-
The Making of the Top 100 Researcher List
At Black Hat USA each year, we unveil the Top 100 Security Researcher list to reflect the amazing engagement we get from the community. During this period, we had several thousand researchers engage with the Microsoft Security Response Center (MSRC). We appreciate all the partnership and...- News
- Thread
- 2016 acknowledgements annual report blackhat usa bounty for defense community engagement cybersecurity industry collaboration microsoft mitigation bounty msrc research research impact research methodologies research recognition security researcher security risks top 100 vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Inside the MSRC– The Monthly Security Update Releases
For the second in this series of blog entries we want to look into which vulnerability reports make it into the monthly release cadence. It may help to start with some history. In September 2003 we made a change from a release anytime approach to a mostly predictable, monthly release cadence...- News
- Thread
- automatic updates backporting customer action extended security updates fix documentation microsoft security monthly releases online services opportunistic updates phil misner risk assessment risk management security lifecycle security research software release support lifecycle update tuesday vulnerabilities vulnerability reporting
- Replies: 0
- Forum: Security Alerts
-
Taking your feedback on the Security Update Guide
The Link Removed has been in public preview since November 2016. This month marked our first release when security update information was published entirely in the new format. Over the last few months, customers and partners have provided a lot of feedback on the direction and implementation of...- News
- Thread
- advisories api bugs cve dashboard data population excel feedback identifier impact it professionals machine-readable msrc powershell public preview security technet transparency update guide
- Replies: 0
- Forum: Security Alerts
-
MS17-016 - Important: Security Update for Windows IIS (4013074) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (March 14, 2017): Click here to enter text. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker with access to the local system executes a malicious...- News
- Thread
- admin rights exploit iis local system malicious software march microsoft ms17-016 remote code execution security security patch update user account user rights version 1.0 vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS17-012 - Critical: Security Update for Microsoft Windows (4013078) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (March 14, 2017): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow remote code execution if an attacker running inside a virtual machine runs a...- News
- Thread
- application bulletin critical cybersecurity extended security updates march microsoft ms17-012 patch remote code execution revision note security technet update version virtual machine vulnerabilities windows update
- Replies: 0
- Forum: Security Alerts
-
MS17-021 - Important: Security Update for Windows DirectShow (4010318) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (March 14, 2017): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow an Information Disclosure if Windows DirectShow opens specially crafted media content that is hosted on...- News
- Thread
- 4010318 attack bulletin directshow exploitation information disclosure malicious website march media content microsoft patch revision note security security bulletin system compromise update version 1.0 vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
F
Windows 7 Exception 0x80000003 error occurs on shutdown of Win 7 Pro also OXEA47337
Hi, Recently when shutting down Windows 7 professional and error is flashed in a window for a very short time. I have been able to see, I believe, and error "Exception 0x80000003" by shutting down repeatedly. I also saw OXEA47337 today and a partial OEXC38... the other day. Additionally, in...- Frank McLean
- Thread
- acronis true image device manager error exception 0x80000003 fix malwarebytes network adapter oexc38 oxea47337 shutdown software installation system repair tech support teredo tunneling troubleshooting user inquiry windows 7 yellow exclamation
- Replies: 70
- Forum: Windows Help and Support
-
MS17-004 - Important: Security Update for Local Security Authority Subsystem Service...
Severity Rating: Important Revision Note: V1.0 (January 10, 2017): Bulletin Published Summary: A denial of service vulnerability exists in the way the Local Security Authority Subsystem Service (LSASS) handles authentication requests. An attacker who successfully exploited the vulnerability...- News
- Thread
- authentication denial of service extended security updates lsass ms17-004 reboot update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-138 - Important: Security Update for Microsoft Virtual Hard Disk Driver (3199647) -...
Severity Rating: Important Revision Note: V1.0 (November 8, 2016): Bulletin published. Summary: The Windows Virtual Hard Disk Driver improperly handles user access to certain files. An attacker can manipulate files in locations not intended to be available to the user by exploiting this...- News
- Thread
- access control bulletin driver issues exploit file management important manipulation microsoft ms16-138 patch revision note risk assessment security technical details update virtual drive vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-121 - Important: Security Update for Microsoft Office (3194063) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Office. An Office RTF remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly...- News
- Thread
- arbitrary code bulletin cybersecurity exploitation microsoft microsoft office ms16-121 october patch remote code execution revision note rtf security software update threat mitigation update user context vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-110 - Important: Security Update for Microsoft Windows (3178467) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (September 13, 2016): Bulletin published. Summary: This security update resolves multiple vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow remote code execution if an attacker creates a specially crafted...- News
- Thread
- bulletin microsoft ms16-110 remote code execution security update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS16-100 - Important: Security Update for Secure Boot (3179577) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker installs an affected boot manager and bypasses Windows security...- News
- Thread
- 2016 attacker boot manager bypass microsoft ms16-100 revision note secure boot security security features update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-097 - Critical: Security Update for Microsoft Graphics Component (3177393) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, and Microsoft Lync. The vulnerabilities could allow remote code execution if a user either visits...- News
- Thread
- 2016 administration bulletin critical documents execution graphics lync microsoft office patch remote code execution revision security skype update user rights vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS16-101 - Important: Security Update for Windows Authentication Methods (3178465) -...
Severity Rating: Important Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves multiple vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker runs a specially crafted application on a domain-joined...- News
- Thread
- authentication domain ms16-101 patch privilege security update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS16-091 - Important: Security Update for .NET Framework (3170048) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (July 12, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft .NET Framework. The vulnerability could cause information disclosure if an attacker uploads a specially crafted XML file to web-based...- News
- Thread
- 2016 backend security bug fixes cybersecurity information disclosure microsoft ms16-091 net framework patch revision note risk management security software update tech news technical bulletin update vulnerability web apps xml
- Replies: 0
- Forum: Security Alerts
-
MS16-074 - Important: Security Update for Microsoft Graphics Component (3164036) -...
Severity Rating: Important Revision Note: V1.0 (June 14, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow elevation of privilege if a user opens a specially crafted document or visits a...- News
- Thread
- bulletin components crafted documents elevate fix graphics important june microsoft ms16-074 patch privilege revision security update vulnerability website windows
- Replies: 0
- Forum: Security Alerts
-
MS16-061 - Important: Security Update for Microsoft RPC (3155520) - Version: 1.1
Severity Rating: Important Revision Note: V1.1 (May 11, 2016): Bulletin revised to change the vulnerability impact from elevation of privilege to remote code execution, and the title of CVE 2016-0178 to RPC Network Data Representation Engine Remote Code Execution Vulnerability. This is an...- News
- Thread
- 2016 cve 2016-0178 extended security updates informational change ms16-061 remote code execution revision note rpc update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-062 - Important: Security Update for Windows Kernel-Mode Drivers (3158222) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (May 10, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a...- News
- Thread
- 2016 application bulletin drivers elevation important kernel-mode microsoft ms16-062 patch privilege revision security security patch system technical update vulnerabilities windows
- Replies: 0
- Forum: Security Alerts
-
MS16-058 - Important: Security Update for Windows IIS (3141083) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (May 10, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker with access to the local system executes a malicious application. An...- News
- Thread
- 2016 admin rights bulletin exploitation iis malicious software microsoft ms16-058 patch remote code execution revision note security security bulletin update user account user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-105 - Important: Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (September 8, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker runs a specially crafted application that could cause Windows...- News
- Thread
- 2015 application attacker bulletin configuration extended security updates feature bypass hyper-v important microsoft ms15-105 patch revision note security technet update vulnerability windows
- Replies: 0
- Forum: Security Alerts