|

Windows Issues
Most recent Windows issues / vulnerabilities.
As you will see, many of the patches are marked bold and
red. This is done to make it clear to you,
when you scan down the page, just how many critical vulnerabilities are really
endangering your computer(s),
and presenting opportunities for malware writers. A casual sweep down the
page tells an interesting story.
MOTIVATION: 95% of (KNOWN) malware CANNOT run on fully patched systems.
That means, however, that not only the operating system must be fully updated,
but of course also all other applications that you might have installed.
News
Patch Tuesday, April 2010
MS10-019 (KB981210) Vulnerability in Windows could allow
Remote Code Execution
MS10-020 (KB980232) Vulnerability in SMB Client could allow
Remote Code Execution
MS10-021 (KB979683) Vulnerability in Windows Kernel could allow
Elevation of Privilege
MS10-022 (KB981210) Vulnerability in VBScript Scripting Engine could allow
Remote Code Execution
MS10-023 (KB981160) Vulnerability in MS Office Publisher could allow
Remote Code Execution
MS10-024 (KB981832) Vulnerability in MS Exchange could allow
Denial of Service
MS10-025 (KB980858) Vulnerability in MS Windows Media Services could allow
Remote Code Execution
MS10-026 (KB977816) Vulnerability in MS MPEG Layer-3 Codecs could allow
Remote Code Execution
MS10-027 (KB979402) Vulnerability in Windows Media Player could allow
Remote Code Execution
MS10-028 (KB981210) Vulnerability in Windows could allow
Remote Code Execution
MS10-029 (KB978338) Vulnerability in Windows ISATAP Component could allow
Spoofing
Out-of-Schedule Update, 30th March 2010
MS10-018 (KB981374) Internet Explorer cumulative update
Critical
Intended to fix urgent issues for old browsers (IE6.0 + 7.0) this patch also
partly applies to IE 8.0; so there!
Important for everyone, in reality. C: more @:
TechEYE.net
Patch Tuesday, March 2010
MS10-016 (KB975561) Vulnerability in MS Windows Movie Maker could allow
Remote Code Execution
Out-of-Schedule Update, 5th March 2010
(KB976002)
MS Browser Choice Screen Update for EEA Users of Windows XP
(NO Security Rating)
Anyway
it's only for European users. (Browser link is OK now.)
Out-of-Schedule Patches, 24th February 2010
(KB976662) Update for Java
Script handling (CJSON feature) in Internet Explorer 8
Remote Code Execution
(KB979306) Cumulative Time
Zone Update
Important
Patch Tuesday, February 2010
MS10-003 (KB978214) Vulnerability in the MS Office
could allow
Remote Code Execution
MS10-004 (KB975416) Vulnerability in the MS Office (Powerpoint)
could allow
Remote Code Execution
MS10-005 (KB978706) Vulnerability in the MS Paint
could allow
Remote Code Execution
MS10-006 (KB978251) Vulnerability in SMB Client
could allow
Remote Code Execution
MS10-007 (KB975713) Vulnerability in Windows Shell Handler
could allow
Remote Code Execution
MS10-008 (KB978762) Cumulative Security Update of Active Kill Bits
Critical
MS10-009 (KB974145) Vulnerability in Windows TCP/IP
could allow
Remote Code Execution
MS10-010 (KB977894) Vulnerability in Windows Server 2008 Hyper-V
could allow Denial of Service
MS10-011 (KB978037) Vulnerability in Windows Client/Server Run-time
Subsystem
could allow
Elevation of privilege
MS10-012 (KB971468) Vulnerability in SMB Server
could allow
Remote Code Execution
MS10-013 (KB977935) Vulnerability in MS DirectShow
could allow
Remote Code Execution
MS10-014 (KB977290) Vulnerability in Kerberos
could allow
Denial of Service
MS10-015 (KB977165) Vulnerability in MS DirectShow
could allow
Remote Code Execution
Out-of-Schedule Patches, Thursday January 21
MS10-002 (KB978207) Cumulative update for IE
CRITICAL
The "Google-China Syndrome" patch. Must be installed immediately.
C: more @ the
Register: Google's China Syndrome
Out-of-Schedule Patches, Wednesday January 20
(KB979202) Silverlight
update IMPORTANT
Security, performance and reliability enhancements.
Just interesting, this popped up real fast, as if in conjunction with the
reportedly
fast-coming IE update, perhaps a coincidence.
Patch Tuesday, January 2010
MS10-001 (KB972270) Vulnerability in the Embedded OpenType Font Engine
could allow
Remote Code Execution
Patch Tuesday, December 2009
MS09-069 (KB974392) Vulnerability in Local Security Auth. System could allow
Remote Code Execution
MS09-070 (KB971726) Vulnerability Active Directory Federation Services could allow
Remote Code Execution
MS09-071 (KB974318) Vulnerability in Internet Authentication Service could allow
Remote Code Execution
MS09-072 (KB976325) Cumulative Security Update for Internet Explorer
(Highly) Critical
MS09-073 (KB975539) Vulnerability in Wordpad and Office Text Converters could allow
Remote Code Execution
MS09-074 (KB967183) Vulnerability MS Office Project could allow
Remote Code Execution
Out-of-Schedule Patches, Tuesday November 24
(KB973687) Extraneous DTD
call prevention patch (1) IMPORTANT
(KB973688) Extraneous DTD call
prevention patch (2) IMPORTANT
(KB976098) Revised Daylight
Saving Time patch IMPORTANT
Patch Tuesday, November 2009
MS09-063 (KB973565) Vulnerability in Web Services on Devices API could allow
Remote Code Execution
MS09-064 (KB974793) Vulnerability in License Logging Server could allow
Remote Code Execution
MS09-065 (KB969947) Vulnerabilities Windows Kernel-mode Drivers could allow
Remote Code Execution
MS09-066 (KB973309) Vulnerability in Active Directory could allow
Denial of Service
MS09-067 (KB972652) Vulnerability in MS Office Excel could allow
Remote Code Execution
Out-of-Schedule Patch, Tuesday, November 3, 2009
(KB976749) Update for IE 8.0
following security update 974455 (MS09-054)
Important
Patch Tuesday, October 2009
MS09-050 (KB975517) Vulnerabilities in SMBv2 could allow
Remote Code Execution
MS09-051 (KB955682) Vuln. in Windows Media Runtime could allow
Remote Code Execution
MS09-052 (KB974112) Vulnerabilities Windows Media Player could allow
Remote Code Execution
MS09-053 (KB965254) Vulnerabilities in FTP Service for IIS could allow
Remote Code Execution
MS09-054 (KB974455) Cumulative Security Update for Internet Explorer
Critical
MS09-055 (KB973525) Cumulative Security Update of ActiveX Kill Bits
Critical
MS09-056 (KB974571) Vulnerabilities in Windows CryptoAPI could allow
Spofing
MS09-057 (KB979059) Vulnerabilities in Indexing Service could allow
Remote Code Execution
MS09-058 (KB971486) Vulnerabilities in Windows Kernel could allow
Elevation of Privilege
MS09-059 (KB965467) Vulnerability in Local Security Auth. Subsys.
Service could allow Denial of Service
MS09-060 (KB973965) Vulnerabilities in Active Template Library (ATL)
ActiveX could allow
Remote Code Execution
MS09-061 (KB974378) Vulnerabilities in MS .NET Common Lang. Runtime could allow
Remote Code Execution
MS09-062 (KB957488) Vulnerabilities in GDI+ could allow
Remote Code Execution
Patch Tuesday, September 2009
MS09-045 (KB971961) Vulnerability in JScripting Engine could allow
Remote Code Execution
MS09-046 (KB956844) Vuln. in DHTML Editing Component ActiveX Control could allow
Remote Code Execution
MS09-047 (KB973812) Vulnerabilities in Windows Media format could allow
Remote Code Execution
MS09-048 (KB967723) Vulnerabilities in Windows TCP/IP could allow
Remote Code Execution
MS09-049 (KB970710) Vulnerabilities in Wireless LAN AutoConfig Service could allow
Remote Code Execution
Out-of-Schedule Patch, Tuesday, August 28, 2009
(KB9701653) Cumulative Time
Zone Update
Important
Patch Tuesday, August 2009
MS09-036 (KB970957) Vulnerability in ASP.NET in MS Windows could allow
Denial of Service
MS09-037 (KB973908) Vulnerabilities in MS Active Templ. Lib. (ATL) could allow
Remote Code Execution
MS09-038 (KB971557) Vulnerabilities in Windows Media File
Processing could allow
Remote Code Execution
MS09-039 (KB969883) Vulnerabilities in WINS could allow
Remote Code Execution
MS09-040 (KB971032) Vulnerability in Message Queuing could allow
Elevation of privilege
MS09-041 (KB971657) Vulnerability in Workstation Service could allow
Elevation of Privilege
MS09-042 (KB960859) Vulnerability in Telnet could allow
Remote Code Execution
MS09-043 (KB957638) Vulnerabilities in MS Office Web Components could allow
Remote Code Execution
MS09-044 (KB970927) Vulnerabilities in Remote Desktop Connection could allow
Remote Code Execution
Urgent Out-of-Schedule Patches, Tuesday, July 28,
2009
MS09-034 (KB961051) Cumulative Security Update for Internet Explorer
Critical
MS09-035 (KB96706) Vuln. in Visual Studio Active Templ. libraries could allow
Remote Code Execution
Patch Tuesday, July 2009
MS09-028 (KB971633) Vulnerabilities in MS direct Show could allow
Remote Code Execution
MS09-029 (KB961371) Vulnerabilities in Embedded Open Type Font Engine could allow
Remote Code Execution
MS09-030 (KB969516) Vulnerabilities in MS Office Publisher Show could allow
Remote Code Execution
MS09-031 (KB970953) Vulnerabilities in MS ISA Server 2006 Show could
cause Elevation of Privilege
MS09-032 (KB973346) Cumulative Security Update of ActiveX Kill Bits
Critical
MS09-033 (KB969856) Vulnerability in MS Virtual PC & Virtual Server could allow
Elevation of privilege
Patch Tuesday, June 2009
MS09-018 (KB961055) Vulnerabilities in Active Directory could allow
Remote Code Execution
MS09-019 (KB969897) Cumulative update for IE
Critical
MS09-020 (KB970483) Vulnerabilities in IIS could allow
Elevation of Privilege
MS09-021 (KB969462) Vulnerabilities in MS Office Excel could allow
Remote Code Execution
MS09-022
(KB961501) Vulnerabilities in
Windows Print Spooler could allow
Remote Code Execution
MS09-023 (KB967340) Vulnerabilities in Windows Search could allow
Information disclosure
MS09-024 (KB957632) Vulnerabilities in MS Works (Home Version of Office) could allow
Remote Code Execution
MS09-025 (KB968537) Vulnerabilities in Windows Kernel
Remote Code Execution
MS09-026
(KB970238)
Vulnerabilities in RPC could allow
Elevation of Privilege
MS09-027 (KB969514) Vulnerabilities in MS Office Word could allow
Remote Code Execution
Patch Tuesday, May 2009
MS09-017 (KB967340) Vulnerabilities in MS Office Excel could allow
Remote Code Execution
Patch Tuesday, April 2009
MS09-009 (KB968557) Vulnerabilities in MS Office Excel could cause
Remote Code Execution
MS09-010 (KB960477) Vulnerabilities in Wordpad and Office text
converters could allow Remote Code Execution
MS09-011 (KB961373) Vulnerability in MS DirectShow could allow
Remote Code Execution
MS09-012 (KB959454) Vulnerabilities in Windows could allow
Elevation of Privilege
MS09-013 (KB960803) Vulnerabilities in Windows HTTP Services could allow
Remote Code Execution
MS09-014 (KB963027) Cumulative Security Update for Internet Explorer
Critical
MS09-015 (KB959426)
Blended Threat Vuln. in SearchPath could allow
Elevation of Privilege
MS09-016 (KB959420) Vulnerabilities in ISA Server & Forefront Threat
Mgt. Gtw. could cause Elevation of Privilege
Patch Tuesday, March 2009
MS09-006 (KB961260) Vulnerabilities in Windows Kernel could allow
Elevation of Privilege
MS09-007 (KB959239) Vulnerabilities in SChannel could allow
Spoofing
MS09-008 (KB959420) Vulnerabilities in DNS and WINS Server could allow
Spoofing
Patch Tuesday, February 2009
MS09-003 (KB959239) Vulnerabilities in MS Exchange could allow
Remote Code Execution
MS09-004 (KB959420) Vulnerabilities in MS SQL could allow
Remote Code Execution
MS09-005 (KB957634) Vulnerabilities in MS Office Visio could allow
Remote Code Execution
Patch Tuesday, January 2009
MS09-001 (KB958687) Vulnerabilities in SMB could allow
Remote Code Execution
MS09-002 (KB961260) Cumulative security update for Internet Explorer
Critical
Urgent Out-of-Schedule Patch, Wednesday,
December 17, 2008
MS08-078 (KB961051) Vulnerability in Internet Explorer could allow
Remote Code Execution
As always, there is a good short article at the Inquirer,
here
Patch Tuesday, December 2008
MS08-070 (KB932349) Vulnerabilities in Visual Basic 6.0 Runtime (ActiveX
Controls) could allow
Remote Code Execution
MS08-071 (KB956802) Vulnerabilities in GDI could allow
Remote Code Execution
MS08-072 (KB957173) Vulnerabilities in Microsoft Office Word could allow
Remote Code Execution
MS08-073 (KB958215) Cumulative Security Update for Internet Explorer -
Critical
MS08-074 (KB959070) Vulnerabilities in Microsoft Office Excel could
allow Remote Code Execution
MS08-075 (KB959349) Vulnerabilities in Windows Search (optional
component) could allow Remote Code Execution
MS08-076 (KB959807) Vulnerabilities in Windows Media Components could
allow Remote Code Execution
MS08-077 (KB957175) Vulnerability in Microsoft Office SharePoint Server
could allow Elevation of Privilege
Patch Tuesday, November 2008
MS08-068 (KB957097) Vulnerability in SMB could allow
Remote Code Execution
MS08-069 (KB955218) Vulnerabilities in Microsoft XML Core Services could
allow Remote Code Execution
Urgent Out-of-Schedule PatchTuesday,
October 23, 2008
MS08-067 (KB958644) Vulnerability in Server Service could allow
Remote Code Execution
Patch Tuesday, October 2008
MS08-056 (KB957699) Vulnerabilities in Microsoft Office could allow
Information Disclosure
MS08-057 (KB956416) Vulnerability in Microsoft Excel could allow
Remote Code Execution
MS08-058 (KB956390) Cumulative Security Update for Internet Explorer -
Critical
MS08-059 (KB956695) Vulnerability in Host Integration Server RPC Service
could allow Remote Code Execution
MS08-060 (KB954211) Vulnerability in Active Directory could allow
Remote Code Execution
MS08-061
(KB954211) Vulnerability in Windows Kernel could allow
Elevation of Privilege
MS08-062
(KB953155) Vulnerability in Windows Internet Printing Service could allow
Remote Code Execution
MS08-063 (KB957095) Vulnerabilities in SMB could allow
Remote Code Execution
MS08-064 (KB956841) Vulnerabilities in Virtual Address Descriptor
Manipulation could allow
Elevation of Privilege
MS08-065 (KB951071) Vulnerabilities in Message Queuing could allow
Elevation of Privilege
MS08-066 (KB956803) Vulnerabilities in Microsoft Ancillary Function
Driver could allow
Elevation of Privilege
Patch Tuesday, September 2008
MS08-052 (KB954593) Vulnerabilities in GDI+ could allow
Remote Code Execution
MS08-053 (KB954156) Vulnerability in Windows Media Encoder 9 could allow
Remote Code Execution
MS08-054 (KB954154) Vulnerability in Windows Media Player could allow
Remote Code Execution
MS08-055 (KB955047) Vulnerability in Microsoft Office could allow
Remote Code Execution
Patch Tuesday, August 2008
EEYE has noted attacks re. MS08-41 and 42 prior to
Microsoft's release of these two patches.
MS08-041 (KB955617) Vulnerability in ActiveX Control for Snapshot Viewer
(Access) could allow Remote Code Execution
MS08-042 (KB955048) Vulnerability in Microsoft Word could allow
Remote Code Execution
MS08-043 (KB954066) Vulnerability in Microsoft Excel could allow
Remote Code Execution
MS08-044 (KB924090) Vulnerability in Microsoft Office Filters could
allow Remote Code Execution
MS08-045 (KB953838) Cumulative Security Update for Internet Explorer
Critical
MS08-046 (KB952954) Vulnerability in Ms Windows Image Color Mgt. System
could allow Remote Code Execution
MS08-047 (KB953733) Vulnerability in IPsec Policy Processing could allow
Information Disclosure
MS08-048 (KB951066)
Security Update for Outlook Express and Windows Mail -
Important
MS08-049 (KB949785) Event System could allow
Remote Code Execution
MS08-050 (KB955702) Vulnerability in Windows Messenger could allow
Information Disclosure
MS08-051 (KB949785) Vulnerability in Microsoft PowerPoint could allow
Remote Code Execution
Patch Tuesday, July 2008
(11th July update)
MS08-037 (KB953230+KB951748) Vulnerabilities in DNS could allow
Spoofing (IMPORTANT)
Warning: Please TEST this patch
thoroughly before implementing! Seems to be incompatible
with ZoneAlarm Security Suite 70-470-000 and previous version.
293 complaints at CheckPoint's site full of VERY angry,
soon-to-be-ex-customers vent their
frustration with a very inept response to a serious product error. A very
typical example
of a reaction of today's support collapse is
'Big_Tom's blog entry. Says it all, really. . .
That worked! Late 10th, July Checkpoint Technology found the time to put out a warning,
and later, to issue a new version, 70-483-000 which reestablishes the
functionality.
MS08-038 (KB950582) Vulnerability in Windows Explorer could allow
Remote Code Execution
MS08-039 (KB950762) Vulnerabilities in Pragmatic General Multicast (PGM) could allow
Denial of Service
MS08-040 (KB950759) Vulnerabilities in MS-SQL Server could allow
Elevation of Privilege
Patch Tuesday, June 2008
MS08-030 (KB951376) Vulnerability in Bluetooth Stack could allow
Remote Code Execution
MS08-031 (KB950759) Cumulative security update for Internet Explorer
(Critical)
MS08-032 (KB950760) Cumulative security update of ActiveX Kill Bits
(Moderate)
MS08-033 (KB951698) Vulnerabilities in DirectX could allow
Remote Code Execution
MS08-034 (KB958745) Vulnerability in WINS could allow
Denial of Service
MS08-035 (KB953235) Vulnerability in Active Directory could allow
Denial of Service
MS08-036 (KB950762) Vuln. in Pragmatic General Multicast (PGM) Engine could allow
Denial of Service
Patch Tuesday, May 2008
MS08-026 (KB951207) Vulnerabilities in MS-Word could allow
Remote Code Execution
MS08-027 (KB951208) Vulnerabilities in MS-Publisher could allow
Remote Code Execution
MS08-028 (KB950749) Vulnerabilities in MS Jet Database Engine could allow
Remote Code Execution
MS08-029 (KB952044) Vulnerabilities in MS Malware Protection Engine could allow
Denial of Service
Patch Tuesday, April 2008
MS08-018 (KB950183) Vulnerability in MS-Project could allow
Remote Code Execution
MS08-021 (KB948590) Vulnerabilities in MS-Outlook could allow
Remote Code Execution
MS08-022 (KB944338) Vulnerabilities in VBScript & JScript SE's could allow
Remote Code Execution
MS08-023 (KB948881) Security update of Active X Kill Bits
(Critical)
MS08-024 (KB947864) Cumulative security update for Internet Explorer
(Critical)
MS08-019 (KB949032) Vulnerabilities in MS-Visio could allow
Remote Code Execution
MS08-020 (KB945553) Vulnerability in DNS Client could allow
Spoofing
MS08-025 (KB941693) Vulnerability in Windows Kernel could allow
Elevation of Privilege
Patch Tuesday, March 2008
MS08-014 (KB949029) Vulnerabilities in MS-Excel could allow
Remote Code Execution
MS08-015 (KB949031) Vulnerabilities in MS-Outlook could allow
Remote Code Execution
MS08-016 (KB949030) Vulnerabilities in MS-Office could allow
Remote Code Execution
MS08-017 (KB947077) Vulnerabilities in MS-Word could allow
Remote Code Execution
Patch Tuesday, February 2008
MS08-007 (KB946026) Vuln. in WebDAV Mini-Redirector could allow
Remote Code Execution
MS08-008 (KB947890) Vulnerabilities in OLE Automation could allow
Remote Code Execution
MS08-009 (KB947077) Vulnerabilities in MS-Word could allow
Remote Code Execution
MS08-010 (KB944533) Cumulative Sec. Update for Internet Explorer
(Remote Code Execution)
MS08-012 (KB947085) Vulnerabilities in MS-Publisher could allow
Remote Code Execution
MS08-013 (KB947108) Vulnerabilities in MS-Office could allow
Remote Code Execution
MS08-003 (KB946538) Vulnerabilities in ACTIVE DIRECTORY could allow
Denial of Service
MS08-004 (KB946456) Vulnerabilities in Windows TCP/IP could allow
Elevation of Privilege
MS08-005 (KB942831) Vulnerabilities in I I S could allow
Elevation of Privilege
MS08-006 (KB942830) Vulnerabilities in I I S could allow
Remote Code Execution
MS08-011 (KB947081) Vulnerabilities in MS-Works File Converter could allow
Remote Code Execution
Patch Tuesday, January 2008
MS08-001 (KB941644) Vulnerabilities in Windows TCP/IP could allow
Remote Code Execution
MS08-002 (KB943485) Vulnerabilities in LSASS TCP/IP could allow
Elevation of Privilege
Patch Tuesday, December 2007
MS07-064 (KB941568) Vulnerabilities in DirectXI could allow
Remote Code Execution
MS07-068 (KB941569/944275) Vulnerability in WMF Format could allow
Remote Code Execution
MS07-069 (KB942615) Cumulative Security Update for Internet Explorer
(Critical)
MS07-063 (KB942624) Vulnerabilities in SMBv2 could allow
Remote Code Execution
MS07-065 (KB937894) Vulnerabilities in Message Queuing could allow
Remote Code Execution
MS07-066 (KB943078) Vulnerabilities in Windows Kernel could allow
Elevation of Privilege
MS07-067 (KB944653) Vulnerabilities in Macrovision Driver could allow
local
Elevation of Privilege
Out-of-Schedule Issue, 4th December 2007
The Sydney Morning Herald details in this article a very serious
vulnerability in MS Internet Explorer,
which originates in the way that IE automatically processes proxy settings.
This vulnerability is critical
- originally discovered in 1999 and thought to be fixed, has surfaced again.
Lately, thousands of internet
users in Britain were redirected to an online auction site when a criminal
hacked wpad.co.uk and used the
website to serve up bogus configuration information that redirected hijacked
browsers to an online auction site,
eebuy.co.uk.
Please apply remedial actions detailed below immediately - as no PATCH has been
issued yet.
(KB945713) Internal Errors in WeB Proxy Auto-Discovery (WPAD) processing could
allow Remote Code Execution
The Original security bulletin from December 1999 is here:
MS99-054 (KB247333) WPAD Spoofing
(Critical )
Patch Tuesday, November 2007
MS07-061 (KB923810) Vulnerabilities in Windows URI could allow
Remote Code Execution
MS07-062 (KB941202) Vulnerability in DNS could allow Spoofing
(Medium - or perhaps,
Critical )
This vulnerability is critical if it is successfully
exploited, particularly in conjunction with
advanced botnets, and just now the 4 STORM offspring botnets, plus the remainder
of the original
STORM net, would be prime users of this vulnerability. For this reason,
this vulnerability might
have to be regarded as CRITICAL.
Patch Tuesday, October 2007
MS07-055 (KB923810) Vulnerabilities in Kodak Image Viewer could allow
Remote Code Execution
MS07-056 (KB941202) Security Update for Outlook Express and Windows Mail
(Critical)
MS07-057 (KB939653) Cumulative Security Update for Internet Explorer
(Critical)
MS07-060 (KB942695) Vulnerability in Microsoft Word could allow
Remote Code Execution
MS07-058 (KB933729) Vulnerability in RPC could allow
Denial of Service
MS07-059 (KB942017) Vulnerability in SharePoint & Office SharePoint Svr.
could allow
Elevation of Privilege
Patch Tuesday, September 2007
MS07-051 (KB938827) Vulnerability in Microsoft Agent could allow
Remote Code Execution
MS07-052 (KB941522) Vuln. in Crystal Reports for Visual Studio could
allow
Remote Code Execution
MS07-053 (KB939778) Vulnerability in Windows Services for UNIX could
allow
Remote Code Execution
MS07-054 (KB942099) Vulnerability in MSN and Windows Live Messengers
could allow
Remote Code Execution
Patch Tuesday, August 2007
MS07-042 (KB936227) Vulnerabilities in Microsoft Core Services could allow
Remote Code Execution
MS07-043 (KB921503) Vuln. in in OLE Automation could allow Remote
Code Execution
MS07-044 (KB940965) Vulnerability in Microsoft Excel could allow
Remote
Code Execution
MS07-045 (KB937143) Cumulative Security Update for Internet Explorer -
Remote
Code Execution
MS07-046( KB938829)
Vulnerability in GDI
could
allow
Remote
Code Execution
MS07-047 (KB936782) Vulnerabilities in Windows Media Player
could
allow
Remote
Code Execution
MS07-048 (KB938123) Vulnerabilities in Windows Gadgets
could
allow
Remote
Code Execution
MS07-049 (KB937986) Vuln. in Virtual PC and Virtual Server
could
allow
Elevation of Privilege
MS07-050 (KB938127)
Vulnerabilities in Vector Markup Language
could allow
Remote
Code Execution
VISTA - Admission from Microsoft - finally,
26th July 2007
As everyone knows, VISTA has not been the most successful software
release, but it is a significant
step to take for Microsoft to publicly admit failure.
The
Register discusses the issues and point to
the fact, that only 650 applications were VISTA ready by the time of launch - an
all time low.
Patch Tuesday, July 2007
MS07-036 (KB936542) Vulnerabilities in Microsoft Excel could allow
Remote Code Execution
MS07-037 (KB936548) Vuln. in Microsoft Office Publisher 2007 could allowRemote
Code Execution
MS07-038 (KB935807) Vulnerability in VISTA Firewall could Allow
Information Disclosure
MS07-039 (KB926122)
Vulnerability in
Active Directory could Allow
Remote
Code Execution
MS07-040 (KB931212)
Vulnerabilities in .NET Framework
could Allow
Remote
Code Execution
Nothing like OLD news, right?
Just revisiting Secunia's finding back from 24th August 2005 about HIDDEN
REGISTRY KEYS.
The bad news: This issue has still seems not to have been fixed.
It is relatively serious, as overly long registry entries can be made invisible
to the standard registry
editor regedit. The
article at SANS Internet Storm Center is still very interesting. Today's
stronger
(best-of-breed)
anti malware solutions should be able to identify such entries, however.
Patch Tuesday, June 2007
MS07-030 (KB927051)Vulnerabilities in Microsoft Visio could allow
Remote Code Execution
MS07-031 (KB935840) Vuln. in the Windows Schannel Sec. Pckg. could allowRemote
Code Execution
MS07-032 (KB931213) Vulnerability in Windows Vista Could Allow
Information Disclosure
MS07-033 (KB933566) Cumulative Update for Internet Explorer
Several Critical Issues
MS07-034 (KB929123) Cumulative Sec. Upd for Outlook Express & Windows
Mail
Critical - 4 issues
MS07-035 (KB935839) Vulnerability in Win32 API could allow
Arbitrary
Code to Run
Patch Tuesday, May 2007
(No MS-no) (KB930916)
Error message when you try to open files on a NTFS file system volume on
a
Windows XP-based computer: "Stop 0x0000008E" (Serious reliability issue)
(Was part of monthly upd. for WGA-customers)
MS07-023 (KB934453) A security vulnerability exists in MS Excel 2002 that
could allow
Remote Code Execution
MS07-024 (KB934394) Vulnerability in Microsoft Word 2002 that could allow
Arbitrary
Code to Run
MS07-025 (KB934705) Vulnerability in Microsoft Office XP that could allow
Remote Code Execution
MS07-026 (KB931832) Vulnerabilities in Microsoft Exchange could cllow
Remote Code Execution
MS07-027 (KB931768) Cumulative Security Update for Internet Explorer
Critical
MS07-028 (KB931906) Vulnerability in CAPICOM could allow
Remote Code Execution
MS07-029 (KB935966) Vulnerability in Windows DNS RPC Interface
could sllow Remote Code Execution
Patch Tuesday, April 2007
MS07-022
(KB931784)Kernel vulnerability that could allow full control and Remote Code Execution
MS07-021
(KB930178) Vulnerabilities in CSRSS could allow
Remote Code Execution
MS07-019
(KB931261) Vulnerability in Universal P & Play could allow
Remote Code Execution
MS07-020
(KB932168) Vulnerability in Microsoft Agent could allow
Remote Code Execution
A day later, the Malicious Software Removal
tool was distributed - Microsoft apparently being too
busy getting it ready for the normal schedule. No publicity about this fact,
however.
Urgent Out-of-Schedule Patch
April 2007
MS07-017 (KB925902) Vulnerabilities in GDI
could allow
Remote Code Execution
This critical patch was issued by Microsoft 3rd April 2007, and is a
patch-for-a-patch...
Yes, it's been seen many times before, strengthening the question marks against
Microsoft's
product testing and verification methods. Worrying for private as corporate
users alike.
The scandal, yes - it is a scandal, about this patch is very well written in
George Ou's blog at
TechRepublic: "Why Is
Microsoft Hell-bent on Ruining It's Reputation?"
Furthermore, it's a global patch: It applies to VISTA as well as XP, the
server 200X family and 2000SP4!
The patch concerns a stack-based buffer overflow in the animated cursor code in
Microsoft Windows
2000 SP4 through Vista allows remote attackers to execute arbitrary code or
cause a denial of service
(persistent reboot) via a malformed .ANI, cur, or .ico file, which results in
memory corruption when
processing cursors, animated cursors, and icons, a similar issue to
CVE-2005-0416, as originally
demonstrated using Internet Explorer 6 and 7.
The patch has been issued out-of-schedule due to an alarming rise in actual uses
of this exploit, so
the advice from MS, CA and F-Secure is to PATCH RIGHT NOW!
30 Days with Windows VISTA April 2007 + May 2007
There's a very good and very in depth article over at
HardOCP about installing and using VISTA
for actual work, multimedia and gaming, both 32-bit and 64-bit. It is a
long 9-pager, but very
accurate and balanced in its observations - this is not a Microsoft-bashing
exercise. Highly
recommended for those who might consider VISTA a replacement for their
daily work OS.
Hint: VISTA is not nearly there yet; our own observations with VISTA Business
(32-bit, for
maximum compatibility with XP-based software) also indicate sudden re-boots,
installation
problems, general non-functionality, and a frustrating user interface for other
than novice
user tasks.
UPDATE: VISTA's Long Goodbye Deleting files in VISTA can take HOURS for
large multi-media
files... Apparently a result of either a basic construction flaw or a result of
DRM measures
(often called DRM infection by now). This article at
The Register explains the details.
This is not just a user issue. Corporations need to make sure this
issue is corrected before
any roll-out takes place.
Patch Tuesday, March 2007- a day that
never came!!! March 2007
They've done it again!! Microsoft once again slips up the
patching schedule.
N F C (That is: No FURTHER Comments) . . .
Mpas-d.exe, who's that?
February 2007
Answer: It is part of Defender - so not a module to worry about. However,
you should always pay
attention to unexpected launches of seemingly known modules. It always pays to
have a bit of healthy
skepticism, when "strange" things happen in your (XP) system...
VISTA Secure?
February 2007
A very good article in
The Register details the user experience and the security implications.
The main culprit is the UAC, much discussed elsewhere, but also IE 7.0 gets a
thorough going-over.
The between-the-lines conclusion is: wait for Vienna or maybe a very
restructured security
architecture in VISTA-SP1, being a bit naive & hopeful, perhaps?
Patch Tuesday, February 2007
Critical
MS07-008 - Vulnerability in HTML Help
ActiveX Control could allow Remote Code Execution
MS07-009 - Vulnerability in Microsoft Data
Access Components could allow Remote Code Execution
MS07-010 - Vulnerability in Microsoft
Malware Protection Engine could allow Remote Code
Execution
MS07-014 - Vulnerabilities in Microsoft Word
could allow Remote Code Execution
MS07-015 - Vulnerabilities in Microsoft
Office could allow Remote Code Execution
MS07-016 - Cumulative Security Update for
Internet Explorer
Important
MS07-005 - Vulnerability in Step-by-Step
Interactive Training could allow Remote Code
Execution
MS07-006 - Vulnerability in Windows Shell
could allow Elevation of Privilege
MS07-007 - Vulnerability in Windows Image
Acquisition Service could allow Elevation of Privilege
MS07-011 - Vulnerability in Microsoft OLE
Dialog could allow Remote Code Execution
MS07-012 - Vulnerability in Microsoft MFC could
allow Remote Code Execution
MS07-013 - Vulnerability in Microsoft
RichEdit could allow Remote Code Execution
-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, January 2007
Critical
MS07-002 - Vulnerabilities in Microsoft
Excel could allow Remote Code Execution
MS07-003 - Vulnerabilities in Microsoft
Outlook could allow Remote Code Execution
MS07-004 - Vulnerability in Vector Markup
Language could allow Remote Code Execution
Important
MS07-001 - Vulnerability in Microsoft Office
2003 Brazilian Portuguese Grammar Checker
Could Allow
Remote Code Execution
-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, December 2006
Critical
MS06-072 - Cumulative Security Update for
Internet Explorer
MS06-073
- Vulnerability in Visual Studio 2005 could allow
Remote Code Execution
MS06-078 - Vulnerability in Windows Media
Format could allow Remote Code Execution
MS06-059 - Re-Release: Vulnerabilities in
Excel could allow Remote Code Execution
Important
MS06-074
- Vulnerability in SNMP could allow Remote Code
Execution
MS06-075 - Vulnerability in Windows could
allow Elevation of Privilege
MS06-076 - Cumulative Security Update for
Outlook Express
MS06-077 - Vulnerability in Remote
Installation Service could allow Remote Code Execution
-------------------------------------------------------------------------------------------------------------------
Patch Tuesday, November 2006
MS06-067 - Cumulative Security Update for
Internet Explorer Remote Code Execution
This is the all-important update to 3 different vulnerabilities, each
of them serious.
The most noted KB927892 (below).
MS06-068 - Vulnerability in Microsoft Agent
could allow Remote Code Execution
MS06-069 - Vulnerabilities in Macromedia
Flash Player from Adobe could allow Remote Code
Execution
MS06-070 - Vulnerability in Workstation
Service could allow Remote Code Execution
MS06-071 - Vulnerability in Microsoft XML
Core Services could allow Remote Code Execution
Open vulnerability in Microsoft's XML Core Services XMLHTTP ActiveX
control

Link to
Microsoft's Security Advisory (KB927892)
Vulnerability in Microsoft XML Core Services could allow Remote Code Execution.
Microsoft has now admitted that a critical vulnerability exists in the above
ActiveX control.
The vulnerability is being used right now by several hackers, and both
Secunia
and
US-CERT
report of sightings in the wild.
This is not the first vulnerability in exactly this area. Back in February 2002
this was patched:

A properly patched Windows system may not be completely exposed, but the
following advice
should prevent infection:
Do not open links in-mails, and block the use of ActiveX until a patch has been
published.
Patch Tuesday, October 2006
MS06-057 - Vulnerability in Windows Shell could allow
Remote Code Execution
MS06-058 - Vulnerabilities in
Microsoft PowerPoint could Lead to Remote Code
Execution
MS06-059 - Vulnerabilities in Microsoft Excel could allow
Remote Code Execution
MS06-060 - Vulnerability in Microsoft
Word could allow Remote Code Execution
MS06-061 - Vulnerabilities in
Microsoft XML Core Services could allow Remote Code
Execution
MS06-062 - Vulnerabilities in Microsoft Office could lead to
Remote Code Execution
MS06-063 - Vulnerability in Server Service could allow
Denial of Service
MS06-056 - Vulnerability in ASP.NET could
allow Information Disclosure
MS06-065 - Vulnerability in Windows
Object Packager could allow Remote Execution
MS06-064 - Vulnerability in TCP-IP
IPv6 could result in Denial of Service
--------------------------------------------------------------------------------------------------------------------
URGENT: Out-of-schedule Patch
MS06-055 (KB925486) A security issue has been identified in the way
Vector Markup Language
(VML) is handled that could allow an attacker to
compromise a computer running Microsoft
Windows and gain control over it. Remote Code Execution
Rated Critical and for immediate implementation.
--------------------------------------------------------------------------------------------------------------------
Patch Tuesday, September 2006
MS06-052 Vulnerability in Pragmatic General Multicast (PGM) could
allow Remote Code Execution
MS06-053 Vulnerability in Indexing Service could allow Cross-Site
Scripting
Vulnerability in Indexing Service could allow Cross-Site Scripting (Not
critical)
Audio playback does not play the audio file from the correct position after you
pause
Error message when you try to update a Microsoft Windows-based computer:
"0x80070002"
MS06-054 Vulnerability in Microsoft Publisher could allow
Remote Code Execution
The only critical patch this month was MS06-054, and, just like the Excel
and Word issues,
requires the user to open a malformed file. The other
patches this month are both taken
care of by other prudent security measures.
So, it was a very easy month this time also.
--------------------------------------------------------------------------------------------------------------------
URGENT: Out-of-schedule Patch for the MS06-042 Patch
A patch for the patch; it's happened a number of times before.
To quote Microsoft: "Security issues have been identified that could allow an
attacker to
compromise a computer running Microsoft Internet Explorer and gain
control over it."
In other words:
Remote Code Execution
Direct download at:
Cumulative Update for Internet Explorer 6 SP1 (KB918899)
This is yet another example of why staying alert re. security issues can be very
important;
as soon as a patch is released the "zero-day/hour" count starts
(unless publicly available
code/exploit was already available). So we
shall see how soon examples appear in the wild.
The potential victims
are of course all users who do not apply such important patches immediately.
A very important issue for business, who rely on the well-functioning (remote)
systems of their customers.
--------------------------------------------------------------------------------------------------------------------
Patch Tuesday, August 2006
A large event involving what proved to be a block buster vulnerability
(MS06-040)
which was used by malware writers to create "wgareg.exe" and "wgavm.exe".
Antivirus vendors have named this threat W32.Wargbot (Symantec),
Worm.IRCBOT.JK/JL
(Trend Micro), IRC.Mocbot (McAfee), and IRCBOT-ST (F-Secure).
The use of the wga prefix supposedly served to mask the process for the
semi-technically
minded user population.
The full list, the critical first:
MS06-040 - Vulnerability in Server Service could allow
Remote Code Execution
MS06-041 - Vulnerability in DNS Resolution could allow
Remote Code Execution
MS06-042 - Cumulative Security Update for Internet
Explorer
MS06-043 - Vulnerability in Microsoft Windows could
allow Remote Code Execution
MS06-044 - Vulnerability in Microsoft Management Console
could allow Remote Code Execution
MS06-046 - Vulnerability in HTML Help
could allow
Remote
Code Execution
MS06-047 - Vulnerability in Microsoft Visual Basic for
Applications could allow Remote Code Execution
MS06-048 - Vulnerabilities in Microsoft Office could
allow Remote Code Execution
MS06-051 - Vulnerability in Windows Kernel
could result
in Remote Code Execution
Rated as moderate:
MS06-045 - Vulnerability in Windows Explorer could
allow Remote Code Execution
MS06-049 - Vulnerability in Windows Kernel could result
in Elevation of Privilege
MS06-050 - Vulnerabilities in Microsoft Windows
Hyperlink Object Library could allow Remote Code Execution
The negative news:
1. Everyone is once again reminded of the narrowing test & patch window.
Corporate procedures
need updating to ensure that parches are installed as quickly as
possible following publication from
Microsoft. Many companies have a 7-day window which has not
been adequate for some time now.
This could be the business case mandating a sweeping change.
2. There were 10 (T E N) vulnerabilities related to remote code execution (!)
Microsoft sets a new record here - for a single month.
3. It is disturbing that at this late stage in the product's life such an amount
of serious security issues can
be found. Please also remember that the growth in malware focuses exactly on
this type of vulnerability,
not jut the actual example re. MS06-040, but the majority of new malware of 2006 up
till now!
The positive news:
AV companies are getting better prepared at the more focused efforts from Virus
writers.
Microsoft has a strong focus on eliminating vulnerabilities, and each new
vulnerability discovered
in Windows XP hopefully ensures a better Windows VISTA. A possible problem
with this assumption is
that VISTA is written from the ground up. Thus there is no guarantee that
experience with XP vulnerability
remedies can be directly transferred to the (now) finishing stages of work on
the VISTA product.
--------------------------------------------------------------------------------------------------------------------
Patch Tuesday, July 2006
A relatively successful update with 2 very interesting critical updates:
MS06-038
Vulnerability in Microsoft Office could allow Remote Code Execution
(915384)
http://www.microsoft.com/technet/security/bulletin/MS06-038.mspx
A very relevant anti-malware update -and relevant for all users of Microsoft
Office,
ALSO for the APPLE users.
MS06-039
Vulnerability in Microsoft Office could allow Remote Code Execution (915384)
http://www.microsoft.com/technet/security/bulletin/MS06-039.mspx
As above and equally important.
The other updates were mostly related to servers - no less
important.
--------------------------------------------------------------------------------------------------------------------
"Best of 2005":
Patch Tuesday, September 2005 - a day that never came!!!

This short note was available on the updated Microsoft update site - after
pulling the statement:
"Late in the testing process, Microsoft encountered a quality issue that
necessitated the update
to go through additional testing and development before it is released,-"
from the site replacing
it with the above. The problem for Windows users is that one of the
critical patches was a
"wormable" vulnerability (discovered by eEye)
JUST as serious as the MS05-039! Windows users will
have to live in the vain hope no-one really finds out what this one was about
until Microsoft is good
and ready to let everyone patch up properly. . .
(back)
|