<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Microsoft Windows</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/microsoft-windows/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 06:08:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A live BlueHat Prize webcast and the August 2011 security updates</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/08/09/a-live-bluehat-prize-webcast-and-the-august-2011-security-updates.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/08/09/a-live-bluehat-prize-webcast-and-the-august-2011-security-updates.aspx#comments</comments>
		<pubDate>Tue, 09 Aug 2011 18:09:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Security Bulletin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello all. It has been very nearly a week since our <a href="http://www.bluehatprize.com/"><span style="color: #000066">BlueHat Prize contest announcement</span></a> at Black Hat. Now that everyone&#8217;s had some time to digest the basics, we&#8217;ve asked Senior Security Strategist and chief BlueHat Prize architect Katie Moussouris to stop by the Trustworthy Computing studio today at 11 a.m. PDT&#160;to answer a few more questions about the contest. &#160;She&#8217;ll discuss how it works and what she expects will happen next, and she&#8217;ll answer some common questions such as who owns the intellectual property. We&#8217;ll be taking your questions, too! Register for the webcast at this <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032491582&#38;Culture=en-US">link</a>.</p>
<p class="paragraph">As I previously mentioned in the <a href="http://blogs.technet.com/b/msrc/archive/2011/08/03/advance-notification-service-for-the-august-2011-bulletin-release.aspx">Advance Notification Service blog</a> post on Thursday, today we are releasing 13 security bulletins, two of which are rated Critical in severity, nine Important and two Moderate.</p>
<p class="paragraph">These bulletins will increase protection by addressing 22 unique vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on the two critical updates:</p>
<ul>
<li><b>MS11-057 (Internet Explorer).</b> This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. Microsoft is not aware of any attacks leveraging the vulnerabilities addressed in this bulletin.</li>
<li><b>MS11-058 (DNS Server)</b>. This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker sends a specially crafted Naming Authority Pointer (NAPTR) query to a DNS server. Servers that do not have the DNS role enabled are not at risk.</li>
</ul>
<p class="paragraph">In this video, Jerry Bryant discusses this month's bulletins in further detail, focusing on these two bulletins:</p>

<p class="paragraph">As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6567.aug11_2D00_deploy.png" target="_blank"><img border="0" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6567.aug11_2D00_deploy.png" width="500" /></a></p>
<p class="paragraph">Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/2860.aug11_2D00_xi.png" target="_blank"><img border="0" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/2860.aug11_2D00_xi.png" width="500" /></a></p>
<p class="paragraph">You can find more information about this month's security updates on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx">Summary web page</a>. In addition, the <a href="http://blogs.technet.com/b/srd/">SRD blog</a> today has more information on MS11-058&#8217;s Exploitability Index rating and on the month&#8217;s deployment priorities.</p>
<p class="paragraph">Per our usual process, we&#8217;ll offer the monthly technical webcast on Wednesday, hosted by Jerry Bryant and Jonathan Ness. I invite you to tune in and learn more about the June security bulletins, as well as other announcements made today. The webcast is scheduled for Wednesday, August 10, 2011 at 11 a.m. PDT, and you can register <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032487857&#38;Culture=en-US">here</a>.</p>
<p class="paragraph">For all the latest information, please also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline">@MSFTSecResponse</span></a>.</p>
<p class="paragraph">Thank you,</p>
<p class="paragraph">Angela Gunn<br />Trustworthy Computing.</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3445929" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello all. It has been very nearly a week since our <a href="http://www.bluehatprize.com/"><span style="color: #000066;" color="#000066">BlueHat Prize contest announcement</span></a> at Black Hat. Now that everyone&rsquo;s had some time to digest the basics, we&rsquo;ve asked Senior Security Strategist and chief BlueHat Prize architect Katie Moussouris to stop by the Trustworthy Computing studio today at 11 a.m. PDT&nbsp;to answer a few more questions about the contest. &nbsp;She&rsquo;ll discuss how it works and what she expects will happen next, and she&rsquo;ll answer some common questions such as who owns the intellectual property. We&rsquo;ll be taking your questions, too! Register for the webcast at this <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032491582&amp;Culture=en-US">link</a>.</p>
<p class="paragraph">As I previously mentioned in the <a href="http://blogs.technet.com/b/msrc/archive/2011/08/03/advance-notification-service-for-the-august-2011-bulletin-release.aspx">Advance Notification Service blog</a> post on Thursday, today we are releasing 13 security bulletins, two of which are rated Critical in severity, nine Important and two Moderate.</p>
<p class="paragraph">These bulletins will increase protection by addressing 22 unique vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on the two critical updates:</p>
<ul>
<li><b>MS11-057 (Internet Explorer).</b> This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. Microsoft is not aware of any attacks leveraging the vulnerabilities addressed in this bulletin.</li>
<li><b>MS11-058 (DNS Server)</b>. This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker sends a specially crafted Naming Authority Pointer (NAPTR) query to a DNS server. Servers that do not have the DNS role enabled are not at risk.</li>
</ul>
<p class="paragraph">In this video, Jerry Bryant discusses this month's bulletins in further detail, focusing on these two bulletins:</p>
<script type="text/javascript" src="http://technet.microsoft.com/en-us/videoembed/august-2011-security-bulletin-release-overview"></script>
<p class="paragraph">As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6567.aug11_2D00_deploy.png" ><img border="0" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6567.aug11_2D00_deploy.png" width="500" /></a></p>
<p class="paragraph">Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/2860.aug11_2D00_xi.png" ><img border="0" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/2860.aug11_2D00_xi.png" width="500" /></a></p>
<p class="paragraph">You can find more information about this month's security updates on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx">Summary web page</a>. In addition, the <a href="http://blogs.technet.com/b/srd/">SRD blog</a> today has more information on MS11-058&rsquo;s Exploitability Index rating and on the month&rsquo;s deployment priorities.</p>
<p class="paragraph">Per our usual process, we&rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Jerry Bryant and Jonathan Ness. I invite you to tune in and learn more about the June security bulletins, as well as other announcements made today. The webcast is scheduled for Wednesday, August 10, 2011 at 11 a.m. PDT, and you can register <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032487857&amp;Culture=en-US">here</a>.</p>
<p class="paragraph">For all the latest information, please also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline;">@MSFTSecResponse</span></a>.</p>
<p class="paragraph">Thank you,</p>
<p class="paragraph">Angela Gunn<br />Trustworthy Computing.</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3445929" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/08/09/a-live-bluehat-prize-webcast-and-the-august-2011-security-updates.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-03-44-59-29/August-2011-Bulletin-Release-_2D00_Final-_2D00_-Customer-Ready.pptx" length="543350" type="application/octet-stream" />
		</item>
		<item>
		<title>Rustock updates and Advance Notification Service for the July 2011 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/07/07/rustock-updates-and-advance-notification-service-for-the-july-2011-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/07/07/rustock-updates-and-advance-notification-service-for-the-july-2011-security-bulletin-release.aspx#comments</comments>
		<pubDate>Thu, 07 Jul 2011 17:00:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ANS]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><span style="font-size: small"><span style="font-family: Calibri">Hello all --</span></span></p>
<p></p>
<p><span style="font-family: Calibri;font-size: small">This week we released a </span><a href="http://www.microsoft.com/security/sir/story/default.aspx#!rustock"><span style="font-family: Calibri;color: #000077;font-size: small">special Security Intelligence Report</span></a><span style="font-family: Calibri;font-size: small">that showcases some of the data we amassed in the wake of the big Rustock botnet takedown in the spring of 2010. The new SIR also delves into the diplomacy, secrecy and intellectual property law that all played important roles in the successful international effort that led to the takedown of the Rustock botnet on March 16. This was Microsoft&#8217;s second global botnet takedown effort, after </span><a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2010/02/24/cracking-down-on-botnets.aspx"><span style="font-family: Calibri;color: #000077;font-size: small">Waledac</span></a><span style="font-family: Calibri"><span style="font-size: small"><span style="color: #000077">&#160;in February, 2011</span>.</span></span></p>
<p><span style="font-family: Calibri;font-size: small">In addition, as part of our normal monthly bulletin cadence, we&#8217;re providing our </span><a href="http://www.microsoft.com/technet/security/bulletin/ms11-jul.mspx"><span style="font-family: Calibri;color: #000077;font-size: small">Advance Notification Service</span></a><span style="font-size: small"><span style="font-family: Calibri"> for July&#8217;s security bulletins today. This month we'll release four bulletins, one of them rated Critical and three rated Important, addressing issues in Microsoft Windows and Office. We'll close 22 vulnerabilities with those bulletins. </span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">The bulletin release is once again slated for the second Tuesday of the month &#8211; July 12th at 10:00 a.m. PDT. Come back to this blog then for our official risk and impact analysis, as well as deployment guidance and a brief video overview of the month's highlights.</span></span></p>
<p><span style="font-family: Calibri;font-size: small">The monthly technical webcast next week will be hosted once again by Jerry Bryant and Dustin Childs. We invite you to tune in and learn more about the new security bulletin releases as well as other announcements to be made on Tuesday. That webcast is scheduled for Wednesday, July 13, 2011 at 11:00 a.m. PDT (UTC -7), and the registration form can be found </span><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032487855&#38;culture=en-US"><span style="font-family: Calibri;color: #000077;font-size: small">here</span></a><span style="font-size: small"><span style="font-family: Calibri">. </span></span></p>
<p class="paragraph">For all the latest information, you can also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline">@MSFTSecResponse</span></a>.</p>
<p><span style="font-size: small"><span style="font-family: Calibri">Thank you, </span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Angela Gunn <br />Trustworthy Computing.</span></span></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3439957" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Hello all --</span></span></p>
<p></p>
<p><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">This week we released a </span><a href="http://www.microsoft.com/security/sir/story/default.aspx#!rustock"><span style="font-family: Calibri; color: #000077; font-size: small;" size="3" face="Calibri" color="#000077">special Security Intelligence Report</span></a><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">that showcases some of the data we amassed in the wake of the big Rustock botnet takedown in the spring of 2010. The new SIR also delves into the diplomacy, secrecy and intellectual property law that all played important roles in the successful international effort that led to the takedown of the Rustock botnet on March 16. This was Microsoft&rsquo;s second global botnet takedown effort, after </span><a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2010/02/24/cracking-down-on-botnets.aspx"><span style="font-family: Calibri; color: #000077; font-size: small;" size="3" face="Calibri" color="#000077">Waledac</span></a><span style="font-family: Calibri;" face="Calibri"><span style="font-size: small;" size="3"><span style="color: #000077;" color="#000077">&nbsp;in February, 2011</span>.</span></span></p>
<p><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">In addition, as part of our normal monthly bulletin cadence, we&rsquo;re providing our </span><a href="http://www.microsoft.com/technet/security/bulletin/ms11-jul.mspx"><span style="font-family: Calibri; color: #000077; font-size: small;" size="3" face="Calibri" color="#000077">Advance Notification Service</span></a><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri"> for July&rsquo;s security bulletins today. This month we'll release four bulletins, one of them rated Critical and three rated Important, addressing issues in Microsoft Windows and Office. We'll close 22 vulnerabilities with those bulletins. </span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">The bulletin release is once again slated for the second Tuesday of the month &ndash; July 12th at 10:00 a.m. PDT. Come back to this blog then for our official risk and impact analysis, as well as deployment guidance and a brief video overview of the month's highlights.</span></span></p>
<p><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">The monthly technical webcast next week will be hosted once again by Jerry Bryant and Dustin Childs. We invite you to tune in and learn more about the new security bulletin releases as well as other announcements to be made on Tuesday. That webcast is scheduled for Wednesday, July 13, 2011 at 11:00 a.m. PDT (UTC -7), and the registration form can be found </span><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032487855&amp;culture=en-US"><span style="font-family: Calibri; color: #000077; font-size: small;" size="3" face="Calibri" color="#000077">here</span></a><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">. </span></span></p>
<p class="paragraph">For all the latest information, you can also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline;">@MSFTSecResponse</span></a>.</p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Thank you, </span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Angela Gunn <br />Trustworthy Computing.</span></span></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3439957" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/07/07/rustock-updates-and-advance-notification-service-for-the-july-2011-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Q&amp;A from April 2011 Security Bulletin Webcast</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/04/14/q-amp-a-from-april-2011-security-bulletin-webcast.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/04/14/q-amp-a-from-april-2011-security-bulletin-webcast.aspx#comments</comments>
		<pubDate>Thu, 14 Apr 2011 16:38:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[monthly bulletin release]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q & A]]></category>
		<category><![CDATA[Webcast Q&A]]></category>
		<category><![CDATA[Webcast Q&amp]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello, </p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/p/april-2011-security-bulletin-q-a.aspx">April Security Bulletin Webcast Questions &#38; Answers page</a>. We fielded 14 questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools. There were two questions during the webcast that we were unable to answer and we have included those questions and answers on the QA page.</p>
<p>I also want to provide some clarity regarding our announcement that SMS 2003 with SUIT is retiring this month. SMS 2.0 and the SUIT add-on that can be installed on either SMS 2.0 or SMS 2003 are going out of support this month. SMS 2003 is not scheduled to go out of support until 2015. Customers who currently use SMS 2003 with SUIT should plan to use SCCM 2007 or SMS 2003 with ITMU starting next month.&#160; </p>
<p>We invite our customers to join us for the next public webcast on Wednesday, May 11th at 11am PDT (-8 UTC), when we will go into detail about the&#160;April bulletin release&#160;and answer questions live on the air. </p>
<p>Customers can register to attend at the link below:</p>
<p><b>Date: Wednesday, March 9, 2011<br />Time: 11:00 a.m. PST (UTC -8)</b><b><br />Register: </b><a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032455049&#38;EventCategory=4"><b>Attendee Registration </b></a></p>
<p>&#160;"

"</p>
<p>&#160;</p>
<p>Thanks -</p>
<p>Jerry Bryant</p>
<p>Group Manager, Response Communications<br />Trustworthy Computing Group</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3421636" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello, </p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/p/april-2011-security-bulletin-q-a.aspx">April Security Bulletin Webcast Questions &amp; Answers page</a>. We fielded 14 questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools. There were two questions during the webcast that we were unable to answer and we have included those questions and answers on the QA page.</p>
<p>I also want to provide some clarity regarding our announcement that SMS 2003 with SUIT is retiring this month. SMS 2.0 and the SUIT add-on that can be installed on either SMS 2.0 or SMS 2003 are going out of support this month. SMS 2003 is not scheduled to go out of support until 2015. Customers who currently use SMS 2003 with SUIT should plan to use SCCM 2007 or SMS 2003 with ITMU starting next month.&nbsp; </p>
<p>We invite our customers to join us for the next public webcast on Wednesday, May 11th at 11am PDT (-8 UTC), when we will go into detail about the&nbsp;April bulletin release&nbsp;and answer questions live on the air. </p>
<p>Customers can register to attend at the link below:</p>
<p><b>Date: Wednesday, March 9, 2011<br />Time: 11:00 a.m. PST (UTC -8)</b><b><br />Register: </b><a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032455049&amp;EventCategory=4"><b>Attendee Registration </b></a></p>
<p>&nbsp;"
<script type="text/javascript" src="http://technet.microsoft.com/objectforward/default.aspx?type=VideoPlayer&amp;video=http%3A%2F%2Fcontent1.catalog.video.msn.com%2Fe2%2Fds%2F01e3126c-5807-4811-8126-53664e81e4e7.wmv&amp;thumb=http%3A%2F%2Fcontent3.catalog.video.msn.com%2Fe2%2Fds%2F493ccceb-464d-491c-92a9-01dedf56fdd9.png&amp;title=April%202011%20Security%20Bulletin%20Release%20Webcast&amp;width=400&amp;height=400"></script>
"</p>
<p>&nbsp;</p>
<p>Thanks -</p>
<p>Jerry Bryant</p>
<p>Group Manager, Response Communications<br />Trustworthy Computing Group</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3421636" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/04/14/q-amp-a-from-april-2011-security-bulletin-webcast.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2011 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/03/08/march-2011-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/03/08/march-2011-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 08 Mar 2011 17:54:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Malicious Software Removal Tool (MSRT)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[monthly bulletin release]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello all --</p>
<p>Today, as part of our monthly security bulletin release, we have three bulletins addressing four vulnerabilities in Microsoft Windows and Microsoft Office. One bulletin is rated Critical, and this is the bulletin we recommend for priority deployment: </p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-015.mspx">MS11-015</a>. This bulletin resolves one Critical-level and one Important-level vulnerability affecting certain media files in all versions of Microsoft Windows. It has an Exploitability Index rating of 1. Due to the nature of the affected software, this bulletin carries a Critical-level severity rating for all affected client systems, but only an Important-level rating for Windows Server 2008 R2 for x64. Other versions of Windows Server - 2003, 2008 and 2008 R2 - are unaffected. For both the Critical- and Important-level vulnerabilities, an attacker would have to convince a user to open a maliciously crafted file for an attack to work.</li>
</ul>
<p>Our other two bulletins are somewhat similar in nature, both addressing the DLL-preloading issue described in <a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx">Security Advisory 2269637</a>, and both carrying an Important-level severity rating and an Exploitability Index rating of 1.</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-016.mspx">MS11-016</a> is a DLL-preloading issue affecting Microsoft Groove 2007 Service Pack 2, which makes this an Office bulletin. Versions 2007 and 2010 of Groove are unaffected, as is Microsoft SharePoint Workspace 2010.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-017.mspx">MS11-017</a> is also a DLL-preloading issue, in this instance in Microsoft Windows Remote Client Desktop. This security update is rated Important for Remote Desktop Connection 5.2 Client, Remote Desktop Connection 6.0 Client, Remote Desktop Connection 6.1 Client, and Remote Desktop Connection 7.0 Client.</li>
</ul>
<p>We continue to address DLL-preloading issues as they are discovered; however, it's important to note that we have not seen exploitation of these issues in the wild.</p>
<p>In this video, Jerry Bryant discusses this month's bulletins in further detail, focusing on MS11-015:</p>
<p>

</p>
<p>As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0247.1103-deployment.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0247.1103-deployment.png" border="0" /></a> </p>
<p>Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5460.1103-severity_2D00_xi.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5460.1103-severity_2D00_xi.png" border="0" /></a> </p>
<p>More information about this month's security updates can be found on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-mar.mspx">summary web page</a>. </p>
<p>As we often do in the wake of a Service Pack release, we've gotten deployment questions about Windows 7 SP1. To assist customers in that process, our TechNet site has posted an <a href="http://technet.microsoft.com/en-us/library/ff817622(WS.10).aspx">SP1 deployment guide</a> to aid you in testing and deployment. You'll also find release notes and links to handy information -- for example, <a href="http://go.microsoft.com/fwlink/?LinkId=194725">a spreadsheet</a> that contains a list of all the hotfixes and security updates that are included in the Service Pack -- as well as information on new features and functionality.</p>
<p>We'd also like to update you on <a href="http://www.microsoft.com/technet/security/advisory/2501696.mspx">Security Advisory 2501696</a>, which describes an MHTML-related vulnerability in Microsoft Windows. Microsoft is actively monitoring the threat landscape in conjunction with our <a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx">Microsoft Active Protections Program</a> (MAPP) partners. We are currently working to provide a solution through our monthly security update release process and will continue to monitor the issue as we prepare that.</p>
<p>Finally, we mentioned previously that changes are coming to the system we use for publishing our bulletins and security advisories. We still expect those changes to go live in June of this year. The main impact to customers will be a URL change from microsoft.com/technet/security to technet.microsoft.com/security. We are planning to have both the old and new sites available simultaneously for a period of time.</p>
<p>Please join the monthly technical webcast with your hosts, Jerry Bryant and Dustin Childs, to learn more about the March 2011 security bulletins. The webcast is scheduled for Wednesday, March 9, 2011 at 11:00 a.m. PST (UTC -8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032455049&#38;EventCategory=4&#38;culture=en-US&#38;CountryCode=US">here</a>. </p>
<p>For all the latest information, you can follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline">@MSFTSecResponse</span></a>.</p>
<p>Thanks,</p>
<p>Angela Gunn<br />Trustworthy Computing.</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3392517" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello all --</p>
<p>Today, as part of our monthly security bulletin release, we have three bulletins addressing four vulnerabilities in Microsoft Windows and Microsoft Office. One bulletin is rated Critical, and this is the bulletin we recommend for priority deployment: </p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-015.mspx">MS11-015</a>. This bulletin resolves one Critical-level and one Important-level vulnerability affecting certain media files in all versions of Microsoft Windows. It has an Exploitability Index rating of 1. Due to the nature of the affected software, this bulletin carries a Critical-level severity rating for all affected client systems, but only an Important-level rating for Windows Server 2008 R2 for x64. Other versions of Windows Server - 2003, 2008 and 2008 R2 - are unaffected. For both the Critical- and Important-level vulnerabilities, an attacker would have to convince a user to open a maliciously crafted file for an attack to work.</li>
</ul>
<p>Our other two bulletins are somewhat similar in nature, both addressing the DLL-preloading issue described in <a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx">Security Advisory 2269637</a>, and both carrying an Important-level severity rating and an Exploitability Index rating of 1.</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-016.mspx">MS11-016</a> is a DLL-preloading issue affecting Microsoft Groove 2007 Service Pack 2, which makes this an Office bulletin. Versions 2007 and 2010 of Groove are unaffected, as is Microsoft SharePoint Workspace 2010.</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms11-017.mspx">MS11-017</a> is also a DLL-preloading issue, in this instance in Microsoft Windows Remote Client Desktop. This security update is rated Important for Remote Desktop Connection 5.2 Client, Remote Desktop Connection 6.0 Client, Remote Desktop Connection 6.1 Client, and Remote Desktop Connection 7.0 Client.</li>
</ul>
<p>We continue to address DLL-preloading issues as they are discovered; however, it's important to note that we have not seen exploitation of these issues in the wild.</p>
<p>In this video, Jerry Bryant discusses this month's bulletins in further detail, focusing on MS11-015:</p>
<p>
<script src="http://technet.microsoft.com/en-us/videoembed/march-2011-security-bulletin-release-overview" type="text/javascript"></script>
</p>
<p>As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0247.1103-deployment.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0247.1103-deployment.png" border="0" /></a> </p>
<p>Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5460.1103-severity_2D00_xi.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5460.1103-severity_2D00_xi.png" border="0" /></a> </p>
<p>More information about this month's security updates can be found on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-mar.mspx">summary web page</a>. </p>
<p>As we often do in the wake of a Service Pack release, we've gotten deployment questions about Windows 7 SP1. To assist customers in that process, our TechNet site has posted an <a href="http://technet.microsoft.com/en-us/library/ff817622(WS.10).aspx">SP1 deployment guide</a> to aid you in testing and deployment. You'll also find release notes and links to handy information -- for example, <a href="http://go.microsoft.com/fwlink/?LinkId=194725">a spreadsheet</a> that contains a list of all the hotfixes and security updates that are included in the Service Pack -- as well as information on new features and functionality.</p>
<p>We'd also like to update you on <a href="http://www.microsoft.com/technet/security/advisory/2501696.mspx">Security Advisory 2501696</a>, which describes an MHTML-related vulnerability in Microsoft Windows. Microsoft is actively monitoring the threat landscape in conjunction with our <a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx">Microsoft Active Protections Program</a> (MAPP) partners. We are currently working to provide a solution through our monthly security update release process and will continue to monitor the issue as we prepare that.</p>
<p>Finally, we mentioned previously that changes are coming to the system we use for publishing our bulletins and security advisories. We still expect those changes to go live in June of this year. The main impact to customers will be a URL change from microsoft.com/technet/security to technet.microsoft.com/security. We are planning to have both the old and new sites available simultaneously for a period of time.</p>
<p>Please join the monthly technical webcast with your hosts, Jerry Bryant and Dustin Childs, to learn more about the March 2011 security bulletins. The webcast is scheduled for Wednesday, March 9, 2011 at 11:00 a.m. PST (UTC -8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032455049&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US">here</a>. </p>
<p>For all the latest information, you can follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline;">@MSFTSecResponse</span></a>.</p>
<p>Thanks,</p>
<p>Angela Gunn<br />Trustworthy Computing.</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3392517" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/03/08/march-2011-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advance Notification Service for the March 2011 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/03/03/advance-notification-service-for-the-march-2011-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/03/03/advance-notification-service-for-the-march-2011-security-bulletin-release.aspx#comments</comments>
		<pubDate>Thu, 03 Mar 2011 19:32:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[ANS]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello all --</p>
<p>Today, as part of our usual monthly bulletin cadence, we are providing our <a href="http://www.microsoft.com/technet/security/bulletin/ms11-mar.mspx">Advance Notification Service</a> for March's security bulletins. This month we'll release three bulletins, one of them rated Critical and two rated Important, addressing issues in Microsoft Windows and Office. We'll close four vulnerabilities with those bulletins. </p>
<p>The bulletin release is once again slated for the second Tuesday of the month -- March 8th at 10:00 a.m. PST. Come back to this blog then for our official risk and impact analysis, as well as deployment guidance and a brief video overview of the month's highlights.</p>
<p>The monthly technical webcast next week will be hosted by Jerry Bryant and Dustin Childs. We invite you to tune in and learn more about the new security bulletin releases as well as other announcements to be made on Tuesday. That webcast is scheduled for Wednesday, March 9, 2011 at 11:00 a.m. PST (UTC -8), and the registration form can be found <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032455049&#38;EventCategory=4">here</a>. </p>
<p>Thank you, </p>
<p>Angela Gunn <br />Trustworthy Computing.</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3391587" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello all --</p>
<p>Today, as part of our usual monthly bulletin cadence, we are providing our <a href="http://www.microsoft.com/technet/security/bulletin/ms11-mar.mspx">Advance Notification Service</a> for March's security bulletins. This month we'll release three bulletins, one of them rated Critical and two rated Important, addressing issues in Microsoft Windows and Office. We'll close four vulnerabilities with those bulletins. </p>
<p>The bulletin release is once again slated for the second Tuesday of the month -- March 8th at 10:00 a.m. PST. Come back to this blog then for our official risk and impact analysis, as well as deployment guidance and a brief video overview of the month's highlights.</p>
<p>The monthly technical webcast next week will be hosted by Jerry Bryant and Dustin Childs. We invite you to tune in and learn more about the new security bulletin releases as well as other announcements to be made on Tuesday. That webcast is scheduled for Wednesday, March 9, 2011 at 11:00 a.m. PST (UTC -8), and the registration form can be found <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032455049&amp;EventCategory=4">here</a>. </p>
<p>Thank you, </p>
<p>Angela Gunn <br />Trustworthy Computing.</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3391587" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/03/03/advance-notification-service-for-the-march-2011-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2011 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/02/08/february-2011-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/02/08/february-2011-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 08 Feb 2011 18:03:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[monthly bulletin release]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[Security Update]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello all --</p>
<p>Today, as part of our monthly security
bulletin release, we have 12 bulletins addressing 22 vulnerabilities in
Microsoft Windows, Office, Internet Explorer, and IIS (Internet Information
Services). Three bulletins are rated Critical, and these are the bulletins we
recommend for priority deployment: &#160;</p>
<p>o&#160;&#160;&#160;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-003.mspx">MS11-003</a>. This bulletin resolves three
critical-level and moderate-level vulnerabilities affecting all versions of
Internet Explorer. Due to existing mitigations, this bulletin is only rated at
Moderate severity for all versions of Windows Server, has an Exploitability
Index rating of 1, and will deprecate <a href="http://www.microsoft.com/technet/security/advisory/2488013.mspx">Security
Advisory 2488013</a>.</p>
<p>o&#160;&#160;&#160;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-006.mspx">MS11-006</a>. This bulletin addresses one Critical-level
vulnerability affecting Windows XP, Vista, Server 2003, and Server 2008. Newer
versions of our operating system are unaffected. The vulnerability involves
Windows Shell Graphics and could if exploited lead to remote code execution.
This has an Exploitability Index rating of 1 and will deprecate <a href="http://www.microsoft.com/technet/security/advisory/2490606.mspx">Security
Advisory 2490606</a> which we released on January 4<sup>th</sup>. Since that
time, we have not seen any attacks against this issue.</p>
<p>o&#160;&#160;&#160;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-007.mspx">MS11-007</a>. This bulletin addresses one privately
reported vulnerability affecting all supported versions of Windows and
involving the OpenType Compact Font Driver. It's rated Critical for Windows
Vista, Windows 7, Server 2008 and Server 2008 R2; it's rated Important for
Windows XP and Server 2003. &#160;This issue has
an Exploitability Index rating of 2.</p>
<p>In this video, Jerry Bryant discusses this
month's bulletins in further detail:</p>
<p>

</p>
<p>As always, we recommend that customers
deploy all security updates as soon as possible. Below is our deployment
priority guidance to further assist customers in their deployment planning
(click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6813.deploy_2D00_feb11.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6813.deploy_2D00_feb11.png" width="500" border="0" /></a></p>
<p>Our risk and impact graph shows an aggregate
view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5504.severity_2D00_exploit_2D00_feb11.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5504.severity_2D00_exploit_2D00_feb11.png" width="500" border="0" /></a></p>
<p>More information about this month's
security updates can be found on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">summary web page</a>.&#160; </p>
<p>As mentioned, we are addressing <a href="http://www.microsoft.com/technet/security/advisory/2488013.mspx">Security Advisory 2488013</a> as part of the regularly scheduled
Internet Explorer cumulative update. This Security Advisory and the zero-day
disclosure on which it was predicated caused discussion in the security
community, and some observers thought that we might be forced to release an
out-of-band bulletin to protect customers. However, out-of-band releases are
disruptive to customers and we try to avoid them where possible. Based on our
capabilities to closely monitor the threat landscape, we were able to determine
that attempts to attack this vulnerability were very low. With that
information, we were able to extensively test a bulletin to be released as part
of our regular bulletin cadence. The MMPC (Microsoft Malware Protection Center)
blog <ins cite="mailto:Angela%20Gunn" datetime="2011-02-08T09:09"><a href="http://blogs.technet.com/b/mmpc/archive/2011/02/08/cve-2010-3971-not-quite-the-weekend-warrior.aspx">has
details</a></ins> about the telemetry we used to guide us. There we
contrast this issue with telemetry from an out-of-band release last year to
demonstrate why one was not needed here.</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5710.CVE_2D00_2010_2D00_3971_2D00_vs_2D00_CVE_2D00_2010_2D00_2568.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5710.CVE_2D00_2010_2D00_3971_2D00_vs_2D00_CVE_2D00_2010_2D00_2568.png" width="500" border="0" /></a></p>
<p>Also this month, we're updating <a href="http://www.microsoft.com/technet/security/advisory/967940.mspx">Security Advisory 967940</a>, "Update for Windows Autorun," to change
how earlier versions of Windows handle security when reading "non-shiny"
storage media. ("Shiny" storage media would include CD-ROMs and DVDs.) Windows
7 already disables Autorun for devices such as USB thumb drives, which prevents
malware lurking on such drives from loading itself onto computers without user
interaction. With the change to the Advisory, earlier versions of Windows that
receive their updates automatically via Windows Update "AutoUpdate" will now
gain that security-conscious functionality as well. We believe this is a huge
step towards combating one of the most prevalent infection vectors used by
malware such as Conficker.</p>
<p>Finally, we're excited to announce that
changes are coming to the system we use for publishing our bulletins and
security advisories - changes that will bring better integration with the
wealth of other content on Technet and a richer experience for customers. We
are expecting the changes to go live in the June 2011 timeframe. The main
impact to customers will be a URL change from microsoft.com/technet/security to
technet.microsoft.com/security. We are planning to have both the old and new
sites available simultaneously for a period of time and will be providing more
details in March. </p>
<p>Please join the monthly technical webcast
with your hosts, Jerry Bryant and Jonathan Ness, to learn more about all the February
2011 security bulletins. The webcast is scheduled for Wednesday, February 9,
2011 at 11:00 a.m. PST (UTC -8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032455047&#38;EventCategory=4&#38;culture=en-US&#38;CountryCode=US">here</a>. </p>
<p>For all the latest information, you can
follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline">@MSFTSecResponse</span></a>.</p>
<p>Thanks,</p>
<p>Angela Gunn<br />
Trustworthy Computing.</p>
<p>&#160;</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3385819" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello all --</p>
<p>Today, as part of our monthly security
bulletin release, we have 12 bulletins addressing 22 vulnerabilities in
Microsoft Windows, Office, Internet Explorer, and IIS (Internet Information
Services). Three bulletins are rated Critical, and these are the bulletins we
recommend for priority deployment: &nbsp;</p>
<p>o&nbsp;&nbsp;&nbsp;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-003.mspx">MS11-003</a>. This bulletin resolves three
critical-level and moderate-level vulnerabilities affecting all versions of
Internet Explorer. Due to existing mitigations, this bulletin is only rated at
Moderate severity for all versions of Windows Server, has an Exploitability
Index rating of 1, and will deprecate <a href="http://www.microsoft.com/technet/security/advisory/2488013.mspx">Security
Advisory 2488013</a>.</p>
<p>o&nbsp;&nbsp;&nbsp;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-006.mspx">MS11-006</a>. This bulletin addresses one Critical-level
vulnerability affecting Windows XP, Vista, Server 2003, and Server 2008. Newer
versions of our operating system are unaffected. The vulnerability involves
Windows Shell Graphics and could if exploited lead to remote code execution.
This has an Exploitability Index rating of 1 and will deprecate <a href="http://www.microsoft.com/technet/security/advisory/2490606.mspx">Security
Advisory 2490606</a> which we released on January 4<sup>th</sup>. Since that
time, we have not seen any attacks against this issue.</p>
<p>o&nbsp;&nbsp;&nbsp;
<a href="http://www.microsoft.com/technet/security/bulletin/ms11-007.mspx">MS11-007</a>. This bulletin addresses one privately
reported vulnerability affecting all supported versions of Windows and
involving the OpenType Compact Font Driver. It's rated Critical for Windows
Vista, Windows 7, Server 2008 and Server 2008 R2; it's rated Important for
Windows XP and Server 2003. &nbsp;This issue has
an Exploitability Index rating of 2.</p>
<p>In this video, Jerry Bryant discusses this
month's bulletins in further detail:</p>
<p>
<script src="http://technet.microsoft.com/objectforward/default.aspx?type=VideoPlayer&amp;video=http%3A%2F%2Fcontent1.catalog.video.msn.com%2Fe2%2Fds%2F057fc8aa-730e-493f-973f-53072c6fdd5d.wmv&amp;thumb=http%3A%2F%2Fcontent3.catalog.video.msn.com%2Fe2%2Fds%2F02a36acc-b8a8-4595-9cbf-0b083bf91436.png&amp;title=February%202011%20Security%20Bulletin%20Release%20Overview&amp;width=400&amp;height=400"></script>
</p>
<p>As always, we recommend that customers
deploy all security updates as soon as possible. Below is our deployment
priority guidance to further assist customers in their deployment planning
(click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6813.deploy_2D00_feb11.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6813.deploy_2D00_feb11.png" width="500" border="0" /></a></p>
<p>Our risk and impact graph shows an aggregate
view of this month's severity and exploitability index (click for larger view).</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5504.severity_2D00_exploit_2D00_feb11.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5504.severity_2D00_exploit_2D00_feb11.png" width="500" border="0" /></a></p>
<p>More information about this month's
security updates can be found on the Microsoft Security Bulletin <a href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">summary web page</a>.&nbsp; </p>
<p>As mentioned, we are addressing <a href="http://www.microsoft.com/technet/security/advisory/2488013.mspx">Security Advisory 2488013</a> as part of the regularly scheduled
Internet Explorer cumulative update. This Security Advisory and the zero-day
disclosure on which it was predicated caused discussion in the security
community, and some observers thought that we might be forced to release an
out-of-band bulletin to protect customers. However, out-of-band releases are
disruptive to customers and we try to avoid them where possible. Based on our
capabilities to closely monitor the threat landscape, we were able to determine
that attempts to attack this vulnerability were very low. With that
information, we were able to extensively test a bulletin to be released as part
of our regular bulletin cadence. The MMPC (Microsoft Malware Protection Center)
blog <ins cite="mailto:Angela%20Gunn" datetime="2011-02-08T09:09"><a href="http://blogs.technet.com/b/mmpc/archive/2011/02/08/cve-2010-3971-not-quite-the-weekend-warrior.aspx">has
details</a></ins> about the telemetry we used to guide us. There we
contrast this issue with telemetry from an out-of-band release last year to
demonstrate why one was not needed here.</p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5710.CVE_2D00_2010_2D00_3971_2D00_vs_2D00_CVE_2D00_2010_2D00_2568.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5710.CVE_2D00_2010_2D00_3971_2D00_vs_2D00_CVE_2D00_2010_2D00_2568.png" width="500" border="0" /></a></p>
<p>Also this month, we're updating <a href="http://www.microsoft.com/technet/security/advisory/967940.mspx">Security Advisory 967940</a>, "Update for Windows Autorun," to change
how earlier versions of Windows handle security when reading "non-shiny"
storage media. ("Shiny" storage media would include CD-ROMs and DVDs.) Windows
7 already disables Autorun for devices such as USB thumb drives, which prevents
malware lurking on such drives from loading itself onto computers without user
interaction. With the change to the Advisory, earlier versions of Windows that
receive their updates automatically via Windows Update "AutoUpdate" will now
gain that security-conscious functionality as well. We believe this is a huge
step towards combating one of the most prevalent infection vectors used by
malware such as Conficker.</p>
<p>Finally, we're excited to announce that
changes are coming to the system we use for publishing our bulletins and
security advisories - changes that will bring better integration with the
wealth of other content on Technet and a richer experience for customers. We
are expecting the changes to go live in the June 2011 timeframe. The main
impact to customers will be a URL change from microsoft.com/technet/security to
technet.microsoft.com/security. We are planning to have both the old and new
sites available simultaneously for a period of time and will be providing more
details in March. </p>
<p>Please join the monthly technical webcast
with your hosts, Jerry Bryant and Jonathan Ness, to learn more about all the February
2011 security bulletins. The webcast is scheduled for Wednesday, February 9,
2011 at 11:00 a.m. PST (UTC -8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032455047&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US">here</a>. </p>
<p>For all the latest information, you can
follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse"><span style="text-decoration: underline;">@MSFTSecResponse</span></a>.</p>
<p>Thanks,</p>
<p>Angela Gunn<br />
Trustworthy Computing.</p>
<p>&nbsp;</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3385819" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/02/08/february-2011-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft releases Security Advisory 2501696</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx#comments</comments>
		<pubDate>Fri, 28 Jan 2011 18:12:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello. Today we're releasing <a href="http://www.microsoft.com/technet/security/advisory/2501696.mspx">Security
Advisory 2501696</a>, which describes
a publicly disclosed scripting vulnerability affecting all versions of
Microsoft Windows. The main impact of the vulnerability is unintended
information disclosure. We're aware of published
information and proof-of-concept code that attempts to exploit this
vulnerability, but we haven't seen any indications of active
exploitation.</p>
<p>The vulnerability lies in the
MHTML (MIME Encapsulation of Aggregate HTML) protocol handler, which is used by
applications to render certain kinds of documents. The impact of an attack on
the vulnerability would be similar to that of server-side cross-site-scripting
(XSS) vulnerabilities.&#160; For instance, an
attacker could construct an HTML link designed to trigger a malicious script
and somehow convince the targeted user to click it. When the user clicked that
link, the malicious script would run on the user's computer for the rest of the
current Internet Explorer session.&#160; Such
a script might collect user information (eg., email), spoof content displayed
in the browser, or otherwise interfere with the user's experience. </p>
<p>The workaround we are
recommending customers apply locks down the MHTML protocol and effectively
addresses the issue on the client system where it exists. We are providing a
Microsoft Fix-it package to further automate installation.</p>
<p>In our collaboration with other
service providers, we are looking for possible ways that they can take steps to
provide protection on the server side. Our Security Research &#38; Defense team
has written <a href="http://blogs.technet.com/b/srd/">a blog post</a> that discusses some possible options.
However, due to the nature of the issue, the only workaround Microsoft can officially
recommend is what we have identified in the advisory. We will continue to work
closely with others in the industry and appreciate the collaboration we have had
to date. </p>
<p>We have initiated our <a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx">Software
Security Incident Response Process (SSIRP)</a> to manage this issue. We're also in
communication with other service providers to explain how the issue might
affect third-party Web sites and to collaborate on developing a variety of
further solutions that address the varied needs of all parts of the Internet ecosystem
- large sites, small sites, and all those who visit them.</p>
<p>Meanwhile, we are working on a security
update to address this vulnerability and we are monitoring the threat landscape
very closely. If the situation changes, we'll post updates here on the MSRC
blog. </p>
<p>Thanks -</p>
<p>Angela Gunn<br />
Trustworthy Computing</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3383298" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello. Today we're releasing <a href="http://www.microsoft.com/technet/security/advisory/2501696.mspx">Security
Advisory 2501696</a>, which describes
a publicly disclosed scripting vulnerability affecting all versions of
Microsoft Windows. The main impact of the vulnerability is unintended
information disclosure. We're aware of published
information and proof-of-concept code that attempts to exploit this
vulnerability, but we haven't seen any indications of active
exploitation.</p>
<p>The vulnerability lies in the
MHTML (MIME Encapsulation of Aggregate HTML) protocol handler, which is used by
applications to render certain kinds of documents. The impact of an attack on
the vulnerability would be similar to that of server-side cross-site-scripting
(XSS) vulnerabilities.&nbsp; For instance, an
attacker could construct an HTML link designed to trigger a malicious script
and somehow convince the targeted user to click it. When the user clicked that
link, the malicious script would run on the user's computer for the rest of the
current Internet Explorer session.&nbsp; Such
a script might collect user information (eg., email), spoof content displayed
in the browser, or otherwise interfere with the user's experience. </p>
<p>The workaround we are
recommending customers apply locks down the MHTML protocol and effectively
addresses the issue on the client system where it exists. We are providing a
Microsoft Fix-it package to further automate installation.</p>
<p>In our collaboration with other
service providers, we are looking for possible ways that they can take steps to
provide protection on the server side. Our Security Research &amp; Defense team
has written <a href="http://blogs.technet.com/b/srd/">a blog post</a> that discusses some possible options.
However, due to the nature of the issue, the only workaround Microsoft can officially
recommend is what we have identified in the advisory. We will continue to work
closely with others in the industry and appreciate the collaboration we have had
to date. </p>
<p>We have initiated our <a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx">Software
Security Incident Response Process (SSIRP)</a> to manage this issue. We're also in
communication with other service providers to explain how the issue might
affect third-party Web sites and to collaborate on developing a variety of
further solutions that address the varied needs of all parts of the Internet ecosystem
- large sites, small sites, and all those who visit them.</p>
<p>Meanwhile, we are working on a security
update to address this vulnerability and we are monitoring the threat landscape
very closely. If the situation changes, we'll post updates here on the MSRC
blog. </p>
<p>Thanks -</p>
<p>Angela Gunn<br />
Trustworthy Computing</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3383298" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2010 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/12/14/december-2010-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/12/14/december-2010-security-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 14 Dec 2010 18:05:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[monthly bulletin release]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[Security Bulletin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hi everyone. As part of our usual cycle of monthly
security updates, today Microsoft is releasing 17 bulletins addressing 40
vulnerabilities in Microsoft Windows, Office, Internet Explorer, SharePoint
Server and Exchange. Two of those bulletins carry a Critical rating, while 14
are rated Important and one is rated Moderate. </p>
<p>We've assigned our highest deployment priority to the two
Critical bulletins, though we recommend that customers deploy all updates as
soon as possible.</p>
<ul class="unIndentedList">
<li>
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-090.mspx">MS10-090</a> This bulletin resolves seven issues -- five Critical, two Moderate --
affecting all supported versions of Internet Explorer, on both Windows clients
and Windows servers. Among its other updates, it addresses a vulnerability
previously described in <a href="http://www.microsoft.com/technet/security/advisory/2458511.mspx">Security Advisory 2458511</a>.
</li>
<li>
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-091.mspx">MS10-091</a> This bulletin is Critical and addresses three vulnerabilities in Windows'
OpenType Font driver. All three issues were privately reported and we are not
aware of any active attacks using them.</li>
</ul>
<p>As mentioned, the other 15 bulletins this month carry
lower severity ratings - including <a href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a>, the bulletin that closes out the last known vulnerability exploited by
the Stuxnet malware. To assist in your planning and implementation of the
bulletins, please consult this month's Deployment Priority chart (click for
larger view).</p>
<p>
<a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0676.2010_2D00_12-deployment.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0676.2010_2D00_12-deployment.png" width="500" border="0" /></a>
</p>
<p>Jerry Bryant, group manager for response communications,
gives more information about the December bulletins in this overview video:</p>
<p>

</p>
<p>&#160;</p>
<p>More information about this month's security updates can
be found on the Microsoft Security Bulletin summary <a href="http://www.microsoft.com/technet/security/bulletin/ms10-dec.mspx">web page</a>.&#160; Our <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">Exploitability Index</a> provides additional information to help
customers plan for deployment of these monthly security bulletins. </p>
<p>
<a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6445.2010_2D00_12-severity-xi.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6445.2010_2D00_12-severity-xi.png" width="500" border="0" /></a></p>
<p>&#160;</p>
<p>We are also releasing updated Malicious Software Removal
Tool signatures this month. The <a href="http://blogs.technet.com/b/mmpc/">MMPC blog</a> goes into detail on QakBot, the subject of
this month's update.</p>
<p>Finally, we invite everyone to join the monthly technical
webcast to learn more about the December 2010 security bulletin release. The webcast
is scheduled for Wednesday, December 15, 2010 at 11:00 a.m. PST (UTC
-8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032454444&#38;CountryCode=US">here</a>. </p>
<p>Remember, you can follow the MSRC team for late-breaking
news and updates on the threat landscape on Twitter at <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a>.</p>
<p>Thanks,</p>
<p>
Angela Gunn<br />
Senior Marketing Communications Manager
</p>
<p>&#160;</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3375005" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hi everyone. As part of our usual cycle of monthly
security updates, today Microsoft is releasing 17 bulletins addressing 40
vulnerabilities in Microsoft Windows, Office, Internet Explorer, SharePoint
Server and Exchange. Two of those bulletins carry a Critical rating, while 14
are rated Important and one is rated Moderate. </p>
<p>We've assigned our highest deployment priority to the two
Critical bulletins, though we recommend that customers deploy all updates as
soon as possible.</p>
<ul class="unIndentedList">
<li>
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-090.mspx">MS10-090</a> This bulletin resolves seven issues -- five Critical, two Moderate --
affecting all supported versions of Internet Explorer, on both Windows clients
and Windows servers. Among its other updates, it addresses a vulnerability
previously described in <a href="http://www.microsoft.com/technet/security/advisory/2458511.mspx">Security Advisory 2458511</a>.
</li>
<li>
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-091.mspx">MS10-091</a> This bulletin is Critical and addresses three vulnerabilities in Windows'
OpenType Font driver. All three issues were privately reported and we are not
aware of any active attacks using them.</li>
</ul>
<p>As mentioned, the other 15 bulletins this month carry
lower severity ratings - including <a href="http://www.microsoft.com/technet/security/bulletin/ms10-092.mspx">MS10-092</a>, the bulletin that closes out the last known vulnerability exploited by
the Stuxnet malware. To assist in your planning and implementation of the
bulletins, please consult this month's Deployment Priority chart (click for
larger view).</p>
<p>
<a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0676.2010_2D00_12-deployment.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0676.2010_2D00_12-deployment.png" width="500" border="0" /></a>
</p>
<p>Jerry Bryant, group manager for response communications,
gives more information about the December bulletins in this overview video:</p>
<p>
<script src="http://technet.microsoft.com/en-us/objectforward/default.aspx?type=VideoPlayer&amp;video=http%3A%2F%2Fcontent4.catalog.video.msn.com%2Fe2%2Fds%2Ff690e2a7-9176-4a9b-bb07-eee00196f03a.wmv&amp;thumb=http%3A%2F%2Fcontent1.catalog.video.msn.com%2Fe2%2Fds%2F28d7c056-90d1-444f-92ff-5cb3ffd663eb.png&amp;title=&amp;width=400&amp;height=400" type="text/javascript"></script>
</p>
<p>&nbsp;</p>
<p>More information about this month's security updates can
be found on the Microsoft Security Bulletin summary <a href="http://www.microsoft.com/technet/security/bulletin/ms10-dec.mspx">web page</a>.&nbsp; Our <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">Exploitability Index</a> provides additional information to help
customers plan for deployment of these monthly security bulletins. </p>
<p>
<a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6445.2010_2D00_12-severity-xi.png"><img src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6445.2010_2D00_12-severity-xi.png" width="500" border="0" /></a></p>
<p>&nbsp;</p>
<p>We are also releasing updated Malicious Software Removal
Tool signatures this month. The <a href="http://blogs.technet.com/b/mmpc/">MMPC blog</a> goes into detail on QakBot, the subject of
this month's update.</p>
<p>Finally, we invite everyone to join the monthly technical
webcast to learn more about the December 2010 security bulletin release. The webcast
is scheduled for Wednesday, December 15, 2010 at 11:00 a.m. PST (UTC
-8). Registration is available <a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032454444&amp;CountryCode=US">here</a>. </p>
<p>Remember, you can follow the MSRC team for late-breaking
news and updates on the threat landscape on Twitter at <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a>.</p>
<p>Thanks,</p>
<p>
Angela Gunn<br />
Senior Marketing Communications Manager
</p>
<p>&nbsp;</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3375005" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/12/14/december-2010-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2010 Security Bulletin Release</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/09/13/september-2010-security-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/09/13/september-2010-security-bulletin-release.aspx#comments</comments>
		<pubDate>Mon, 13 Sep 2010 22:05:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[Exploitability Index]]></category>
		<category><![CDATA[Malicious Software Removal Tool (MSRT)]]></category>
		<category><![CDATA[Microsoft Active Protections Program (MAPP)]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[monthly bulletin release]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Hi everyone,</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="color: #000000">With this month's bulletin release, I want to highlight the great work done through our partnerships in the<span style="color: #0f76ef"> </span></span><a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx"><span style="color: #000080">Microsoft Active Protections Program (MAPP). MAPP</span></a><span style="color: #000000"> represents our commitment to community based defense and a shared sense of responsibility to help protect the computing ecosystem. In July of this year, the Stuxnet malware emerged onto the threat landscape and resulted in the release of an out-of-band security update, </span></span></span></span></span><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="color: #000000">MS10-046</span></span></span></span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="color: #000000">, to address a zero-day vulnerability the malware used to compromise </span><span style="background-color: #ffffff"><span style="color: #000000">systems. <span>Additionally, we updated the<a href="http://www.microsoft.com/security/malwareremove/default.aspx"> Microsoft Malicious Software Removal Tool (MSRT</a></span><span><a href="http://www.microsoft.com/security/malwareremove/default.aspx">)</a> in August </span><span>to remove Stuxnet and we are able to report that according to our telemetry, the threat has gone way down from the spike we saw in early August.</span></span><span style="color: black">&#160;</span><span style="color: #1f497d"></span></span></span></span></span></span></span></span> </p>
<p><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif">Since that time, Microsoft and partners in our MAPP program have continued to investigate this extremely complex malware. Today, we are releasing </span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-061.mspx"><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif">MS10-061</span></span></a><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif"> to address another vulnerability first discovered and reported to us by Kaspersky Lab and then later by Symantec. This vulnerability in the Print Spooler Service is rated Critical for Windows XP and Important on all other affected platforms and is used by Stuxnet to spread to systems inside the network where the Print Spooler service is exposed without authentication. </span></span></p>
<p>
</p><p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">In addition, Microsoft researchers uncovered two additional Elevation of Privilege (EoP) vulnerabilities (one of which was also reported to us by Kaspersky, and later independently confirmed by Symantec) used by the malware to gain full control of the infected system. One of these EoP vulnerabilities affects Windows XP and the other affects Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2. These are local EoP issues which means that an attacker, in this case Stuxnet, already has permission to run code on the system or has compromised the system through some other means. We are currently working to address both issues in a future bulletin. </span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">We want to thank both Kaspersky Lab and Symantec for their collaboration in uncovering these vulnerabilities and for coordinating with us to protect customers. This is what community based defense is all about.</span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">As we look at our other high priority bulletins for this month, I would like to emphasize the fact that there are no critical bulletins for Windows 7 or Windows Server 2008 R2. This is due to security enhancements such as additional heap mitigations built into the newer operating systems. Additionally, this month's Office bulletin does not affect Office 2010. I will also state that we are still investigating and working on updates for public issues that do affect these platforms. We want customers to know that we continue to work hard to address these issues and that our efforts to produce comprehensive updates and release them in a predictable manner is something that comes "in the box" when you buy our software. </span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">As you can see from our aggregate severity and exploitability index chart below, there are two bulletins that are both Critical and have an exploitability index rating of 1. The first is </span></span></span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-061.mspx"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">MS10-061</span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"> that I discussed above and the second, </span></span></span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-062.mspx"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">MS10-062</span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">, involves a vulnerability in the MPEG-4 codec affecting supported versions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This issue can be exploited if a user opens a specially crafted media file or receives streaming content from the web. </span></span></span></span></p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5482.Sept-2010-Risk-and-Impact.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5482.Sept-2010-Risk-and-Impact.png" border="0" /></a></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">The remaining bulletins are given a 2 or a 3 in our deployment priority list. This guidance is intended to help customers prioritize bulletin deployment and is based on several factors including severity, exploitability, breadth of platforms, and available mitigations and workarounds. Since every environment is different, we do recommend that customers evaluate accordingly and apply the updates as soon as possible.</span></span></p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/3580.Sept-2010-Overview-Final.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8156.September-2010-Deployment-Priority-Slide.png" border="0" /></a></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">In the video below, Adrian Stone and I give an overview of this month&#8217;s bulletin release and discuss why we have prioritized the bulletins the way we did.&#160;</span></span></p>
<p>

</p>

<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">
<p class="MsoNormal">Please join Adrian and me tomorrow, September 15, at 11:00 a.m. PDT (UTC -7) for a public webcast where we will go into more details about these bulletins. We will also have a room full of subject matter experts standing by to help answer all of your questions during the session. You can register here:<a name="OLE_LINK2"></a></p>
</span></span></p>
<p class="MsoNormal"><a href="https://msevents.microsoft.com/CUI/Register.aspx?culture=en-US&#38;EventID=1032454433"><span style="font-size: x-small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">https://msevents.microsoft.com/CUI/Register.aspx?culture=en-US&#38;EventID=1032454433</span></span></span></a></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">We will also release two security advisories this month:</span></span></p>
<p>
<ul>
<li>
<div><a href="http://www.microsoft.com/technet/security/advisory/2401593.mspx"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Security Advisory 2401593</span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">, which describes a vulnerability affecting Outlook Web Access (OWA) that may affect Microsoft Exchange customers to gain elevation of privilege. An attacker who successfully exploited this vulnerability could hijack an authenticated OWA session. </span></span></div>
</li>
</ul>
<ul>
<li><a href="http://microsoft.com/technet/security/advisory/973811.mspx"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Security Advisory 973811</span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">, is an updated Advisory enabling Outlook Express and Windows Mail to opt in to Extended Protection for Authentication. </span></span></li>
</ul>
</p><p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Finally, this month, we also released an update for the User Profile Hive Cleanup Service. This is an optional tool for Windows 2000, Windows XP and Windows Server 2003 that simplifies user management. The tool is not formally supported by Microsoft, but as it's a common tool to many system administrators, we released a new version to address a security vulnerability reported by a security researcher. More information can be found on the </span></span><a href="http://blogs.technet.com/b/uphclean/"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">UPHClean blog</span></span></a><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">.</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Thanks!</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small">Jerry Bryant<br />Group Manager, Response Communications</span></span></p>
<div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3355234" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Hi everyone,</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="color: #000000;">With this month's bulletin release, I want to highlight the great work done through our partnerships in the<span style="color: #0f76ef;"> </span></span><a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx"><span style="color: #000080;">Microsoft Active Protections Program (MAPP). MAPP</span></a><span style="color: #000000;"> represents our commitment to community based defense and a shared sense of responsibility to help protect the computing ecosystem. In July of this year, the Stuxnet malware emerged onto the threat landscape and resulted in the release of an out-of-band security update, </span></span></span></span></span><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="color: #000000;">MS10-046</span></span></span></span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="color: #000000;">, to address a zero-day vulnerability the malware used to compromise </span><span style="background-color: #ffffff;"><span style="color: #000000;">systems. <span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;">Additionally, we updated the<a href="http://www.microsoft.com/security/malwareremove/default.aspx"> Microsoft Malicious Software Removal Tool (MSRT</a></span><span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"><a href="http://www.microsoft.com/security/malwareremove/default.aspx">)</a> in August </span><span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;">to remove Stuxnet and we are able to report that according to our telemetry, the threat has gone way down from the spike we saw in early August.</span></span><span style="color: black;">&nbsp;</span><span style="color: #1f497d;"><o :p></o></span></span></span></span></span></span></span></span> </p>
<p><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;">Since that time, Microsoft and partners in our MAPP program have continued to investigate this extremely complex malware. Today, we are releasing </span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-061.mspx"><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;">MS10-061</span></span></a><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;"> to address another vulnerability first discovered and reported to us by Kaspersky Lab and then later by Symantec. This vulnerability in the Print Spooler Service is rated Critical for Windows XP and Important on all other affected platforms and is used by Stuxnet to spread to systems inside the network where the Print Spooler service is exposed without authentication. </span></span></p>
<p>
</p><p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">In addition, Microsoft researchers uncovered two additional Elevation of Privilege (EoP) vulnerabilities (one of which was also reported to us by Kaspersky, and later independently confirmed by Symantec) used by the malware to gain full control of the infected system. One of these EoP vulnerabilities affects Windows XP and the other affects Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2. These are local EoP issues which means that an attacker, in this case Stuxnet, already has permission to run code on the system or has compromised the system through some other means. We are currently working to address both issues in a future bulletin. </span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">We want to thank both Kaspersky Lab and Symantec for their collaboration in uncovering these vulnerabilities and for coordinating with us to protect customers. This is what community based defense is all about.</span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">As we look at our other high priority bulletins for this month, I would like to emphasize the fact that there are no critical bulletins for Windows 7 or Windows Server 2008 R2. This is due to security enhancements such as additional heap mitigations built into the newer operating systems. Additionally, this month's Office bulletin does not affect Office 2010. I will also state that we are still investigating and working on updates for public issues that do affect these platforms. We want customers to know that we continue to work hard to address these issues and that our efforts to produce comprehensive updates and release them in a predictable manner is something that comes "in the box" when you buy our software. </span></span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">As you can see from our aggregate severity and exploitability index chart below, there are two bulletins that are both Critical and have an exploitability index rating of 1. The first is </span></span></span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-061.mspx"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">MS10-061</span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"> that I discussed above and the second, </span></span></span></span><a href="http://microsoft.com/technet/security/bulletin/ms10-062.mspx"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">MS10-062</span></span></span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">, involves a vulnerability in the MPEG-4 codec affecting supported versions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. This issue can be exploited if a user opens a specially crafted media file or receives streaming content from the web. </span></span></span></span></p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5482.Sept-2010-Risk-and-Impact.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5482.Sept-2010-Risk-and-Impact.png" border="0" /></a></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">The remaining bulletins are given a 2 or a 3 in our deployment priority list. This guidance is intended to help customers prioritize bulletin deployment and is based on several factors including severity, exploitability, breadth of platforms, and available mitigations and workarounds. Since every environment is different, we do recommend that customers evaluate accordingly and apply the updates as soon as possible.</span></span></p>
<p><a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/3580.Sept-2010-Overview-Final.png"><img width="500" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8156.September-2010-Deployment-Priority-Slide.png" border="0" /></a></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">In the video below, Adrian Stone and I give an overview of this month&rsquo;s bulletin release and discuss why we have prioritized the bulletins the way we did.&nbsp;</span></span></p>
<p>
<script type="text/javascript" src="http://technet.microsoft.com/objectforward/default.aspx?type=VideoPlayer&amp;video=http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2FE%2FF%2F6%2FEF67E595-C126-4B37-960A-62FC8A3A48BD%2FHDI-TechEdge-Winvideo-sb_09152010_overview1.wmv&amp;thumb=http%3A%2F%2Fcontent5.catalog.video.msn.com%2Fe2%2Fds%2Ff0adc01b-603b-4612-bf39-4c720813be76.jpg&amp;title=Microsoft%20September%202010%20Security%20Bulletin%20Overview&amp;width=400&amp;height=400"></script>
</p>

<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">
<p class="MsoNormal">Please join Adrian and me tomorrow, September 15, at 11:00 a.m. PDT (UTC -7) for a public webcast where we will go into more details about these bulletins. We will also have a room full of subject matter experts standing by to help answer all of your questions during the session. You can register here:<a name="OLE_LINK2"></a></p>
</span></span></p>
<p class="MsoNormal"><a href="https://msevents.microsoft.com/CUI/Register.aspx?culture=en-US&amp;EventID=1032454433"><span style="font-size: x-small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">https://msevents.microsoft.com/CUI/Register.aspx?culture=en-US&amp;EventID=1032454433</span></span></span></a><o :p></o></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">We will also release two security advisories this month:</span></span></p>
<p>
<ul>
<li>
<div><a href="http://www.microsoft.com/technet/security/advisory/2401593.mspx"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Security Advisory 2401593</span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">, which describes a vulnerability affecting Outlook Web Access (OWA) that may affect Microsoft Exchange customers to gain elevation of privilege. An attacker who successfully exploited this vulnerability could hijack an authenticated OWA session. </span></span></div>
</li>
</ul>
<ul>
<li><a href="http://microsoft.com/technet/security/advisory/973811.mspx"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Security Advisory 973811</span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">, is an updated Advisory enabling Outlook Express and Windows Mail to opt in to Extended Protection for Authentication. </span></span></li>
</ul>
</p><p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Finally, this month, we also released an update for the User Profile Hive Cleanup Service. This is an optional tool for Windows 2000, Windows XP and Windows Server 2003 that simplifies user management. The tool is not formally supported by Microsoft, but as it's a common tool to many system administrators, we released a new version to address a security vulnerability reported by a security researcher. More information can be found on the </span></span><a href="http://blogs.technet.com/b/uphclean/"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">UPHClean blog</span></span></a><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">.</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Thanks!</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;">Jerry Bryant<br />Group Manager, Response Communications</span></span></p>
<div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3355234" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/09/13/september-2010-security-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update on the publicly disclosed Win32k.sys EoP Vulnerability</title>
		<link>http://blogs.technet.com/b/msrc/archive/2010/08/10/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2010/08/10/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability.aspx#comments</comments>
		<pubDate>Tue, 10 Aug 2010 22:35:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft Windows]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><span style="font-size: small"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: small"><span style="font-family: times new roman,times">
<p>Hi everyone,</p>
<p>Yesterday we <a href="http://twitter.com/msftsecresponse">tweeted</a> to let customers know that we were investigating a publicly disclosed vulnerability in the Windows Kernel-mode drivers (win32k.sys) affecting all supported operating systems. We are not aware of attacks that try to use the reported vulnerability or of any customer impact at this time. Today we have more information, as well as a planned course of action.</p>
<p>While most in the industry reported this as a low-severity vulnerability, it generated quite a bit of attention, and as always, we started our investigation as soon as we became aware of the issue. We have not yet reported on this issue because it's important we're thorough in our investigations, and there were a couple of possible vectors that we wanted to validate (or invalidate as the case may be) before we commented or defined a course of action.</p>
<p>As a result, we are now able to report that this is a local elevation of privilege vulnerability only. This type of issue allows attackers to gain system-level privileges <i>after</i> they have already obtained an account on the target system. &#160;For this issue to be exploited, an attacker must have valid log-on credentials on the target system and be able to log on locally, or must already have code running on the target system. The vulnerability cannot be exploited remotely, or by anonymous users.&#160; </p>
<p>We will not be releasing a security advisory for this issue, but it will be included in a future security update. We will continue monitoring the threat landscape and alert customers if anything changes.</p>
<p>Thanks to Dustin Childs and the rest of our security engineering team for their quick and thorough work to determine the cause and extent of this issue across platforms!</p>
<p>Thanks,</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
</span></span></span></span></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3349441" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: small;"><span style="font-family: times new roman,times;">
<p>Hi everyone,</p>
<p>Yesterday we <a href="http://twitter.com/msftsecresponse">tweeted</a> to let customers know that we were investigating a publicly disclosed vulnerability in the Windows Kernel-mode drivers (win32k.sys) affecting all supported operating systems. We are not aware of attacks that try to use the reported vulnerability or of any customer impact at this time. Today we have more information, as well as a planned course of action.</p>
<p>While most in the industry reported this as a low-severity vulnerability, it generated quite a bit of attention, and as always, we started our investigation as soon as we became aware of the issue. We have not yet reported on this issue because it's important we're thorough in our investigations, and there were a couple of possible vectors that we wanted to validate (or invalidate as the case may be) before we commented or defined a course of action.</p>
<p>As a result, we are now able to report that this is a local elevation of privilege vulnerability only. This type of issue allows attackers to gain system-level privileges <i>after</i> they have already obtained an account on the target system. &nbsp;For this issue to be exploited, an attacker must have valid log-on credentials on the target system and be able to log on locally, or must already have code running on the target system. The vulnerability cannot be exploited remotely, or by anonymous users.&nbsp; </p>
<p>We will not be releasing a security advisory for this issue, but it will be included in a future security update. We will continue monitoring the threat landscape and alert customers if anything changes.</p>
<p>Thanks to Dustin Childs and the rest of our security engineering team for their quick and thorough work to determine the cause and extent of this issue across platforms!</p>
<p>Thanks,</p>
<p>Jerry Bryant<br />Group Manager, Response Communications</p>
</span></span></span></span></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3349441" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2010/08/10/update-on-the-publicly-disclosed-win32k-sys-eop-vulnerability.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

