<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Security Update Webcast Q&amp;A</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/security-update-webcast-qa/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Wed, 28 Jul 2010 16:31:39 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>August 2009 Security Bulletin Webcast Video and Customer Q and A</title>
		<link>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx#comments</comments>
		<pubDate>Fri, 14 Aug 2009 23:42:53 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[Defense-in-depth]]></category>
		<category><![CDATA[Internet Explorer (IE)]]></category>
		<category><![CDATA[Killbit]]></category>
		<category><![CDATA[Mitigations]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q&A]]></category>
		<category><![CDATA[Security Update Webcast Q&amp]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273699</guid>
		<description><![CDATA[<p>As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).</p>  <p>It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a>: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a <a href="http://support.microsoft.com/fixit#tab0">Microsoft Fix it</a> solution) to customers while we worked towards an update for the underlying issue. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)</a>: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx">MS09-034 – Cumulative Security Update for Internet Explorer (972260)</a>: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)</a>: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this <a href="http://go.microsoft.com/?linkid=9674481">MSDN article</a>. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)</a>: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. </li>    <li><a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. </li> </ul>  <p>To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.</p>  <p>Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx%20">Q&#38;A here&#62;&#62;</a>.</p>  <p>Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&#38;A session:</p>  <table border="0" cellspacing="0" cellpadding="2" width="541"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="289">More viewing and listening options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3">MP3 Audio</a></li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&#38;culture=en-US">Click here to register &#62;&#62;</a>.</p>  <p>Finally, please visit our <a href="http://blogs.technet.com/srd">Security Research &#38; Defense blog</a> where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new <a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx">blog aggregator</a> useful for getting a consolidated view of all of our Trustworthy Computing blogs. </p>  <p>Thanks, </p>  <p>Jerry Bryant </p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p>As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).</p>  <p>It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:</p>  <ul>   <li><a href="http://www.microsoft.com/technet/security/advisory/972890.mspx">Security Advisory 972890</a>: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a <a href="http://support.microsoft.com/fixit#tab0">Microsoft Fix it</a> solution) to customers while we worked towards an update for the underlying issue. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx">MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)</a>: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx">MS09-034 – Cumulative Security Update for Internet Explorer (972260)</a>: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx">MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)</a>: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this <a href="http://go.microsoft.com/?linkid=9674481">MSDN article</a>. </li>    <li><a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx">MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)</a>: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. </li>    <li><a href="http://www.microsoft.com/technet/security/advisory/973882.mspx">Security Advisory 973882</a>: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. </li> </ul>  <p>To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.</p>  <p>Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the <a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx%20">Q&amp;A here&gt;&gt;</a>.</p>  <p>Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&amp;A session:</p>  <table border="0" cellspacing="0" cellpadding="2" width="541"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png, postid=5067" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="289">More viewing and listening options:         <br />          <ul>           <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3">MP3 Audio</a></li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;culture=en-US">Click here to register &gt;&gt;</a>.</p>  <p>Finally, please visit our <a href="http://blogs.technet.com/srd">Security Research &amp; Defense blog</a> where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new <a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx">blog aggregator</a> useful for getting a consolidated view of all of our Trustworthy Computing blogs. </p>  <p>Thanks, </p>  <p>Jerry Bryant </p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Bulletin Webcast Video, Questions and Answers – May 2009</title>
		<link>http://blogs.technet.com/msrc/archive/2009/05/15/security-bulletin-webcast-video-and-q-a-may-2009.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/05/15/security-bulletin-webcast-video-and-q-a-may-2009.aspx#comments</comments>
		<pubDate>Fri, 15 May 2009 20:17:53 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q&A]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3241910</guid>
		<description><![CDATA[<p><font face="Calibri" size="3">In the May 2009 security bulletin webcast, we addressed several questions relating to <a href="http://microsoft.com/technet/security/bulletin/ms09-017.mspx" target="_blank">MS09-017</a> in addition to questions about WSUS and MBSA. For those questions that came in after we concluded the webcast, we have provided answers in the published Q&#38;A which you can find here:      <br /></font><a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-May-2009.aspx"><font face="Calibri" size="3">http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-May-2009.aspx</font></a></p>  <p><font face="Calibri" size="3">Also, here is the link to the Q&#38;A index page in case you want to view previous months:      <br /></font><a href="http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx"><font face="Calibri" size="3">http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx</font></a></p>  <p><font face="Calibri" size="3">Here is the video of the session that includes our detailed look at the bulletin and the live questions and answers session:</font></p>  <table cellspacing="0" cellpadding="2" width="567" border="0"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="315"><font face="Calibri" size="3">More listening and viewing options:            <br /></font>          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.wmv"><font face="Calibri" size="3">Windows Media Video (WMV)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.wma"><font face="Calibri" size="3">Windows Media Audio (WMA)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_large_edge.png"><font face="Calibri" size="3">Large Preview Image (PNG)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_small_edge.png"><font face="Calibri" size="3">Small Preview Image (PNG)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.mp4"><font face="Calibri" size="3">iPod Video (MP4)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.mp3"><font face="Calibri" size="3">MP3 Audio</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/9/4/0/3/MSRCMay09Webcast_s_edge.wmv"><font face="Calibri" size="3">Streaming WMV (512kbps)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_2MB_edge.wmv"><font face="Calibri" size="3">High Quality WMV (2.5 Mbps)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_Zune_edge.wmv"><font face="Calibri" size="3">Zune Video (WMV)</font></a><font face="Calibri" size="3"> </font></li>         </ul>       </td>     </tr>   </tbody></table>  <p><font face="Calibri" size="3">As always, customers experiencing issues installing any of the updates this month should contact our Customer Service and Support group:</font></p>  <p><font face="Calibri" size="3">Customers in the U.S. and Canada can receive technical support from Microsoft Customer Support Services at 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates.</font></p>  <p><font face="Calibri" size="3">International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the </font><a href="http://msdn.microsoft.com/en-us/library/ms955707.aspx"><font face="Calibri" size="3">International Support Web site</font></a><font face="Calibri" size="3">.</font></p>  <p><font face="Calibri" size="3">Please join us for our next live webcast on June 10, 2009 at 11:00 am PDT (UTC –7). Follow this link to pre-register:      <br /></font><a title="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032395225" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032395225"><font face="Calibri" size="3">http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&#38;EventID=1032395225</font></a></p>  <p><font face="Calibri" size="3">Hope to see you then!</font></p>  <p><font face="Calibri" size="3">Jerry Bryant</font></p>  <p><font face="Calibri" size="3">*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights.*</font></p>  <p><font face="Calibri" size="3"></font></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3241910" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><font face="Calibri" size="3">In the May 2009 security bulletin webcast, we addressed several questions relating to <a href="http://microsoft.com/technet/security/bulletin/ms09-017.mspx" >MS09-017</a> in addition to questions about WSUS and MBSA. For those questions that came in after we concluded the webcast, we have provided answers in the published Q&amp;A which you can find here:      <br /></font><a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-May-2009.aspx"><font face="Calibri" size="3">http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-May-2009.aspx</font></a></p>  <p><font face="Calibri" size="3">Also, here is the link to the Q&amp;A index page in case you want to view previous months:      <br /></font><a href="http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx"><font face="Calibri" size="3">http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx</font></a></p>  <p><font face="Calibri" size="3">Here is the video of the session that includes our detailed look at the bulletin and the live questions and answers session:</font></p>  <table cellspacing="0" cellpadding="2" width="567" border="0"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/VideoPlayer2009_01_29.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/9/4/0/3/MSRCMay09Webcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_large_edge.png, postid=3049" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="315"><font face="Calibri" size="3">More listening and viewing options:            <br /></font>          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.wmv"><font face="Calibri" size="3">Windows Media Video (WMV)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.wma"><font face="Calibri" size="3">Windows Media Audio (WMA)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_large_edge.png"><font face="Calibri" size="3">Large Preview Image (PNG)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_small_edge.png"><font face="Calibri" size="3">Small Preview Image (PNG)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.mp4"><font face="Calibri" size="3">iPod Video (MP4)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_edge.mp3"><font face="Calibri" size="3">MP3 Audio</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/9/4/0/3/MSRCMay09Webcast_s_edge.wmv"><font face="Calibri" size="3">Streaming WMV (512kbps)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_2MB_edge.wmv"><font face="Calibri" size="3">High Quality WMV (2.5 Mbps)</font></a><font face="Calibri" size="3"> </font></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/9/4/0/3/MSRCMay09Webcast_Zune_edge.wmv"><font face="Calibri" size="3">Zune Video (WMV)</font></a><font face="Calibri" size="3"> </font></li>         </ul>       </td>     </tr>   </tbody></table>  <p><font face="Calibri" size="3">As always, customers experiencing issues installing any of the updates this month should contact our Customer Service and Support group:</font></p>  <p><font face="Calibri" size="3">Customers in the U.S. and Canada can receive technical support from Microsoft Customer Support Services at 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates.</font></p>  <p><font face="Calibri" size="3">International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the </font><a href="http://msdn.microsoft.com/en-us/library/ms955707.aspx"><font face="Calibri" size="3">International Support Web site</font></a><font face="Calibri" size="3">.</font></p>  <p><font face="Calibri" size="3">Please join us for our next live webcast on June 10, 2009 at 11:00 am PDT (UTC –7). Follow this link to pre-register:      <br /></font><a title="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032395225" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032395225"><font face="Calibri" size="3">http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032395225</font></a></p>  <p><font face="Calibri" size="3">Hope to see you then!</font></p>  <p><font face="Calibri" size="3">Jerry Bryant</font></p>  <p><font face="Calibri" size="3">*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.*</font></p>  <p><font face="Calibri" size="3"></font></p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3241910" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/05/15/security-bulletin-webcast-video-and-q-a-may-2009.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2009 Bulletin Release</title>
		<link>http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx</link>
		<comments>http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx#comments</comments>
		<pubDate>Tue, 12 May 2009 16:59:34 +0000</pubDate>
		<dc:creator>MSRCTEAM</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Monthly Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Security Update Webcast]]></category>
		<category><![CDATA[Security Update Webcast Q&A]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3239869</guid>
		<description><![CDATA[<p><b>Summary of Microsoft’s monthly security bulletin release for May 2009.</b></p>  <p>Today we released one security bulletin, <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a>, affecting our PowerPoint products. This update addresses several vulnerabilities including the issue described in <a href="http://www.microsoft.com/technet/security/advisory/969136.mspx">Microsoft Security Advisory 969136</a>. In that advisory, we noted that we were aware of limited, targeted attacks. </p>  <p>The security of our customers is important to us and due to these active attacks, we have released the updates for one product line (all versions of Microsoft Office for Windows) so that the majority of our customers can protect their systems. We are able to do this because the updates were ready within the predictable release cycle for the entire product line. Updates for the additional products (Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, Open XML File Format Converter for Mac, Microsoft Works 8.5 and Microsoft Works 9.0) will be released when testing is complete and we can ensure high quality. When ready, we will revise the bulletin and notify customers.</p>  <p><b>Risk and Impact</b></p>  <p>To help with risk assessment and impact analysis, Microsoft provides detailed information in the vulnerability information section of the bulletin as well as the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx">Exploitability Index</a>. The aggregate severity of the bulletin is critical and we give it a 1 on the Exploitability Index which means consistent exploit code is likely (and indeed already in the wild for one vulnerability in this update). Of the 14 vulnerabilities being addressed, there are some things to note:</p>  <ul>   <li>We are only (currently) aware of active attacks against CVE-2009-0556. </li>    <li>We are not aware (currently) of any active or reliable exploits of CVE-2009-0556 against affected versions of Office for Mac. </li>    <li>Microsoft Office 2007, Microsoft Office 2008 for Mac, Microsoft Office PowerPoint Viewers, and Microsoft Works versions 8.5 and 9.0 do not contain the CVE-2009-0556 vulnerability. </li>    <li>When we released Microsoft Security Advisory 969136 on April 2, 2009, both the <a href="http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx">Security Research &#38; Defense</a> and the <a href="http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx">Microsoft Malware Protection Center</a> (MMPC) teams posted analysis to their blogs. This information provides valuable insight in to the active exploits. </li>    <li>The bulletin is rated critical only for Microsoft Office PowerPoint 2000 SP3. All other versions have an aggregate rating of important. </li>    <li>The only vulnerability that affects all products in the affected products list is CVE-2009-0224. This vulnerability was responsibly disclosed, is rated critical on Microsoft Office PowerPoint 2000 SP3 and important for all the other affected products. </li> </ul>  <p><b>Mitigations and Workarounds</b></p>  <p>For mitigations and workarounds, I will simply reiterate the information previously stated in the Security Research &#38; Defense blog:</p>  <p>There are a couple workarounds you can apply in your environment to protect yourself from potential attacks. If your environment has mostly already migrated to using PPTX, you can temporarily disable the binary file format in your organization using the <a href="http://support.microsoft.com/kb/922848">FileBlock</a> registry configuration described in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> security bulletin. Alternatively, you can temporarily force all legacy PowerPoint files to open in the <a href="http://support.microsoft.com/kb/935865">Microsoft Isolated Conversion Environment (MOICE)</a>. The steps to enable MOICE are listed in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> security bulletin. </p>  <p><b>More Information</b></p>  <p>In the following 8 minute video, I sit down with Adrian Stone from the MSRC to cover this release in a little more detail:</p>  <table cellspacing="0" cellpadding="2" width="578" border="0"><tbody>     <tr>       <td valign="top" width="250">    <a href="http://go.microsoft.com/fwlink/?LinkID=124807"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </td>        <td valign="top" width="326">More viewing &#38; listening options:         <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.mp3">MP3 Audio</a></li>            <li><a href="//mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/7/9/2/MSRCMay09Overview_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>As always, our friends in the MSRC have provided further analysis in the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> so have a look at that and if you have questions, please join us for our regular live webcast tomorrow (Wednesday May 13, 2009) at 11:00 am PDT (UTC –7). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032395223">Click HERE to register</a>.</p>  <p>On the malware front, the Microsoft Malware Protection Center (MMPC) has added two new items to the Malicious Software Removal Tool (MSRT): <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan%3aWin32%2fWinwebsec">Win32/Winwebsec</a> and <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan%3aWin32%2fFakePowav">Win32/FakePowav.B</a>. Customers can download the Malicious Software Removal Tool (MSRT) <a href="http://www.microsoft.com/malwareremove">here</a>. Additional details can also be found on the <a href="http://blogs.technet.com/mmpc/">Microsoft Malware Protection Center blog</a>.</p>  <p><b>Support </b></p>  <p>Customers in the U.S. and Canada can receive technical support from <a href="http://go.microsoft.com/fwlink/?LinkId=21131">Security Support</a> or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates. For more information about available support options, see <a href="http://support.microsoft.com/">Microsoft Help and Support</a>.</p>  <p>International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the <a href="http://go.microsoft.com/fwlink/?LinkId=21155">International Support Web site</a>.</p>  <p>Thanks,</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &#34;AS IS&#34; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3239869" width="1" height="1"/>]]></description>
			<content:encoded><![CDATA[<p><b>Summary of Microsoft’s monthly security bulletin release for May 2009.</b></p>  <p>Today we released one security bulletin, <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a>, affecting our PowerPoint products. This update addresses several vulnerabilities including the issue described in <a href="http://www.microsoft.com/technet/security/advisory/969136.mspx">Microsoft Security Advisory 969136</a>. In that advisory, we noted that we were aware of limited, targeted attacks. </p>  <p>The security of our customers is important to us and due to these active attacks, we have released the updates for one product line (all versions of Microsoft Office for Windows) so that the majority of our customers can protect their systems. We are able to do this because the updates were ready within the predictable release cycle for the entire product line. Updates for the additional products (Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, Open XML File Format Converter for Mac, Microsoft Works 8.5 and Microsoft Works 9.0) will be released when testing is complete and we can ensure high quality. When ready, we will revise the bulletin and notify customers.</p>  <p><b>Risk and Impact</b></p>  <p>To help with risk assessment and impact analysis, Microsoft provides detailed information in the vulnerability information section of the bulletin as well as the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx">Exploitability Index</a>. The aggregate severity of the bulletin is critical and we give it a 1 on the Exploitability Index which means consistent exploit code is likely (and indeed already in the wild for one vulnerability in this update). Of the 14 vulnerabilities being addressed, there are some things to note:</p>  <ul>   <li>We are only (currently) aware of active attacks against CVE-2009-0556. </li>    <li>We are not aware (currently) of any active or reliable exploits of CVE-2009-0556 against affected versions of Office for Mac. </li>    <li>Microsoft Office 2007, Microsoft Office 2008 for Mac, Microsoft Office PowerPoint Viewers, and Microsoft Works versions 8.5 and 9.0 do not contain the CVE-2009-0556 vulnerability. </li>    <li>When we released Microsoft Security Advisory 969136 on April 2, 2009, both the <a href="http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx">Security Research &amp; Defense</a> and the <a href="http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx">Microsoft Malware Protection Center</a> (MMPC) teams posted analysis to their blogs. This information provides valuable insight in to the active exploits. </li>    <li>The bulletin is rated critical only for Microsoft Office PowerPoint 2000 SP3. All other versions have an aggregate rating of important. </li>    <li>The only vulnerability that affects all products in the affected products list is CVE-2009-0224. This vulnerability was responsibly disclosed, is rated critical on Microsoft Office PowerPoint 2000 SP3 and important for all the other affected products. </li> </ul>  <p><b>Mitigations and Workarounds</b></p>  <p>For mitigations and workarounds, I will simply reiterate the information previously stated in the Security Research &amp; Defense blog:</p>  <p>There are a couple workarounds you can apply in your environment to protect yourself from potential attacks. If your environment has mostly already migrated to using PPTX, you can temporarily disable the binary file format in your organization using the <a href="http://support.microsoft.com/kb/922848">FileBlock</a> registry configuration described in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> security bulletin. Alternatively, you can temporarily force all legacy PowerPoint files to open in the <a href="http://support.microsoft.com/kb/935865">Microsoft Isolated Conversion Environment (MOICE)</a>. The steps to enable MOICE are listed in the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">MS09-017</a> security bulletin. </p>  <p><b>More Information</b></p>  <p>In the following 8 minute video, I sit down with Adrian Stone from the MSRC to cover this release in a little more detail:</p>  <table cellspacing="0" cellpadding="2" width="578" border="0"><tbody>     <tr>       <td valign="top" width="250"><object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"> <param name="source" value="http://edge.technet.com/App_Themes/default/VideoPlayer2009_01_29.xap" /> <param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/7/9/2/MSRCMay09Overview_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_large_edge.png, postid=2977" /> <param name="background" value="#00FFFFFF" /> <a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object></td>        <td valign="top" width="326">More viewing &amp; listening options:         <br />          <ul>           <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.wmv">Windows Media Video (WMV)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.wma">Windows Media Audio (WMA)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_large_edge.png">Large Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_small_edge.png">Small Preview Image (PNG)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.mp4">iPod Video (MP4)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_edge.mp3">MP3 Audio</a></li>            <li><a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/7/9/2/MSRCMay09Overview_s_edge.wmv">Streaming WMV (512kbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_2MB_edge.wmv">High Quality WMV (2.5 Mbps)</a></li>            <li><a href="http://mschnlnine.vo.llnwd.net/d1/edge/7/7/9/2/MSRCMay09Overview_Zune_edge.wmv">Zune Video (WMV)</a></li>         </ul>       </td>     </tr>   </tbody></table>  <p>As always, our friends in the MSRC have provided further analysis in the <a href="http://blogs.technet.com/srd">Security Research and Defense blog</a> so have a look at that and if you have questions, please join us for our regular live webcast tomorrow (Wednesday May 13, 2009) at 11:00 am PDT (UTC –7). <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032395223">Click HERE to register</a>.</p>  <p>On the malware front, the Microsoft Malware Protection Center (MMPC) has added two new items to the Malicious Software Removal Tool (MSRT): <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan%3aWin32%2fWinwebsec">Win32/Winwebsec</a> and <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Trojan%3aWin32%2fFakePowav">Win32/FakePowav.B</a>. Customers can download the Malicious Software Removal Tool (MSRT) <a href="http://www.microsoft.com/malwareremove">here</a>. Additional details can also be found on the <a href="http://blogs.technet.com/mmpc/">Microsoft Malware Protection Center blog</a>.</p>  <p><b>Support </b></p>  <p>Customers in the U.S. and Canada can receive technical support from <a href="http://go.microsoft.com/fwlink/?LinkId=21131">Security Support</a> or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates. For more information about available support options, see <a href="http://support.microsoft.com/">Microsoft Help and Support</a>.</p>  <p>International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the <a href="http://go.microsoft.com/fwlink/?LinkId=21155">International Support Web site</a>.</p>  <p>Thanks,</p>  <p>Jerry Bryant</p>  <p>*This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights*</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3239869" width="1" height="1"/>]]></content:encoded>
			<wfw:commentRss>http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
