Revision Note: V1.0 (January 12, 2016): Advisory published.
Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory. These ActiveX kill bits are included in the Internet Explorer cumulative update released on January 12, 2016.
Continue reading...
activex
advisory
browser security
content advisory
cumulative update
internet explorer
january 2016
kill bits
microsoft
patch management
revision note
securitysecurityadvisory
software update
tech news
update
version 1.0
vulnerability
web browsing
Revision Note: V1.0 (December 8, 2015): Advisory published.
Summary: Microsoft is aware of an SSL/TLS digital certificate for *.xboxlive.com for which the private keys were inadvertently disclosed. The certificate could be used in attempts to perform man-in-the-middle attacks. It cannot be used...
advisory
certificate
cybersecurity
digital certificate
man-in-the-middle
microsoft
private keys
securitysecurityadvisory
spoofing
ssl
supported releases
technet
tls
update
v1.0
vulnerability
windows
xbox live
Revision Note: V1.0 (September 24, 2015): Advisory published.
Summary: Microsoft is aware of four digital certificates that were inadvertently disclosed by D-Link Corporation that could be used in attempts to spoof content. The disclosed end-entity certificates cannot be used to issue other...
certificate management
code signing
content security
cybersecurity
d-link
digital certificates
disclosed information
impersonation
incident notification
microsoft
securityadvisorysecurity risks
spoofing
technical note
threat awareness
update
v1.0
vulnerability
windows
windows support
Revision Note: V1.0 (September 24, 2015): Advisory published.
Summary: Microsoft is aware of four digital certificates that were inadvertently disclosed by D-Link Corporation that could be used in attempts to spoof content. The disclosed end-entity certificates cannot be used to issue other...
Today, Microsoft is announcing the end-of-support of the RC4 cipher in Microsoft Edge and Internet Explorer 11. Starting in early 2016, the RC4 cipher will be disabled by-default and will not be used during TLS fallback negotiations.
There is consensus across the industry that RC4 is no longer...
attacks
cipher
cryptography
edge
encryption
end of support
fallback
industry consensus
internet explorer
microsoft
rc4
securitysecurityadvisory
support
tls
user advice
web browsers
windows 10
windows 7
windows 8.1
Severity Rating: Important
Revision Note: V1.0 (April 14, 2015): Bulletin published.
Summary: This security update resolves a vulnerability in Microsoft Windows. An attacker who successfully exploited the vulnerability could leverage a known invalid task to cause Task Scheduler to run a...
administrator
april 2015
bulletin
cybersecurity
data protection
elevation
exploitation
microsoft
revision note
securitysecurityadvisory
software
system account
task scheduler
update
user rights
vulnerability
windows
Today, as part of Update Tuesday, we released 14 security bulletins to address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Exchange, and Internet Explorer.
We encourage customers to apply all of these updates. For more information about this month’s security updates...
bulletins
common vulnerabilities
cve
exploitability index
internet explorer
internet security
march 2015
microsoft office
microsoft windows
msrc
patch management
securitysecurityadvisorysecurity features
software updates
tech news
update tuesday
updates
vulnerabilities
Today, as part of Update Tuesday, we released seven security updates – three rated Critical and four rated Important in severity, to address 24 unique Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office and Exchange.
We encourage you to apply all of...
adobe flash
common vulnerabilities
critical updates
cumulative update
december 2014
exchange server
exploit index
important updates
internet explorer
microsoft bulletin
microsoft office
msrc
patch tuesday
remote code execution
securitysecurityadvisorysecurity bulletin
technet
updates
vulnerability
Today, as part of Update Tuesday, we released 14 security updates – four rated Critical, nine rated Important, and two rated Moderate, to address 33 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office, .NET Framework, Internet Information Services...
adfs
critical
cve
deployment
encryption
exploit index
iis
important
internet explorer
microsoft
moderate
net framework
november 2014
office
rdp
securitysecurityadvisory
updates
vulnerabilities
windows
Revision Note: V1.0 (October 14, 2014): Advisory published
Summary: Microsoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not...
Revision Note: V1.0 (July 10, 2014): Advisory published.
Summary: Microsoft is aware of improperly issued SSL certificates that could be used in attempts to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. The SSL certificates were improperly issued by the National...
Microsoft has released a Security Update to address a critical vulnerability in all versions of Internet Explorer, on Windows XP, Vista, 7 and 8. It is available via Windows Update...
automatic update
browser security
critical vulnerability
ie 11
internet explorer
kb2964358
manual update
microsoft
migration
securitysecurityadvisory
standalone update
update release
updates
user guidance
windows 7
windows 8
windows 8.1
windows vista
windows xp
Severity Rating:
Revision Note: V2.0 (February 11, 2014): Revised advisory to announce that the 2862973 update for all affected releases of Microsoft Windows is now offered through automatic updating. Customers who previously applied the 2862973 update do not need to take any action.
Summary...
automatic updates
certificate program
cryptography
cybersecurity
man-in-the-middle
md5 hashing
microsoft
phishing attacks
root certificates
securityadvisory
vulnerability
windows 7
windows 8
windows server
windows update
windows vista
Severity Rating:
Revision Note: V1.0 (August 4, 2013): Advisory published.
Summary: Microsoft is aware of a public report that describes a known weakness in the Wi-Fi authentication protocol known as PEAP-MS-CHAPv2 (Protected Extensible Authentication Protocol with Microsoft Challenge Handshake...
Severity Rating:
Revision Note: V1.1 (June 13, 2012): Advisory revised to notify customers that Windows Mobile 6.x, Windows Phone 7, and Windows Phone 7.5 devices are not affected by the issue.
Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived...
active attacks
browser security
certificate authority
cybersecurity
digital certificates
internet explorer
it security
man-in-the-middle
microsoft
phishing
revision note
securityadvisorysecurity update
spoofing
unauthorized access
vulnerability
web security
windows mobile
windows phone
T. S. Elliot once said, “What we call the beginning is often the end. And to make an end is to make a beginning. The end is where we start from.” So as we put one season to bed, let’s start another by looking at the April security updates. Today, we release four bulletins to address 11 CVEs in...
adobe flash
april 2014
bulletin
cumulative update
cve
exploit index
guidance
internet explorer
microsoft knowledge base
microsoft office
microsoft word
office 2003
remote code execution
securitysecurityadvisory
support end
updates
vulnerabilities
webcast
windows xp
Today we released Security Advisory 2896666 regarding an issue that affects customers using Microsoft Windows Vista and Windows Server 2008, Microsoft Office 2003 through 2010, and all supported versions of Microsoft Lync. We are aware of targeted attacks, largely in the Middle East and South...
anti-virus
customer guidance
emet
exploit
firewall
malware
microsoft
microsoft office
risk management
securityadvisory
software updates
threat landscape
tiff codec
user interaction
vulnerability
windows server
windows vista
We are committed to adapting our policies as the world evolves and with the new Windows Store, we evaluated how to best release security updates for Windows Store apps. Our goal is to have a quick, transparent and painless security update process. With this in mind, we will deliver high quality...
Original release date: November 13, 2012 | Last revised: January 24, 2013
Systems Affected
Microsoft Windows
Microsoft Office
Microsoft .NET Framework
Internet Explorer
Overview Select Microsoft software products contain multiple vulnerabilities. Microsoft has released...
admin recommendations
automatic updates
cybersecurity
denial of service
impact assessment
internet explorer
microsoft
net framework
office
patch management
remote access
securitysecurityadvisory
software risks
system administration
tech bulletin
updates
user guidance
vulnerabilities
windows
At the end of each year, some folks take a moment to jot down predictions about what the coming year has in store. I, on the other hand, do not do predictions. I am neither prognosticator, seer, fortune teller, prophet, clairvoyant, soothsayer, nor medium; although I have been accused of being a...