<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DP's Security Bits</title><link>http://msmvps.com/blogs/donpatterson/default.aspx</link><description>Don Patterson (aka DP)</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><item><title>Title: Microsoft Security Bulletin Minor Revisions - July 18, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/19/title-microsoft-security-bulletin-minor-revisions-july-18-2008.aspx</link><pubDate>Sat, 19 Jul 2008 09:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641419</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1641419</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/19/title-microsoft-security-bulletin-minor-revisions-july-18-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 18, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a minor revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; * &lt;b&gt;MS08-040 - Important&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS08-040 - Important&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Reason for Revision: V1.4 (July 18, 2008): Corrected the list of&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; valid product instance names in the Microsoft SQL Server 2000&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop Engine (WMSDE) subsection under the Security Update&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Information section. Also added entry to the Frequently Asked&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Questions (FAQ) Related to This Security Update to&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; communicate a detection change in the way that Windows Server&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Update Services (WSUS) offers the update for Microsoft SQL&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server 2000 Desktop Engine (WMSDE).&amp;nbsp; &lt;br /&gt;&amp;nbsp; - Originally posted: July 8, 2008&lt;br /&gt;&amp;nbsp; - Updated: July 18, 2008&lt;br /&gt;&amp;nbsp; - Bulletin Severity Rating: Important&lt;br /&gt;&amp;nbsp; - Version: 1.4&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641419" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Major Revisions - July 10, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/11/microsoft-security-bulletin-major-revisions-july-10-2008.aspx</link><pubDate>Fri, 11 Jul 2008 06:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640329</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1640329</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/11/microsoft-security-bulletin-major-revisions-july-10-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 10, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; * MS08-037 - Important&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS08-037 - Important&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;- &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp;- Reason for Revision: V2.0 (July 10, 2008): Bulletin revised to&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inform users of ZoneAlarm and Check Point Endpoint Security&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; of an Internet connectivity issue detailed in the section,&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Frequently Asked Questions (FAQ) Related to this Security&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Update. The revision did not change the security update files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; in this bulletin, but users of ZoneAlarm and Check Point&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Endpoint Security should read the FAQ entries for guidance.&amp;nbsp; &lt;br /&gt;&amp;nbsp;- Originally posted: July 8, 2008&lt;br /&gt;&amp;nbsp;- Updated: July 10, 2008&lt;br /&gt;&amp;nbsp;- Bulletin Severity Rating: Important&lt;br /&gt;&amp;nbsp;- Version: 2.0&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640329" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Sun Releases Updates for Java SE</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/10/sun-releases-updates-for-java-se.aspx</link><pubDate>Thu, 10 Jul 2008 20:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640260</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1640260</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/10/sun-releases-updates-for-java-se.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; Sun has released updates for
Java SE. These updates address multiple vulnerabilities in Java Runtime
Environment (JRE), Java Web Start, Java Management Extensions (JMX),
JDK, and Java Runtime Environment Virtual Machine. These
vulnerabilities may allow a remote attacker to execute arbitrary code,
bypass security restrictions, obtain sensitive information or cause a
denial-of-service condition.&lt;br /&gt;&lt;br /&gt;US-CERT encourages users to review the following Sun Alerts and apply any necessary updates:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1" target="_self"&gt;238628&lt;/a&gt; - Security Vulnerabilities in the Java Runtime Environment related to the processing of XML Data&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238666-1" target="_self"&gt;238666&lt;/a&gt; - A Security Vulnerability with the processing of fonts in the Java Runtime Environment may allow Elevation of Privileges&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1" target="_self"&gt;238687&lt;/a&gt; - Security Vulnerabilities in the Java Runtime Environment Scripting Language Support&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238905-1" target="_self"&gt;238905&lt;/a&gt; - Multiple Security Vulnerabilities in Java Web Start may allow Privileges to be Elevated&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238965-1" target="_self"&gt;238965&lt;/a&gt; - Security Vulnerability in Java Management Extensions (JMX)&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238966-1" target="_self"&gt;238966&lt;/a&gt; - Security Vulnerability in JDK/JRE Secure Static Versioning&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238967-1" target="_self"&gt;238967&lt;/a&gt;
- Security Vulnerability in the Java Runtime Environment Virtual
Machine may allow an untrusted Application or Applet to Elevate
Privileges&lt;/li&gt;
&lt;li&gt;Sun Alert &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-238968-1" target="_self"&gt;238968&lt;/a&gt; - Security Vulnerabilities in the Java Runtime Environment may allow Same Origin Policy to be Bypassed&lt;/li&gt;
&lt;/span&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;US-CERT will provide additional information as it becomes available.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.us-cert.gov/current/index.html#sun_releases_updates_for_java"&gt;http://www.us-cert.gov/current/index.html#sun_releases_updates_for_java&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640260" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Alerts/default.aspx">Alerts</category></item><item><title>Microsoft Security Advisory Notification - July 9, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/microsoft-security-advisory-notification-july-9-2008.aspx</link><pubDate>Wed, 09 Jul 2008 22:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640046</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1640046</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/microsoft-security-advisory-notification-july-9-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 9, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* &lt;b&gt;Microsoft Security Advisory (954960)&lt;/b&gt;&lt;br /&gt;&amp;nbsp; - Title: Microsoft Windows Server Update Services&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (WSUS) Blocked from Deploying Security Updates&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/954960.mspx"&gt;http://www.microsoft.com/technet/security/advisory/954960.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: July 9, 2008: Advisory updated to reflect&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; availability of fix.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640046" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Minor Revisions - July 9, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/microsoft-security-bulletin-minor-revisions-july-9-2008.aspx</link><pubDate>Wed, 09 Jul 2008 20:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640036</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1640036</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/microsoft-security-bulletin-minor-revisions-july-9-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 9, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a minor revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; * MS08-040 - Important&lt;br /&gt;&amp;nbsp; * MS08-039 - Important&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS08-040 - Important&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Reason for Revision: V1.1 (July 9, 2008): Removed erroneous&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; references to SQL Server 2005 Service Pack 1 in the MBSA and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SMS Detection and Deployment tables. Also clarified&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permissions requirements for vulnerability mitigating factors.&amp;nbsp; &lt;br /&gt;&amp;nbsp; - Originally posted: July 8, 2008&lt;br /&gt;&amp;nbsp; - Updated: July 9, 2008&lt;br /&gt;&amp;nbsp; - Bulletin Severity Rating: Important&lt;br /&gt;&amp;nbsp; - Version: 1.1&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;* &lt;b&gt;MS08-039 - Important&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Reason for Revision: V1.1 (July 9, 2008): Changed the information&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; reference link for OWA Premium in the Mitigating Factors&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sections for both vulnerabilities.&amp;nbsp; &lt;br /&gt;&amp;nbsp; - Originally posted: July 8, 2008&lt;br /&gt;&amp;nbsp; - Updated: July 9, 2008&lt;br /&gt;&amp;nbsp; - Bulletin Severity Rating: Important&lt;br /&gt;&amp;nbsp; - Version: 1.1&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640036" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>DNS Implementations Vulnerable to Cache Poisoning</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/dns-implementations-vulnerable-to-cache-poisoning.aspx</link><pubDate>Wed, 09 Jul 2008 09:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639941</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639941</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/09/dns-implementations-vulnerable-to-cache-poisoning.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; US-CERT is aware of deficiencies
in the DNS protocol. Implementations of this protocol may leave the
affected system vulnerable to DNS cache poisoning attacks. If an
attacker can successfully conduct a cache poisoning attack, they may be
able to cause a nameserver&amp;#39;s clients to contact the incorrect, and
possibly malicious, hosts for particular services. This may allow an
attacker to obtain sensitive information or mislead users into
believing they are visiting a legitimate website.&lt;br /&gt;&lt;br /&gt;US-CERT encourages users to review &amp;quot;&lt;a href="http://www.kb.cert.org/vuls/id/800113" target="_self"&gt;VU#800113&lt;/a&gt;
- Multiple DNS implementations vulnerable to cache poisoning&amp;quot; and apply
any necessary solutions listed in that document to help mitigate the
risks.&lt;br /&gt;&lt;br /&gt;US-CERT will provide additional information as it becomes available.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.us-cert.gov/current/index.html#dns_implementations_vulnerable_to_cache"&gt;http://www.us-cert.gov/current/index.html#dns_implementations_vulnerable_to_cache&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639941" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Alerts/default.aspx">Alerts</category></item><item><title>Microsoft Security Advisory Notification - July 8, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/08/microsoft-security-advisory-notification-july-8-2008.aspx</link><pubDate>Wed, 09 Jul 2008 03:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639915</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639915</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/08/microsoft-security-advisory-notification-july-8-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 8, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* Microsoft Security Advisory (953635)&lt;br /&gt;&amp;nbsp; - Title: Vulnerability in Microsoft Word Could Allow&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote Code Execution&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/953635.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953635.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: Advisory published.&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639915" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin(s) for July 8, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/08/microsoft-security-bulletin-s-for-july-8-2008.aspx</link><pubDate>Tue, 08 Jul 2008 16:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639803</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639803</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/08/microsoft-security-bulletin-s-for-july-8-2008.aspx#comments</comments><description>&lt;p&gt;
&lt;span style="font-weight:bold;"&gt; Note&lt;/span&gt;: There
may be latency issues due to replication, if the page does not display
keep refreshing&lt;br /&gt;
July 8, 2008
&lt;/p&gt;
&lt;p&gt;Today
Microsoft released the following Security Bulletin(s).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Note: &lt;a href="http://www.microsoft.com/technet/security" target="_blank"&gt;www.microsoft.com/technet/security&lt;/a&gt;
and &lt;a href="http://www.microsoft.com/security" target="_blank"&gt;www.microsoft.com/security&lt;/a&gt;
are
authoritative in all matters concerning Microsoft Security Bulletins!
ANY e-mail, web board or newsgroup posting (including this one) should
be verified by visiting these sites for official information. Microsoft
never sends security or other updates as attachments. These updates
must be downloaded from the microsoft.com download center or Windows
Update. See the individual bulletins for details.&lt;br /&gt;
&lt;br /&gt;
Because some malicious messages attempt to masquerade as official
Microsoft security notices, it is recommended that you physically type
the URLs into your web browser and not click on the hyperlinks
provided.
&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx"&gt;July
Bulletin Summary&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-weight:bold;"&gt;Important (4)&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-040.mspx"&gt;MS08-040&lt;/a&gt;
- Vulnerabilities in Microsoft SQL Server Could Allow Elevation of
Privilege (941203)&lt;br /&gt;
&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx"&gt;MS08-038&lt;/a&gt;
- Vulnerability in Windows Explorer Could Allow Remote Code Execution
(950582)&lt;br /&gt;
&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx"&gt;MS08-037&lt;/a&gt;
- Vulnerabilities in DNS Could Allow Spoofing (953230)&lt;br /&gt;
&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-039.mspx"&gt;MS08-039&lt;/a&gt;
- Vulnerabilities in Outlook Web Access for Exchange Server Could Allow
Elevation of Privilege (953747)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;
&lt;br /&gt;
This represents our regularly scheduled monthly bulletin
release
(second Tuesday of each month). Please note that Microsoft may release
bulletins out side of this schedule if we determine the need to do so.&lt;/p&gt;
&lt;p&gt;If you have
any questions regarding the patch or its implementation after
reading the above listed bulletin you should contact Product Support
Services in the United States at 1-866-PCSafety (1-866-727-2338).
International customers should contact their local subsidiary.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639803" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Advisory Notification - July 7, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/07/microsoft-security-advisory-notification-july-7-2008.aspx</link><pubDate>Mon, 07 Jul 2008 18:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639657</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639657</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/07/microsoft-security-advisory-notification-july-7-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 7, 2008&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* &lt;b&gt;Microsoft Security Advisory (955179)&lt;/b&gt;&lt;br /&gt;&amp;nbsp; - Title: Vulnerability in the ActiveX Control for the&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Snapshot Viewer for Microsoft Access Could Allow Remote Code&lt;br /&gt;Execution&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/955179.mspx"&gt;http://www.microsoft.com/technet/security/advisory/955179.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: Advisory published.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639657" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Advance Notification for July 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/03/microsoft-security-bulletin-advance-notification-for-july-2008.aspx</link><pubDate>Thu, 03 Jul 2008 19:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639268</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639268</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/03/microsoft-security-bulletin-advance-notification-for-july-2008.aspx#comments</comments><description>&lt;p&gt;Issued: July 3, 2008&lt;br /&gt;&lt;br /&gt;This is an advance notification of security bulletins that&lt;br /&gt;Microsoft is intending to release on July 8, 2008.&lt;br /&gt;&lt;br /&gt;The full version of the Microsoft Security Bulletin Advance&lt;br /&gt;Notification for July 2008 can be found at&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This bulletin advance notification will be replaced with the &lt;br /&gt;July bulletin summary on July 8, 2008. For more information&lt;br /&gt;about the bulletin advance notification service, see&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/advance.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/advance.mspx&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;To receive automatic notifications whenever &lt;br /&gt;Microsoft Security Bulletins are issued, subscribe to Microsoft&lt;br /&gt;Technical Security Notifications on&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/notify.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/notify.mspx&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Microsoft will host a webcast to address customer questions on&lt;br /&gt;these bulletins on Wednesday, July 9, 2008,&lt;br /&gt;at 11:00 AM Pacific Time (US &amp;amp; Canada). Register for the July&lt;br /&gt;Security Bulletin Webcast at &lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/summary.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/summary.mspx&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Microsoft also provides information to help customers prioritize&lt;br /&gt;monthly security updates with any non-security, high-priority&lt;br /&gt;updates that are being released on the same day as the monthly&lt;br /&gt;security updates. Please see the section, Other Information.&lt;br /&gt;&lt;br /&gt;This advance notification provides the software subject as the&lt;br /&gt;bulletin identifier, because the official Microsoft Security&lt;br /&gt;Bulletin numbers are not issued until release. The bulletin summary&lt;br /&gt;that replaces this advance notification will have the proper&lt;br /&gt;Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the&lt;br /&gt;bulletin identifier. The security bulletins for this month are as&lt;br /&gt;follows, in order of severity:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Important Security Bulletins&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;SQL Bulletin&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;i&gt;&lt;b&gt;Affected Software:&lt;/b&gt;&lt;/i&gt; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft SQL Server 2000 Desktop Engine (WMSDE) on&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Windows 2000 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft SQL Server 2000 Desktop Engine (WMSDE) on&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 1 and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Internal Database (WYukon) Service Pack 2 on&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 1 and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft SQL Server 2000 Desktop Engine (WMSDE) on&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 x64 Edition and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Internal Database (WYukon) x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on Windows Server 2003 x64 Edition and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Internal Database (WYukon) Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on Windows Server 2008 for 32-bit Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Internal Database (WYukon) x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on Windows Server 2008 for x64-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 7.0 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 7.0 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 2000 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 2000 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 2000 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Edition Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 2000 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Edition Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 2005 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 2005 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 2005 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 2005 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for SQL Server 2005 with SP2 for&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for SQL Server 2005 with SP2 for&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for Microsoft Data Engine (MSDE) 1.0 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for Microsoft Data Engine (MSDE) 1.0 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for Microsoft SQL Server 2000 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop Engine (MSDE 2000) Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for Microsoft SQL Server 2000 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop Engine (MSDE 2000) Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for Microsoft SQL Server 2005 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Express Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for Microsoft SQL Server 2005 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Express Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GDR update for Microsoft SQL Server 2005 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Express Edition with Advanced Services Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - QFE update for Microsoft SQL Server 2005 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Express Edition with Advanced Services Service Pack 2&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Impact: Elevation of Privilege&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Version Number: 1.0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Bulletin 1&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;i&gt;&lt;b&gt;Affected Software:&lt;/b&gt;&lt;/i&gt; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Vista and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Vista Service Pack 1&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Vista x64 Edition and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Vista x64 Edition Service Pack 1&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Server 2008 for 32-bit Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Server 2008 for x64-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Windows Server 2008 for Itanium-based Systems&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Impact: Remote Code Execution&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Version Number: 1.0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Bulletin 2&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;i&gt;&lt;b&gt;Affected Software:&lt;/b&gt;&lt;/i&gt; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Microsoft Windows 2000 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Microsoft Windows 2000 Service Pack 4&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Windows XP Service Pack 2 and &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows XP Service Pack 3&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Windows XP Professional x64 Edition and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows XP Professional x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Windows Server 2003 Service Pack 1 and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Windows Server 2003 Service Pack 1 and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Windows Server 2003 x64 Edition and &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Windows Server 2003 x64 Edition and &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 x64 Edition Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Client update for Windows Server 2003 with SP1 for &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Systems and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 with SP2 for Itanium-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Windows Server 2003 with SP1 for &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Itanium-based Systems and&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows Server 2003 with SP2 for Itanium-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Windows Server 2008 for 32-bit Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Server update for Windows Server 2008 for x64-based Systems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Windows Server 2008 Server Core installation affected)&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Impact: Spoofing&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Version Number: 1.0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Exchange Server Bulletin&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; - &lt;i&gt;&lt;b&gt;Affected Software:&lt;/b&gt;&lt;/i&gt; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft Exchange Server 2003 Service Pack 2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft Exchange Server 2007&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Microsoft Exchange Server 2007 Service Pack 1&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Impact: Elevation of Privilege&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Version Number: 1.0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Other Information&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Microsoft Windows Malicious Software Removal Tool:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Microsoft will release an updated version of the Microsoft Windows&lt;br /&gt;Malicious Software Removal Tool on Windows Update, Microsoft Update,&lt;br /&gt;Windows Server Update Services, and the Download Center.&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Non-Security, High-Priority Updates on MU, WU, and WSUS:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For information about non-security releases on Windows Update and&lt;br /&gt;Microsoft &lt;br /&gt;update, please see:&lt;br /&gt;* &lt;a href="http://support.microsoft.com/kb/894199"&gt;http://support.microsoft.com/kb/894199&lt;/a&gt;: Microsoft Knowledge Base&lt;br /&gt;&amp;nbsp; Article 894199, Description of Software Update Services and&lt;br /&gt;&amp;nbsp; Windows Server Update Services changes in content for 2008.&lt;br /&gt;&amp;nbsp; Includes all Windows content.&lt;br /&gt;* &lt;a href="http://technet.microsoft.com/en-us/wsus/bb466214.aspx"&gt;http://technet.microsoft.com/en-us/wsus/bb466214.aspx&lt;/a&gt;: New,&lt;br /&gt;&amp;nbsp; Revised, and Released Updates for Microsoft Products Other Than&lt;br /&gt;&amp;nbsp; Microsoft Windows&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639268" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Advisory Notification - July 2, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/03/microsoft-security-advisory-notification-july-2-2008.aspx</link><pubDate>Thu, 03 Jul 2008 04:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639204</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639204</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/03/microsoft-security-advisory-notification-july-2-2008.aspx#comments</comments><description>&lt;p&gt; &lt;i&gt;Issued: July 2, 2008&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* &lt;b&gt;Microsoft Security Advisory (953818)&lt;/b&gt;&lt;br /&gt;&amp;nbsp; - Title: Blended Threat from Combined Attack Using&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apple&amp;#39;s Safari on the Windows Platform&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/953818.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953818.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: July 2, 2008: Updated the Suggested Actions.&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639204" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Firefox 2.0.0.15 Released</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/02/firefox-2-0-0-15-released.aspx</link><pubDate>Wed, 02 Jul 2008 10:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639085</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639085</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/02/firefox-2-0-0-15-released.aspx#comments</comments><description>&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;Known Vulnerabilities Fixed in Firefox 2.0.0.15: &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;&lt;/span&gt;&lt;br /&gt;MFSA 2008-33 Crash and remote code execution in block reflow&lt;br /&gt;MFSA 2008-32 Remote site run as local file via Windows URL shortcut&lt;br /&gt;MFSA 2008-31 Peer-trusted certs can use alt names to spoof&lt;br /&gt;MFSA 2008-30 File location URL in directory listings not escaped properly&lt;br /&gt;MFSA 2008-29 Faulty .properties file results in uninitialized memory being used&lt;br /&gt;MFSA 2008-28 Arbitrary socket connections with Java LiveConnect on Mac OS X&lt;br /&gt;MFSA 2008-27 Arbitrary file upload via originalTarget and DOM Range&lt;br /&gt;MFSA 2008-25 Arbitrary code execution in mozIJSSubScriptLoader.loadSubScript()&lt;br /&gt;MFSA 2008-24 Chrome script loading from fastload file&lt;br /&gt;MFSA 2008-23 Signed JAR tampering&lt;br /&gt;MFSA 2008-22 XSS through JavaScript same-origin violation&lt;br /&gt;MFSA 2008-21 Crashes with evidence of memory corruption (rv:1.8.1.15)&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15"&gt;http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639085" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Apple closes holes in Mac OS X, Safari</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/07/02/apple-closes-holes-in-mac-os-x-safari.aspx</link><pubDate>Wed, 02 Jul 2008 09:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639081</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1639081</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/07/02/apple-closes-holes-in-mac-os-x-safari.aspx#comments</comments><description>&lt;p&gt;&lt;span class="body"&gt;
&lt;p&gt;
Apple plugged 25 security holes in components of its Mac OS X operating
system on Monday, closing remote execution vulnerabilities in its
Safari Web browser and the Ruby Web programming language.&lt;/p&gt;
&lt;p&gt;
The software patch -- the fourth this year for Apple&amp;#39;s Mac OS X -- also
fixed flaws in the open-source Apache Tomcat Java server, Apple&amp;#39;s VPN
client, the operating system&amp;#39;s screen lock, and the handling of
potentially unsafe types of content. While the open-source Apache
Tomcat server racked up the most vulnerabilities, the most severe
issues affect the Ruby Web programming language, WebKit library for
Safari, and Mac OS X core library functions.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/brief/767"&gt;http://www.securityfocus.com/brief/767&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639081" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Advisory Notification - June 30, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/30/microsoft-security-advisory-notification-june-30-2008.aspx</link><pubDate>Mon, 30 Jun 2008 22:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638934</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1638934</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/30/microsoft-security-advisory-notification-june-30-2008.aspx#comments</comments><description>&lt;p&gt;&lt;br /&gt;&lt;i&gt;Issued: June 30, 2008&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;* &lt;b&gt;Microsoft Security Advisory (954960)&lt;/b&gt;&lt;br /&gt;&amp;nbsp; - Title: Microsoft Windows Server Update Services&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (WSUS) Blocked from Deploying Security Updates&lt;br /&gt;&amp;nbsp; - &lt;a target="_blank" href="http://www.microsoft.com/technet/security/advisory/954960.mspx"&gt;http://www.microsoft.com/technet/security/advisory/954960.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: Advsiory published.&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638934" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Onslaught of fake Microsoft patch spam</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/30/onslaught-of-fake-microsoft-patch-spam.aspx</link><pubDate>Mon, 30 Jun 2008 21:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638929</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1638929</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/30/onslaught-of-fake-microsoft-patch-spam.aspx#comments</comments><description>&lt;p&gt;Websense&amp;reg; Security Labs&amp;trade; ThreatSeeker&amp;trade; Network has discovered a
substantial number of spam messages utilizing a reliable social
engineering trick that lures users to download a Microsoft critical
security update.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://securitylabs.websense.com/content/Alerts/3122.aspx"&gt;Details ...&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638929" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Alerts/default.aspx">Alerts</category></item><item><title>Malware morphs to greater numbers</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/25/malware-morphs-to-greater-numbers.aspx</link><pubDate>Wed, 25 Jun 2008 20:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637678</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1637678</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/25/malware-morphs-to-greater-numbers.aspx#comments</comments><description>&lt;p&gt;&lt;span class="body"&gt;&lt;p&gt;The number of signatures required to detect malicious code skyrocketed
in the first half of 2008, increasing by 80 percent since the end of
2007, according to data released by antivirus firm F-Secure on Tuesday.&lt;/p&gt;
&lt;p&gt;
The data -- part of the F-Secure&amp;#39;s &lt;a href="http://www.f-secure.com/2008/1/index.html" target="_blank"&gt;IT Security Threat Summary&lt;/a&gt;
-- showed that the company currently requires nearly 900,000 different
signatures, also referred to as &amp;quot;definitions&amp;quot; or &amp;quot;detections,&amp;quot; in its
product to catch current threats, up from &lt;a href="http://www.securityfocus.com/brief/655"&gt;500,000 signatures&lt;/a&gt; at the end of 2007.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/brief/763"&gt;http://www.securityfocus.com/brief/763&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637678" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Advisory Notification - June 24, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/25/microsoft-security-advisory-notification-june-24-2008.aspx</link><pubDate>Wed, 25 Jun 2008 17:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637607</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1637607</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/25/microsoft-security-advisory-notification-june-24-2008.aspx#comments</comments><description>&lt;p&gt;&lt;i&gt;Issued: June 24, 2008&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* Microsoft Security Advisory (954462)&lt;br /&gt;&amp;nbsp; - Title: Rise in SQL Injection Attacks Exploiting&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unverified User Data Input&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/954462.mspx"&gt;http://www.microsoft.com/technet/security/advisory/954462.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: Advisory published.&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637607" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Revisions - June 24, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/24/microsoft-security-bulletin-revisions-june-24-2008.aspx</link><pubDate>Tue, 24 Jun 2008 21:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637340</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1637340</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/24/microsoft-security-bulletin-revisions-june-24-2008.aspx#comments</comments><description>&lt;p&gt;&lt;i&gt;Issued: June 24, 2008&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; * &lt;span style="font-weight:bold;"&gt;MS07-042 - Critical&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS07-042 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;- &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp;- Reason for Revision: V4.0 (June 24, 2008): Bulletin updated:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Added Windows XP Service Pack 3, Windows Vista Service Pack&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1, Windows Vista x64 Edition Service Pack 1, Windows Server&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2008 for 32-bit Systems, Windows Server 2008 for x64-based&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Systems, and Windows Server 2008 for Itanium-based Systems as&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; affected software. This is a detection update only. There&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; were no changes to the binaries.&amp;nbsp; &lt;br /&gt;&amp;nbsp;- Originally posted: August 14, 2007&lt;br /&gt;&amp;nbsp;- Updated: June 24, 2008&lt;br /&gt;&amp;nbsp;- Bulletin Severity Rating: Critical&lt;br /&gt;&amp;nbsp;- Version: 4.0&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637340" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Advisory Notification - June 20, 2008</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/21/microsoft-security-advisory-notification-june-20-2008.aspx</link><pubDate>Sat, 21 Jun 2008 16:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636523</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1636523</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/21/microsoft-security-advisory-notification-june-20-2008.aspx#comments</comments><description>&lt;p&gt; &lt;i&gt;Issued: June 20, 2008&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;* Microsoft Security Advisory (953818)&lt;br /&gt;&amp;nbsp; - Title: Blended Threat from Combined Attack Using&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apple&amp;#39;s Safari on the Windows Platform&lt;br /&gt;&amp;nbsp; - &lt;a href="http://www.microsoft.com/technet/security/advisory/953818.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953818.mspx&lt;/a&gt;&lt;br /&gt;&amp;nbsp; - Revision Note: June 20, 2008: Advisory updated to provide&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; link to related Apple security advisory.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636523" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>New Phishing/Storm Worm Variant Spreading</title><link>http://msmvps.com/blogs/donpatterson/archive/2008/06/20/new-phishing-storm-worm-variant-spreading.aspx</link><pubDate>Fri, 20 Jun 2008 10:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636010</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1636010</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2008/06/20/new-phishing-storm-worm-variant-spreading.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Arial, Geneva, Helvetica"&gt; US-CERT has received reports
of new phishing activity, some of which has been linked to Storm Worm.
The latest activity is centered around messages related to the recent
earthquake in China and the upcoming Olympic Games. This Trojan is
spread via an unsolicited email message that contains a link to a
malicious website. This website contains a video that, when opened, may
run the executable file &amp;quot;beijing.exe&amp;quot; to infect the user&amp;#39;s system with
malicious code.&lt;br /&gt;&lt;br /&gt;Reports, including a posting by &lt;a href="https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;amp;thread.id=207" target="_self"&gt;Symantec&lt;/a&gt;, indicate that the following subject lines are being used. Please note that subject lines can change at any time.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;font face="Arial, Geneva, Helvetica"&gt;&lt;li&gt;The most powerful quake hits China&lt;/li&gt;&lt;li&gt;Countless victims of earthquake in China&lt;/li&gt;&lt;li&gt;Death toll in China is growing&lt;/li&gt;&lt;li&gt;Recent earthquake in china took a heavy toll&lt;/li&gt;&lt;li&gt;Recent china earthquake kills million&lt;/li&gt;&lt;li&gt;China is paralyzed by new earthquake&lt;/li&gt;&lt;li&gt;Death toll in China exceeds 1000000&lt;/li&gt;&lt;li&gt;A new powerful disaster in China&lt;/li&gt;&lt;li&gt;A new deadly catastrophe in China&lt;/li&gt;&lt;li&gt;2008 Olympic Games are under the threat&lt;/li&gt;&lt;li&gt;China&amp;#39;s most deadly earthquake&lt;br /&gt;&lt;/li&gt;&lt;/font&gt;&lt;/ul&gt;&lt;font face="Arial, Geneva, Helvetica"&gt;US-CERT encourages users and administrators to take the following preventative measures to mitgate the security risks:&lt;br /&gt;&lt;/font&gt;&lt;ul&gt;&lt;font face="Arial, Geneva, Helvetica"&gt;&lt;li&gt;Install anti-virus software, and keep its virus signature files up-to-date.&lt;/li&gt;&lt;li&gt;Do not follow unsolicited web links received in email messages.&lt;/li&gt;&lt;li&gt;Refer to the &lt;a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_self"&gt;Recognizing and Avoiding Email Scams&lt;/a&gt; (pdf) document for more information on avoiding email scams.&lt;/li&gt;&lt;li&gt;Refer to the &lt;a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self"&gt;Avoiding Social Engineering and Phishing Attacks&lt;/a&gt; document for more information on social engineering attacks.&lt;/li&gt;&lt;/font&gt;&lt;/ul&gt;&lt;p&gt;&lt;font face="Arial, Geneva, Helvetica"&gt;US-CERT reminds users to beware of future phishing attacks that may target natural disasters and the Olympic Games.
















  
&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.us-cert.gov/current/index.html#new_storm_worm_variant_spreads2"&gt;http://www.us-cert.gov/current/index.html#new_storm_worm_variant_spreads2&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636010" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Alerts/default.aspx">Alerts</category></item></channel></rss>