Registration: <a title="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721" href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721">https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032427721</a></p>  <p>Thanks!</p>  <p>Jerry Bryant   <br />Group Manager, Response Communications</p>  <p>Follow us on Twitter: <a href="http://twitter.com/msftsecresponse">@MSFTSecResponse</a></p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3323198" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/04/05/march-out-of-band-security-bulletin-webcast.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Bulletin MS10-018 Released</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/03/30/security-bulletin-ms10-018-released.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/03/30/security-bulletin-ms10-018-released.aspx#comments</comments>
		<pubDate>Tue, 30 Mar 2010 16:59:46 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Responsible Disclosure]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3322093</guid>
		<description><![CDATA[<p>Hi everyone,</p>  <p>Today we released <a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx">MS10-018</a> out-of-band due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">Security Advisory 981374</a>. I want to reiterate that Internet Explorer 8 is not affected by this issue so customers using this version are not affected by these attacks and we continue to encourage customers to upgrade to the newer version because it provides more security and protection. </p>  <p>MS10-018 is a typical cumulative update for Internet Explorer and was originally going to be released during the normal update cycle on the 13<sup>th</sup> of April. The Internet Explorer team accelerated testing of this update due to the growing attacks against the publicly disclosed vulnerability (<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806">CVE-2010-0806</a>), and the update has reached the appropriate quality bar for distribution to customers. Releasing the update early provides Internet Explorer 6 and 7 customers protection against the active attacks and provides users of all versions of Internet Explorer protection against nine other vulnerabilities. I clarify this in the following video:</p>  <table border="0" cellspacing="0" cellpadding="2" width="648"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="396">More listening and viewing options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.mp3">MP3 Audio</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Here is a simplified view of the ten vulnerabilities and their aggregate severity on Internet Explorer 6, 7, and 8:</p> <a href="http://blogs.technet.com/photos/msrcteam/images/3322077/original.aspx" target="_blank"><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3322077/original.aspx" width="500" /></a>   <p>* Vulnerability under active attack.</p>  <p>This table demonstrates what we have been saying about the improved security and protection offered in Internet Explorer 8 and why we continue to encourage customers to upgrade. </p>  <p>Since we announced yesterday that we would be releasing this bulletin out-of-band, we have been asked if it addresses the vulnerability that was used in the “pwn2own” contest at the CanSecWest security conference last week. We are still investigating that issue at this time so we do not have an update available. In accordance with the contest rules, the vulnerabilities used are responsibly disclosed so that the respective vendors can produce updates to protect their customers before the vulnerabilities can be used by criminals. Microsoft continues to encourage responsible disclosure and we are a sponsor of the CanSecWest conference because we believe in working closely with security researchers to protect customers and the entire computing ecosystem. </p>  <p>If you can, please join Adrian Stone and I today for a live webcast where we will cover the details of this bulletin and take customer questions live. Here is the registration information: </p>  <p>Date: Tuesday March 30, 2010    <br />Time: 1:00 p.m. PST (UTC -8)     <br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112</a></p>  <p>Jerry Bryant    <br />Group Manager – Response Communications </p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3322093" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>  <p>Today we released <a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx">MS10-018</a> out-of-band due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">Security Advisory 981374</a>. I want to reiterate that Internet Explorer 8 is not affected by this issue so customers using this version are not affected by these attacks and we continue to encourage customers to upgrade to the newer version because it provides more security and protection. </p>  <p>MS10-018 is a typical cumulative update for Internet Explorer and was originally going to be released during the normal update cycle on the 13<sup>th</sup> of April. The Internet Explorer team accelerated testing of this update due to the growing attacks against the publicly disclosed vulnerability (<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806">CVE-2010-0806</a>), and the update has reached the appropriate quality bar for distribution to customers. Releasing the update early provides Internet Explorer 6 and 7 customers protection against the active attacks and provides users of all versions of Internet Explorer protection against nine other vulnerabilities. I clarify this in the following video:</p>  <table border="0" cellspacing="0" cellpadding="2" width="648"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /> <param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_320_edge.png, postid=20951" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="396">More listening and viewing options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_edge.mp3">MP3 Audio</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/1/5/9/0/2/msrcmaroob4c_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Here is a simplified view of the ten vulnerabilities and their aggregate severity on Internet Explorer 6, 7, and 8:</p> <a href="http://blogs.technet.com/photos/msrcteam/images/3322077/original.aspx" ><img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3322077/original.aspx" width="500" /></a>   <p>* Vulnerability under active attack.</p>  <p>This table demonstrates what we have been saying about the improved security and protection offered in Internet Explorer 8 and why we continue to encourage customers to upgrade. </p>  <p>Since we announced yesterday that we would be releasing this bulletin out-of-band, we have been asked if it addresses the vulnerability that was used in the “pwn2own” contest at the CanSecWest security conference last week. We are still investigating that issue at this time so we do not have an update available. In accordance with the contest rules, the vulnerabilities used are responsibly disclosed so that the respective vendors can produce updates to protect their customers before the vulnerabilities can be used by criminals. Microsoft continues to encourage responsible disclosure and we are a sponsor of the CanSecWest conference because we believe in working closely with security researchers to protect customers and the entire computing ecosystem. </p>  <p>If you can, please join Adrian Stone and I today for a live webcast where we will cover the details of this bulletin and take customer questions live. Here is the registration information: </p>  <p>Date: Tuesday March 30, 2010    <br />Time: 1:00 p.m. PST (UTC -8)     <br />Registration: <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112</a></p>  <p>Jerry Bryant    <br />Group Manager – Response Communications </p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3322093" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/03/30/security-bulletin-ms10-018-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer Cumulative Update Releasing Out-of-Band</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/03/29/internet-explorer-cumulative-update-releasing-out-of-band.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/03/29/internet-explorer-cumulative-update-releasing-out-of-band.aspx#comments</comments>
		<pubDate>Mon, 29 Mar 2010 16:35:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3321818</guid>
		<description><![CDATA[<p class="MsoNormal"><span><font size="3" face="Calibri">Today we issued <span>our <a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx"><span>Advanced Notification Service (ANS)</span></a> to </span>advise customers that we will be releasing security update MS10-018 tomorrow, March 30, 2010, at approximately10:00 a.m. PDT (UTC-8).&#160;MS10-018 resolves </font><a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"><span><font size="3" face="Calibri">Security Advisory 981374</font></span></a><font size="3"></font><font face="Calibri">, addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is unaffected by the vulnerability addressed in the advisory and we continue to encourage all customers to upgrade to this version to benefit from the improved security protection it offers.</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p><span><font face="Calibri">
<p class="MsoNormal"><span><font size="3">We recommend that customers install the update as soon as it is available. Once applied, customers are protected against the known attacks related to Security Advisory 981374. We have been monitoring this issue and have determined an out-of-band release is needed to protect customers. For customers using automatic updates, this update will automatically be applied once it is released.<span>&#160; </span>Additionally, because Security Bulletin MS10-18 is a cumulative update, it will also address nine other vulnerabilities in Internet Explorer that were planned for release on April 13.</font></span></p></font></span>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Please join us Tuesday, March 30 at 1:00 p.m. PST (UTC -8) for a public webcast where we will present information on the bulletin and take customer questions. Registration information:</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span>Date: Tuesday March 30, 2010<br />Time: 1:00 p.m. PST (UTC -8) <br />Registration: </span><span><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112"><font color="#0000ff">https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112</font></a> </span></font></p>
<p class="MsoNormal"><font size="3"></font><font face="Calibri"><span></span></font>&#160;</p>
<p class="MsoNormal"><span><font size="3" face="Calibri">More information about the upcoming security bulletin can be found Microsoft’s </font><a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx"><span><font size="3" face="Calibri">Advance Notification Service (ANS) webpage</font></span></a><font size="3"></font><font face="Calibri">. </font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri"></font></span>&#160;</p><span>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">UPDATE:<br />We have received several questions about this bulletin today. Basically, if Internet Explorer 6 and 7 are the only versions affected by the active attacks, why does the Advance Notification page state that Internet Explorer 8 and Windows 7 are affected? To clarify, the Security Advisory was released due to one vulnerability that is under active attack. That vulnerability only affects Internet Explorer 6 and 7. However, the bulletin, MS10-018, that we will release tomorrow, addresses 9 additional vulnerabilities. Some of those also affect Internet Explorer 8. All of the 9 additional vulnerabilities were responsibly disclosed and we are not aware of any active attacks against them.</font></span></p></span>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Thanks,</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Jerry Bryant<br />Group Manager – Response Communications </font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri"></font></span>&#160;</p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights*</font></span></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3321818" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3 face=Calibri>Today we issued <span style="COLOR: black">our <a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx"><span style="TEXT-DECORATION: none; text-underline: none">Advanced Notification Service (ANS)</span></a> to </span>advise customers that we will be releasing security update MS10-018 tomorrow, March 30, 2010, at approximately10:00 a.m. PDT (UTC-8).&nbsp;MS10-018 resolves </font><a href="http://www.microsoft.com/technet/security/advisory/981374.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/981374.mspx"><span style="TEXT-DECORATION: none; text-underline: none"><font size=3 face=Calibri>Security Advisory 981374</font></span></a><font size=3></font><font face=Calibri>, addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is unaffected by the vulnerability addressed in the advisory and we continue to encourage all customers to upgrade to this version to benefit from the improved security protection it offers.</font></span></p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri>< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p></o></font></span>&nbsp;</p><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font face=Calibri>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3>We recommend that customers install the update as soon as it is available. Once applied, customers are protected against the known attacks related to Security Advisory 981374. We have been monitoring this issue and have determined an out-of-band release is needed to protect customers. For customers using automatic updates, this update will automatically be applied once it is released.<span style="mso-spacerun: yes">&nbsp; </span>Additionally, because Security Bulletin MS10-18 is a cumulative update, it will also address nine other vulnerabilities in Internet Explorer that were planned for release on April 13.<o :p></o></font></span></p><o :p></o></font></span>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri></font></span>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri>Please join us Tuesday, March 30 at 1:00 p.m. PST (UTC -8) for a public webcast where we will present information on the bulletin and take customer questions. Registration information:</font></span></p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-outline-level: 2" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri><o :p></o></font></span>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'">Date: Tuesday March 30, 2010<br />Time: 1:00 p.m. PST (UTC -8) <br />Registration: </span><span style="COLOR: #1f497d; mso-bidi-font-family: Calibri"><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112" mce_href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112"><font color=#0000ff>https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032448112</font></a> </span></font></p>
<p style="MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3></font><font face=Calibri><span style="COLOR: #1f497d; mso-bidi-font-family: Calibri"><o :p></o></span></font>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>More information about the upcoming security bulletin can be found Microsoft’s </font><a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx"><span style="TEXT-DECORATION: none; text-underline: none"><font size=3 face=Calibri>Advance Notification Service (ANS) webpage</font></span></a><font size=3></font><font face=Calibri>. </font></span></p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri></font></span>&nbsp;</p><span style="mso-bidi-font-family: Calibri">
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3></font><font face=Calibri>UPDATE:<br />We have received several questions about this bulletin today. Basically, if Internet Explorer 6 and 7 are the only versions affected by the active attacks, why does the Advance Notification page state that Internet Explorer 8 and Windows 7 are affected? To clarify, the Security Advisory was released due to one vulnerability that is under active attack. That vulnerability only affects Internet Explorer 6 and 7. However, the bulletin, MS10-018, that we will release tomorrow, addresses 9 additional vulnerabilities. Some of those also affect Internet Explorer 8. All of the 9 additional vulnerabilities were responsibly disclosed and we are not aware of any active attacks against them.<o :p></o></font></span></p></span>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3></font><font face=Calibri><o :p></o></font></span>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri>Thanks,</font></span></p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri><o :p></o></font></span>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri>Jerry Bryant<br />Group Manager – Response Communications </font></span></p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri><o :p></o></font></span>&nbsp;</p>
<p style="MARGIN: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'"><font size=3></font><font face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights*<o :p></o></font></span></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3321818" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/03/29/internet-explorer-cumulative-update-releasing-out-of-band.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update on Security Advisory 981374</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/03/12/update-on-security-advisory-981374.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/03/12/update-on-security-advisory-981374.aspx#comments</comments>
		<pubDate>Fri, 12 Mar 2010 21:34:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Emerging Threat]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Mitigations]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Workarounds]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3318766</guid>
		<description><![CDATA[<p>Hi everyone,</p>
<p>I’m writing to let you know that we have updated <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">Security Advisory 981374</a> with new workaround information. We are aware that exploit code has been made public for this issue. As with our last update, Internet Explorer 8 remains unaffected by the vulnerability addressed in the advisory and we continue to encourage all customers to upgrade to this version. </p>
<p>On Wednesday we added a workaround to the advisory that helps to mitigate the vulnerability by disabling the peer factory class through the modification of a registry key. With today’s update, we have added a <a href="http://support.microsoft.com/kb/981374">Microsoft Fix It</a> to automate this workaround for Windows XP and Windows Server 2003 customers. As always, customers should test this thoroughly before deploying as certain functionality that depends on the peer factory class, such as printing from Internet Explorer and the use of web folders, may be affected. </p>
<p>We have seen speculation that Microsoft might release an update for this issue out-of-band. I can tell you that we are working hard to produce an update which is now in testing. This is a critical and time intensive step of the process as the update must be tested against affected versions of Internet Explorer on all supported versions of Windows. Additionally, each supported language version needs to be tested as well as testing against thousands of third party applications. We never rule out the possibility of an out-of-band update. When the update is ready for broad distribution, we will make that decision based on customer needs. </p>
<p>Please review the advisory for more information. We will keep you posted as additional information becomes available. </p>
<p>Jerry Bryant <br />Sr. Security Communications Manager Lead</p>
<p>*This posting is provided "AS IS" with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3318766" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>
<p>I’m writing to let you know that we have updated <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/981374.mspx">Security Advisory 981374</a> with new workaround information. We are aware that exploit code has been made public for this issue. As with our last update, Internet Explorer 8 remains unaffected by the vulnerability addressed in the advisory and we continue to encourage all customers to upgrade to this version. </p>
<p>On Wednesday we added a workaround to the advisory that helps to mitigate the vulnerability by disabling the peer factory class through the modification of a registry key. With today’s update, we have added a <a href="http://support.microsoft.com/kb/981374" mce_href="http://support.microsoft.com/kb/981374">Microsoft Fix It</a> to automate this workaround for Windows XP and Windows Server 2003 customers. As always, customers should test this thoroughly before deploying as certain functionality that depends on the peer factory class, such as printing from Internet Explorer and the use of web folders, may be affected. </p>
<p>We have seen speculation that Microsoft might release an update for this issue out-of-band. I can tell you that we are working hard to produce an update which is now in testing. This is a critical and time intensive step of the process as the update must be tested against affected versions of Internet Explorer on all supported versions of Windows. Additionally, each supported language version needs to be tested as well as testing against thousands of third party applications. We never rule out the possibility of an out-of-band update. When the update is ready for broad distribution, we will make that decision based on customer needs. </p>
<p>Please review the advisory for more information. We will keep you posted as additional information becomes available. </p>
<p>Jerry Bryant <br />Sr. Security Communications Manager Lead</p>
<p>*This posting is provided "AS IS" with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3318766" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/03/12/update-on-security-advisory-981374.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Advisory 981374 Released</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/03/09/security-advisory-981374-released.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/03/09/security-advisory-981374-released.aspx#comments</comments>
		<pubDate>Tue, 09 Mar 2010 16:28:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Emerging Threat]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3317883</guid>
		<description><![CDATA[<p class="MsoNormal"><font size="3" face="Calibri">Hi everyone,</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">Today we released </font><a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"><font color="#0000ff" size="3" face="Calibri">Security Advisory 981374</font></a><font size="3" face="Calibri"> addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is not affected by this issue. Customers using Internet Explorer 6 or 7 should </font><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx"><font size="3" face="Calibri">upgrade to Internet Explorer 8</font></a><font size="3" face="Calibri"> immediately to benefit from the improved security features and defense in depth protections. Additionally, Internet Explorer 5.01 on Windows 2000 is not affected.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6. </font><a href="http://www.microsoft.com/windows/windows-vista/features/IE7-protected-mode.aspx"><font size="3" face="Calibri">Internet Explorer Protected Mode</font></a><font size="3" face="Calibri"> in Internet Explorer 7 running on Windows Vista helps to mitigate the impact of this issue. Additionally, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as </font><a href="http://go.microsoft.com/fwlink/?LinkId=92039"><font color="#0000ff" size="3" face="Calibri">Enhanced Security Configuration</font></a><font size="3" face="Calibri">. This mode sets the security level for the Internet zone to <span>High</span>. This is a mitigating factor for Web sites that you have not added to the Internet Explorer Trusted sites zone. Please review the Security Advisory for additional workarounds which include modifying the Access Control List (ACL) on iepeers.dll (the affected component), setting the Internet and local Intranet security zones to "high", configuring Internet Explorer to prompt before running Active Scripting, and enabling Data Execution Prevention (DEP) where possible which makes it difficult to successfully exploit the vulnerability.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">&#160;</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">As always, we are investigating this issue and will take appropriate action to protect customers when we have finalized a solution. This may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.</font></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">Anyone believed to have been affected can visit: </font></span><a href="http://www.microsoft.com/protect/support/default.mspx"><span><font size="3" face="Calibri">http://www.microsoft.com/protect/support/default.mspx</font></span></a><span><font size="3" face="Calibri"> and should contact the national law enforcement agency in their country. T<span>hose in the United States can contact Customer Service and Support at no charge using the PC Safety hotline at 1-866-727-2338 (PCSAFETY).<span>&#160; </span>Additionally, customers in the United States </span>should contact their local FBI office or report their situation at: </font></span><a href="http://www.ic3.gov/"><span><font color="#0000ff" size="3" face="Calibri">www.ic3.gov</font></span></a><font size="3"></font><font face="Calibri"><span>. </span><span>Customers should follow the guidance in the advisory and our Protect Your PC guidance of enabling a firewall, getting software updates, and installing antivirus software (learn more by visiting the </span></font><a href="http://www.microsoft.com/protect"><span><font size="3" face="Calibri">Protect Your PC web site</font></span></a><span><font size="3" face="Calibri">). International customers can find their Regional Customer Service Representative </font></span><a href="http://support.microsoft.com/common/international.aspx"><span><font size="3" face="Calibri">http://support.microsoft.com/common/international.aspx</font></span></a><span><font size="3"></font><font face="Calibri">.</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">We are also working with our </font></span><a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"><span><font color="#0000ff" size="3" face="Calibri">Microsoft Active Protections Program (MAPP)</font></span></a><span><font size="3" face="Calibri">, the </font></span><a href="http://www.microsoft.com/security/msra/default.mspx"><span><font color="#0000ff" size="3" face="Calibri">Microsoft Security Response Alliance (MSRA)</font></span></a><font size="3"></font><font face="Calibri"><span>, authorities and other industry partners to help provide broader protections for customers. Together with our partners, we will continue to monitor the threat landscape and will take action against any web sites that seek to exploit this vulnerability.</span><span></span></font></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">The Security Advisory will be updated with any new developments so if you are not already subscribed to our </font></span><a href="http://technet.microsoft.com/en-us/security/dd252948.aspx"><span><font color="#0000ff" size="3" face="Calibri">comprehensive alerts</font></span></a><font size="3"></font><font face="Calibri"><span>, please do so in order to be alerted by email when new information is added.</span> </font></p>
<p class="MsoNormal"><font size="3" face="Calibri">Please review the advisory for additional details and if the situation changes, we will provide an update here on the MSRC blog.</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">Jerry Bryant<br />Sr. Security Communications Manager Lead</font></p>
<p class="MsoNormal"><font size="3" face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights.*</font></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3317883" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>Hi everyone,</font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>Today we released </font><a href="http://www.microsoft.com/technet/security/advisory/981374.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/981374.mspx"><font color=#0000ff size=3 face=Calibri>Security Advisory 981374</font></a><font size=3 face=Calibri> addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is not affected by this issue. Customers using Internet Explorer 6 or 7 should </font><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx" mce_href="http://www.microsoft.com/windows/internet-explorer/default.aspx"><font size=3 face=Calibri>upgrade to Internet Explorer 8</font></a><font size=3 face=Calibri> immediately to benefit from the improved security features and defense in depth protections. Additionally, Internet Explorer 5.01 on Windows 2000 is not affected.</font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal>< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><font size=3 face=Calibri>At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6. </font><a href="http://www.microsoft.com/windows/windows-vista/features/IE7-protected-mode.aspx" mce_href="http://www.microsoft.com/windows/windows-vista/features/IE7-protected-mode.aspx"><font size=3 face=Calibri>Internet Explorer Protected Mode</font></a><font size=3 face=Calibri> in Internet Explorer 7 running on Windows Vista helps to mitigate the impact of this issue. Additionally, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as </font><a href="http://go.microsoft.com/fwlink/?LinkId=92039" mce_href="http://go.microsoft.com/fwlink/?LinkId=92039"><font color=#0000ff size=3 face=Calibri>Enhanced Security Configuration</font></a><font size=3 face=Calibri>. This mode sets the security level for the Internet zone to <span style="mso-bidi-font-weight: bold">High</span>. This is a mitigating factor for Web sites that you have not added to the Internet Explorer Trusted sites zone. Please review the Security Advisory for additional workarounds which include modifying the Access Control List (ACL) on iepeers.dll (the affected component), setting the Internet and local Intranet security zones to "high", configuring Internet Explorer to prompt before running Active Scripting, and enabling Data Execution Prevention (DEP) where possible which makes it difficult to successfully exploit the vulnerability.</font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal><o :p><font size=3 face=Calibri>&nbsp;</font></o></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>As always, we are investigating this issue and will take appropriate action to protect customers when we have finalized a solution. This may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.</font></p>
<p style="MARGIN: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="COLOR: black; mso-bidi-font-family: Calibri"><font size=3 face=Calibri>Anyone believed to have been affected can visit: </font></span><a href="http://www.microsoft.com/protect/support/default.mspx" mce_href="http://www.microsoft.com/protect/support/default.mspx"><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>http://www.microsoft.com/protect/support/default.mspx</font></span></a><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri> and should contact the national law enforcement agency in their country. T<span style="COLOR: black">hose in the United States can contact Customer Service and Support at no charge using the PC Safety hotline at 1-866-727-2338 (PCSAFETY).<span style="mso-spacerun: yes">&nbsp; </span>Additionally, customers in the United States </span>should contact their local FBI office or report their situation at: </font></span><a href="http://www.ic3.gov/" mce_href="http://www.ic3.gov/"><span style="mso-bidi-font-family: Calibri"><font color=#0000ff size=3 face=Calibri>www.ic3.gov</font></span></a><font size=3></font><font face=Calibri><span style="COLOR: black; mso-bidi-font-family: Calibri">. </span><span style="mso-bidi-font-family: Calibri">Customers should follow the guidance in the advisory and our Protect Your PC guidance of enabling a firewall, getting software updates, and installing antivirus software (learn more by visiting the </span></font><a href="http://www.microsoft.com/protect" mce_href="http://www.microsoft.com/protect"><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>Protect Your PC web site</font></span></a><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>). International customers can find their Regional Customer Service Representative </font></span><a href="http://support.microsoft.com/common/international.aspx" mce_href="http://support.microsoft.com/common/international.aspx"><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>http://support.microsoft.com/common/international.aspx</font></span></a><span style="mso-bidi-font-family: Calibri"><font size=3></font><font face=Calibri>.<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>We are also working with our </font></span><a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"><span style="mso-bidi-font-family: Calibri"><font color=#0000ff size=3 face=Calibri>Microsoft Active Protections Program (MAPP)</font></span></a><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>, the </font></span><a href="http://www.microsoft.com/security/msra/default.mspx" mce_href="http://www.microsoft.com/security/msra/default.mspx"><span style="mso-bidi-font-family: Calibri"><font color=#0000ff size=3 face=Calibri>Microsoft Security Response Alliance (MSRA)</font></span></a><font size=3></font><font face=Calibri><span style="mso-bidi-font-family: Calibri">, authorities and other industry partners to help provide broader protections for customers. Together with our partners, we will continue to monitor the threat landscape and will take action against any web sites that seek to exploit this vulnerability.</span><span style="FONT-FAMILY: 'Times New Roman','serif'"><o :p></o></span></font></p>
<p style="MARGIN: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal><span style="mso-bidi-font-family: Calibri"><font size=3 face=Calibri>The Security Advisory will be updated with any new developments so if you are not already subscribed to our </font></span><a href="http://technet.microsoft.com/en-us/security/dd252948.aspx" mce_href="http://technet.microsoft.com/en-us/security/dd252948.aspx"><span style="mso-bidi-font-family: Calibri"><font color=#0000ff size=3 face=Calibri>comprehensive alerts</font></span></a><font size=3></font><font face=Calibri><span style="mso-bidi-font-family: Calibri">, please do so in order to be alerted by email when new information is added.</span> </font></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>Please review the advisory for additional details and if the situation changes, we will provide an update here on the MSRC blog.</font></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>Jerry Bryant<br />Sr. Security Communications Manager Lead</font></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights.*</font></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3317883" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/03/09/security-advisory-981374-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Investigating a new win32hlp and Internet Explorer issue</title>
		<link>http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx#comments</comments>
		<pubDate>Mon, 01 Mar 2010 00:15:31 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Emerging Threat]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3315922</guid>
		<description><![CDATA[<p>Hi everyone,</p>  <p>On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box. We are not aware of any attacks seeking to exploit this issue at this time and in the current state of our investigation, we have determined that users running Windows 7, Windows Server 2008 R2, Windows Server 2008, and Windows Vista, are not affected by this issue. </p>  <p>The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system. To help customers better understand unsafe file types, we have published a white paper on the topic which you can find by clicking <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#38;FamilyID=b7d03027-9791-443b-8bbe-0542b3aa4bfe">this link</a>.</p>  <p>Once we have completed our investigation, we will take appropriate action to protect customers. To minimize risk to computer users, Microsoft continues to encourage responsible disclosure. Reporting vulnerabilities directly to vendors without further disclosure helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of – and work to exploit – a vulnerability. Responsible disclosure protects the computer ecosystem and individual computer users from harm.</p>  <p>Anyone believed to have been affected can visit: <a href="http://www.microsoft.com/protect/support/default.mspx">http://www.microsoft.com/protect/support/default.mspx</a> and should contact the national law enforcement agency in their country.&#160; Those in the United States can contact Customer Service and Support at no charge (for computer security related issues) using the PC Safety hotline at 1-866-727-2338 (PCSAFETY). Customers outside of the United States can visit <a href="http://support.microsoft.com/international">http://support.microsoft.com/international</a> to find local support information.</p>  <p>We continue to encourage customers to follow the “Protect Your Computer” guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. Additional information can be found at: <a href="http://www.microsoft.com/protect">www.microsoft.com/protect</a>.</p>  <p>We will provide more information on this issue as it becomes available.</p>  <p>Thanks,</p>  <p>Jerry Bryant   <br />Sr. Security Communications Manager Lead</p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3315922" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone,</p>  <p>On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box. We are not aware of any attacks seeking to exploit this issue at this time and in the current state of our investigation, we have determined that users running Windows 7, Windows Server 2008 R2, Windows Server 2008, and Windows Vista, are not affected by this issue. </p>  <p>The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system. To help customers better understand unsafe file types, we have published a white paper on the topic which you can find by clicking <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=b7d03027-9791-443b-8bbe-0542b3aa4bfe">this link</a>.</p>  <p>Once we have completed our investigation, we will take appropriate action to protect customers. To minimize risk to computer users, Microsoft continues to encourage responsible disclosure. Reporting vulnerabilities directly to vendors without further disclosure helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of – and work to exploit – a vulnerability. Responsible disclosure protects the computer ecosystem and individual computer users from harm.</p>  <p>Anyone believed to have been affected can visit: <a href="http://www.microsoft.com/protect/support/default.mspx">http://www.microsoft.com/protect/support/default.mspx</a> and should contact the national law enforcement agency in their country.&#160; Those in the United States can contact Customer Service and Support at no charge (for computer security related issues) using the PC Safety hotline at 1-866-727-2338 (PCSAFETY). Customers outside of the United States can visit <a href="http://support.microsoft.com/international">http://support.microsoft.com/international</a> to find local support information.</p>  <p>We continue to encourage customers to follow the “Protect Your Computer” guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. Additional information can be found at: <a href="http://www.microsoft.com/protect">www.microsoft.com/protect</a>.</p>  <p>We will provide more information on this issue as it becomes available.</p>  <p>Thanks,</p>  <p>Jerry Bryant   <br />Sr. Security Communications Manager Lead</p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3315922" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory 979352 Updated</title>
		<link>http://blogs.technet.com/msrc/archive/2010/01/15/advisory-979352-updated.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2010/01/15/advisory-979352-updated.aspx#comments</comments>
		<pubDate>Sat, 16 Jan 2010 01:42:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploitability]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3306059</guid>
		<description><![CDATA[<p class="MsoNormal"><font size="3" face="Calibri">Hello, </font></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">Today we updated </font></span><a href="http://www.microsoft.com/technet/security/advisory/979352.mspx"><span><font size="3" face="Calibri">Security Advisory 979352</font></span></a><span><font size="3"></font><font face="Calibri"> to let customers know that we are aware that exploit code for the vulnerability used in recent attacks against IE 6 users, has<span>&#160;</span>now been made public. Information on which versions of Internet Explorer are vulnerable and what customers can do to protect themselves is included in the updated Security Advisory.</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Our teams are continuing to work on an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out-of-band. </font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">Additionally our </font></span><a href="http://blogs.technet.com/srd"><span><font color="#0000ff" size="3" face="Calibri">Security Research &#38; Defense team</font></span></a><span><font size="3"></font><font face="Calibri"> has written up a blog with additional technical details on the exploit, the vulnerability, mitigations and workarounds.</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">We continue to recommend customers review the information in the Advisory, implement the workarounds and mitigations, consider updating to Internet Explorer 8 which includes important protections not present in IE 6, and follow the information on our </font></span><a href="http://www.microsoft.com/protect"><span><font color="#0000ff" size="3" face="Calibri">Protect Your PC website</font></span></a><span><font size="3"></font><font face="Calibri">.</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Thanks,</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Jerry Bryant</font></span></p>
<p class="MsoNormal"><span><font size="3"></font><font face="Calibri">Senior Security Communications Manager Lead</font></span></p>
<p class="MsoNormal"><span><font size="3" face="Calibri">*This posting is provided "AS IS" with no warranties, and confers no rights.*</font></span></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3306059" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><font size=3 face=Calibri>Hello, </font></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3 face=Calibri>Today we updated </font></span><a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/979352.mspx"><span style="mso-bidi-font-style: italic"><font size=3 face=Calibri>Security Advisory 979352</font></span></a><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri> to let customers know that we are aware that exploit code for the vulnerability used in recent attacks against IE 6 users, has<span style="mso-spacerun: yes">&nbsp;</span>now been made public. Information on which versions of Internet Explorer are vulnerable and what customers can do to protect themselves is included in the updated Security Advisory.< ?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri>Our teams are continuing to work on an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out-of-band. <o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3 face=Calibri>Additionally our </font></span><a href="http://blogs.technet.com/srd" mce_href="http://blogs.technet.com/srd"><span style="mso-bidi-font-style: italic"><font color=#0000ff size=3 face=Calibri>Security Research &amp; Defense team</font></span></a><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri> has written up a blog with additional technical details on the exploit, the vulnerability, mitigations and workarounds.<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3 face=Calibri>We continue to recommend customers review the information in the Advisory, implement the workarounds and mitigations, consider updating to Internet Explorer 8 which includes important protections not present in IE 6, and follow the information on our </font></span><a href="http://www.microsoft.com/protect" mce_href="http://www.microsoft.com/protect"><span style="mso-bidi-font-style: italic"><font color=#0000ff size=3 face=Calibri>Protect Your PC website</font></span></a><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri>.<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri>Thanks,<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri>Jerry Bryant<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3></font><font face=Calibri>Senior Security Communications Manager Lead<o :p></o></font></span></p>
<p style="MARGIN: 0in 0in 10pt" class=MsoNormal><span style="mso-bidi-font-style: italic"><font size=3 face=Calibri>*This posting is provided "AS IS" with no warranties, and confers no rights.*</font></span></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3306059" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2010/01/15/advisory-979352-updated.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
