<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Microsoft</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/microsoft/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 06:08:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>January 2012 Security Bulletin Webcast Q&amp;A</title>
		<link>http://blogs.technet.com/b/msrc/archive/2012/01/12/january-2012-security-bulletin-webcast-q-amp-a.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2012/01/12/january-2012-security-bulletin-webcast-q-amp-a.aspx#comments</comments>
		<pubDate>Fri, 13 Jan 2012 00:49:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Bulletin Webcast]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/p/january-2012-security-bulletin-q-a.aspx"> January Security Bulletin Webcast Questions &#38; Answers page</a>. We fielded nine questions on various topics during the <a href="http://technet.microsoft.com/en-us/edge/january-2012-security-bulletin-webcasts">webcast</a>, including bulletins released, deployment tools, and update detection tools. There were two questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&#38;A page.</p>
<p>We invite our customers to join us for the next public webcast on Wednesday, February 15 at 11am PST (UTC -8), when we will go into detail about the February bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, February 15, 2012<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499501&#38;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Angela Gunn<br /> Trustworthy Computing</p>
<div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3475246" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/p/january-2012-security-bulletin-q-a.aspx"> January Security Bulletin Webcast Questions &amp; Answers page</a>. We fielded nine questions on various topics during the <a href="http://technet.microsoft.com/en-us/edge/january-2012-security-bulletin-webcasts">webcast</a>, including bulletins released, deployment tools, and update detection tools. There were two questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&amp;A page.</p>
<p>We invite our customers to join us for the next public webcast on Wednesday, February 15 at 11am PST (UTC -8), when we will go into detail about the February bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, February 15, 2012<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499501&amp;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Angela Gunn<br /> Trustworthy Computing</p>
<script type="text/javascript" src="http://technet.microsoft.com/en-us/videoembed/january-2012-security-bulletin-webcasts"></script><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3475246" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2012/01/12/january-2012-security-bulletin-webcast-q-amp-a.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2012 Security Bulletins Released</title>
		<link>http://blogs.technet.com/b/msrc/archive/2012/01/10/january-2012-security-bulletins-released.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2012/01/10/january-2012-security-bulletins-released.aspx#comments</comments>
		<pubDate>Tue, 10 Jan 2012 18:46:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello. As I previously mentioned in the <a href="http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx">Advance Notification Service blog post</a> on Thursday, today we are releasing seven security bulletins, one of which is rated Critical in severity, with the remaining six classified as Important.</p>
<p>These bulletins will address eight vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on the sole critical update:</p>
<ul>
<li><b>MS12-004 (Windows Media Player)</b>: Vulnerabilities in Windows Media Player Could Cause Remote Code Execution. This bulletin &#8211; the only one in January&#8217;s set to include multiple CVEs &#8211; addresses two issues that could arise if a would-be attacker sent a malicious MIDI or DirectShow file to a targeted user. Both of these issues were cooperatively disclosed to Microsoft, and we know of no active exploitation in the wild. Still, we recommend that customers read through the bulletin information concerning MS12-004 and apply it as soon as possible.</li>
</ul>
<p>In the video at the bottom of this post, Pete Voss discusses this month's bulletins in further detail.</p>
<p>As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><span class="style1"><span class="style1"><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG"> <img alt="Deployment Priority" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG" width="500" height="281" /></a></span></span></p>
<p>Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><span class="style1"><span class="style1"><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG"> <img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG" width="500" height="281" /></a></span></span></p>
<p>You can find more information about this month's security updates on the Microsoft Security Bulletin Summary web page.</p>
<p>As you may remember, last month we announced a bulletin addressing the SSL issue we described in Security Advisory 2588513. Days before release, we noted a compatibility problem that might have affected certain users of third-party products, and decided to hold that bulletin until we could complete further investigation. We&#8217;re-releasing that bulletin today as MS12-006; we&#8217;re also providing further information and guidance to customers with a Knowledge Base article and a Fix-it that will be useful in certain installation circumstances.</p>
<p>As usual, our colleagues in SRD have prepared blog posts that delve more deeply into technical details of this month&#8217;s releases. In addition to a discussion of this month&#8217;s deployment priorities, SRD has a post examining some of the finer points of MS12-001, which addresses an Important-class issue affecting the SafeSEH security mitigation, and an overview of the aforementioned MS12-004.</p>
<p>Per our usual process, we&#8217;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Dustin Childs. I invite you to tune in and learn more about the January security bulletins, as well as other announcements made today. The webcast is scheduled for tomorrow, January 11, 2012, at 11 A.M. PST. <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&#38;Culture=en-US">Click here to register.</a></p>
<p>Thanks,<br /> Angela Gunn<br /> Trustworthy Computing.</p>
<div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3474774" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello. As I previously mentioned in the <a href="http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx">Advance Notification Service blog post</a> on Thursday, today we are releasing seven security bulletins, one of which is rated Critical in severity, with the remaining six classified as Important.</p>
<p>These bulletins will address eight vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on the sole critical update:</p>
<ul>
<li><b>MS12-004 (Windows Media Player)</b>: Vulnerabilities in Windows Media Player Could Cause Remote Code Execution. This bulletin &ndash; the only one in January&rsquo;s set to include multiple CVEs &ndash; addresses two issues that could arise if a would-be attacker sent a malicious MIDI or DirectShow file to a targeted user. Both of these issues were cooperatively disclosed to Microsoft, and we know of no active exploitation in the wild. Still, we recommend that customers read through the bulletin information concerning MS12-004 and apply it as soon as possible.</li>
</ul>
<p>In the video at the bottom of this post, Pete Voss discusses this month's bulletins in further detail.</p>
<p>As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).</p>
<p><span class="style1"><span class="style1"><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG"> <img alt="Deployment Priority" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG" width="500" height="281" /></a></span></span></p>
<p>Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).</p>
<p><span class="style1"><span class="style1"><a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG"> <img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG" width="500" height="281" /></a></span></span></p>
<p>You can find more information about this month's security updates on the Microsoft Security Bulletin Summary web page.</p>
<p>As you may remember, last month we announced a bulletin addressing the SSL issue we described in Security Advisory 2588513. Days before release, we noted a compatibility problem that might have affected certain users of third-party products, and decided to hold that bulletin until we could complete further investigation. We&rsquo;re-releasing that bulletin today as MS12-006; we&rsquo;re also providing further information and guidance to customers with a Knowledge Base article and a Fix-it that will be useful in certain installation circumstances.</p>
<p>As usual, our colleagues in SRD have prepared blog posts that delve more deeply into technical details of this month&rsquo;s releases. In addition to a discussion of this month&rsquo;s deployment priorities, SRD has a post examining some of the finer points of MS12-001, which addresses an Important-class issue affecting the SafeSEH security mitigation, and an overview of the aforementioned MS12-004.</p>
<p>Per our usual process, we&rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Dustin Childs. I invite you to tune in and learn more about the January security bulletins, as well as other announcements made today. The webcast is scheduled for tomorrow, January 11, 2012, at 11 A.M. PST. <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;Culture=en-US">Click here to register.</a></p>
<p>Thanks,<br /> Angela Gunn<br /> Trustworthy Computing.</p>
<script type="text/javascript" src="http://technet.microsoft.com/en-us/videoembed/january-2012-update-tuesday-overview"></script><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3474774" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2012/01/10/january-2012-security-bulletins-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2012 ANS is released</title>
		<link>http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx#comments</comments>
		<pubDate>Thu, 05 Jan 2012 17:50:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ANS]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello. Today we&#8217;re releasing our <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan">advance notification</a> for the January security bulletin release, which is scheduled for Tuesday, January 10. This month&#8217;s release includes seven bulletins addressing eight vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software. As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.</p>
<p>We&#8217;ll release all seven bulletins on Tuesday, January 10 at approximately 10 a.m. PST. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.</p>
<p>In addition, eagle-eyed readers of the summary page will notice an unusual vulnerability classification, &#8220;Security Feature Bypass,&#8221; for one of our Important-severity bulletins. SFB-class issues in themselves can&#8217;t be leveraged by an attacker; rather, a would-be attacker would use them to facilitate use of another exploit. For those interested in learning more, we expect the SRD blog to publish a detailed analysis of the matter on Tuesday.</p>
<p>Please join Dustin Childs and Pete Voss for a webcast on Wednesday. They&#8217;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.</p>
<p><b>Date:</b> Wednesday, January 11<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&#38;Culture=en-US">Click Here To Register</a></b></p>
<p>Thanks,<br /> Angela Gunn <br /> Trustworthy Computing</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3474114" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello. Today we&rsquo;re releasing our <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan">advance notification</a> for the January security bulletin release, which is scheduled for Tuesday, January 10. This month&rsquo;s release includes seven bulletins addressing eight vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software. As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.</p>
<p>We&rsquo;ll release all seven bulletins on Tuesday, January 10 at approximately 10 a.m. PST. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.</p>
<p>In addition, eagle-eyed readers of the summary page will notice an unusual vulnerability classification, &ldquo;Security Feature Bypass,&rdquo; for one of our Important-severity bulletins. SFB-class issues in themselves can&rsquo;t be leveraged by an attacker; rather, a would-be attacker would use them to facilitate use of another exploit. For those interested in learning more, we expect the SRD blog to publish a detailed analysis of the matter on Tuesday.</p>
<p>Please join Dustin Childs and Pete Voss for a webcast on Wednesday. They&rsquo;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.</p>
<p><b>Date:</b> Wednesday, January 11<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b><a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;Culture=en-US">Click Here To Register</a></b></p>
<p>Thanks,<br /> Angela Gunn <br /> Trustworthy Computing</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3474114" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Out-Of-Band Bulletin Release: Q&amp;A and Webcast</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-bulletin-release-q-amp-a-and-webcast.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-bulletin-release-q-amp-a-and-webcast.aspx#comments</comments>
		<pubDate>Fri, 30 Dec 2011 23:00:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx"> December 2011 Out-of-Band Security Bulletin Webcast Questions &#38; Answers page</a>. We fielded 41 questions on the subject of <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100 </a>. There were four questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&#38;A page.</p>
<p>We invite our customers to join us for the next public webcast scheduled for Wednesday, January 11, 2012 at 11 a.m. PST (UTC -8), when we will go into detail about the January 2012 bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, January 11, 2012<br /> <b>Time:</b> 11:00 a.m. PDT (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&#38;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Pete Voss<br /> Sr. Response Communications Manager<br /> Microsoft Trustworthy Computing</p>
<div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473499" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx"> December 2011 Out-of-Band Security Bulletin Webcast Questions &amp; Answers page</a>. We fielded 41 questions on the subject of <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100 </a>. There were four questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&amp;A page.</p>
<p>We invite our customers to join us for the next public webcast scheduled for Wednesday, January 11, 2012 at 11 a.m. PST (UTC -8), when we will go into detail about the January 2012 bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, January 11, 2012<br /> <b>Time:</b> 11:00 a.m. PDT (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Pete Voss<br /> Sr. Response Communications Manager<br /> Microsoft Trustworthy Computing</p>
<script type="text/javascript" src="http://technet.microsoft.com/en-us/videoembed/out-of-band-security-bulletin-webcast"></script><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473499" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-bulletin-release-q-amp-a-and-webcast.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Out-Of-Band Security Bulletin Webcast Q&amp;A</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx#comments</comments>
		<pubDate>Fri, 30 Dec 2011 22:50:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[Bulletin Webcast]]></category>
		<category><![CDATA[Q&A]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><b>Hosts:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Jonathan Ness, Security Development Manager, MSRC</b></p>
<p><strong>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Pete Voss, Sr. Response Communications Manager, Trustworthy Computing</strong></p>
<p><b>Website:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; </b>TechNet/Security<b></b></p>
<p><b>Chat Topic: &#160;&#160;&#160; </b>December 2011 Out-Of-Band Security Bulletin Release<b></b></p>
<p><b>Date:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; </b>Thursday, December 29, 2011<b></b></p>
<p><strong>Q: How are Denial of Service, Tampering, Information Disclosure orSpoofing issues rated?</strong><br /><strong>A: </strong>The <a href="http://technet.microsoft.com/en-us/security/cc998259">Exploitability Index</a> only attempts to rate vulnerabilities that can be leveraged for code execution. Vulnerabilities that could allow denial of service, tampering, information disclosure or spoofing will receive an Exploitability Index rating of "3." The notes for that particular CVE will also reflect the nature of the vulnerability.</p>
<p><b>Q:&#160;One angle I'm interested in is those Microsoft products that might use </b><a href="http://support.microsoft.com/kb/2659968"><b>forms authentication</b></a><b>, such as Exchange 2010 or TMG 2010. If we're using forms authentication there, does that mean we're vulnerable?<br />A:</b> Any products that are using ASP.NET forms authentication will be secured with <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">this update</a>. This includes SharePoint and Exchange, when they are using ASP.NET <a href="http://support.microsoft.com/kb/2659968">forms authentication</a>. If these products are using a Forms Authentication module other than the one provided by ASP.NET, then the issue addressed in this bulletin does not apply to you.&#160;<b></b></p>
<p><b>Q:&#160;Why does Windows Update on Windows 2008 servers show this update, but the check-box next to it is un-checked? What is the difference between patches that are checked by default and those that are not checked?<br />A:</b> In the case of "Important Updates", an update that is in the "PENDING" state will be unchecked when you view it in Windows Update. This means it is already queued for downloading. You can manually override this to start the download manually by checking the box next to the update.&#160;<b></b></p>
<p><b>Q:&#160;Please confirm that if an IIS instance is installed that we are at risk for one of the CVE's and therefore we should patch ASAP. The assumption is that the server has IIS without .NET components.<br />A:</b> By default, IIS is not installed with .NET and by default,&#160;.NET is not installed by ASP.NET.&#160;Customers would first need to have installed .NET framework with ASP.NET in order to be vulnerable to the vulnerabilities documented by <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>.<b></b></p>
<p><b>Q:&#160;What level of testing or specific tests is recommended for applications using ASP.NET? Is it highly likely that the hashing change will impact applications using the framework?<br />A:</b> Microsoft recommends that customers test this update before deploying. There is a change in how forms authentication occurs and will require updates to be deployed at the same time across server environments. <a href="http://support.microsoft.com/kb/2659968">Click here for more about forms authentication</a>. &#160;<b></b></p>
<p><b>Q:&#160;Can sample DoS requests be provided to allow us to understand what the DOS signature may look like so we can test the patch as well as monitor our production environments until the patching is completed?<br /></b><b>A:</b> For more technical information regarding <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>,&#160;please see the <a href="http://blogs.technet.com/b/srd/">SRD blog</a>, where we have shared a short signature detecting this issue.</p>
<p><b>Q:&#160;Is this critical to environments where there are no Internet-facing systems? And what if there is no IIS installed on the workstation -- is it atrisk?</b><b><br />A:</b> Exploitation requires ASP.NET installed and to be exposed to input from unauthenticated users. Typically this is through IIS.&#160;If workstations do not have ASP.NET or IIS installed, then those systems are not exposed.&#160;<b></b></p>
<p><b>Q:&#160;In the Critical Elevation of Privilege can the attacker elevate is privilege only if they have the username <i>without</i> having the password? Can we have machines with the fix and without the fix working with each other?<br />A:</b> Yes, the attacker only needs the username to carry out the attack. The fix involves changing the format of the forms authentication ticket, so that unpatched and patched machines cannot work with each other. So after patching you cannot have machines with the fix and without it working together, unless you set a configuration setting on the patched machines. For details, please <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">read the FAQ for this CVE</a> for more information on applying updates to web farms.<b></b></p>
<p><b>Q:&#160;For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE-2011-3414</b></a><b>, is there a requirement of authentication to exploit the DoS vulnerability successfully?<br />A:</b> No, <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414">CVE-2011-3414</a> is anunauthenticated Denial of Service.<b></b></p>
<p><b>Q:&#160;What could be a potential impact on server running IIS with custom code? In short, can this update impact server or service to go down after installation? Do you have any suggestions on installation on web servers running custom code?<br />A:</b> This update is specifically for ASP.NET, but the issue that was disclosed is an industry-wide issue concerning hash collisions. So, it is possible for your custom code to be affected, but you will need to investigate what kind of hash-tables your custom code uses and if it operates on untrusted user data.<b></b></p>
<p><b>Q:&#160;Is there a client-side patch that will protect users that fall for phishing attacks and visit websites that have not patched?<br /></b><b>A:</b> As clients are not affected by server-sided vulnerability, the security update does need to be installed on the server.&#160;<b></b></p>
<p><b>Q:&#160;If the main target is Internet facing systems with IIS &#38; ASP.NET installed, should I concentrate on patching my webservers first before patching client systems?</b><b><br />A:</b> Prioritization for this update would be specific to users&#8217; environments, but servers that are internet-facing and accept input from unauthenticated or untrusted user-provided content are most affected and should be prioritized. Likewise, clients are typically not in a web server role, and so systems that are running a web server role should be prioritized.&#160;<b></b></p>
<p><b>Q:&#160;What steps can I take to reproduce and see if/how my site is affected, and so I can confirm the issue is gone after applying the patch?<br /></b><b>A: </b>For the protection of customers,&#160;Microsoft does not disclose proof of concept code (POC).&#160;The technical details of this issue are however public.</p>
<p><b>Q: If Microsoft .NET Framework is installed on an IIS Server, does this mean that ASP.NET is also installed but possibly not enabled?<br />A:</b> Whether you have the .NET Framework (and ASP.NET) installed on a machine will depend upon the specific OS platform. Windows Server 2008, Windows Server 2008 SP2, Windows Server 2008 R2 and Windows Server 2008 R2 SP1 all ship with the .NET Framework 2.0 or higher, which includes ASP.NET, and you should install the corresponding patches listed in the security bulletin. If you are using an older Server OS such as Windows Server 2003 SP2 x86, then that platform includes .NET Framework 1.1 SP1, and you should install the corresponding patch listed in the security bulletin.&#160;<b></b></p>
<p><b>Q:&#160;From a desktop browsing experience, this update will patch Windows XP, Vista and 7. If machines do not have IIS installed and enabled, as well as ASP.NET enabled, is the criticality of this update reduced? For example if the user goes to an internet site, would their desktop PC be vulnerable? It seems to be mostly if you have IIS and ASP.net installed and acting as a web server.<br />A: </b>If you have a client machine with no ASP.NET installed, then your desktop PC would not be vulnerable to the particular security issues that are being addressed in this update.<b></b></p>
<p><b>Q:&#160;ASP.Net has been identified for the DoS. How about classic ASP/ISAPI applications? Is it just a .Net hash-table issue? And has the Microsoft Foundation Class / ATL / Visual Basic 6.0 been checked?<br />A:</b> This is an industry-wide issue that could affect a broad spectrum of technologies. Since ASP.NET was at the greatest risk because of the public disclosure, we have focused our efforts so far on making sure we secure ASP.NET. We are actively investigating other technologies where this could be vulnerable and so far we do not think that classic ASP is vulnerable. Information on other affected technologies will be revealed as the issue develops.<b></b></p>
<p><b>Q: So just to be clear, Exchange 2010 Outlook Web Access isn't vulnerable to the privilege of escalation? Just to the DOS?<br />A:</b> OWA 2010 can be configured for forms-based authentication. Based on this, it should be considered vulnerable. If there is any doubt, <a href="http://support.microsoft.com/kb/2638420">Microsoft KB Article 2638420</a> discusses parameters you can check for to verify if an application is using forms auth. Specifically, to determine whether your application uses forms authentication,<br />examine the System.web file. Applications that use forms authentication use the following entry in System.web file: &#60;authentication mode="Forms"&#62;</p>
<p><b>Q: What tools are available to remotely scan systems to see if they&#8217;re vulnerable -- that is, that IIS and ASP are installed and active?<br />A:</b> The Detection and Deployment Tools and Guidance section in the security bulletin provides information on how to identify systems to which this update applies. If you want to identify whether a system has IIS installed with ASP.NET enabled, the answer depends on the operating system that each system is running.</p>
<p><b>Q: Are only webservers vulnerable?&#160;We have limited personnel this weekend for QA and deployment.&#160;Are we pretty much covered if we just deploy to systems in our DMZ this weekend and then rest of the enterprise next week?<br />A:</b> Prioritization for this update would be specific to users&#8217; environments, but servers that are internet-facing and accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers.&#160;<b></b></p>
<p><b>Q:&#160;Sites that disallow "application/x-www-form-urlencoded&#8221; or &#8220;multipart/form-data&#8221; HTTP content types are not vulnerable. Is this set to disallow by default? How do we verify if it is set to disallow?<br /></b><b>A:</b> No, application/x-www-form-urlencoded or multipart/form-data are not disallowed by default.&#160;Customers will need to explicitly disallow these.&#160;Customers can do this by <a href="http://learn.iis.net/page.aspx/143/use-request-filtering/">using IIS request filtering</a>.&#160;</p>
<p><b>Q:&#160;Forms authorization login from TMG/ISA doesn't use ASP.NET. Is it still vulnerable?</b><b><br />A:</b> TMG is not exposed and is not related to the ASP.NET issue described in the bulletin.<b></b></p>
<p><b>Q: Do you suggest immediate patching of all servers (internal/external) or just of externally available servers and allow internal servers to be patched during the next patching cycle?<br />A:</b>&#160;Once again, prioritization for this update would be specific to each user&#8217;s environment, but servers that are internet-facing and accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers.&#160;<b></b></p>
<p><strong>Q:&#160;Is the critical CVE related to </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a><strong> only an issue if the site is configured to support </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a><strong> <i>without</i> cookies? Or, are all </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a>&#160;<strong>implementations impacted?<br />A:</strong> No, this issue applies to all types of ASP.NET forms authentication, cookie and cookie-less.<b></b></p>
<p><b>Q:&#160;For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE 2011-3414</b></a><b>, does the patch change the size of request header accepted, place controls on the amount of CPU that can be used, or change the hashing functions used?<br /></b><b>A:</b>The security update addresses this issue by limiting the number of inputs ASP.NET accepts from clients.</p>
<p><b>Q:&#160;Does this patch limit the number of parameters passed in the post request? If so, what is the new limit? I am trying to determine what application problems may arise after applying the update.</b><b><br />A:</b> The security update addresses this issue by limiting the number of inputs ASP.NET accepts from clients.&#160;If you are interested in changing the number of parameters passed in the post request, please&#160;see the&#160;section of the bulletin titled <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><i>Workarounds for Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414</i>.&#160;</a><b></b></p>
<p><b>Q:&#160;Can the normally scheduled January bulletins be installed independently of the critical one?<br /></b><b>A:</b> Yes, Future security updates can be installed independently of this issue.&#160;Microsoft does recommend all customers always read security updates to ensure they fully understand any known issues that may be documented in the security bulletin.</p>
<p><b>Q:&#160;Is the attack vector based on the server or the client? Do we concentrate on server or desktop side first?</b><b><br />A:</b> The vulnerabilities in the bulletins are primarily focused on systems operating in a Web server role that use ASP.NET. Clients are typically not in a web server role.<b></b></p>
<p><b>Q:&#160;Could you provide more detail around the 3rd mitigation factor -- specifically the account registration procedure?<br />A:</b> I am assuming this question is about the first mitigating factor for <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3416">CVE-2011-3416</a>: forms authentication bypass. Essentially, to pull off an Elevation of Privilege attack, the attacker would need a valid account on the system they are trying to compromise and the user name of the target of the attack.<b></b></p>
<p><b>Q:&#160;Can an ASP.NET site (e.g. SharePoint 2010 site) using authentication (NTLM/Kerberos) come under the DoS attack as described in CVE-2011-3414 by an unauthenticated user?</b><b><br />A:</b> NTLM/Kerberos authentication changes the attack vector of the vulnerability.&#160;An ASP.NET site can come under a DOS attack &#8211; however, the attacker would then need to be authenticated.&#160;<b></b></p>
<p><b>Q:&#160;Will this affect -- or will I need to be aware of -- this update impacting ASP.NET session and machine key settings in IIS for a load balanced environment, where all machine keys are matches to make sure sessions are the same across a server farm?<br />A:</b> This update changes the way in which forms authentication tickets are created, so all servers would need to use the old or the new ticket format in order to maintain compatibility. Please refer to <a href="http://support.microsoft.com/kb/2659968">Knowledge Base Article 2659968</a> for deployment guidance for this update.<b></b></p>
<p><b>Q:&#160;What about servers that have IP address access limitations? Since we are resource-limited, we'd like to skip these servers that are only allowing certain IPs to access IIS. </b><b><br />A:</b> As we&#8217;ve mentioned, prioritization for this update would be specific to users environments, but servers that are Internet-facing and can accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers. Servers that have additional protections may reduce the potential attack risk of these vulnerabilities.&#160;Customers are encouraged to analyze their own environments.</p>
<p><b>Q:&#160;We have ASP.NET prohibited in in our Web Service Extensions -- IIS 6. Are we still vulnerable?<br /></b><b>A:</b> No. If ASP.NET is not enabled, you are not vulnerable.</p>
<p><strong>Q:&#160;The Section </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><i><strong>Workarounds for Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414</strong></i></a>&#160;<strong>in the bulletin is confusing. Is it required to put this script and then install the update?&#160;<br />A:</strong> Workaround refers to a setting or configuration change that does not correct the underlying vulnerability, but would help block known attack vectors before you apply the update. Microsoft has tested the following workarounds and states in the discussion whether a workaround reduces functionality.&#160;Customers are always encouraged to apply the security update.&#160;The workarounds are not a prerequisite for installing the security update.</p>
<p><b>Q:&#160;If TMG is not affected then, if TMG is protecting an Exchange 2010 server and the TMG is handling the forum authorization, would the patch for an Exchange server be necessary?<br /></b><b>A:</b> Although firewall solutions could protect systems behind the firewall it is important to understand the types of traffic that that FW may proxy to servers behind it. Systems behind the firewall are still vulnerable to internal attacks and have vulnerable code and should be updated to be properly protected.</p>
<p><b>Q:&#160;Is AppSettings.MaxHttpCollectionKeys the new parameter that contains the maximum number of form entries?<br />A:</b> Yes it is.<b></b></p>
<p><b>Q:&#160;For ASP.NET on Internet-facing systems requiring authentication, does an attacker have to have a valid user name AND the valid password to carry out an attack?<br />A:</b> No. The only requirement is to have the target's username, and *any* valid account on the system.<b></b></p>
<p><b>Q:&#160;Will any </b><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><b>forms authentication</b></a><b> tickets generated before the patch is applied be rendered invalid once the patch is applied?&#160;<br />A: </b>Yes. The change in the forms authentication ticket format will render all pre-patch tickets invalid once the update is applied.<b></b></p>
<p><b>Q:&#160;Our ASP.NET application requires large file uploads and requires our &#60;httpRuntime maxRequestLength="200&#8221;/&#62; to be set to 102400. How will we be able to handle that and not remain vulnerable?<br />A:</b> The maxRequestLength setting is just a workaround. You will not need to worry about this after applying the security update and can remove any previously set workaround configurations.<b></b></p>
<p><b>Q:&#160;These updates run on Windows clients whether or not IIS or ASP is installed. Are the updates not effective in this case?<br /></b><b>A:</b>&#160;By default, IIS is not installed with .NET and by default,&#160;.NET is not installed by ASP.NET.&#160;Customers would first need to installed .NET framework with ASP.NET in order to be vulnerable to the vulnerabilities documented in <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>.<b></b></p>
<p><b>Q:&#160;Will there be changes to WSUS to only show the patch needed when ASP.NET is installed?<br />A:</b> Updates that shipped in the security bulletin today are updates for the .NET Framework component. As such, the detection logic for these updates scans for different versions of the .NET Framework and offers the appropriate patch. The patches will be offered as long as the .NET Framework (which contains ASP.NET) is installed and irrespective of whether ASP.NET is registered and in use or not.<b></b></p>
<p><b>Q: For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE-2011-3414</b></a><b>, would one machine perform a denial of service based on the hash algorithms the server hosting the page has to consume?</b><br />A: Yes, one machine could effectively perform a denial of service, should it launch the correct type of attack.</p>
<p><b>Q: How much of live client-side authentication is vulnerable? Or is it server-side only (patch your servers, and client side is only vulnerable to the redirected site)?</b><br />A: The LiveID authentication system is not forms-based.&#160; Therefore, the forms-based authentication vulnerabilities do not affect LiveID.&#160; Further, it is all server-side and at this point we have applied the security update to our LiveID servers.</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473498" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><b>Hosts:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Jonathan Ness, Security Development Manager, MSRC</b></p>
<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pete Voss, Sr. Response Communications Manager, Trustworthy Computing</strong></p>
<p><b>Website:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b>TechNet/Security<b></b></p>
<p><b>Chat Topic: &nbsp;&nbsp;&nbsp; </b>December 2011 Out-Of-Band Security Bulletin Release<b></b></p>
<p><b>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b>Thursday, December 29, 2011<b></b></p>
<p><strong>Q: How are Denial of Service, Tampering, Information Disclosure orSpoofing issues rated?</strong><br /><strong>A: </strong>The <a href="http://technet.microsoft.com/en-us/security/cc998259">Exploitability Index</a> only attempts to rate vulnerabilities that can be leveraged for code execution. Vulnerabilities that could allow denial of service, tampering, information disclosure or spoofing will receive an Exploitability Index rating of "3." The notes for that particular CVE will also reflect the nature of the vulnerability.</p>
<p><b>Q:&nbsp;One angle I'm interested in is those Microsoft products that might use </b><a href="http://support.microsoft.com/kb/2659968"><b>forms authentication</b></a><b>, such as Exchange 2010 or TMG 2010. If we're using forms authentication there, does that mean we're vulnerable?<br />A:</b> Any products that are using ASP.NET forms authentication will be secured with <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">this update</a>. This includes SharePoint and Exchange, when they are using ASP.NET <a href="http://support.microsoft.com/kb/2659968">forms authentication</a>. If these products are using a Forms Authentication module other than the one provided by ASP.NET, then the issue addressed in this bulletin does not apply to you.&nbsp;<b></b></p>
<p><b>Q:&nbsp;Why does Windows Update on Windows 2008 servers show this update, but the check-box next to it is un-checked? What is the difference between patches that are checked by default and those that are not checked?<br />A:</b> In the case of "Important Updates", an update that is in the "PENDING" state will be unchecked when you view it in Windows Update. This means it is already queued for downloading. You can manually override this to start the download manually by checking the box next to the update.&nbsp;<b></b></p>
<p><b>Q:&nbsp;Please confirm that if an IIS instance is installed that we are at risk for one of the CVE's and therefore we should patch ASAP. The assumption is that the server has IIS without .NET components.<br />A:</b> By default, IIS is not installed with .NET and by default,&nbsp;.NET is not installed by ASP.NET.&nbsp;Customers would first need to have installed .NET framework with ASP.NET in order to be vulnerable to the vulnerabilities documented by <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>.<b></b></p>
<p><b>Q:&nbsp;What level of testing or specific tests is recommended for applications using ASP.NET? Is it highly likely that the hashing change will impact applications using the framework?<br />A:</b> Microsoft recommends that customers test this update before deploying. There is a change in how forms authentication occurs and will require updates to be deployed at the same time across server environments. <a href="http://support.microsoft.com/kb/2659968">Click here for more about forms authentication</a>. &nbsp;<b></b></p>
<p><b>Q:&nbsp;Can sample DoS requests be provided to allow us to understand what the DOS signature may look like so we can test the patch as well as monitor our production environments until the patching is completed?<br /></b><b>A:</b> For more technical information regarding <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>,&nbsp;please see the <a href="http://blogs.technet.com/b/srd/">SRD blog</a>, where we have shared a short signature detecting this issue.</p>
<p><b>Q:&nbsp;Is this critical to environments where there are no Internet-facing systems? And what if there is no IIS installed on the workstation -- is it atrisk?</b><b><br />A:</b> Exploitation requires ASP.NET installed and to be exposed to input from unauthenticated users. Typically this is through IIS.&nbsp;If workstations do not have ASP.NET or IIS installed, then those systems are not exposed.&nbsp;<b></b></p>
<p><b>Q:&nbsp;In the Critical Elevation of Privilege can the attacker elevate is privilege only if they have the username <i>without</i> having the password? Can we have machines with the fix and without the fix working with each other?<br />A:</b> Yes, the attacker only needs the username to carry out the attack. The fix involves changing the format of the forms authentication ticket, so that unpatched and patched machines cannot work with each other. So after patching you cannot have machines with the fix and without it working together, unless you set a configuration setting on the patched machines. For details, please <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">read the FAQ for this CVE</a> for more information on applying updates to web farms.<b></b></p>
<p><b>Q:&nbsp;For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE-2011-3414</b></a><b>, is there a requirement of authentication to exploit the DoS vulnerability successfully?<br />A:</b> No, <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414">CVE-2011-3414</a> is anunauthenticated Denial of Service.<b></b></p>
<p><b>Q:&nbsp;What could be a potential impact on server running IIS with custom code? In short, can this update impact server or service to go down after installation? Do you have any suggestions on installation on web servers running custom code?<br />A:</b> This update is specifically for ASP.NET, but the issue that was disclosed is an industry-wide issue concerning hash collisions. So, it is possible for your custom code to be affected, but you will need to investigate what kind of hash-tables your custom code uses and if it operates on untrusted user data.<b></b></p>
<p><b>Q:&nbsp;Is there a client-side patch that will protect users that fall for phishing attacks and visit websites that have not patched?<br /></b><b>A:</b> As clients are not affected by server-sided vulnerability, the security update does need to be installed on the server.&nbsp;<b></b></p>
<p><b>Q:&nbsp;If the main target is Internet facing systems with IIS &amp; ASP.NET installed, should I concentrate on patching my webservers first before patching client systems?</b><b><br />A:</b> Prioritization for this update would be specific to users&rsquo; environments, but servers that are internet-facing and accept input from unauthenticated or untrusted user-provided content are most affected and should be prioritized. Likewise, clients are typically not in a web server role, and so systems that are running a web server role should be prioritized.&nbsp;<b></b></p>
<p><b>Q:&nbsp;What steps can I take to reproduce and see if/how my site is affected, and so I can confirm the issue is gone after applying the patch?<br /></b><b>A: </b>For the protection of customers,&nbsp;Microsoft does not disclose proof of concept code (POC).&nbsp;The technical details of this issue are however public.</p>
<p><b>Q: If Microsoft .NET Framework is installed on an IIS Server, does this mean that ASP.NET is also installed but possibly not enabled?<br />A:</b> Whether you have the .NET Framework (and ASP.NET) installed on a machine will depend upon the specific OS platform. Windows Server 2008, Windows Server 2008 SP2, Windows Server 2008 R2 and Windows Server 2008 R2 SP1 all ship with the .NET Framework 2.0 or higher, which includes ASP.NET, and you should install the corresponding patches listed in the security bulletin. If you are using an older Server OS such as Windows Server 2003 SP2 x86, then that platform includes .NET Framework 1.1 SP1, and you should install the corresponding patch listed in the security bulletin.&nbsp;<b></b></p>
<p><b>Q:&nbsp;From a desktop browsing experience, this update will patch Windows XP, Vista and 7. If machines do not have IIS installed and enabled, as well as ASP.NET enabled, is the criticality of this update reduced? For example if the user goes to an internet site, would their desktop PC be vulnerable? It seems to be mostly if you have IIS and ASP.net installed and acting as a web server.<br />A: </b>If you have a client machine with no ASP.NET installed, then your desktop PC would not be vulnerable to the particular security issues that are being addressed in this update.<b></b></p>
<p><b>Q:&nbsp;ASP.Net has been identified for the DoS. How about classic ASP/ISAPI applications? Is it just a .Net hash-table issue? And has the Microsoft Foundation Class / ATL / Visual Basic 6.0 been checked?<br />A:</b> This is an industry-wide issue that could affect a broad spectrum of technologies. Since ASP.NET was at the greatest risk because of the public disclosure, we have focused our efforts so far on making sure we secure ASP.NET. We are actively investigating other technologies where this could be vulnerable and so far we do not think that classic ASP is vulnerable. Information on other affected technologies will be revealed as the issue develops.<b></b></p>
<p><b>Q: So just to be clear, Exchange 2010 Outlook Web Access isn't vulnerable to the privilege of escalation? Just to the DOS?<br />A:</b> OWA 2010 can be configured for forms-based authentication. Based on this, it should be considered vulnerable. If there is any doubt, <a href="http://support.microsoft.com/kb/2638420">Microsoft KB Article 2638420</a> discusses parameters you can check for to verify if an application is using forms auth. Specifically, to determine whether your application uses forms authentication,<br />examine the System.web file. Applications that use forms authentication use the following entry in System.web file: &lt;authentication mode="Forms"&gt;</p>
<p><b>Q: What tools are available to remotely scan systems to see if they&rsquo;re vulnerable -- that is, that IIS and ASP are installed and active?<br />A:</b> The Detection and Deployment Tools and Guidance section in the security bulletin provides information on how to identify systems to which this update applies. If you want to identify whether a system has IIS installed with ASP.NET enabled, the answer depends on the operating system that each system is running.</p>
<p><b>Q: Are only webservers vulnerable?&nbsp;We have limited personnel this weekend for QA and deployment.&nbsp;Are we pretty much covered if we just deploy to systems in our DMZ this weekend and then rest of the enterprise next week?<br />A:</b> Prioritization for this update would be specific to users&rsquo; environments, but servers that are internet-facing and accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers.&nbsp;<b></b></p>
<p><b>Q:&nbsp;Sites that disallow "application/x-www-form-urlencoded&rdquo; or &ldquo;multipart/form-data&rdquo; HTTP content types are not vulnerable. Is this set to disallow by default? How do we verify if it is set to disallow?<br /></b><b>A:</b> No, application/x-www-form-urlencoded or multipart/form-data are not disallowed by default.&nbsp;Customers will need to explicitly disallow these.&nbsp;Customers can do this by <a href="http://learn.iis.net/page.aspx/143/use-request-filtering/">using IIS request filtering</a>.&nbsp;</p>
<p><b>Q:&nbsp;Forms authorization login from TMG/ISA doesn't use ASP.NET. Is it still vulnerable?</b><b><br />A:</b> TMG is not exposed and is not related to the ASP.NET issue described in the bulletin.<b></b></p>
<p><b>Q: Do you suggest immediate patching of all servers (internal/external) or just of externally available servers and allow internal servers to be patched during the next patching cycle?<br />A:</b>&nbsp;Once again, prioritization for this update would be specific to each user&rsquo;s environment, but servers that are internet-facing and accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers.&nbsp;<b></b></p>
<p><strong>Q:&nbsp;Is the critical CVE related to </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a><strong> only an issue if the site is configured to support </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a><strong> <i>without</i> cookies? Or, are all </strong><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><strong>forms authentication</strong></a>&nbsp;<strong>implementations impacted?<br />A:</strong> No, this issue applies to all types of ASP.NET forms authentication, cookie and cookie-less.<b></b></p>
<p><b>Q:&nbsp;For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE 2011-3414</b></a><b>, does the patch change the size of request header accepted, place controls on the amount of CPU that can be used, or change the hashing functions used?<br /></b><b>A:</b>The security update addresses this issue by limiting the number of inputs ASP.NET accepts from clients.</p>
<p><b>Q:&nbsp;Does this patch limit the number of parameters passed in the post request? If so, what is the new limit? I am trying to determine what application problems may arise after applying the update.</b><b><br />A:</b> The security update addresses this issue by limiting the number of inputs ASP.NET accepts from clients.&nbsp;If you are interested in changing the number of parameters passed in the post request, please&nbsp;see the&nbsp;section of the bulletin titled <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><i>Workarounds for Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414</i>.&nbsp;</a><b></b></p>
<p><b>Q:&nbsp;Can the normally scheduled January bulletins be installed independently of the critical one?<br /></b><b>A:</b> Yes, Future security updates can be installed independently of this issue.&nbsp;Microsoft does recommend all customers always read security updates to ensure they fully understand any known issues that may be documented in the security bulletin.</p>
<p><b>Q:&nbsp;Is the attack vector based on the server or the client? Do we concentrate on server or desktop side first?</b><b><br />A:</b> The vulnerabilities in the bulletins are primarily focused on systems operating in a Web server role that use ASP.NET. Clients are typically not in a web server role.<b></b></p>
<p><b>Q:&nbsp;Could you provide more detail around the 3rd mitigation factor -- specifically the account registration procedure?<br />A:</b> I am assuming this question is about the first mitigating factor for <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3416">CVE-2011-3416</a>: forms authentication bypass. Essentially, to pull off an Elevation of Privilege attack, the attacker would need a valid account on the system they are trying to compromise and the user name of the target of the attack.<b></b></p>
<p><b>Q:&nbsp;Can an ASP.NET site (e.g. SharePoint 2010 site) using authentication (NTLM/Kerberos) come under the DoS attack as described in CVE-2011-3414 by an unauthenticated user?</b><b><br />A:</b> NTLM/Kerberos authentication changes the attack vector of the vulnerability.&nbsp;An ASP.NET site can come under a DOS attack &ndash; however, the attacker would then need to be authenticated.&nbsp;<b></b></p>
<p><b>Q:&nbsp;Will this affect -- or will I need to be aware of -- this update impacting ASP.NET session and machine key settings in IIS for a load balanced environment, where all machine keys are matches to make sure sessions are the same across a server farm?<br />A:</b> This update changes the way in which forms authentication tickets are created, so all servers would need to use the old or the new ticket format in order to maintain compatibility. Please refer to <a href="http://support.microsoft.com/kb/2659968">Knowledge Base Article 2659968</a> for deployment guidance for this update.<b></b></p>
<p><b>Q:&nbsp;What about servers that have IP address access limitations? Since we are resource-limited, we'd like to skip these servers that are only allowing certain IPs to access IIS. </b><b><br />A:</b> As we&rsquo;ve mentioned, prioritization for this update would be specific to users environments, but servers that are Internet-facing and can accept input from unauthenticated or untrusted user provided content may be at greater risk than internal servers. Servers that have additional protections may reduce the potential attack risk of these vulnerabilities.&nbsp;Customers are encouraged to analyze their own environments.</p>
<p><b>Q:&nbsp;We have ASP.NET prohibited in in our Web Service Extensions -- IIS 6. Are we still vulnerable?<br /></b><b>A:</b> No. If ASP.NET is not enabled, you are not vulnerable.</p>
<p><strong>Q:&nbsp;The Section </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"><i><strong>Workarounds for Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414</strong></i></a>&nbsp;<strong>in the bulletin is confusing. Is it required to put this script and then install the update?&nbsp;<br />A:</strong> Workaround refers to a setting or configuration change that does not correct the underlying vulnerability, but would help block known attack vectors before you apply the update. Microsoft has tested the following workarounds and states in the discussion whether a workaround reduces functionality.&nbsp;Customers are always encouraged to apply the security update.&nbsp;The workarounds are not a prerequisite for installing the security update.</p>
<p><b>Q:&nbsp;If TMG is not affected then, if TMG is protecting an Exchange 2010 server and the TMG is handling the forum authorization, would the patch for an Exchange server be necessary?<br /></b><b>A:</b> Although firewall solutions could protect systems behind the firewall it is important to understand the types of traffic that that FW may proxy to servers behind it. Systems behind the firewall are still vulnerable to internal attacks and have vulnerable code and should be updated to be properly protected.</p>
<p><b>Q:&nbsp;Is AppSettings.MaxHttpCollectionKeys the new parameter that contains the maximum number of form entries?<br />A:</b> Yes it is.<b></b></p>
<p><b>Q:&nbsp;For ASP.NET on Internet-facing systems requiring authentication, does an attacker have to have a valid user name AND the valid password to carry out an attack?<br />A:</b> No. The only requirement is to have the target's username, and *any* valid account on the system.<b></b></p>
<p><b>Q:&nbsp;Will any </b><a href="http://msdn.microsoft.com/en-us/library/ff647070.aspx"><b>forms authentication</b></a><b> tickets generated before the patch is applied be rendered invalid once the patch is applied?&nbsp;<br />A: </b>Yes. The change in the forms authentication ticket format will render all pre-patch tickets invalid once the update is applied.<b></b></p>
<p><b>Q:&nbsp;Our ASP.NET application requires large file uploads and requires our &lt;httpRuntime maxRequestLength="200&rdquo;/&gt; to be set to 102400. How will we be able to handle that and not remain vulnerable?<br />A:</b> The maxRequestLength setting is just a workaround. You will not need to worry about this after applying the security update and can remove any previously set workaround configurations.<b></b></p>
<p><b>Q:&nbsp;These updates run on Windows clients whether or not IIS or ASP is installed. Are the updates not effective in this case?<br /></b><b>A:</b>&nbsp;By default, IIS is not installed with .NET and by default,&nbsp;.NET is not installed by ASP.NET.&nbsp;Customers would first need to installed .NET framework with ASP.NET in order to be vulnerable to the vulnerabilities documented in <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a>.<b></b></p>
<p><b>Q:&nbsp;Will there be changes to WSUS to only show the patch needed when ASP.NET is installed?<br />A:</b> Updates that shipped in the security bulletin today are updates for the .NET Framework component. As such, the detection logic for these updates scans for different versions of the .NET Framework and offers the appropriate patch. The patches will be offered as long as the .NET Framework (which contains ASP.NET) is installed and irrespective of whether ASP.NET is registered and in use or not.<b></b></p>
<p><b>Q: For </b><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3414"><b>CVE-2011-3414</b></a><b>, would one machine perform a denial of service based on the hash algorithms the server hosting the page has to consume?</b><br />A: Yes, one machine could effectively perform a denial of service, should it launch the correct type of attack.</p>
<p><b>Q: How much of live client-side authentication is vulnerable? Or is it server-side only (patch your servers, and client side is only vulnerable to the redirected site)?</b><br />A: The LiveID authentication system is not forms-based.&nbsp; Therefore, the forms-based authentication vulnerabilities do not affect LiveID.&nbsp; Further, it is all server-side and at this point we have applied the security update to our LiveID servers.</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473498" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft releases MS11-100 for Security Advisory 2659883</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx#comments</comments>
		<pubDate>Thu, 29 Dec 2011 18:00:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello,</p>
<p>Today we released Security Update <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a> to address the issue described in <a href="http://technet.microsoft.com/en-us/security/advisory/2659883">Security Advisory 2659883</a>.</p>
<p>The security update has a severity rating of Critical and resolves a publicly disclosed remote unauthenticated Denial of Service issue in ASP.NET versions 1.1 and above on all supported versions of .NET Framework. Of note, the new method of hash collision attacks used to exploit this vulnerability is an industry-wide issue affecting various Web platforms, including ASP.NET.</p>
<p>While we have seen no attacks attempting to exploit this vulnerability, we encourage affected customers to test and deploy the update as soon as possible. Consumers are not vulnerable unless they are running a Web server from their computer. More technical details can be found at the <a href="http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx">Security Research &#38; Defense Blog</a>.</p>
<p>For all the latest information, you can also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a>.</p>
<p>Thanks,<br /> Dave Forstrom<br /> Director<br /> Microsoft Trustworthy Computing</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473283" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>Today we released Security Update <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100">MS11-100</a> to address the issue described in <a href="http://technet.microsoft.com/en-us/security/advisory/2659883">Security Advisory 2659883</a>.</p>
<p>The security update has a severity rating of Critical and resolves a publicly disclosed remote unauthenticated Denial of Service issue in ASP.NET versions 1.1 and above on all supported versions of .NET Framework. Of note, the new method of hash collision attacks used to exploit this vulnerability is an industry-wide issue affecting various Web platforms, including ASP.NET.</p>
<p>While we have seen no attacks attempting to exploit this vulnerability, we encourage affected customers to test and deploy the update as soon as possible. Consumers are not vulnerable unless they are running a Web server from their computer. More technical details can be found at the <a href="http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx">Security Research &amp; Defense Blog</a>.</p>
<p>For all the latest information, you can also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a>.</p>
<p>Thanks,<br /> Dave Forstrom<br /> Director<br /> Microsoft Trustworthy Computing</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473283" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Notification for out-of-band release to address Security Advisory 2659883</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/28/advanced-notification-for-out-of-band-release-to-address-security-advisory-2659883.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/28/advanced-notification-for-out-of-band-release-to-address-security-advisory-2659883.aspx#comments</comments>
		<pubDate>Thu, 29 Dec 2011 03:51:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ANS]]></category>
		<category><![CDATA[OOB]]></category>
		<category><![CDATA[Security Advisory]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><span style="font-size: small"><span style="font-family: Calibri">Hello,</span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Today we&#8217;re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in </span></span><a href="http://technet.microsoft.com/en-us/security/advisory/2659883"><span style="color: #0000ff;font-family: Calibri;font-size: small">Security Advisory 2659883</span></a><span style="font-size: small"><span style="font-family: Calibri"><span style="text-decoration: underline"><span style="color: #0000ff">.</span></span> The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST.</span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">The bulletin has a severity rating of Critical and addresses a publicly disclosed vulnerability in ASP.NET that affects all versions of the .NET Framework. While we&#8217;re currently unaware of any attacks targeting ASP.NET, we encourage all customers to test and deploy the update when it is available. </span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">We will also hold a special edition webcast on Thursday, December 29 at 1 p.m. PST. Click <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032502798&#38;Culture=en-US" target="_blank">here</a> to register.</span></span></p>
<p><span style="font-family: Calibri;font-size: small">For all the latest information, you can also follow the MSRC team on Twitter at </span><a href="https://twitter.com/#!/msftsecresponse"><span style="color: #0000ff;font-family: Calibri;font-size: small">@MSFTSecResponse</span></a><span style="font-size: small"><span style="font-family: Calibri">.</span></span></p>
<p><span style="font-family: Calibri;font-size: small">&#160;</span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Thanks,</span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Dave Forstrom</span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Director</span></span></p>
<p><span style="font-size: small"><span style="font-family: Calibri">Microsoft Trustworthy Computing</span></span></p>
<p></p>
<p></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473183" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Hello,</span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Today we&rsquo;re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in </span></span><a href="http://technet.microsoft.com/en-us/security/advisory/2659883"><span style="color: #0000ff; font-family: Calibri; font-size: small;" size="3" face="Calibri" color="#0000ff">Security Advisory 2659883</span></a><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri"><span style="text-decoration: underline;"><span style="color: #0000ff;" color="#0000ff">.</span></span> The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST.</span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">The bulletin has a severity rating of Critical and addresses a publicly disclosed vulnerability in ASP.NET that affects all versions of the .NET Framework. While we&rsquo;re currently unaware of any attacks targeting ASP.NET, we encourage all customers to test and deploy the update when it is available. </span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">We will also hold a special edition webcast on Thursday, December 29 at 1 p.m. PST. Click <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032502798&amp;Culture=en-US" >here</a> to register.</span></span></p>
<p><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">For all the latest information, you can also follow the MSRC team on Twitter at </span><a href="https://twitter.com/#!/msftsecresponse"><span style="color: #0000ff; font-family: Calibri; font-size: small;" size="3" face="Calibri" color="#0000ff">@MSFTSecResponse</span></a><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">.</span></span></p>
<p><span style="font-family: Calibri; font-size: small;" size="3" face="Calibri">&nbsp;</span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Thanks,</span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Dave Forstrom</span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Director</span></span></p>
<p><span style="font-size: small;" size="3"><span style="font-family: Calibri;" face="Calibri">Microsoft Trustworthy Computing</span></span></p>
<p></p>
<p></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473183" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/28/advanced-notification-for-out-of-band-release-to-address-security-advisory-2659883.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft releases Security Advisory 2659883, offers workaround for industry-wide issue</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/28/microsoft-releases-security-advisory-2659883-offers-workaround-for-industry-wide-issue.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/28/microsoft-releases-security-advisory-2659883-offers-workaround-for-industry-wide-issue.aspx#comments</comments>
		<pubDate>Wed, 28 Dec 2011 12:57:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello,</p>
<p>Today we published <a href="http://technet.microsoft.com/en-us/security/advisory/2659883">Security Advisory 2659883</a> to provide a workaround to help protect ASP.NET customers from a publicly disclosed vulnerability that affects various Web platforms industry-wide. We are not aware of any attacks using this vulnerability, which affects all supported versions of .NET Framework, however we recommend customers use the mitigation and workaround described in the Advisory to help protect sites against this new method to exploit hash tables.</p>
<p>Our teams are working around the clock worldwide to develop a security update of appropriate quality to address this issue. Meanwhile, our Security Research &#38; Defense team has written<a href="http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx"> a blog post</a> to explain how to know if you are vulnerable and detect exploitation, as well as background on the workaround. We are also working closely with our <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx">Microsoft Active Protections Program (MAPP)</a> to help our partners build protections when and where possible. We will continue to update customers with new information as it becomes available.</p>
<p>For all the latest information, you can also follow the MSRC team on Twitter at <a href="https://twitter.com/#!/msftsecresponse">@MSFTSecResponse.</a></p>
<p>Thanks,<br /> Dave Forstrom<br /> Director<br /> Microsoft Trustworthy Computing</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473097" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>Today we published <a href="http://technet.microsoft.com/en-us/security/advisory/2659883">Security Advisory 2659883</a> to provide a workaround to help protect ASP.NET customers from a publicly disclosed vulnerability that affects various Web platforms industry-wide. We are not aware of any attacks using this vulnerability, which affects all supported versions of .NET Framework, however we recommend customers use the mitigation and workaround described in the Advisory to help protect sites against this new method to exploit hash tables.</p>
<p>Our teams are working around the clock worldwide to develop a security update of appropriate quality to address this issue. Meanwhile, our Security Research &amp; Defense team has written<a href="http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx"> a blog post</a> to explain how to know if you are vulnerable and detect exploitation, as well as background on the workaround. We are also working closely with our <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx">Microsoft Active Protections Program (MAPP)</a> to help our partners build protections when and where possible. We will continue to update customers with new information as it becomes available.</p>
<p>For all the latest information, you can also follow the MSRC team on Twitter at <a href="https://twitter.com/#!/msftsecresponse">@MSFTSecResponse.</a></p>
<p>Thanks,<br /> Dave Forstrom<br /> Director<br /> Microsoft Trustworthy Computing</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3473097" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/28/microsoft-releases-security-advisory-2659883-offers-workaround-for-industry-wide-issue.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Bulletin Release Q&amp;A and Slide Deck</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/19/december-2011-bulletin-release-q-amp-a-and-slide-deck.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/19/december-2011-bulletin-release-q-amp-a-and-slide-deck.aspx#comments</comments>
		<pubDate>Mon, 19 Dec 2011 18:32:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[Q&A]]></category>
		<category><![CDATA[Webcast Q&A]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx"> December Security Bulletin Webcast Questions &#38; Answers page</a>. We fielded six questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools.</p>
<p>For more details on this month&#8217;s bulletins, click here to <a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/3058.December-2011-Webcast-Deck_5F00_FINAL.pptx">view the slide deck</a> used in the webcast. See below to view the webcast.</p>
<div style="width: 480px;height: 270px"></div>
<p>We invite our customers to join us for the next public webcast on Wednesday, January 11, 2012 at 11am PST (UTC -8), when we will go into detail about the January bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, January 11, 2012<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&#38;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Jerry Bryant<br /> Group Manager, Response Communications<br /> Microsoft Trustworthy Computing</p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3472029" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>Hello,</p>
<p>Today we published the <a href="http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx"> December Security Bulletin Webcast Questions &amp; Answers page</a>. We fielded six questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools.</p>
<p>For more details on this month&rsquo;s bulletins, click here to <a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/3058.December-2011-Webcast-Deck_5F00_FINAL.pptx">view the slide deck</a> used in the webcast. See below to view the webcast.</p>
<div style="width: 480px; height: 270px;"><object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGMANAA3AGMAMwA2ADIAMQAtAGEAMQBlADYALQA0ADAANQAyAC0AOABhAGQAZAAtADAAZgA0AGUANABhADYAOQA2AGYANgA5ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQBjADQANwBjADMANgAyADEALQBhADEAZQA2AC0ANAAwADUAMgAtADgAYQBkAGQALQAwAGYANABlADQAYQA2ADkANgBmADYAOQAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"><param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /><param name="initParams" value="Culture=en-us,Uuid=c47c3621-a1e6-4052-8add-0f4e4a696f69,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=c47c3621-a1e6-4052-8add-0f4e4a696f69,Mode=Player" /><param name="enableHtmlAccess" value="true" /><param name="allowHtmlPopupwindow" value="true" /><param name="background" value="#FF000000" /></object></div>
<p>We invite our customers to join us for the next public webcast on Wednesday, January 11, 2012 at 11am PST (UTC -8), when we will go into detail about the January bulletin release and answer questions live on the air.</p>
<p>Customers can register to attend at the link below:<br /> <b>Date:</b> Wednesday, January 11, 2012<br /> <b>Time:</b> 11:00 a.m. PST (UTC -8)<br /> <b>Register:</b> <a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;Culture=en-US">Attendee Registration</a></p>
<p>Thanks,<br /> Jerry Bryant<br /> Group Manager, Response Communications<br /> Microsoft Trustworthy Computing</p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3472029" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/19/december-2011-bulletin-release-q-amp-a-and-slide-deck.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Security Bulletin Webcast Q&amp;A</title>
		<link>http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx</link>
		<comments>http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx#comments</comments>
		<pubDate>Thu, 15 Dec 2011 23:32:00 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[webcast]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<p><b>Hosts:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;Jonathan Ness, Security Development Manager, MSRC<br /></b><b>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Jerry Bryant, Group Manager, Trustworthy Computing Communications</b></p>
<p><b>Website:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; </b>TechNet/Security<b></b></p>
<p><b>Chat Topic: &#160;&#160;&#160; </b>December 2011 Security Bulletin Release<b></b></p>
<p><b>Date:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; </b>Wednesday, December 14, 2011<b>&#160;</b></p>
<p><b>Q: Some of my users had issues with text being deleted from Word documents. Is this an issue with the </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-089"><b>Office security bulletin</b></a><b>?&#160;<br /></b>A: We are not aware of any issues ofwords being removed from the document. If this continues, please contact support at 1-866-PC-SAFETY.</p>
<p><b>Q: You said that </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-090"><b>MS11-090</b></a><b> only applied to Windows XP and Windows Server 2003, but my WSUS is showing it needed for my Windows 7 and Windows Server 2008 &#38; 2008 R2 machines.<br /></b>A: The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-090">MS11-090</a>&#160;bulletin is a Cumulative Security Update of ActiveX Kill Bits. It addresses a new CVE that only affects Windows XP and Windows Server 2003, but also contains kill bits for various third party software, and affects a broader set of platforms than just Windows XP and Server 2003.&#160;<b></b></p>
<p><b>Q: Will raising the Excel macro security level to high and ensuring that all macro code is digitally signed mitigate the Excel risks for this month?<br /></b>A: The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-096">December Excel update</a> fixes a vulnerability in the document parsing functionality in excel. This functionality is invoked when an Excel document is loaded into the Excel Application. While limiting macros execution in Excel is good security practice, it will not help you if trying to use it to mitigate the issue addressed by the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-096">December Excel update</a>.<br /><br /><b>Q: Is there a link to the work-around fix for the Duqu-type open font vulnerability that you discussed?<br /></b>A: The Workaround section for the <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3402">CVE-2011-3402</a> in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-087">MS11-087</a>&#160;bulletin explains how to apply and undo the workaround, and it also contains links to Fix It related to these operations.<b></b></p>
<p><b>Q: Once </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b> updates are installed, we have had some instances of Excel and Word documents opening very slowly across our network. You mentioned that </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b> can help reduce attack vectors. Can you share any information on the effects of installing </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b>?<br /></b>A: We released a fix to increase the performance of opening across the network.The fix is documented in <a href="http://support.microsoft.com/kb/2570623">KB2570623</a>.<b></b></p>
<p><b>Q: On my WSUS server, I searched </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-088"><b>MS11-088</b></a><b> and </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> was found but </b><a href="http://support.microsoft.com/kb/2647540"><b>KB2647540</b></a><b> was not found. As the Detection &#38; Deployment indicates through the Download Center, should </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> be approved through WSUS and</b><a href="http://support.microsoft.com/kb/2647540"><b> KB2647540</b></a><b> be manually applied? Is </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> complete on WSUS?<br /></b>A: <a href="http://support.microsoft.com/kb/2647540">KB2647540</a> is currently only available via the Download Center. The update will also be provided through our other standard distribution methods once testing has been completed to ensure distribution will be successful through these channels.&#160;<b></b></p><div style="clear:both"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3471348" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><b>Hosts:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Jonathan Ness, Security Development Manager, MSRC<br /></b><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Jerry Bryant, Group Manager, Trustworthy Computing Communications</b></p>
<p><b>Website:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b>TechNet/Security<b></b></p>
<p><b>Chat Topic: &nbsp;&nbsp;&nbsp; </b>December 2011 Security Bulletin Release<b></b></p>
<p><b>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </b>Wednesday, December 14, 2011<b>&nbsp;</b></p>
<p><b>Q: Some of my users had issues with text being deleted from Word documents. Is this an issue with the </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-089"><b>Office security bulletin</b></a><b>?&nbsp;<br /></b>A: We are not aware of any issues ofwords being removed from the document. If this continues, please contact support at 1-866-PC-SAFETY.</p>
<p><b>Q: You said that </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-090"><b>MS11-090</b></a><b> only applied to Windows XP and Windows Server 2003, but my WSUS is showing it needed for my Windows 7 and Windows Server 2008 &amp; 2008 R2 machines.<br /></b>A: The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-090">MS11-090</a>&nbsp;bulletin is a Cumulative Security Update of ActiveX Kill Bits. It addresses a new CVE that only affects Windows XP and Windows Server 2003, but also contains kill bits for various third party software, and affects a broader set of platforms than just Windows XP and Server 2003.&nbsp;<b></b></p>
<p><b>Q: Will raising the Excel macro security level to high and ensuring that all macro code is digitally signed mitigate the Excel risks for this month?<br /></b>A: The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-096">December Excel update</a> fixes a vulnerability in the document parsing functionality in excel. This functionality is invoked when an Excel document is loaded into the Excel Application. While limiting macros execution in Excel is good security practice, it will not help you if trying to use it to mitigate the issue addressed by the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-096">December Excel update</a>.<br /><br /><b>Q: Is there a link to the work-around fix for the Duqu-type open font vulnerability that you discussed?<br /></b>A: The Workaround section for the <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3402">CVE-2011-3402</a> in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-087">MS11-087</a>&nbsp;bulletin explains how to apply and undo the workaround, and it also contains links to Fix It related to these operations.<b></b></p>
<p><b>Q: Once </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b> updates are installed, we have had some instances of Excel and Word documents opening very slowly across our network. You mentioned that </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b> can help reduce attack vectors. Can you share any information on the effects of installing </b><a href="http://technet.microsoft.com/en-us/library/gg985445(office.12).aspx"><b>Office File Validation</b></a><b>?<br /></b>A: We released a fix to increase the performance of opening across the network.The fix is documented in <a href="http://support.microsoft.com/kb/2570623">KB2570623</a>.<b></b></p>
<p><b>Q: On my WSUS server, I searched </b><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-088"><b>MS11-088</b></a><b> and </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> was found but </b><a href="http://support.microsoft.com/kb/2647540"><b>KB2647540</b></a><b> was not found. As the Detection &amp; Deployment indicates through the Download Center, should </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> be approved through WSUS and</b><a href="http://support.microsoft.com/kb/2647540"><b> KB2647540</b></a><b> be manually applied? Is </b><a href="http://support.microsoft.com/kb/2596511"><b>KB2596511</b></a><b> complete on WSUS?<br /></b>A: <a href="http://support.microsoft.com/kb/2647540">KB2647540</a> is currently only available via the Download Center. The update will also be provided through our other standard distribution methods once testing has been completed to ensure distribution will be successful through these channels.&nbsp;<b></b></p><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3471348" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

