Severity Rating: Critical
Revision Note: V1.0 (September 8, 2015): Bulletin published.
Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file...
Severity Rating: Critical
Revision Note: V1.0 (August 11, 2015): Bulletin published.
Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An...
Severity Rating: Important
Revision Note: V1.0 (July 14, 2015): Bulletin published.
Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if the Windows graphics component fails to properly process bitmap conversions. An...
Original release date: October 17, 2014
Systems Affected
All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this...
Revision Note: V1.0 (October 14, 2014): Advisory published
Summary: Microsoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not...
HP is warning customers: Check your laptop charging cord to see if it's at risk of overheating.
Hewlett-Packard (HPQ, Tech30) and federal regulators on Tuesday recalled 6 million power cords sold between September 2010 and June 2012 with some HP and Compaq notebook computers, as well as certain...
As security professionals, we are trained to think in worst-case scenarios. We run through the land of the theoretical, chasing “what if” scenarios as though they are lightning bugs to be gathered and stashed in a glass jar. Most of time, this type of thinking is absolutely the correct thing...
best practices
bulletin
critical update
customer impact
cve
cybersecurity
flash player
internet explorer
legacy support
microsoft
protected mode
remote code execution
research
riskassessment
security
smartscreen
theoretical thinking
update
vulnerabilities
web standards
Today we provide advance notification for the release of seven Bulletins, two rated Critical and five rated Important in severity. These Updates are for Microsoft Word, Microsoft Office and Internet Explorer. The Update for Internet Explorer addresses Link Removed, which we have not seen used in...
advisory
bulletin
configuration
credentials
deployment
internet explorer
microsoft office
pdt
riskassessment
security
server 2008
server 2012
timeline
update
windows 7
windows 8
word
Today, we’re providing advance notification for the release of eight bulletins, three Critical and five Important, for November 2013. The Critical updates address vulnerabilities in Internet Explorer and Microsoft Windows, and the Important updates address issues in Windows and Office.
While...
advisory
bulletin
critical
deployment
gdi+
important
internet explorer
lync
office
office 2003
office 2007
office 2010
riskassessment
security
update
vulnerabilities
windows
windows server
windows vista
windows xp
Severity Rating: Critical
Revision Note: V1.0 (September 10, 2013): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a file that contains a specially crafted OLE...
admin rights
critical severity
exploit
extended security updates
microsoft
ms13-070
ole vulnerability
remote code execution
riskassessment
user privileges
Severity Rating: Important
Revision Note: V1.0 (May 14, 2013): Bulletin published.
Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted file or previews a specially...
Today we’re providing Advance Notification of five bulletins for release on Tuesday, June 11, 2013. This release brings one Critical- and four Important-class bulletins. The Critical-rated bulletin addresses issues in Internet Explorer, and the Important-rated bulletins address issues in...
In celebration of spring’s onset, today we’re providing advance notification for the April 2013 release of nine bulletins; two Critical and seven Important. The Critical bulletins address vulnerabilities in Microsoft Windows and Internet Explorer, and the seven Important-rated...
antimalware
april 2012
bulletin
critical
deployment
impact analysis
important
internet explorer
microsoft
msrc
notifications
office
riskassessment
security
server software
testing
trustworthy computing
update
vulnerabilities
windows
Today we’re providing advance notification for the release of seven bulletins, four Critical and three Important, for March 2013. The Critical bulletins address vulnerabilities in Microsoft Silverlight, Internet Explorer, Office and Microsoft Server Software. The three Important-rated...
bulletin
critical
deployment
important
internet explorer
march 2013
microsoft
notifications
office
riskassessment
security
server software
silverlight
technet
testing
trustworthy computing
update
vulnerabilities
windows
We’re kicking off the February 2013 Security Bulletin Release with Advance Notification of 12 bulletins for release Tuesday, February 12. This release brings five Critical and seven Important-class bulletins, which address 57 unique vulnerabilities. The Critical-rated bulletins address...
bulletin
communication
critical issues
deployment
exchange
february
important issues
internet explorer
microsoft
msrc
net framework
notifications
office
riskassessment
security
server software
trustworthy computing
update
vulnerabilities
windows
On behalf of all of us here at Microsoft, I’d like to wish everyone a very happy New Year!
With 2013 starting on a Tuesday, our monthly bulletin release is upon us a bit earlier than usual. Next Tuesday we’ll release seven bulletins; two Critical and five Important, which address...
2013
bulletin
critical update
deployment
guidance
impact analysis
important updates
microsoft
msrc
net framework
news
office
riskassessment
security
server software
testing
trustworthy computing
update process
vulnerabilities
windows
Severity Rating: Important
Revision Note: V1.0 (November 13, 2012): Bulletin published.
Summary: This security update resolves four privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially...
As previously mentioned in the Advance Notification blog on Thursday, today we’re releasing seven bulletins, one Critical-class and six Important-class bulletins. Before we discuss those releases, let’s take a closer look at the Security Advisories we also released today.
Security...
Hello --
As per our usual cadence, today we’re releasing our advance notification for this month’s security bulletin release, which is scheduled for Tuesday, July 10. The July release includes nine bulletins addressing 16 vulnerabilities in Microsoft Windows, Microsoft Office...
advance notification
bulletin
customer guidance
deployment
impact analysis
internet explorer
july 2012
microsoft
office
patch management
release information
riskassessment
security
testing
update
visual basic
vulnerabilities
webcast
windows