Sign in
MSRC
Home
About the Team
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
MSRC
>
January, 2006
January, 2006
Connect to Us
RSS for Posts
@msftsecresponse
Security Newsletter
Report a Vulnerability
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecresponse
Monthly Archives
Archives
June 2013
(3)
May 2013
(5)
April 2013
(5)
March 2013
(4)
February 2013
(6)
January 2013
(7)
December 2012
(5)
November 2012
(5)
October 2012
(4)
September 2012
(9)
August 2012
(4)
July 2012
(8)
June 2012
(8)
May 2012
(5)
April 2012
(4)
March 2012
(5)
February 2012
(3)
January 2012
(3)
December 2011
(9)
November 2011
(5)
October 2011
(3)
September 2011
(7)
August 2011
(5)
July 2011
(5)
June 2011
(3)
May 2011
(5)
April 2011
(5)
March 2011
(4)
February 2011
(4)
January 2011
(5)
December 2010
(6)
November 2010
(4)
October 2010
(3)
September 2010
(10)
August 2010
(8)
July 2010
(9)
June 2010
(5)
May 2010
(5)
April 2010
(11)
March 2010
(11)
February 2010
(9)
January 2010
(14)
December 2009
(7)
November 2009
(8)
October 2009
(4)
September 2009
(7)
August 2009
(4)
July 2009
(11)
June 2009
(4)
May 2009
(6)
April 2009
(12)
March 2009
(8)
February 2009
(9)
January 2009
(7)
December 2008
(11)
November 2008
(7)
October 2008
(15)
September 2008
(4)
August 2008
(5)
July 2008
(12)
June 2008
(8)
May 2008
(3)
April 2008
(4)
March 2008
(6)
February 2008
(2)
January 2008
(3)
December 2007
(7)
November 2007
(3)
October 2007
(5)
September 2007
(5)
August 2007
(4)
July 2007
(3)
June 2007
(2)
May 2007
(7)
April 2007
(18)
March 2007
(5)
February 2007
(4)
January 2007
(6)
December 2006
(10)
November 2006
(7)
October 2006
(8)
September 2006
(9)
August 2006
(10)
July 2006
(9)
June 2006
(16)
May 2006
(8)
April 2006
(7)
March 2006
(9)
February 2006
(6)
January 2006
(11)
December 2005
(7)
November 2005
(11)
October 2005
(9)
September 2005
(9)
August 2005
(13)
July 2005
(11)
June 2005
(11)
May 2005
(5)
April 2005
(2)
March 2005
(2)
February 2005
(16)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
MSRC
Looking at the WMF issue, how did it get there?
Posted
over 7 years ago
by
stepto
1
Comments
Hi everyone, Stephen Toulouse here. Now that the monthly release has passed and people are deploying the updates I wanted to take a moment to discuss some things related to questions we’ve been receiving on the recent WMF issue. (Which was addressed in MS06-001). One question we’ve gotten is about SetAbortProc , the function that allows printing jobs to be cancelled. (The link is to the public documentation of the function) Specifically people are wondering about how the vulnerability was present...
MSRC
Information on new WMF Posting
Posted
over 7 years ago
by
stepto
Lennart Wistrand here. I wanted to write a few lines about the public post made over the weekend about a new specially crafted WMF image that could potentially cause the application using the Windows Graphics Rendering Engine to crash. As it turns out, these crashes are not exploitable but are instead Windows performance issues that could cause some WMF applications to unexpectedly exit. These issues do not allow an attacker to run code or crash the operating system. They may cause the WMF application...
MSRC
Updated Advisory: WMF Vulnerability
Posted
over 7 years ago
by
stepto
Hi folks- Kevin Kean here again. We here in the MSRC have been hard at work on this WMF vulnerability and so I wanted to provide you all with an update on the situation. When the MSRC learned of the attacks on December 27, 2005, we mobilized under what we call the Software Security Incident Response Process (SSIRP) to analyze the attack, assess its scope and determine and the appropriate guidance for customers, as well as to engage with anti-virus partners and law enforcement. Based on...
MSRC
Mike Nash on the Security Update for the WMF Vulnerability
Posted
over 7 years ago
by
stepto
Hi there. Mike Nash from Microsoft here. For those of you who don’t know me, I am the Corporate Vice President responsible for security at Microsoft. Given the recent events around the Windows Meta File format vulnerability, an ongoing dialogue I have had with some customers and our recent decision to release an update for Windows out of band to correct this vulnerability, I thought I would take a minute to give you a sense of the thought process behind Microsoft’s decision. As you know, we...
MSRC
WMF Vulnerability Security Update
Posted
over 7 years ago
by
stepto
Mike Reavey here from the MSRC- I just wanted to provide another quick update on the WMF vulnerability situation. Microsoft is continuing to work on finalizing a security update for the vulnerability in WMF that is currently being exploited by some malicious attackers. The update has been on an expedited track since Microsoft became aware of the attacks on December 27th. We still anticipate releasing the security fix for this issue on January 10, 2006, once testing for quality and application compatibility...
MSRC
Microsoft Security Advisory on Win32/Sober
Posted
over 7 years ago
by
stepto
Hi everyone, Stephen Toulouse here. There is a lot of activity happening within the MSRC this week so I wanted to make sure that, in addition to the guidance we’ve put out around the WMF vulnerability, that we also let you know that we’ve issued a security advisory regarding recent variants of the Win32/Sober worm. To be clear, these are separate and unrelated issues, however getting guidance out to customers is equally important when customers are faced with any sort of malicious threat. The...
MSRC
Security updates available on ISO-9660 image files
Posted
over 7 years ago
by
stepto
I wanted to let you know about a new offering that those of you enterprise customers that download multiple security updates in multiple languages might find useful. Starting with the January 2006 release, each month we're making security and high-priority non-security updates that are available on Windows Update also available on an ISO-9660 CD image. This has items available from Windows Update only, so this means that you won't find updates for things like Office or Exchange. This isn't intended...
MSRC
MU and WSUS Information about Today's Bulletin Release
Posted
over 7 years ago
by
stepto
Hey folks – Mike Reavey here stepping in for Craig as he continues to work through some last minute issues on this Tuesday’s release. Today we’ve released two Security Bulletins. The first one, MS06-002 resolves a vulnerability in Font processing in Windows and is rated Critical. The second bulletin, MS06-003 is also rated Critical, and applies to Office and Exchange customers, and resolves an issue in Transport Neutral Encapsulation (TNEF). We’re actively working through a delay on getting the MS06...
MSRC
Trivia: security@microsoft.com and Windows development
Posted
over 7 years ago
by
stepto
Why is security@microsoft.com an auto-responder and not a redirect to secure@microsoft.com? Well, security@microsoft.com is the Microsoft internal physical security alias, and has been since we started using email. As I am sure you can imagine, the amount of email we get at that alias that is external is quite a lot. Thus the autoresponder instead of a human filter which informs you that secure@microsoft.com is the appropriate alias to report security vulnerabilities (and points to other security...
MSRC
Win32/MyWife.E
Posted
over 7 years ago
by
stepto
Hi everyone, just wanted to quickly point out that the Anti-malware team has posted a short note on the Win32/Mywife.E mass mailer worm. Pretty much all current AV protects against this worm, so running updated anti-virus is an important thing to do. In addition Windows OneCare members are also protected. The worm doesn't exploit a vulnerability, and requires user interaction. There's more over at the anti-malware blog . S. *This posting is provided "AS IS" with no warranties, and confers no...
Page 1 of 2 (11 items)
1
2