Jerry Bryant's Security Blog

Security Program Manager - Microsoft PSS Security Team

August 2005 - Posts

Visio Connector for MBSA 2.0

If you like a graphical view of your security scans, you won't want to miss this.

At a glance, you'll be able to:
· Pinpoint vulnerabilities on the color-coded diagram.
· Identify solutions in the detailed network diagram scan results.
· Prioritize actions based on the results presented in the network diagram.

See: http://www.microsoft.com/technet/security/tools/mbsavisio.mspx

MS05-038 Cumulative Patch for IE - Issues

There were some issues with the digital signatures on some of the IE updates that were preventing installation. For that reason the updates were removed from the download center. Windows Update, Microsoft Update, SUS and WSUS are not affected. Will try to post an update as soon as more information is available.

Update: the bulletin was updated today and the downloads restored to the download center.

Microsoft Security Bulletin(s) for August 2005

August 9, 2005
Today Microsoft released the following Security Bulletin(s).

Note: www.microsoft.com/technet/security and www.microsoft.com/security are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.

Bulletin Summary:

http://www.microsoft.com/technet/security/Bulletin/ms05-Aug.mspx

Critical Bulletins:
 
Cumulative Security Update for Internet Explorer (896727)
http://www.microsoft.com/technet/security/Bulletin/ms05-038.mspx

Vulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588)
http://www.microsoft.com/technet/security/Bulletin/ms05-039.mspx

Vulnerability in Print Spooler Service Could Allow Remote Code Execution (896423)
http://www.microsoft.com/technet/security/Bulletin/ms05-043.mspx

Important Bulletins:

Vulnerability in Telephony Service Could Allow Remote Code Execution (893756)
http://www.microsoft.com/technet/security/Bulletin/ms05-040.mspx

Moderate Bulletins:

Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (899591)
http://www.microsoft.com/technet/security/Bulletin/ms05-041.mspx

Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587)
http://www.microsoft.com/technet/security/Bulletin/ms05-042.mspx

Re-Released Bulletins:
 
Vulnerabilities in Microsoft Word May Lead to Remote Code Execution (890169)
http://www.microsoft.com/technet/security/Bulletin/ms05-023.mspx

Vulnerability in Microsoft Agent Could Allow Spoofing (890046) (890169)http://www.microsoft.com/technet/security/Bulletin/ms05-032.mspx

This represents our regularly scheduled monthly bulletin release (second Tuesday of each month). Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety (1-866-727-2338). International customers should contact their local subsidiary.