Windows Issues

Most recent Windows issues / vulnerabilities.
As you will see, many of the patches are marked bold and red.  This is done to make it clear to you,
when you scan down the page, just how many critical vulnerabilities are really endangering your computer(s),
and presenting opportunities for malware writers.  A casual sweep down the page tells an interesting story.

MOTIVATION: 95% of (KNOWN) malware CANNOT run on fully patched systems.
That means, however, that not only the operating system must be fully updated,
but of course also all other applications that you might have installed
.

News

Patch Tuesday, April 2010
MS10-019 (KB981210) Vulnerability in Windows could allow Remote Code Execution
MS10-020 (KB980232) Vulnerability in SMB Client could allow Remote Code Execution
MS10-021 (KB979683) Vulnerability in Windows Kernel could allow Elevation of Privilege 
MS10-022 (KB981210) Vulnerability in VBScript Scripting Engine could allow Remote Code Execution 
MS10-023 (KB981160) Vulnerability in MS Office Publisher could allow Remote Code Execution
MS10-024 (KB981832) Vulnerability in MS Exchange could allow Denial of Service 
MS10-025 (KB980858) Vulnerability in MS Windows Media Services could allow Remote Code Execution 
MS10-026 (KB977816) Vulnerability in MS MPEG Layer-3 Codecs could allow Remote Code Execution 
MS10-027 (KB979402) Vulnerability in Windows Media Player could allow Remote Code Execution 
MS10-028 (KB981210) Vulnerability in Windows could allow Remote Code Execution 
MS10-029 (KB978338) Vulnerability in Windows ISATAP Component could allow Spoofing

Out-of-Schedule Update, 30th March 2010
MS10-018 (KB981374) Internet Explorer cumulative update Critical
Intended to fix urgent issues for old browsers (IE6.0 + 7.0) this patch also partly applies to IE 8.0; so there!
Important for everyone, in reality.  C: more @:  TechEYE.net

Patch Tuesday, March 2010
MS10-016 (KB975561) Vulnerability in MS Windows Movie Maker could allow Remote Code Execution

Out-of-Schedule Update, 5th March 2010
(KB976002) MS Browser Choice Screen Update for EEA Users of Windows XP (NO Security Rating)
Anyway it's only for European users.  (Browser link is OK now.)

Out-of-Schedule Patches, 24th February 2010
(KB976662) Update for Java Script handling (CJSON feature) in Internet Explorer 8 Remote Code Execution 
(KB979306) Cumulative Time Zone Update  Important

Patch Tuesday, February 2010
MS10-003 (KB978214) Vulnerability in the MS Office  could allow Remote Code Execution 
MS10-004 (KB975416) Vulnerability in the MS Office (Powerpoint) could allow Remote Code Execution 
MS10-005 (KB978706) Vulnerability in the MS Paint could allow Remote Code Execution 
MS10-006 (KB978251) Vulnerability in SMB Client could allow Remote Code Execution
MS10-007 (KB975713) Vulnerability in Windows Shell Handler could allow Remote Code Execution 
MS10-008 (KB978762) Cumulative Security Update of Active Kill Bits
Critical 
MS10-009 (KB974145) Vulnerability in Windows TCP/IP could allow Remote Code Execution 
MS10-010 (KB977894) Vulnerability in Windows Server 2008 Hyper-V could allow Denial of Service 
MS10-011 (KB978037) Vulnerability in Windows Client/Server Run-time Subsystem could allow
Elevation of privilege 
MS10-012 (KB971468) Vulnerability in SMB Server could allow Remote Code Execution 
MS10-013 (KB977935) Vulnerability in MS DirectShow could allow Remote Code Execution
MS10-014 (KB977290) Vulnerability in Kerberos could allow
Denial of Service
MS10-015 (KB977165) Vulnerability in MS DirectShow could allow Remote Code Execution

Out-of-Schedule Patches, Thursday January 21
MS10-002 (KB978207) Cumulative update for IE CRITICAL
The "Google-China Syndrome" patch. Must be installed immediately.
C: more @ the Register: Google's China Syndrome

Out-of-Schedule Patches, Wednesday January 20
(KB979202) Silverlight update  IMPORTANT
Security, performance and reliability enhancements.
Just interesting, this popped up real fast, as if in conjunction with the reportedly
fast-coming IE update, perhaps a coincidence.


Patch Tuesday, January 2010
MS10-001 (KB972270) Vulnerability in the Embedded OpenType Font Engine could allow Remote Code Execution 

Patch Tuesday, December 2009
MS09-069 (KB974392) Vulnerability in Local Security Auth. System could allow Remote Code Execution 
MS09-070 (KB971726) Vulnerability Active Directory Federation Services could allow Remote Code Execution 
MS09-071 (KB974318) Vulnerability in Internet Authentication Service could allow Remote Code Execution 
MS09-072 (KB976325) Cumulative Security Update for Internet Explorer (Highly) Critical 
MS09-073 (KB975539) Vulnerability in Wordpad and Office Text Converters could allow Remote Code Execution 
MS09-074 (KB967183) Vulnerability MS Office Project could allow Remote Code Execution 

Out-of-Schedule Patches, Tuesday November 24
(KB973687) Extraneous DTD call prevention patch (1) IMPORTANT  
(KB973688) Extraneous DTD call prevention patch (2) IMPORTANT  
(KB976098) Revised Daylight Saving Time patch IMPORTANT

Patch Tuesday, November 2009
MS09-063 (KB973565) Vulnerability in Web Services on Devices API could allow Remote Code Execution 
MS09-064 (KB974793) Vulnerability in License Logging Server could allow Remote Code Execution 
MS09-065 (KB969947) Vulnerabilities Windows Kernel-mode Drivers could allow Remote Code Execution
MS09-066 (KB973309) Vulnerability in Active Directory could allow Denial of Service 
MS09-067 (KB972652) Vulnerability in MS Office Excel could allow Remote Code Execution 

Out-of-Schedule Patch, Tuesday, November 3, 2009
(KB976749) Update for IE 8.0 following security update 974455 (MS09-054)  Important

Patch Tuesday, October 2009
MS09-050 (KB975517) Vulnerabilities in SMBv2 could allow Remote Code Execution 
MS09-051 (KB955682) Vuln. in Windows Media Runtime could allow Remote Code Execution 
MS09-052 (KB974112) Vulnerabilities Windows Media Player could allow Remote Code Execution 
MS09-053 (KB965254) Vulnerabilities in FTP Service for IIS could allow Remote Code Execution 
MS09-054 (KB974455) Cumulative Security Update for Internet Explorer Critical 
MS09-055 (KB973525) Cumulative Security Update of ActiveX Kill Bits Critical 
MS09-056 (KB974571) Vulnerabilities in Windows CryptoAPI could allow Spofing 
MS09-057 (KB979059) Vulnerabilities in Indexing Service could allow Remote Code Execution 
MS09-058 (KB971486) Vulnerabilities in Windows Kernel could allow Elevation of Privilege 
MS09-059 (KB965467) Vulnerability in Local Security Auth. Subsys. Service could allow Denial of Service 
MS09-060 (KB973965) Vulnerabilities in Active Template Library (ATL) ActiveX could allow Remote Code Execution 
MS09-061 (KB974378) Vulnerabilities in MS .NET Common Lang. Runtime could allow Remote Code Execution 
MS09-062 (KB957488) Vulnerabilities in GDI+ could allow Remote Code Execution 

Patch Tuesday, September 2009
MS09-045 (KB971961) Vulnerability in JScripting Engine could allow Remote Code Execution 
MS09-046 (KB956844) Vuln. in DHTML Editing Component ActiveX Control could allow Remote Code Execution 
MS09-047 (KB973812) Vulnerabilities in Windows Media format could allow Remote Code Execution 
MS09-048 (KB967723) Vulnerabilities in Windows TCP/IP could allow Remote Code Execution 
MS09-049 (KB970710) Vulnerabilities in Wireless LAN AutoConfig Service could allow Remote Code Execution 

Out-of-Schedule Patch, Tuesday, August 28, 2009
(KB9701653) Cumulative Time Zone Update  Important

Patch Tuesday, August 2009
MS09-036 (KB970957) Vulnerability in ASP.NET in MS Windows could allow Denial of Service 
MS09-037 (KB973908) Vulnerabilities in MS Active Templ. Lib. (ATL) could allow Remote Code Execution 
MS09-038 (KB971557) Vulnerabilities in Windows Media File  Processing could allow Remote Code Execution 
MS09-039 (KB969883) Vulnerabilities in WINS could allow Remote Code Execution
MS09-040 (KB971032) Vulnerability in Message Queuing could allow Elevation of privilege
MS09-041 (KB971657) Vulnerability in Workstation Service could allow Elevation of Privilege
MS09-042 (KB960859) Vulnerability in Telnet could allow Remote Code Execution
MS09-043 (KB957638) Vulnerabilities in MS Office Web Components could allow Remote Code Execution 
MS09-044 (KB970927) Vulnerabilities in Remote Desktop Connection could allow Remote Code Execution

Urgent Out-of-Schedule Patches, Tuesday, July 28, 2009
MS09-034 (KB961051) Cumulative Security Update for Internet Explorer Critical 
MS09-035 (KB96706) Vuln. in Visual Studio Active Templ. libraries could allow Remote Code Execution

Patch Tuesday, July 2009
MS09-028 (KB971633) Vulnerabilities in MS direct Show could allow Remote Code Execution 
MS09-029 (KB961371) Vulnerabilities in Embedded Open Type Font Engine could allow Remote Code Execution 
MS09-030 (KB969516) Vulnerabilities in MS Office Publisher Show could allow Remote Code Execution 
MS09-031 (KB970953) Vulnerabilities in MS ISA Server 2006 Show could cause Elevation of Privilege 
MS09-032 (KB973346) Cumulative Security Update of ActiveX Kill Bits  Critical 
MS09-033 (KB969856) Vulnerability in MS Virtual PC & Virtual Server could allow Elevation of privilege

Patch Tuesday, June 2009
MS09-018 (KB961055) Vulnerabilities in Active Directory could allow Remote Code Execution
MS09-019 (KB969897) Cumulative update for IE          
Critical    
MS09-020 (KB970483) Vulnerabilities in IIS could allow   Elevation of Privilege 
MS09-021 (KB969462) Vulnerabilities in MS Office Excel could allow Remote Code Execution 
MS09-022
(KB961501) Vulnerabilities in Windows Print Spooler could allow Remote Code Execution 
MS09-023 (KB967340) Vulnerabilities in Windows Search could allow Information disclosure 
MS09-024 (KB957632) Vulnerabilities in MS Works (Home Version of Office) could allow Remote Code Execution 
MS09-025 (KB968537) Vulnerabilities in Windows Kernel Remote Code Execution
MS09-026
(KB970238) Vulnerabilities in RPC could allow Elevation of Privilege
 
MS09-027 (KB969514) Vulnerabilities in MS Office Word could allow Remote Code Execution

Patch Tuesday, May 2009
MS09-017 (KB967340) Vulnerabilities in MS Office Excel could allow Remote Code Execution 

Patch Tuesday, April 2009
MS09-009 (KB968557) Vulnerabilities in MS Office Excel could cause Remote Code Execution 
MS09-010 (KB960477) Vulnerabilities in Wordpad and Office text converters could allow Remote Code Execution  
MS09-011 (KB961373) Vulnerability in MS DirectShow could allow Remote Code Execution 
MS09-012 (KB959454) Vulnerabilities in Windows could allow Elevation of Privilege
MS09-013 (KB960803) Vulnerabilities in Windows HTTP Services could allow Remote Code Execution  
MS09-014 (KB963027) Cumulative Security Update for Internet Explorer
Critical 
MS09-015 (KB959426) Blended Threat Vuln. in SearchPath could allow Elevation of Privilege
MS09-016 (KB959420) Vulnerabilities in ISA Server & Forefront Threat Mgt. Gtw. could cause Elevation of Privilege

Patch Tuesday, March 2009
MS09-006 (KB961260) Vulnerabilities in Windows Kernel could allow Elevation of Privilege
MS09-007 (KB959239) Vulnerabilities in SChannel could allow Spoofing

MS09-008 (KB959420) Vulnerabilities in DNS and WINS Server could allow Spoofing

Patch Tuesday, February 2009
MS09-003 (KB959239) Vulnerabilities in MS Exchange could allow Remote Code Execution
MS09-004 (KB959420) Vulnerabilities in MS SQL could allow Remote Code Execution
MS09-005 (KB957634) Vulnerabilities in MS Office Visio could allow Remote Code Execution

Patch Tuesday, January 2009
MS09-001 (KB958687) Vulnerabilities in SMB could allow Remote Code Execution
MS09-002 (KB961260) Cumulative security update for Internet Explorer Critical


Urgent Out-of-Schedule Patch, Wednesday, December 17, 2008
MS08-078 (KB961051) Vulnerability in Internet Explorer could allow Remote Code Execution
As always, there is a good short article at the Inquirer, here

Patch Tuesday, December 2008
MS08-070 (KB932349) Vulnerabilities in Visual Basic 6.0 Runtime (ActiveX Controls) could allow Remote Code Execution
MS08-071 (KB956802) Vulnerabilities in GDI could allow Remote Code Execution
MS08-072 (KB957173) Vulnerabilities in Microsoft Office Word could allow Remote Code Execution
MS08-073 (KB958215) Cumulative Security Update for Internet Explorer - Critical
MS08-074 (KB959070) Vulnerabilities in Microsoft Office Excel could allow Remote Code Execution
MS08-075 (KB959349) Vulnerabilities in Windows Search (optional component) could allow Remote Code Execution
MS08-076 (KB959807) Vulnerabilities in Windows Media Components could allow Remote Code Execution
MS08-077 (KB957175) Vulnerability in Microsoft Office SharePoint Server could allow Elevation of Privilege

Patch Tuesday, November 2008
MS08-068 (KB957097) Vulnerability in SMB could allow Remote Code Execution
MS08-069 (KB955218) Vulnerabilities in Microsoft XML Core Services could allow Remote Code Execution

Urgent Out-of-Schedule PatchTuesday, October 23, 2008
MS08-067 (KB958644) Vulnerability in Server Service could allow Remote Code Execution

Patch Tuesday, October 2008
MS08-056 (KB957699) Vulnerabilities in Microsoft Office could allow Information Disclosure
MS08-057 (KB956416) Vulnerability in Microsoft Excel could allow Remote Code Execution
MS08-058 (KB956390) Cumulative Security Update for Internet Explorer - Critical
MS08-059 (KB956695) Vulnerability in Host Integration Server RPC Service could allow Remote Code Execution
MS08-060 (KB954211) Vulnerability in Active Directory could allow Remote Code Execution
MS08-061
(KB954211) Vulnerability in Windows Kernel could allow Elevation of Privilege

MS08-062 (KB953155) Vulnerability in Windows Internet Printing Service could allow Remote Code Execution
MS08-063 (KB957095) Vulnerabilities in SMB could allow Remote Code Execution
MS08-064 (KB956841) Vulnerabilities in Virtual Address Descriptor Manipulation could allow Elevation of Privilege
MS08-065 (KB951071) Vulnerabilities in Message Queuing could allow Elevation of Privilege
MS08-066 (KB956803) Vulnerabilities in Microsoft Ancillary Function Driver could allow Elevation of Privilege

Patch Tuesday, September 2008
MS08-052 (KB954593) Vulnerabilities in GDI+  could allow Remote Code Execution
MS08-053 (KB954156) Vulnerability in Windows Media Encoder 9 could allow Remote Code Execution
MS08-054 (KB954154) Vulnerability in Windows Media Player could allow Remote Code Execution
MS08-055 (KB955047) Vulnerability in Microsoft Office could allow Remote Code Execution

Patch Tuesday, August 2008
EEYE has noted attacks re. MS08-41 and 42 prior to Microsoft's release of these two patches.
MS08-041 (KB955617) Vulnerability in ActiveX Control for Snapshot Viewer (Access) could allow Remote Code Execution
MS08-042 (KB955048) Vulnerability in Microsoft Word could allow Remote Code Execution
MS08-043 (KB954066) Vulnerability in Microsoft Excel could allow Remote Code Execution
MS08-044 (KB924090) Vulnerability in Microsoft Office Filters could allow Remote Code Execution
MS08-045 (KB953838) Cumulative Security Update for Internet Explorer Critical
MS08-046 (KB952954) Vulnerability in Ms Windows Image Color Mgt. System could allow Remote Code Execution
MS08-047 (KB953733) Vulnerability in IPsec Policy Processing could allow Information Disclosure
MS08-048 (KB951066) Security Update for Outlook Express and Windows Mail - Important
MS08-049 (KB949785) Event System could allow Remote Code Execution
MS08-050 (KB955702) Vulnerability in Windows Messenger  could allow Information Disclosure
MS08-051 (KB949785) Vulnerability in Microsoft PowerPoint could allow Remote Code Execution

Patch Tuesday, July 2008 (11th July update)
MS08-037 (KB953230+KB951748) Vulnerabilities in DNS could allow Spoofing (IMPORTANT)
Warning: Please TEST this patch thoroughly before implementing! Seems to be incompatible
with ZoneAlarm Security Suite 70-470-000 and previous version.

293 complaints at CheckPoint's site full of VERY angry, soon-to-be-ex-customers vent their
frustration with a very inept response to a serious product error. A very typical example
of a reaction of today's support collapse is 'Big_Tom's blog entry. Says it all, really. . .
That worked!  Late 10th, July Checkpoint Technology found the time to put out a warning,
and later, to issue a new version, 70-483-000 which reestablishes the functionality.

MS08-038 (KB950582) Vulnerability in Windows Explorer could allow Remote Code Execution
MS08-039 (KB950762) Vulnerabilities in Pragmatic General Multicast (PGM) could allow Denial of Service
MS08-040 (KB950759) Vulnerabilities in MS-SQL Server could allow Elevation of Privilege

Patch Tuesday, June 2008
MS08-030 (KB951376) Vulnerability in Bluetooth Stack could allow Remote Code Execution 
MS08-031 (KB950759) Cumulative security update for Internet Explorer (Critical)
MS08-032 (KB950760) Cumulative security update of ActiveX Kill Bits (Moderate)
MS08-033 (KB951698) Vulnerabilities in DirectX could allow Remote Code Execution
MS08-034 (KB958745) Vulnerability in WINS could allow Denial of Service  
MS08-035 (KB953235) Vulnerability in Active Directory could allow Denial of Service
MS08-036 (KB950762) Vuln. in Pragmatic General Multicast (PGM) Engine could allow Denial of Service

Patch Tuesday, May 2008
MS08-026 (KB951207) Vulnerabilities in MS-Word could allow Remote Code Execution 
MS08-027 (KB951208) Vulnerabilities in MS-Publisher could allow Remote Code Execution  
MS08-028 (KB950749) Vulnerabilities in MS Jet Database Engine could allow Remote Code Execution
MS08-029 (KB952044) Vulnerabilities in MS Malware Protection Engine could allow Denial of Service


Patch Tuesday, April 2008
MS08-018 (KB950183) Vulnerability in MS-Project could allow Remote Code Execution 
MS08-021 (KB948590) Vulnerabilities in MS-Outlook could allow Remote Code Execution 
MS08-022 (KB944338) Vulnerabilities in VBScript & JScript SE's could allow Remote Code Execution
MS08-023 (KB948881) Security update of Active X Kill Bits (Critical) 
MS08-024 (KB947864) Cumulative security update for Internet Explorer (Critical)
MS08-019 (KB949032) Vulnerabilities in MS-Visio could allow Remote Code Execution
MS08-020 (KB945553) Vulnerability in DNS Client could allow Spoofing
MS08-025 (KB941693) Vulnerability in Windows Kernel could allow Elevation of Privilege


Patch Tuesday, March 2008
MS08-014 (KB949029) Vulnerabilities in MS-Excel could allow Remote Code Execution
MS08-015 (KB949031) Vulnerabilities in MS-Outlook could allow Remote Code Execution
MS08-016 (KB949030) Vulnerabilities in MS-Office could allow Remote Code Execution
MS08-017 (KB947077) Vulnerabilities in MS-Word could allow Remote Code Execution


Patch Tuesday, February 2008
MS08-007 (KB946026) Vuln. in WebDAV Mini-Redirector could allow Remote Code Execution
MS08-008 (KB947890) Vulnerabilities in OLE Automation could allow Remote Code Execution
MS08-009 (KB947077) Vulnerabilities in MS-Word could allow Remote Code Execution
MS08-010 (KB944533) Cumulative Sec. Update for Internet Explorer (Remote Code Execution)
MS08-012 (KB947085) Vulnerabilities in MS-Publisher could allow Remote Code Execution
MS08-013 (KB947108) Vulnerabilities in MS-Office could allow Remote Code Execution

MS08-003 (KB946538) Vulnerabilities in ACTIVE DIRECTORY could allow Denial of Service
MS08-004 (KB946456) Vulnerabilities in Windows TCP/IP  could allow Elevation of Privilege
MS08-005 (KB942831) Vulnerabilities in I I S  could allow Elevation of Privilege
MS08-006 (KB942830) Vulnerabilities in I I S could allow Remote Code Execution
MS08-011 (KB947081) Vulnerabilities in MS-Works File Converter could allow Remote Code Execution


Patch Tuesday, January 2008
MS08-001 (KB941644) Vulnerabilities in Windows TCP/IP could allow Remote Code Execution
MS08-002 (KB943485) Vulnerabilities in LSASS TCP/IP could allow Elevation of Privilege


Patch Tuesday, December 2007
MS07-064 (KB941568) Vulnerabilities in DirectXI could allow Remote Code Execution
MS07-068 (KB941569/944275) Vulnerability in WMF Format could allow Remote Code Execution
MS07-069 (KB942615) Cumulative Security Update for Internet Explorer (Critical)
MS07-063 (KB942624) Vulnerabilities in SMBv2 could allow Remote Code Execution
MS07-065 (KB937894) Vulnerabilities in Message Queuing could allow Remote Code Execution
MS07-066 (KB943078) Vulnerabilities in Windows Kernel could allow Elevation of Privilege
MS07-067 (KB944653) Vulnerabilities in Macrovision Driver could allow local Elevation of Privilege

Out-of-Schedule Issue, 4th December 2007
The Sydney Morning Herald details in this article a very serious vulnerability in MS Internet Explorer,
which originates in the way that IE automatically processes proxy settings.  This vulnerability is critical
- originally discovered in 1999 and thought to be fixed, has surfaced again. Lately, thousands of internet
users in Britain were redirected to an online auction site when a criminal hacked wpad.co.uk and used the
website to serve up bogus configuration information that redirected hijacked browsers to an online auction site,
eebuy.co.uk. 
Please apply remedial actions detailed below immediately - as no PATCH has been issued yet.

(KB945713) Internal Errors in WeB Proxy Auto-Discovery (WPAD) processing could allow Remote Code Execution
The Original security bulletin from December 1999 is here:
MS99-054 (KB247333) WPAD Spoofing (Critical )

Patch Tuesday, November 2007
MS07-061 (KB923810) Vulnerabilities in Windows URI could allow Remote Code Execution
MS07-062 (KB941202) Vulnerability in DNS could allow Spoofing (Medium - or perhaps, Critical )
This vulnerability is critical if it is successfully exploited, particularly in conjunction with
advanced botnets, and just now the 4 STORM offspring botnets, plus the remainder of the original
STORM net, would be prime users of this vulnerability.  For this reason, this vulnerability might
have to be regarded as CRITICAL.


Patch Tuesday, October 2007
MS07-055 (KB923810) Vulnerabilities in Kodak Image Viewer could allow Remote Code Execution
MS07-056 (KB941202) Security Update for Outlook Express and Windows Mail (Critical)
MS07-057 (KB939653) Cumulative Security Update for Internet Explorer (Critical)
MS07-060 (KB942695) Vulnerability in Microsoft Word could allow Remote Code Execution
MS07-058 (KB933729) Vulnerability in RPC could allow Denial of Service
MS07-059 (KB942017) Vulnerability in SharePoint & Office SharePoint Svr. could allow Elevation of Privilege


Patch Tuesday, September 2007
MS07-051 (KB938827) Vulnerability in Microsoft Agent could allow Remote Code Execution
MS07-052 (KB941522) Vuln. in Crystal Reports for Visual Studio could allow Remote Code Execution
MS07-053 (KB939778) Vulnerability in Windows Services for UNIX could allow Remote Code Execution
MS07-054 (KB942099) Vulnerability in MSN and Windows Live Messengers could allow Remote Code Execution

Patch Tuesday, August 2007
MS07-042 (KB936227) Vulnerabilities in Microsoft Core Services could allow Remote Code Execution
MS07-043 (KB921503) Vuln. in in OLE Automation could allow  Remote Code Execution
MS07-044 (KB940965) Vulnerability in Microsoft Excel could allow Remote Code Execution
MS07-045 (KB937143) Cumulative Security Update for Internet Explorer - Remote Code Execution
MS07-046( KB938829) Vulnerability in GDI could allow Remote Code Execution
MS07-047 (KB936782) Vulnerabilities in Windows Media Player  could allow Remote Code Execution
MS07-048 (KB938123) Vulnerabilities in Windows Gadgets could allow Remote Code Execution

MS07-049 (KB937986) Vuln. in Virtual PC and Virtual Server could allow Elevation of Privilege
MS07-050 (KB938127) Vulnerabilities in Vector Markup Language could allow Remote Code Execution

VISTA - Admission from Microsoft - finally, 26th July 2007
As everyone knows, VISTA has not been the most successful software release, but it is a significant
step to take for Microsoft to publicly admit failure.  The Register discusses the issues and point to
the fact, that only 650 applications were VISTA ready by the time of launch - an all time low.

Patch Tuesday, July 2007
MS07-036 (KB936542) Vulnerabilities in Microsoft Excel could allow Remote Code Execution
MS07-037 (KB936548) Vuln. in Microsoft Office Publisher 2007 could allowRemote Code Execution
MS07-038 (KB935807) Vulnerability in VISTA Firewall could Allow Information Disclosure
MS07-039 (KB926122) Vulnerability in Active Directory could Allow Remote Code Execution
MS07-040 (KB931212) Vulnerabilities in .NET Framework could Allow Remote Code Execution

Nothing like OLD news, right?
Just revisiting  Secunia's finding back from 24th August 2005 about HIDDEN REGISTRY KEYS. 
The bad news: This issue has still seems not to have been fixed.
It is relatively serious, as overly long registry entries can be made invisible to the standard registry
editor regedit.  The article at SANS Internet Storm Center is still very interesting.  Today's stronger
(best-of-breed) anti malware solutions should be able to identify such entries, however.
 
Patch Tuesday, June 2007

MS07-030 (KB927051)Vulnerabilities in Microsoft Visio could allow Remote Code Execution
MS07-031 (KB935840) Vuln. in the Windows Schannel Sec. Pckg. could allowRemote Code Execution
MS07-032 (KB931213) Vulnerability in Windows Vista Could Allow Information Disclosure
MS07-033 (KB933566) Cumulative Update for Internet Explorer Several Critical Issues
MS07-034 (KB929123) Cumulative Sec. Upd for Outlook Express & Windows Mail Critical - 4 issues
MS07-035 (KB935839) Vulnerability in Win32 API could allow Arbitrary Code to Run

Patch Tuesday, May 2007

(No MS-no) (KB930916) Error message when you try to open files on a NTFS file system volume on
a Windows XP-based computer: "Stop 0x0000008E" (Serious reliability issue) (Was part of monthly upd. for WGA-customers)
MS07-023 (KB934453) A security vulnerability exists in MS Excel 2002 that could allow Remote Code Execution
MS07-024 (KB934394) Vulnerability in Microsoft Word 2002 that could allow Arbitrary Code to Run
MS07-025 (KB934705) Vulnerability in Microsoft Office XP that could allow Remote Code Execution
MS07-026 (KB931832) Vulnerabilities in Microsoft Exchange could cllow Remote Code Execution
MS07-027 (KB931768) Cumulative Security Update for Internet Explorer Critical
MS07-028 (KB931906) Vulnerability in CAPICOM could allow Remote Code Execution
MS07-029 (KB935966)  Vulnerability in Windows DNS RPC Interface could sllow Remote Code Execution

Patch Tuesday, April 2007
MS07-022 (KB931784)Kernel vulnerability that could allow full control and Remote Code Execution
MS07-021 (KB930178) Vulnerabilities in CSRSS could allow Remote Code Execution 
MS07-019 (KB931261) Vulnerability in Universal P & Play could allow Remote Code Execution 
MS07-020 (KB932168) Vulnerability in Microsoft Agent could allow Remote Code Execution
A day later, the Malicious Software Removal tool was distributed - Microsoft apparently being too
busy getting it ready for the normal schedule. No publicity about this fact, however.

Urgent Out-of-Schedule Patch April 2007
MS07-017 (KB925902) Vulnerabilities in GDI could allow Remote Code Execution
This critical patch was issued by Microsoft 3rd April 2007, and is a patch-for-a-patch...
Yes, it's been seen many times before, strengthening the question marks against Microsoft's
product testing and verification methods. Worrying for private as corporate users alike.
The scandal, yes - it is a scandal, about this patch is very well written in George Ou's blog at
TechRepublic: "Why Is Microsoft Hell-bent on Ruining It's Reputation?"
Furthermore, it's a global patch: It applies to VISTA as well as XP, the server 200X family and 2000SP4!
The patch concerns a stack-based buffer overflow in the animated cursor code in Microsoft Windows
2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service
(persistent reboot) via a malformed .ANI, cur, or .ico file, which results in memory corruption when
processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally
demonstrated using Internet Explorer 6 and 7.
The patch has been issued out-of-schedule due to an alarming rise in actual uses of this exploit, so
the advice from MS, CA and F-Secure is to PATCH RIGHT NOW! 

30 Days with Windows VISTA
April 2007 + May 2007
There's a very good and very in depth article over at HardOCP about installing and using VISTA
for actual work, multimedia and gaming, both 32-bit and 64-bit.  It is a long 9-pager, but very
accurate and balanced in its observations - this is not a Microsoft-bashing exercise.   Highly
recommended for those who might consider  VISTA a replacement for their daily work OS. 
Hint: VISTA is not nearly there yet; our own observations with VISTA Business (32-bit, for
maximum compatibility with XP-based software) also indicate sudden re-boots, installation
problems, general non-functionality, and a frustrating user interface for other than novice
user tasks.

UPDATE: VISTA's Long Goodbye Deleting files in VISTA can take HOURS for large multi-media
files... Apparently a result of either a basic construction flaw or a result of DRM measures
(often called DRM infection by now).  This article at The Register explains the details. 
This is not just a user issue. Corporations need to make sure this issue is corrected before
any roll-out takes place.

Patch Tuesday, March 2007- a day that never came!!!
  March 2007
They've done it again!!  Microsoft once again slips up the patching schedule.
N F C (That is: No FURTHER Comments) . . .

Mpas-d.exe, who's that? 
February 2007
Answer: It is part of Defender - so not a module to worry about. However, you should always pay
attention to unexpected launches of seemingly known modules. It always pays to have a bit of healthy
skepticism, when "strange" things happen in your (XP) system...

VISTA Secure?
February 2007
A very good article in The Register details the user experience and the security implications.
The main culprit is the UAC, much discussed elsewhere, but also IE 7.0 gets a thorough going-over.
The between-the-lines conclusion is: wait for Vienna or maybe a very restructured security
architecture in VISTA-SP1, being a bit naive & hopeful, perhaps? 

Patch Tuesday, February 2007
Critical

MS07-008 - Vulnerability in HTML Help ActiveX Control could allow Remote Code Execution
MS07-009 - Vulnerability in Microsoft Data Access Components could allow Remote Code Execution
MS07-010 - Vulnerability in Microsoft Malware Protection Engine could allow Remote Code Execution
MS07-014 - Vulnerabilities in Microsoft Word could allow Remote Code Execution
MS07-015 - Vulnerabilities in Microsoft Office could allow Remote Code Execution
MS07-016 - Cumulative Security Update for Internet Explorer

Important
MS07-005 - Vulnerability in Step-by-Step Interactive Training could allow Remote Code Execution
MS07-006 - Vulnerability in Windows Shell could allow Elevation of Privilege
MS07-007 - Vulnerability in Windows Image Acquisition Service could allow Elevation of Privilege
MS07-011 - Vulnerability in Microsoft OLE Dialog could allow Remote Code Execution
MS07-012 - Vulnerability in Microsoft MFC could allow Remote Code Execution
MS07-013 - Vulnerability in Microsoft RichEdit could allow Remote Code Execution


-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, January 2007
Critical
MS07-002 - Vulnerabilities in Microsoft Excel could allow Remote Code Execution
MS07-003 - Vulnerabilities in Microsoft Outlook could allow Remote Code Execution
MS07-004 - Vulnerability in Vector Markup Language could allow Remote Code Execution

Important
MS07-001 - Vulnerability in Microsoft Office 2003 Brazilian Portuguese Grammar Checker
                 Could Allow Remote Code Execution

-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, December 2006
Critical
MS06-072 - Cumulative Security Update for Internet Explorer
MS06-073 - Vulnerability in Visual Studio 2005 could allow Remote Code Execution
MS06-078 - Vulnerability in Windows Media Format could allow Remote Code Execution
MS06-059 - Re-Release: Vulnerabilities in Excel could allow Remote Code Execution

Important
MS06-074 - Vulnerability in SNMP could allow Remote Code Execution
MS06-075 - Vulnerability in Windows could allow Elevation of Privilege
MS06-076 - Cumulative Security Update for Outlook Express
MS06-077 - Vulnerability in Remote Installation Service could allow Remote Code Execution

-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, November 2006
MS06-067 - Cumulative Security Update for Internet Explorer Remote Code Execution
                 
This is the all-important update to 3 different vulnerabilities, each of them serious.
                  The most noted KB927892 (below).
MS06-068 - Vulnerability in Microsoft Agent could allow Remote Code Execution
MS06-069 - Vulnerabilities in Macromedia Flash Player from Adobe could allow Remote Code Execution
MS06-070 - Vulnerability in Workstation Service could allow Remote Code Execution
MS06-071 - Vulnerability in Microsoft XML Core Services could allow Remote Code Execution

Open vulnerability in Microsoft's XML Core Services XMLHTTP ActiveX control


Link to Microsoft's Security Advisory (KB927892)
Vulnerability in Microsoft XML Core Services could allow Remote Code Execution.
Microsoft has now admitted that a critical vulnerability exists in the above ActiveX control.

The vulnerability is being used right now by several hackers, and both Secunia and US-CERT
report of sightings in the wild.

This is not the first vulnerability in exactly this area. Back in February 2002 this was patched:

A properly patched Windows system may not be completely exposed, but the following advice
should prevent infection:
Do not open links in-mails, and block the use of ActiveX until a patch has been published.

Patch Tuesday, October 2006
MS06-057 - Vulnerability in Windows Shell could allow Remote Code Execution
MS06-058  - Vulnerabilities in Microsoft PowerPoint could Lead to Remote Code Execution
MS06-059 - Vulnerabilities in Microsoft Excel could allow Remote Code Execution
MS06-060  - Vulnerability in Microsoft Word could allow Remote Code Execution
MS06-061  - Vulnerabilities in Microsoft XML Core Services could allow Remote Code Execution
MS06-062  - Vulnerabilities in Microsoft Office could lead to Remote Code Execution
MS06-063  - Vulnerability in Server Service could allow Denial of Service
MS06-056
  - Vulnerability in ASP.NET could allow Information Disclosure
MS06-065
 - Vulnerability in Windows Object Packager could allow Remote Execution
MS06-064  - Vulnerability in TCP-IP IPv6 could result in Denial of Service

--------------------------------------------------------------------------------------------------------------------
URGENT: Out-of-schedule Patch
MS06-055 (KB925486) A security issue has been identified in the way Vector Markup Language
(VML) is handled that could allow an attacker to compromise a computer running Microsoft
Windows and gain control over it. Remote Code Execution
Rated Critical and for immediate implementation.
--------------------------------------------------------------------------------------------------------------------

Patch Tuesday, September 2006
MS06-052
Vulnerability in Pragmatic General Multicast (PGM) could allow Remote Code Execution
MS06-053 Vulnerability in Indexing Service could allow Cross-Site Scripting
Vulnerability in Indexing Service could allow Cross-Site Scripting (Not critical)
Audio playback does not play the audio file from the correct position after you pause
Error message when you try to update a Microsoft Windows-based computer: "0x80070002"
MS06-054 Vulnerability in Microsoft Publisher could allow Remote Code Execution

The only critical patch this month was MS06-054, and, just like the Excel and Word issues,
requires the user to open a malformed file.  The other patches this month are both taken
care of by other prudent security measures. So, it was a very easy month this time also.

--------------------------------------------------------------------------------------------------------------------

URGENT: Out-of-schedule Patch for the MS06-042 Patch
A patch for the patch; it's happened a number of times before.
To quote Microsoft: "Security issues have been identified that could allow an attacker to
compromise a computer running Microsoft Internet Explorer and gain control over it
." 
 In other words: Remote Code Execution
Direct download at: Cumulative Update for Internet Explorer 6 SP1 (KB918899)   

This is yet another example of why staying alert re. security issues can be very important;
as soon as a patch is released the "zero-day/hour" count starts (unless publicly available
code/exploit was already available).  So we shall see how soon examples appear in the wild. 
 The potential victims are of course all users who do not apply such important patches immediately
 A very important issue for business, who rely on the well-functioning (remote) systems of their customers.

--------------------------------------------------------------------------------------------------------------------

Patch Tuesday, August 2006
A large event involving what proved to be a block buster vulnerability (MS06-040)
which was used by malware writers to create  "wgareg.exe" and  "wgavm.exe".
Antivirus vendors have named this threat W32.Wargbot (Symantec), Worm.IRCBOT.JK/JL
(Trend Micro), IRC.Mocbot (McAfee), and IRCBOT-ST (F-Secure).
The use of the wga prefix supposedly served to mask the process for the semi-technically
minded user population.  
 
The full list, the critical first:
MS06-040 - Vulnerability in Server Service could allow Remote Code Execution
MS06-041 - Vulnerability in DNS Resolution could allow Remote Code Execution
MS06-042 - Cumulative Security Update for Internet Explorer
MS06-043 - Vulnerability in Microsoft Windows could allow Remote Code Execution
MS06-044 - Vulnerability in Microsoft Management Console could allow Remote Code Execution
MS06-046 - Vulnerability in HTML Help could allow Remote Code Execution
MS06-047 - Vulnerability in Microsoft Visual Basic for Applications could allow Remote Code Execution
MS06-048 - Vulnerabilities in Microsoft Office could allow Remote Code Execution
MS06-051 - Vulnerability in Windows Kernel could result in Remote Code Execution

Rated as moderate:
MS06-045 - Vulnerability in Windows Explorer could allow Remote Code Execution
MS06-049 - Vulnerability in Windows Kernel could result in Elevation of Privilege
MS06-050 - Vulnerabilities in Microsoft Windows Hyperlink Object Library could allow Remote Code Execution

The negative news:
1. Everyone is once again reminded of the narrowing test & patch window.  Corporate procedures
   need updating to ensure that parches are installed as quickly as possible following publication from
   Microsoft.  Many companies have a 7-day window which has not been adequate for some time now.
   This could be the business case mandating a sweeping change.  

2. There were 10 (T E N) vulnerabilities related to remote code execution (!)
   Microsoft sets a new record here - for a single month.

3. It is disturbing that at this late stage in the product's life such an amount of serious security issues can
    be found.  Please also remember that the growth in malware focuses exactly on this type of vulnerability,
    not jut the actual example re. MS06-040, but the majority of new malware of 2006 up till now!

The positive news:
AV companies are getting better prepared at the more focused efforts from Virus writers.
Microsoft has a strong focus on eliminating vulnerabilities, and each new vulnerability discovered
in Windows XP hopefully ensures a better Windows VISTA.  A possible problem with this assumption is
that VISTA is written from the ground up. Thus there is no guarantee that experience with XP vulnerability
remedies can be directly transferred to the (now) finishing stages of work on the VISTA product.


--------------------------------------------------------------------------------------------------------------------
Patch Tuesday, July 2006
A relatively successful update with 2 very interesting critical updates:
MS06-038

Vulnerability in Microsoft Office could allow Remote Code Execution (915384)
http://www.microsoft.com/technet/security/bulletin/MS06-038.mspx
A very relevant anti-malware update -and relevant for all users of Microsoft Office,
ALSO for the APPLE users.

MS06-039
Vulnerability in Microsoft Office could allow Remote Code Execution (915384)
http://www.microsoft.com/technet/security/bulletin/MS06-039.mspx
As above and equally important.
The other updates were mostly related to servers  - no less important.

--------------------------------------------------------------------------------------------------------------------
"Best of 2005":
Patch Tuesday, September 2005 - a day that never came!!! 

This short note was available on the updated Microsoft update site - after pulling the statement:
"Late in the testing process, Microsoft encountered a quality issue that necessitated the update
to go through additional testing and development before it is released
,-"  from the site replacing
it with the above.  The problem for Windows users is that one of the critical patches was a
"wormable" vulnerability (discovered by eEye) JUST as serious as the MS05-039!  Windows users will
have to live in the vain hope no-one really finds out what this one was about until Microsoft is good
and ready to let everyone patch up properly. . . 

 

(back)
 

Send mail to admin@StealthSecure.net with questions or comments about this web site.
Copyright © 2005 - 2010 StealthSecure.net - Copyright of all documents and other content belonging to this site by StealthSecure.net. 
It is illegal to copy or redistribute this information in any way without the expressed written consent of StealthSecure.net.
Adverse consequences of the uses of, or reliance upon, information obtained from StealthSecure.net cannot be made
attributable to the owner(s) of StealthSecure.net.                                                                          Last modified: 01/02/10