<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MVP Jubo Security Blog : Security Bulletins</title><link>http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx</link><description>Tags: Security Bulletins</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Microsoft Security Bulletin Summary for November 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/11/11/1739113.aspx</link><pubDate>Wed, 11 Nov 2009 23:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739113</guid><dc:creator>jubo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1739113</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/11/11/1739113.aspx#comments</comments><description>&lt;p&gt;Yesterday, November 10, was once again patch-tuesday. Microsoft released another 6 security bulletins, addressing a total of 15 vulnerabilities. Three of them rated as &amp;quot;Critical&amp;quot; and three as &amp;quot;Important&amp;quot;. Here&amp;#39;s the list:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=163840"&gt;MS09-063&lt;/a&gt; - Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=163841"&gt;MS09-064&lt;/a&gt; - Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=162428"&gt;MS09-065&lt;/a&gt; - Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Important:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=157862"&gt;MS09-066&lt;/a&gt; - Vulnerability in Active Directory Could Allow Denial of Service (973309)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=165431"&gt;MS09-067&lt;/a&gt; - Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=165890"&gt;MS09-068&lt;/a&gt; - Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at Microsoft &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/security/updates/bulletins/200911.aspx"&gt;Security&lt;/a&gt; website.&lt;/p&gt;
&lt;p&gt;See also the &lt;a target="_blank" href="http://blogs.technet.com/msrc/default.aspx"&gt;MSRC&lt;/a&gt; blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/11/10/november-2009-security-bulletin-release.aspx"&gt;November 2009 Security Bulletin Release&lt;/a&gt;. And the &lt;a target="_blank" href="http://blogs.technet.com/srd/default.aspx"&gt;Security Research and Defense&lt;/a&gt; blog for additional technical information on these updates.&lt;/p&gt;
&lt;p&gt;If your computer has not updated itself yet, then it&amp;#39;s now time to move yor mouse to the &lt;a target="_blank" href="http://update.microsoft.com"&gt;Microsoft Update&lt;/a&gt; website to start downloading the patches.&lt;/p&gt;
&lt;p&gt;Have a wonderful day! The sun was out here today in Washington after days and days of rain...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739113" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for October 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/10/22/1734324.aspx</link><pubDate>Thu, 22 Oct 2009 17:11:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734324</guid><dc:creator>jubo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1734324</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/10/22/1734324.aspx#comments</comments><description>&lt;p&gt;Yes, it has been a while but have been on a trip to Europe and visited family. In the meantime Microsoft released a big security update for patch Tuesday earlier this month. There are 8 &amp;quot;critical&amp;quot; and 5 rated as &amp;quot;Important&amp;quot;. There can be more when you check for them depending on the configuration of your computer. Here&amp;#39;s the list:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=163970"&gt;MS09-050&lt;/a&gt; - Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=125438"&gt;MS09-051&lt;/a&gt; - Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=163913"&gt;MS09-052&lt;/a&gt; - Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=163979"&gt;MS09-054&lt;/a&gt; - Cumulative Security Update for Internet Explorer (974455)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=158202"&gt;MS09-055&lt;/a&gt; - Cumulative Security Update of ActiveX Kill Bits (973525)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=160633"&gt;MS09-060&lt;/a&gt; - Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=160527"&gt;MS09-061&lt;/a&gt; - Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=161342"&gt;MS09-062&lt;/a&gt; - Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=164004"&gt;MS09-053&lt;/a&gt; - Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=163830"&gt;MS09-056&lt;/a&gt; - Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=163832"&gt;MS09-057&lt;/a&gt; - Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=162442"&gt;MS09-058&lt;/a&gt; - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=163843"&gt;MS09-059&lt;/a&gt; - Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at Microsoft &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/security/updates/bulletins/200910.aspx"&gt;Security Updates&lt;/a&gt; website.&lt;/p&gt;
&lt;p&gt;See also the &lt;a target="_blank" href="http://blogs.technet.com/msrc/default.aspx"&gt;MSRC&lt;/a&gt; blog:&amp;nbsp;&lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx"&gt;October 2009 Security Bulletin Release&lt;/a&gt;. And the &lt;a href="http://blogs.technet.com/srd/default.aspx"&gt;Security Research and Defense blog&lt;/a&gt; for additional technical information on these updates.&lt;/p&gt;
&lt;p&gt;Even though this is a bit late, and I really hope you already have updated your computer(s). But if not then you know the drill! Point your mouse to the &lt;a target="_blank" href="http://update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; website and start updating.&lt;/p&gt;
&lt;p&gt;Have a wonderful day... From a &lt;a target="_blank" href="http://www.barnesandnoble.com/"&gt;Barnes &amp;amp; Noble&lt;/a&gt; Starbucks Cafe in the Evergreen State...&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1734324" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for September 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/09/08/1721748.aspx</link><pubDate>Wed, 09 Sep 2009 04:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1721748</guid><dc:creator>jubo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1721748</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/09/08/1721748.aspx#comments</comments><description>&lt;p&gt;Today Microsoft released 5 critical updates. If you have not updated your computer(s) yet, then check with &lt;a target="_blank" href="http://update.microsoft.com"&gt;Microsoft Update&lt;/a&gt; website. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=157304"&gt;MS09-045&lt;/a&gt; -&amp;nbsp;Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=151360"&gt;MS09-049&lt;/a&gt; - Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution (970710)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=158082"&gt;MS09-047&lt;/a&gt; - Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=155978"&gt;MS09-048&lt;/a&gt; - Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=158009"&gt;MS09-046&lt;/a&gt; - Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at Microsoft &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/security/updates/bulletins/200909.aspx"&gt;Security Updates&lt;/a&gt; website.&lt;/p&gt;
&lt;p&gt;See also the &lt;a target="_blank" href="http://blogs.technet.com/msrc/default.aspx"&gt;MSRC&lt;/a&gt; blog:&amp;nbsp;&lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx"&gt;September 2009&lt;/a&gt; Bulletin Release. And the &lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/09/08/assessing-the-risk-of-the-september-critical-security-bulletins.aspx"&gt;Security Research and Defense blog&lt;/a&gt; for additional technical information on these updates.&lt;/p&gt;
&lt;p&gt;Well, you know the drill... point your mouse to the &lt;a target="_blank" href="http://update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; website and start updating. &lt;/p&gt;
&lt;p&gt;Have a wonderful day!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1721748" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for August 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/08/11/1714943.aspx</link><pubDate>Tue, 11 Aug 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714943</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1714943</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/08/11/1714943.aspx#comments</comments><description>&lt;p&gt;Today, August 11th,&amp;nbsp;Microsoft released 5 &amp;quot;critical&amp;quot; updates and 4 &amp;quot;important&amp;quot; updates. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=128110"&gt;MS09-043&lt;/a&gt; - Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=157861"&gt;MS09-044&lt;/a&gt; - Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=155974"&gt;MS09-039&lt;/a&gt; - Vulnerabilities in WINS Could Allow Remote Code Execution (969883)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=155975"&gt;MS09-038&lt;/a&gt; - Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=158695"&gt;MS09-037&lt;/a&gt; - Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=155977"&gt;MS09-041&lt;/a&gt; - Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=155979"&gt;MS09-040&lt;/a&gt; - Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=157296"&gt;MS09-036&lt;/a&gt; - Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=157140"&gt;MS09-042&lt;/a&gt; - Vulnerability in Telnet Could Allow Remote Code Execution (960859)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at Microsoft&amp;nbsp;&lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS09-aug.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/security/updates/bulletins/200908.aspx"&gt;Security Updates&lt;/a&gt; website.&lt;/p&gt;
&lt;p&gt;See also the &lt;a target="_blank" href="http://blogs.technet.com/msrc/default.aspx"&gt;MSRC&lt;/a&gt; blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx"&gt;August 2009 Bulletin Release&lt;/a&gt;. And the &lt;a target="_blank" href="http://blogs.technet.com/srd"&gt;Security Research and Defense&lt;/a&gt; blog for additional technical information on these updates.&lt;/p&gt;
&lt;p&gt;Well, you know the drill... point your mouse to the &lt;a target="_blank" href="http://update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; website and start updating. And I&amp;#39;ll see you next time from a &lt;a target="_blank" href="http://www.starbucks.com"&gt;Starbucks&lt;/a&gt; store somewhere in this beautiful Washington state where we had the first rain after several weeks of beautiful sunshine...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714943" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Advance Notification for July 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/07/25/1710171.aspx</link><pubDate>Sun, 26 Jul 2009 03:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1710171</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1710171</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/07/25/1710171.aspx#comments</comments><description>&lt;p style="PADDING-LEFT:30px;"&gt;&lt;em&gt;Microsoft released an advance notification of two out-of-band security bulletins that Microsoft is intending to release on July 28, 2009. One bulletin will be for the Microsoft Visual Studio product line; application developers should be aware of updates available affecting certain types of applications. The second bulletin contains defense-in-depth changes to Internet Explorer to address attack vectors related to the Visual Studio bulletin, as well as fixes for unrelated vulnerabilities that are rated Critical. Customers who are up to date on their security updates are protected from known attacks related to this out-of-band release&lt;/em&gt;.&lt;/p&gt;
&lt;p style="PADDING-LEFT:30px;"&gt;&lt;em&gt;This bulletin advance notification will be replaced with an update to the &lt;/em&gt;&lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx"&gt;&lt;em&gt;Microsoft Security Bulletin Summary for July 2009&lt;/em&gt;&lt;/a&gt;&lt;em&gt; on July 28, 2009.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Click for more information &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-jul-ans.mspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;See also: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/07/24/advance-notification-for-july-2009-out-of-band-releases.aspx"&gt;Microsoft Security Response Center (MSRC)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1710171" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for July 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/07/16/1702380.aspx</link><pubDate>Thu, 16 Jul 2009 18:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1702380</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1702380</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/07/16/1702380.aspx#comments</comments><description>&lt;p&gt;A little late, but here it is. Microsoft released another couple of updates on the usual &amp;quot;Patch Tuesday&amp;quot;, July 4th. There are three &amp;quot;critical&amp;quot; and three &amp;quot;important&amp;quot; updates to download and to install. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=139788"&gt;MS09-029&lt;/a&gt; - Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=152887"&gt;MS09-028&lt;/a&gt; - Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=157386"&gt;MS09-032&lt;/a&gt; - Cumulative Security Update of ActiveX Kill Bits (973346)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=153891"&gt;MS09-033&lt;/a&gt; - Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=154993"&gt;MS09-031&lt;/a&gt; - Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=147424"&gt;MS09-030&lt;/a&gt; - Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As usual, a more technical version of the Security Bulletin can be found at &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at &lt;a target="_blank" href="http://www.microsoft.com/security/updates/bulletins/200907.aspx"&gt;Microsoft&amp;#39;s Security&lt;/a&gt;&amp;nbsp;website.&lt;/p&gt;
&lt;p&gt;See also the &lt;a target="_blank" href="http://blogs.technet.com/msrc/default.aspx"&gt;MSRC&lt;/a&gt; blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2009/07/15/security-bulletin-webcast-video-questions-and-answers-july-2009.aspx"&gt;Security Bulletin Webcast Video, Questions and Answers &amp;ndash; July 2009&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Have a wonderful day! From a &lt;a target="_blank" href="http://www.starbucks.com/retail/find/storedetails.aspx?sid=9592&amp;amp;coords=First%20Interstate,%2098104|47.60440160534351|-122.331865|15&amp;amp;fs=1"&gt;Starbucks&lt;/a&gt; store in sunny Seattle.... &lt;img src="http://msmvps.com/emoticons/emotion-5.gif" alt="Wink" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1702380" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for June 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/06/18/1695815.aspx</link><pubDate>Thu, 18 Jun 2009 22:06:53 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1695815</guid><dc:creator>jubo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1695815</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/06/18/1695815.aspx#comments</comments><description>&lt;p&gt;In between al the housework and painting Microsoft released 10, but could be more for your configuration, updates and patches for the month of June. There are six “critical”, three “important” and one “moderate” patches. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=151361" target="_blank"&gt;MS09-018&lt;/a&gt; - Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=141786" target="_blank"&gt;MS09-022&lt;/a&gt; - Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=150860" target="_blank"&gt;MS09-019&lt;/a&gt; - Cumulative Security Update for Internet Explorer (969897)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=147416" target="_blank"&gt;MS09-027&lt;/a&gt; - Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=147294" target="_blank"&gt;MS09-021&lt;/a&gt; - Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128104" target="_blank"&gt;MS09-024&lt;/a&gt; - Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=150174" target="_blank"&gt;MS09-026&lt;/a&gt; - Vulnerability in RPC Could Allow Elevation of Privilege (970238)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=150248" target="_blank"&gt;MS09-025&lt;/a&gt; - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=150568" target="_blank"&gt;MS09-020&lt;/a&gt; - Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Moderate:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=143550" target="_blank"&gt;MS09-023&lt;/a&gt; - Vulnerability in Windows Search Could Allow Information Disclosure (963093)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;As usual, a more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200905.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site.&lt;/p&gt;  &lt;p&gt;See also the &lt;a href="http://blogs.technet.com/msrc/default.aspx" target="_blank"&gt;MSRC&lt;/a&gt; blog: &lt;a href="http://blogs.technet.com/msrc/archive/2009/06/09/june-2009-bulletin-release.aspx" target="_blank"&gt;June 2009 Bulletin Release&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Hope you have already updated your machine. If not then you know where to find &lt;a href="http://update.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Have a wonderful day! It’s the 29th day, and counting…, without rain in the Seattle area… I love it.. ;)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695815" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for May 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/05/18/1692622.aspx</link><pubDate>Mon, 18 May 2009 17:04:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1692622</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1692622</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/05/18/1692622.aspx#comments</comments><description>&lt;p&gt;Because of all that moving around, from one continent to the other, and all the reconstruction of the house, I’ve not been able to post the monthly updates here. But if you haven’t done it already then you know the drill: just go to &lt;a href="http://update.microsoft.com" target="_blank"&gt;Microsoft Update&lt;/a&gt; to check for updates and patches. When I checked a few days ago, I also found out that there’s &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=B444BF18-79EA-46C6-8A81-9DB49B4AB6E5&amp;amp;displaylang=en" target="_blank"&gt;Service Pack 2&lt;/a&gt; for Microsoft Office 2007. So, if you don’t have it yet, then go and get it. &lt;/p&gt;  &lt;p&gt;In the meanwhile, for the month of May there are some critical updates for Microsoft Office PowerPoint:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=141704" target="_blank"&gt;MS09-017&lt;/a&gt; - Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200905.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site.&lt;/p&gt;  &lt;p&gt;See also the &lt;a href="http://blogs.technet.com/msrc/default.aspx" target="_blank"&gt;MSRC&lt;/a&gt; blog: &lt;a href="http://blogs.technet.com/msrc/archive/2009/05/12/may-2009-bulletin-release.aspx" target="_blank"&gt;May 2009 Bulletin Release&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Have a great day!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1692622" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for February 2009</title><link>http://msmvps.com/blogs/jubo/archive/2009/02/12/1671669.aspx</link><pubDate>Thu, 12 Feb 2009 09:09:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1671669</guid><dc:creator>jubo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1671669</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2009/02/12/1671669.aspx#comments</comments><description>&lt;p&gt;Here in Holland, just a few days before the big move to the US, there’s still some time left to update the only old, old laptop I still have. A few days ago Microsoft released a few updates/patches and if you haven’t updated your computer yet, then it’s time to do the same thing as I do: visit &lt;a href="http://update.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt;. In the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx" target="_blank"&gt;Security Bulletin&lt;/a&gt; there are two “critical” and two “important” updates:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=139814" target="_blank"&gt;MS09-002&lt;/a&gt; - Cumulative Security Update for Internet Explorer (961260)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=136636" target="_blank"&gt;MS09-003&lt;/a&gt; - Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=139513" target="_blank"&gt;MS09-004&lt;/a&gt; - Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128107" target="_blank"&gt;MS09-005&lt;/a&gt; - Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200902.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site. &lt;/p&gt;  &lt;p&gt;See also &lt;a href="http://blogs.technet.com/msrc/default.aspx" target="_blank"&gt;MSRC&lt;/a&gt; blog: &lt;a href="http://blogs.technet.com/msrc/archive/2009/02/10/february-2009-monthly-bulletin-release.aspx" target="_blank"&gt;February 2009 Monthly Bulletin Release&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Have a wonderful day. Until next time from the other side of the pond…&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1671669" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for November 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/11/13/1653988.aspx</link><pubDate>Thu, 13 Nov 2008 08:56:27 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1653988</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1653988</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/11/13/1653988.aspx#comments</comments><description>&lt;p&gt;On November 11th Microsoft released another few security updates. This time, according to the security bulletin, 1 “critical” and 1 “important” update. But, depending on your configuration, there can be more. See also the “&lt;a target="_blank" href="http://technet.microsoft.com/en-us/wsus/bb466214.aspx"&gt;New, Revised, and Released Updates for Microsoft Products Other Than Microsoft Windows&lt;/a&gt;”, and, of course, there’s always the Microsoft Windows Malicious Software Removal Tool. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=128803"&gt;MS08-069&lt;/a&gt; - Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=133434"&gt;MS08-068&lt;/a&gt; - Vulnerability in SMB Could Allow Remote Code Execution (957097) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms08-nov.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/protect/computer/updates/bulletins/200811.mspx"&gt;Security At Home&lt;/a&gt; site. &lt;/p&gt;  &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a target="_blank" href="http://support.microsoft.com/kb/913086"&gt;Knowledge Base Article 913086&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;International Help and Support&lt;/a&gt;. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;See also MSRC blog: &lt;a href="http://blogs.technet.com/msrc/archive/2008/11/11/november-2008-bulletin-release.aspx"&gt;November 2008 Bulletin Release&lt;/a&gt; and for a more details regarding the MS08-068 SMB Credential issue, see the &lt;a href="http://blogs.technet.com/swi/archive/2008/11/11/smb-credential-reflection.aspx"&gt;Security Vulnerability Research &amp;amp; Defense blog&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Updated all the machines I maintained and so far no issues here… Have a wonderful day!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1653988" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Out-of-band security update: MS08-067 – Critical</title><link>http://msmvps.com/blogs/jubo/archive/2008/10/23/1651843.aspx</link><pubDate>Thu, 23 Oct 2008 17:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1651843</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1651843</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/10/23/1651843.aspx#comments</comments><description>&lt;p&gt;Last night, European time, Microsoft released an out-of-band security update. This update resolves a vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. &lt;/p&gt;
&lt;p&gt;For more information check the &lt;a target="_blank" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;Microsoft Security Bulletin MS08-067&lt;/a&gt;. See also Microsoft Security Response Center (MSRC) post: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2008/10/23/additional-upcoming-bulletin-webcasts.aspx"&gt;Additional Microsoft Security Bulletin Webcasts and Information Available for MS08-067&lt;/a&gt;. For an in-dept technical version check the Microsoft Security Vulnerability Research &amp;amp; Defense blog: &lt;a target="_blank" href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx"&gt;More detail about MS08-067, the out-of-band netapi32.dll security update&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the meantime, move your mouse to the &lt;a target="_blank" href="http://update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; web site and start patching your system. Me, myself and I have installed it on Windows XP Pro machines and Server 2003 machines without any problem.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1651843" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for October 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/10/15/1650893.aspx</link><pubDate>Wed, 15 Oct 2008 10:26:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650893</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1650893</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/10/15/1650893.aspx#comments</comments><description>&lt;p&gt;Lots of updates this week! Yesterday Microsoft released 4 &amp;quot;critical&amp;quot;, 6 &amp;quot;important&amp;quot; and 1 &amp;quot;moderate&amp;quot; updates. Needless to say that if you haven&amp;#39;t updated yet then move your mouse over to &lt;a target="_blank" href="http://update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; web site and start downloading and update your system. Here&amp;#39;s the list:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=128125"&gt;MS08-060&lt;/a&gt; - Vulnerability in Active Directory Could Allow Remote Code Execution (957280)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;MS08-058&lt;/a&gt; - Cumulative Security Update for Internet Explorer (956390)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=125712"&gt;MS08-059&lt;/a&gt; - Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt; - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=125709"&gt;MS08-066&lt;/a&gt; - Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt; - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=120829"&gt;MS08-062&lt;/a&gt; - Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=127994"&gt;MS08-063&lt;/a&gt; - Vulnerability in SMB Could Allow Remote Code Execution (957095)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=128103"&gt;MS08-064&lt;/a&gt; - Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=128102"&gt;MS08-065&lt;/a&gt; - Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Moderate:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=128145"&gt;MS08-056&lt;/a&gt; - Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;All this and of course the update of the Windows Malicious Software Removal Tool. A more technical version of the Security Bulletin can be found at &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/protect/computer/updates/bulletins/200810.mspx"&gt;Security At Home&lt;/a&gt; site.&lt;/p&gt; &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a target="_blank" href="http://support.microsoft.com/kb/913086"&gt;Knowledge Base Article 913086&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;See also MSRC blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2008/10/14/october-2008-monthly-bulletin-release.aspx"&gt;October 2008 Monthly Bulletin Release&lt;/a&gt; and for a more technical version, the &lt;a target="_blank" href="http://blogs.technet.com/swi/archive/2008/10/14/bulletin-severity-for-october-bulletins.aspx"&gt;Security Vulnerability Research &amp;amp; Defense blog&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;So far installed on 5 XP Pro SP3 machines without any problems. &lt;/p&gt; &lt;p&gt;Stay on the safe side and have a great day!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650893" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for September 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/09/12/1647575.aspx</link><pubDate>Fri, 12 Sep 2008 07:04:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1647575</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1647575</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/09/12/1647575.aspx#comments</comments><description>&lt;p&gt;On September 9, Microsoft released four security patches and all of them are &amp;quot;critical&amp;quot;. So, if you haven&amp;#39;t updated it yet then it&amp;#39;s time to do so now. Move your mouse to the &lt;a target="_blank" href="http://update.microsoft.com"&gt;Microsoft Update&lt;/a&gt; web site to download and install the updates. &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=121739"&gt;MS08-054&lt;/a&gt; - Vulnerability in Windows Media Player Could Allow Remote Code Execution (954154)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=125468"&gt;MS08-052&lt;/a&gt; - Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=123091"&gt;MS08-053&lt;/a&gt; - Vulnerability in Windows Media Encoder 9 Could Allow Remote Code Execution (954156)&lt;/li&gt; &lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=125229"&gt;MS08-055&lt;/a&gt; - Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms08-sep.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/protect/computer/updates/bulletins/200809.mspx"&gt;Security At Home&lt;/a&gt; site.  &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a target="_blank" href="http://support.microsoft.com/kb/913086"&gt;Knowledge Base Article 913086&lt;/a&gt;.  &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;  &lt;ul&gt; &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;International Help and Support&lt;/a&gt;. &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;See also MSRC blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2008/09/09/september-2008-monthly-bulletin-release.aspx"&gt;September 2008 Monthly Bulletin Release&lt;/a&gt; and for a more technical version, the &lt;a target="_blank" href="http://blogs.technet.com/swi/"&gt;Security Vulnerability Research &amp;amp; Defense&lt;/a&gt; blog. &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Stay safe and have a great weekend!!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1647575" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for August 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/08/15/1644718.aspx</link><pubDate>Thu, 14 Aug 2008 23:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644718</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1644718</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/08/15/1644718.aspx#comments</comments><description>&lt;p&gt;If you haven&amp;#39;t updated your Windows version yet, then it&amp;#39;s time to do this now. You&amp;#39;ll be busy for a few moments because on August 12th, Microsoft released no less than 11 updates/patches. Can be more depending on your configuration. Of the 11 patches 6 of them are classified as &amp;quot;critical&amp;quot; and 5 are &amp;quot;important&amp;quot;. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkID=120576"&gt;MS08-046&lt;/a&gt; - Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=122772"&gt;MS08-045&lt;/a&gt; - Cumulative Security Update for Internet Explorer (953838)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=122912"&gt;MS08-041&lt;/a&gt; - Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=124306"&gt;MS08-043&lt;/a&gt; - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=120394"&gt;MS08-051&lt;/a&gt; - Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=120819"&gt;MS08-044&lt;/a&gt; - Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (924090)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=120577"&gt;MS08-047&lt;/a&gt; - Vulnerability in IPsec Policy Processing Could Allow Information Disclosure (953733)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=104923"&gt;MS08-049&lt;/a&gt; - Vulnerabilities in Event System Could Allow Remote Code Execution (950974)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=117705"&gt;MS08-048&lt;/a&gt; - Security Update for Outlook Express and Windows Mail (951066)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=108245"&gt;MS08-050&lt;/a&gt; - Vulnerability in Windows Messenger Could Allow Information Disclosure (955702)&lt;/li&gt;
&lt;li&gt;&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=123160"&gt;MS08-042&lt;/a&gt; - Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms08-aug.mspx"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a target="_blank" href="http://www.microsoft.com/protect/computer/updates/bulletins/200808.mspx"&gt;Security At Home&lt;/a&gt; site. &lt;/p&gt;
&lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a target="_blank" href="http://support.microsoft.com/kb/913086"&gt;Knowledge Base Article 913086&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt; &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;See also MSRC blog: &lt;a target="_blank" href="http://blogs.technet.com/msrc/archive/2008/08/12/august-2008-monthly-bulletin-release.aspx"&gt;August 2008 Monthly Bulletin Release&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;No need to tell you what to do... move your mouse to: &lt;a target="_blank" href="http://www.update.microsoft.com/"&gt;Microsoft Update&lt;/a&gt; to see if you have to get a few patches...&lt;/p&gt;
&lt;p&gt;Happy Friday...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644718" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for July 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/07/09/1639935.aspx</link><pubDate>Wed, 09 Jul 2008 08:23:12 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639935</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1639935</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/07/09/1639935.aspx#comments</comments><description>&lt;p&gt;Patch Tuesday or patch Wednesday... it all depends on which part of the world you&amp;#39;re in. For me it&amp;#39;s patch Wednesday and yes, yesterday Microsoft released their monthly bulletin with 4 &amp;quot;important&amp;quot; updates.&lt;/p&gt; &lt;p&gt;On July 8th, Microsoft released the following updates:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=113725" target="_blank"&gt;MS08-040&lt;/a&gt; - Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=117296" target="_blank"&gt;MS08-038&lt;/a&gt; - Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=119620" target="_blank"&gt;MS08-037&lt;/a&gt; - Vulnerabilities in DNS Could Allow Spoofing (953230)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=120820" target="_blank"&gt;MS08-039&lt;/a&gt; - Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200807.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site.  &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a href="http://support.microsoft.com/kb/913086" target="_blank"&gt;Knowledge Base Article 913086&lt;/a&gt;.  &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131" target="_blank"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155" target="_blank"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;See also: &lt;a href="http://blogs.technet.com/msrc/archive/2008/07/08/july-2008-bulletin-monthly-release.aspx" target="_blank"&gt;Microsoft Security Response Center&lt;/a&gt; (MSRC) blog&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;So, you all know the drill! If it&amp;#39;s not downloaded by automatic updates then move your mouse pointer to &lt;a href="http://www.update.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt;...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639935" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Patch Tuesday: Advanced Notification</title><link>http://msmvps.com/blogs/jubo/archive/2008/07/04/1639346.aspx</link><pubDate>Fri, 04 Jul 2008 07:08:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639346</guid><dc:creator>jubo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1639346</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/07/04/1639346.aspx#comments</comments><description>&lt;p&gt;Last time I was a bit late to tell you about the Windows Updates, but this time we have an advanced notification. On July 8th, Microsoft is releasing 4 &amp;quot;important&amp;quot; updates. &lt;/p&gt; &lt;p&gt;For more detailed information check &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and the post at the blog of Microsoft Security Response Center: &lt;a href="http://blogs.technet.com/msrc/archive/2008/07/03/july-2008-monthly-release.aspx" target="_blank"&gt;July 2008 Advance Notification&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;If you want to get these advanced notifications by email, RSS or Messenger then signup at: &lt;a href="http://www.microsoft.com/technet/security/bulletin/notify.mspx" target="_blank"&gt;Microsoft Technical Security Notifications&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Have a wonderful day...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639346" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin Summary for June 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/06/25/1637449.aspx</link><pubDate>Wed, 25 Jun 2008 07:21:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637449</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1637449</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/06/25/1637449.aspx#comments</comments><description>&lt;p&gt;It&amp;#39;s a bit late, Microsoft already posted their patches for this month. So, if you haven&amp;#39;t done that yet then it&amp;#39;s a good idea to point your mouse to &lt;a href="http://windowsupdate.microsoft.com/" target="_blank"&gt;Windows Update&lt;/a&gt; and start getting those updates. &lt;/p&gt; &lt;p&gt;On June 10th, Microsoft released the&amp;nbsp; following updates:&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=119619" target="_blank"&gt;MS08-030&lt;/a&gt; - Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=116367" target="_blank"&gt;MS08-031&lt;/a&gt; - Cumulative Security Update for Internet Explorer (950759)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=118655" target="_blank"&gt;MS08-033&lt;/a&gt; - Vulnerabilities in DirectX Could Allow Remote Code Execution (951698)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=111957" target="_blank"&gt;MS08-034&lt;/a&gt; - Vulnerability in WINS Could Allow Elevation of Privilege (948745)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=111953" target="_blank"&gt;MS08-035&lt;/a&gt; - Vulnerability in Active Directory Could Allow Denial of Service (953235)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=117297" target="_blank"&gt;MS08-036&lt;/a&gt; - Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Moderate:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=116368" target="_blank"&gt;MS08-032&lt;/a&gt; - Cumulative Security Update of ActiveX Kill Bits (950760)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-jun.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200806.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site.  &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a href="http://support.microsoft.com/kb/913086" target="_blank"&gt;Knowledge Base Article 913086&lt;/a&gt;. &lt;p&gt;&amp;nbsp; &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt; &lt;ul&gt; &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131" target="_blank"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155" target="_blank"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;See also: &lt;a href="http://blogs.technet.com/msrc/archive/2008/04/08/june-2008-monthly-release.aspx" target="_blank"&gt;Microsoft Security Response Center&lt;/a&gt; (MSRC) blog &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637449" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for May 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/05/14/1622361.aspx</link><pubDate>Wed, 14 May 2008 07:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1622361</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1622361</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/05/14/1622361.aspx#comments</comments><description>&lt;p&gt;Yesterday, May 13th, Microsoft released 3 &amp;quot;critical&amp;quot; and 1 &amp;quot;moderate&amp;quot; update. If the automatic update didn&amp;#39;t get them yet, then it&amp;#39;s time to move your mouse over to &lt;a href="http://windowsupdate.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt; and start updating your computer. If you haven&amp;#39;t installed SP3 for Windows XP yet, then Microsoft Update will offer you this too.&lt;/p&gt;
&lt;p&gt;This months updates:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=117295" target="_blank"&gt;MS08-026&lt;/a&gt; - Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (951207)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=117907" target="_blank"&gt;MS08-027&lt;/a&gt; - Vulnerability in Microsoft Publisher Could Allow Remote Code Execution (951208)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=114750" target="_blank"&gt;MS08-028&lt;/a&gt; - Vulnerability in Microsoft Jet Database Engine Could Allow Remote Code Execution (950749)&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Moderate:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=117943" target="_blank"&gt;MS08-029&lt;/a&gt; - Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service (952044)&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-may.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200805.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site. &lt;/p&gt;
&lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a href="http://support.microsoft.com/kb/913086"&gt;Knowledge Base Article 913086&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131" target="_blank"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155" target="_blank"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;See also: &lt;a class="" href="http://blogs.technet.com/msrc/archive/2008/04/08/may-2008-monthly-release.aspx" target="_blank"&gt;Microsoft Security Response Center&lt;/a&gt; (MSRC) and Security Vulnerability Research &amp;amp; Defense blog: &lt;a href="http://blogs.technet.com/swi/archive/2008/05/13/file-block-and-ms08-026.aspx" target="_blank"&gt;MS08-026: How to prevent Word from loading RTF files&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1622361" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for April 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/04/11/1582311.aspx</link><pubDate>Fri, 11 Apr 2008 07:08:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1582311</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1582311</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/04/11/1582311.aspx#comments</comments><description>&lt;p&gt;On April 9th, Microsoft released 5 &amp;quot;critical&amp;quot; and 3 &amp;quot;important&amp;quot; updates. If you didn&amp;#39;t get them yet then it&amp;#39;s time to move your mouse to &lt;a href="http://go.microsoft.com/fwlink/?LinkID=40747" target="_blank"&gt;Microsoft Update&lt;/a&gt; and start updating your computer. Installed them on my computers and the ones I maintain without any problems. &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Critical:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=115454" target="_blank"&gt;MS08-018&lt;/a&gt; - Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=111955" target="_blank"&gt;MS08-021&lt;/a&gt; - Vulnerabilities in GDI Could Allow Remote Code Execution (948590)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=108169" target="_blank"&gt;MS08-022&lt;/a&gt; - Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=112366" target="_blank"&gt;MS08-023&lt;/a&gt; - Security Update of ActiveX Kill Bits (948881)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=110557" target="_blank"&gt;MS08-024&lt;/a&gt; - Cumulative Security Update for Internet Explorer (947864)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=108231" target="_blank"&gt;MS08-020&lt;/a&gt; - Vulnerability in DNS Client Could Allow Spoofing (945553)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=111956" target="_blank"&gt;MS08-025&lt;/a&gt; - Vulnerability in Windows Kernel Could Allow Elevation of Privilege (941693)&lt;/li&gt; &lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=115455" target="_blank"&gt;MS08-019&lt;/a&gt; - Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200804.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site.  &lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a href="http://support.microsoft.com/kb/913086" target="_blank"&gt;Knowledge Base Article 913086&lt;/a&gt;.  &lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt; &lt;ul&gt; &lt;li&gt;Customers in the U.S. and Canada can receive technical support from Microsoft &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131" target="_blank"&gt;Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155" target="_blank"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;See also: &lt;a href="http://blogs.technet.com/msrc/archive/2008/04/08/april-2008-monthly-release.aspx" target="_blank"&gt;Microsoft Security Response Center&lt;/a&gt; (MSRC) and &lt;a href="http://blogs.technet.com/swi/default.aspx" target="_blank"&gt;Security Vulnerability Research &amp;amp; Defense&lt;/a&gt; blog.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1582311" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item><item><title>Microsoft Security Bulletin Summary for March 2008</title><link>http://msmvps.com/blogs/jubo/archive/2008/03/12/1540798.aspx</link><pubDate>Wed, 12 Mar 2008 08:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1540798</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1540798</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/03/12/1540798.aspx#comments</comments><description>&lt;p&gt;Yesterday, March 11th, Microsoft released 4 critical updates. So far I have it installed on five XP Pro SP2 machines without any problems. If you haven&amp;#39;t done it yet then point your mouse to &lt;a href="http://update.microsoft.com/" target="_blank"&gt;Microsoft Update&lt;/a&gt; to download and install these patches:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=112111" target="_blank"&gt;MS08-014&lt;/a&gt; - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029) 
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=112113" target="_blank"&gt;MS08-015&lt;/a&gt; - Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (949031) 
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=112112" target="_blank"&gt;MS08-016&lt;/a&gt; - Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (949030) 
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=112114" target="_blank"&gt;MS08-017&lt;/a&gt; - Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (933103)&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;A more technical version of the Security Bulletin can be found at &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-mar.mspx" target="_blank"&gt;TechNet&lt;/a&gt; and an end-user version is available at Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/protect/computer/updates/bulletins/200803.mspx" target="_blank"&gt;Security At Home&lt;/a&gt; site. 
&lt;p&gt;You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft &lt;a href="http://support.microsoft.com/kb/913086" target="_blank"&gt;Knowledge Base Article 913086&lt;/a&gt;. 
&lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt; 
&lt;ul&gt;
&lt;li&gt;Customers in the U.S. and Canada can receive technical support from &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21131"&gt;Microsoft Product Support Services&lt;/a&gt; at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries. Visit the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=21155"&gt;International Help and Support&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;See also: &lt;a class="" href="http://blogs.technet.com/msrc/archive/2008/03/11/march-2008-monthly-release.aspx" target="_blank"&gt;Microsoft Security Response Center&lt;/a&gt; (MSRC) and &lt;a class="" href="http://blogs.technet.com/swi/default.aspx" target="_blank"&gt;Security Vulnerability Research &amp;amp; Defense&lt;/a&gt; blog.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1540798" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Security+Bulletins/default.aspx">Security Bulletins</category></item></channel></rss>