Wednesday, December 9, 2009
Microsoft Patch Tuesday for December 2009
Microsoft's Patch Tuesday (08-12-2009) fix will solve a reported twelve security flaws.Among the critical patches, two affect Windows, and there is one each that addresses issues in Word, Excel, Visual Basic, and Internet Explorer.Three of the six bulletins will be rated “critical”.
The patches will fix security holes in:
- Internet Explorer 5, 6, 7 & 8
- Windows 2000 Service Pack 4
- Windows XP Service Pack 2 & 3
- Windows Vista Service Pack 1 & 2
- Windows Server 2003 Service Pack 2
- Windows Server 2008 Systems Service Pack 2
- Office XP Service Pack 3
- Office 2003 Service Pack 3
For more details visit Microsoft Security Bulletin Summary for December 2009
Security Patches
Other Updates
Thursday, July 16, 2009
Microsoft Patch Tuesday for July 2009
Microsoft released six bulletins for July on Tuesday,three of the vulnerabilities are rated "Critical," and the other three are marked as "Important.".All of the Critical vulnerabilities earned their rating through a remote code execution impact, meaning a hacker could potentially gain control of an infected machine.
They are:
- MS09-029: This covers two vulnerabilities in the Microsoft Windows component, Embedded OpenType Font Engine. The vulnerabilities could allow remote code execution. Rated “critical” for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista,
and Windows Server 2008.
- MS09-028: This update fixes three separate vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file.
- MS09-032: This security update resolves a privately reported vulnerability in Microsoft Video ActiveX Control. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer that uses the ActiveX control. This rated “critical”for all supported editions of Windows XP and “moderate” for all supported editions of Windows Server 2003.
Three other bulletins were issued to cover a solitary bug in Microsoft Virtual PC and Microsoft Virtual Server; a privilege escalation issue in Microsoft Internet Security and Acceleration (ISA) Server 2006; and a remote code execution hole in Microsoft Office Publisher.
More details here :http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx
Friday, April 17, 2009
Patch Your System Promptly
The software you are using today likely has security holes that nobody has discovered yet.If you don't keep up with the latest software, you will eventually get hacked.A patch is a small piece of software designed to fix problems with or update a computer program or its supporting data.
Most major software companies will periodically release patches, , that correct very specific problems in their software programs.Most of the patches are free to download and the majority of them are now simply downloaded from the Internet .A fair percentage of these patches help to address problems, but a poorly composed software patch may actually create new problems.It is very important to keep yourself apprised of security updates to all of the software on your machine. The easiest way to do this is to check the software vendor or developer's website on a regular basis or to join a mailing list that keeps users informed about security vulnerabilities and updates.
The following types of software are most likely to contain a security vulnerability
- Operating Systems - Windows, Macintosh, UNIX/Linux, etc.
- Server Software - Web servers, Mail servers, FTP servers, Database servers, etc.
- Web Browsers - Internet Explorer, Netscape, Safari, Mozilla FireFox, Chrome etc.
- Email Clients - Outlook, Outlook Express, Eudora, Netscape, Mozilla, etc.
- Peer-to-Peer File Sharing software - BitComet, BitLord, BitTorrent, FlashGet, G3 Torrent,KTorrent, LimeWire,QTorrent, rTorrent, Shareaza,Kazaa, Gnutella, eDonkey, etc.
When a patch is released it is important to install it, as it may improve security or fix a compromising bug that previously slipped through. Be sure you download the patch from a reliable source, such as the software's website.
Useful Links
Updates | Windows Updates
- Software Patch
- Mac OS
- Driver Updation | Update Your Drivers
- Secunia Personal Software Inspector (PSI) :Check your PC for insecure programs exposing you to security threats(Freeware)
- Secunia Online Software Inspector (OSI)
- FileHippo's Update Checker
- Free DotNet VersionCheck Utility to check which version of Microsoft .Net Framework is installed on your computer
- Software Update Monitor(SUMO)
- Intel INF Update Utility
- http://www.winfiles.com/
Related Reading :
Wednesday, April 15, 2009
Microsoft Patch Tuesday
Eight security bulletins were released by Microsoft on Tuesday, April 14, 2009, five of which are rated critical. They affect IE (MS09-014), Excel (MS09-009), WordPad and Office Text Converters (MS09-010), ISA Server and Forefront (MS09-016), a whole bunch more...
Microsoft’s summary of the April releases can be found here: Critical Bulletins
Thursday, March 12, 2009
Microsoft Issues Three Updates to Windows
Microsoft ,Tuesday released three security bulletins with fixes for vulnerabilities affecting millions of Windows OS users.
- MS09-006/KB958690 — Critical (XP, Vista, 2000, 2003, 2008):. Provides cover for three newly discovered and privately reported vulnerabilities in Windows. This particular bug allows attackers to remotely execute code via a specially crafted EMF or WMF image. You should install this patch immediately. These vulnerabilities affect all versions of Windows, including Vista and Windows Server 2008.
- MS09-007/KB960225 — Important (XP, Vista, 2000, 2003, 2008): This bulletin includes a patch for a solitary vulnerability in Windows, which could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. To exploit this bug, the attacker needs access to the certificate that the end user has for authentication, which is why it is lowered to “Important.” This is not the worst bug in history, but you will want to install this patch when convenient. This affects 32-bit and 64-bit versions of Windows, including Server Core.
- MS09-008/KB961063/KB961064 – Important (2000, 2003, 2008): The DNS and WINS servers in Windows Server have a vulnerability that could allow someone to mess with the lookups; from there, all sorts of mischief can occur, such as swapping google.com to some undesirable Web site. Install this patch on any server running DNS or WINS that an attacker might have access to. This affects 32-bit and 64-bit versions of Windows Server, including Server Core.
Windows users should treat the “critical” bulletin with the highest possible priority.
Wednesday, December 10, 2008
Microsoft Patch Tuesday
Microsoft dropped a monster Patch Tuesday release with fixes for at least 28 vulnerabilities affecting Windows, Office, Internet Explorer, Visual Basic Active Controls and Windows Media Player.Of the 28 flaws, 23 carry a “critical” rating.
Here are the raw details on all the patches:
- MS08-070 (critical; 6 vulnerabilities fixed): This update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls), which could allow remote code execution if a user browsed a Web site that contains specially crafted content.
- MS08-071 (critical; 2 vulnerabities fixed): This update resolves two privately reported vulnerability in Windows, which could allow remote code execution if a user opens a specially crafted WMF image file.
- MS08-072 (critical; 8 vulnerabilities): This update resolves eight privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Word or Rich Text Format (RTF) file.
- MS08-073 (critical; 4 vulnerabilities fixed): This update resolves four privately reported vulnerabilities in Internet Explorer, which could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
- MS08-074 (critical; 3 vulnerabilities): This update resolves three privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Excel file.
- MS08-075 (critical; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution if a user opens and saves a specially crafted saved-search file within Windows Explorer or if a user clicks a specially crafted search URL.
- MS08-076 (important; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution.
- MS08-077 (important; 1 vulnerability): This update resolves one privately reported vulnerability in Microsoft Office SharePoint, which could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack could result in denial of service or information disclosure.
Thursday, November 13, 2008
MS Patch Tuesday: Critical Windows, Office flaws fixed
Microsoft’s scheduled batch of patches for November fixes at least four documented vulnerabilities affecting Windows, Internet Explorer and Office users.
The updates apply to users running all supported versions of Windows (including Vista and Windows Server 2008) and most versions of Microsoft Office
Details available here
The first critical update cover the risk of remote code execution attacks ,if a Windows user is simply tricked into browsing to a rigged Web page with Internet Explorer
Microsoft Security Bulletin MS08-069
The second update provides cover for a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. Exploit code for this flaw is currently available on the Internet.
Microsoft Security Bulletin MS08-068
Friday, October 24, 2008
Microsoft Releases Emergency Windows Patch
Microsoft Corp. fixed a critical bug in its Windows operating system Thursday, saying that it is being exploited by online criminals and could eventually be used in a widespread "worm" attack.Microsoft says it found evidence two weeks ago of an RPC attack that can potentially infect Windows machines.Microsoft issued urgently this critical patch ahead of regularly scheduled November updates(the second Tuesday of each month).
"It is possible that this vulnerability could be used in the crafting of a wormable exploit. If successfully exploited, an attacker could then install programs or view, change, or delete data; or create new accounts with full user rights," Microsoft said in the Microsoft Security Bulletin MS08-067 released Thursday morning.The company also will reveal more details about the patch in a special Webcast.
Windows Server 2003, 2000, and XP (even with Service Pack 2 or 3 installed) are particularly vulnerable.I would highly recommend applying this patch as soon as possible, either by visiting Windows Update or enabling Automatic Updates.
• Windows 2000 with Service Pack 4 patch download
• Windows XP with Service Pack 2 or 3 patch download
• Windows XP 64-bit Edition patch download
• Windows Server 2003 with Service Pack 1 or 2 patch download
• Windows Server 2003 64-bit Edition patch download
• Windows Vista with or without Service Pack 1 patch download
• Windows Vista 64-bit Edition with or without Service Pack 1 patch download
• Windows Server 2008 32-bit Edition patch download
• Windows Server 2008 64-bit Edition patch download
For more information please read security bulletin MS08-067





