-
MS14-001 - Important : Vulnerabilities in Microsoft Word and Office Web Apps Could Allow...
Severity Rating: Important Revision Note: V1.0 (January 14, 2014): Bulletin published. Summary: This security update resolves three privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a specially crafted file is opened in an affected...- News
- Thread
- 2014 bulletin microsoft office remote code execution security update user rights vulnerabilities word
- Replies: 0
- Forum: Security Alerts
-
Advance Notification Service for the January 2014 Security Bulletin Release
Today we provide advance notification for the release of four bulletins for January 2014. All bulletins this month are rated Important in severity and address vulnerabilities in Microsoft Windows, Office, and Dynamics AX. The update provided in MS14-002 fully addresses the issue first described...- News
- Thread
- 2014 ans bulletin deployment dynamics ax exploit guidance impact microsoft msrc office pst risk security server 2003 update vulnerabilities windows windows xp
- Replies: 0
- Forum: Security Alerts
-
Leaving Las Vegas and the August 2013 security updates
Two weeks ago I, along with 7,500 of my closest friends, attended the Black Hat security conference in Las Vegas, NV. I can’t speak for everyone, but I certainly had a great – if not exhausting – time while there. While there were a lot of great talks, a personal highlight for me each year is...- News
- Thread
- 2013 black hat bluehat bulletin challenges critical update deployment priority internet explorer mapp md5 hashing microsoft nla technology remote code execution security software compatibility trustworthy computing update vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
Predictions for 2014 and the December 2013 Security Bulletin Webcast, Q&A, and Slide Deck
Today we’re publishing the Link Removed. We answered 17 questions in total, with the majority of questions focusing on the Graphics Component bulletin (MS13-096), Security Advisory 2915720 and Security Advisory 2905247. We also wanted to note a new blog on the Microsoft Security Blog site on...- News
- Thread
- 2014 predictions advisory attendee registration blog bulletin communication cyber threats december 2013 deployment graphics holiday live event microsoft predictions q&a ransomware regulation security trustworthy computing webcast
- Replies: 0
- Forum: Security Alerts
-
10 years of Update Tuesdays
On October 1, 2003, Microsoft announced it would move to a monthly security bulletin cadence. Today, marks 10 years since that first monthly security update. We looked at many ways to improve our security preparedness and patch timing was the number one customer request. Your feedback was clear...- News
- Thread
- adaptation anniversary bulletin cadence challenges commitment customers devops discoveries experience feedback industry microsoft milestone october patch preparedness response security update tuesday
- Replies: 0
- Forum: Security Alerts
-
Omphaloskepsis and the December 2013 Security Update Release
There are times when we get too close to a topic. We familiarize ourselves with every aspect and nuance, but fail to recognize not everyone else has done the same. Whether you consider this myopia, navel-gazing, or human nature, the effect is the same. I recognized this during the recent webcast...- News
- Thread
- advisory asp.net authenticode bulletin cumulative update cve december 2013 deployment execution extended security updates internet explorer microsoft mitigation patch management remote code execution staff update tuesday vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-097 - Critical : Cumulative Security Update for Internet Explorer (2898785) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves seven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted...- News
- Thread
- admin rights bulletin critical cumulative update december 2013 extended security updates internet explorer microsoft ms13-097 remote code execution revision note user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS13-102 - Important : Vulnerability in LRPC Client Could Allow Elevation of Privilege...
Severity Rating: Important Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted LPC port message to any LPC...- News
- Thread
- administrator attack bulletin consumer credentials elevation exploitation important lpc ms13-102 patch privately privilege report revision security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-098 - Critical : Vulnerability in Windows Could Allow Remote Code Execution (2893294) -...
Severity Rating: Critical Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user or application runs or installs a specially...- News
- Thread
- bulletin critical extended security updates microsoft ms13-098 pe file portable executable remote code execution vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Advisory (2915720): Changes in Windows Authenticode Signature Verification...
Revision Note: V1.0 (December 10, 2013): Advisory published. Summary: Microsoft is announcing the availability of an update for all supported releases of Windows to change how signatures are verified for binaries signed with the Windows Authenticode signature format. The change is included with...- News
- Thread
- advisory authenticode binaries bulletin infrastructure microsoft regulatory compliance security signature update verification windows
- Replies: 0
- Forum: Security Alerts
-
TA13-317A: Microsoft Updates for Multiple Vulnerabilities
Original release date: November 13, 2013 | Last revised: November 16, 2013 Systems Affected Windows Operating System and Components Microsoft Office Internet Explorer Overview Select Microsoft software products contain multiple vulnerabilities. Microsoft has released updates to address...- News
- Thread
- automatic updates bulletin december 2013 denial of service elevation of privilege information disclosure internet explorer microsoft network security office patch remote code execution security security policies system administration testing update vulnerabilities watering hole campaign windows
- Replies: 0
- Forum: Security Alerts
-
MBSA 2.3 and the November 2013 Security Bulletin Webcast, Q&A, and Slide Deck
Today we’re publishing the Link Removed. The majority of questions focused on the ActiveX Kill Bits bulletin (MS13-090) and the advisories. We also answered a few general questions that were not specific to any of this month’s updates, but that may be of interest. We’ve discussed the Microsoft...- News
- Thread
- activex analyzer bulletin december deployment feedback mbsa microsoft public preview q&a release security server support technet trustworthy computing update webcast windows
- Replies: 0
- Forum: Security Alerts
-
MS13-093 - Important : Vulnerability in Windows Ancillary Function Driver Could Allow...
Severity Rating: Important Revision Note: V1.0 (November 12, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow information disclosure if an attacker logs on to an affected system as a local...- News
- Thread
- bulletin credentials important information disclosure local account microsoft security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-091 - Important : Vulnerabilities in Microsoft Office Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (November 12, 2013): Bulletin published. Summary: This security update resolves three privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a specially crafted WordPerfect document file is...- News
- Thread
- bulletin microsoft office remote code execution security technical update user rights vulnerabilities wordperfect
- Replies: 0
- Forum: Security Alerts
-
MS13-090 - Critical : Cumulative Security Update of ActiveX Kill Bits (2900986) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (November 12, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability exists in the InformationCardSigninHelper Class ActiveX control. The vulnerability...- News
- Thread
- activex bulletin critical cumulative internet explorer remote code execution security update user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS13-095 - Important : Vulnerability in Digital Signatures Could Allow Denial of Service...
Severity Rating: Important Revision Note: V1.0 (November 12, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service when an affected web service processes a specially crafted X.509...- News
- Thread
- bulletin denial of service digital signature microsoft ms13-095 security update vulnerability windows x.509
- Replies: 0
- Forum: Security Alerts
-
Clarification on Security Advisory 2896666 and the ANS for the November 2013 Security Bulletin...
Today, we’re providing advance notification for the release of eight bulletins, three Critical and five Important, for November 2013. The Critical updates address vulnerabilities in Internet Explorer and Microsoft Windows, and the Important updates address issues in Windows and Office. While...- News
- Thread
- advisory bulletin critical deployment gdi+ important internet explorer lync office office 2003 office 2007 office 2010 risk assessment security update vulnerabilities windows windows server windows vista windows xp
- Replies: 8
- Forum: Security Alerts
-
10 years of Update Tuesdays
On October 1, 2003, Microsoft announced it would move to a monthly security bulletin cadence. Today, marks 10 years since that first monthly security update. We looked at many ways to improve our security preparedness and patch timing was the number one customer request. Your feedback was clear...- News
- Thread
- 10 years bulletin celebration commitment communication customer feedback devops evolving security experience global customers microsoft milestone patch response security security preparedness standards technology timeline update tuesday
- Replies: 0
- Forum: Security Alerts
-
The October 2013 security updates
This month we release eight bulletins – four Critical and four Important - which address 26 unique CVEs in Microsoft Windows, Internet Explorer, SharePoint, .NET Framework, Office, and Silverlight. For those who need to prioritize their deployment planning, we recommend focusing on MS13-080...- News
- Thread
- advisory bulletin cve deployment exploitability internet explorer md5 microsoft net framework october office remote code execution security sharepoint ssl trustworthy computing update vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
MS13-087 - Important : Vulnerability in Silverlight Could Allow Information Disclosure...
Severity Rating: Important Revision Note: V1.0 (October 8, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Silverlight. The vulnerability could allow information disclosure if an attacker hosts a website that contains a specially...- News
- Thread
- attack bulletin extended security updates information disclosure microsoft security silverlight user awareness vulnerability web content
- Replies: 0
- Forum: Security Alerts