Sign in
MSRC
Home
About the Team
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
MSRC
>
March, 2006
March, 2006
Connect to Us
RSS for Posts
@msftsecresponse
Security Newsletter
Report a Vulnerability
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecresponse
Monthly Archives
Archives
May 2013
(5)
April 2013
(5)
March 2013
(4)
February 2013
(6)
January 2013
(7)
December 2012
(5)
November 2012
(5)
October 2012
(4)
September 2012
(9)
August 2012
(4)
July 2012
(8)
June 2012
(8)
May 2012
(5)
April 2012
(4)
March 2012
(5)
February 2012
(3)
January 2012
(3)
December 2011
(9)
November 2011
(5)
October 2011
(3)
September 2011
(7)
August 2011
(5)
July 2011
(5)
June 2011
(3)
May 2011
(5)
April 2011
(5)
March 2011
(4)
February 2011
(4)
January 2011
(5)
December 2010
(6)
November 2010
(4)
October 2010
(3)
September 2010
(10)
August 2010
(8)
July 2010
(9)
June 2010
(5)
May 2010
(5)
April 2010
(11)
March 2010
(11)
February 2010
(9)
January 2010
(14)
December 2009
(7)
November 2009
(8)
October 2009
(4)
September 2009
(7)
August 2009
(4)
July 2009
(11)
June 2009
(4)
May 2009
(6)
April 2009
(12)
March 2009
(8)
February 2009
(9)
January 2009
(7)
December 2008
(11)
November 2008
(7)
October 2008
(15)
September 2008
(4)
August 2008
(5)
July 2008
(12)
June 2008
(8)
May 2008
(3)
April 2008
(4)
March 2008
(6)
February 2008
(2)
January 2008
(3)
December 2007
(7)
November 2007
(3)
October 2007
(5)
September 2007
(5)
August 2007
(4)
July 2007
(3)
June 2007
(2)
May 2007
(7)
April 2007
(18)
March 2007
(5)
February 2007
(4)
January 2007
(6)
December 2006
(10)
November 2006
(7)
October 2006
(8)
September 2006
(9)
August 2006
(10)
July 2006
(9)
June 2006
(16)
May 2006
(8)
April 2006
(7)
March 2006
(9)
February 2006
(6)
January 2006
(11)
December 2005
(7)
November 2005
(11)
October 2005
(9)
September 2005
(9)
August 2005
(13)
July 2005
(11)
June 2005
(11)
May 2005
(5)
April 2005
(2)
March 2005
(2)
February 2005
(16)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
MSRC
An update on the IE ActiveX change from Mike Nash
Posted
over 7 years ago
by
stepto
1
Comments
Hi there. Mike Nash from the STU. Earlier this year, during our response to the WMF zero exploit with an out-of-band band security update, I wrote a blog entry explaining the details of how we got to the decision to release that update early. I received a lot of feedback from customers around the world that the blog entry and the internal insights into our decision-making process in that situation was very helpful and that we should make it a consistent practice for issues that have widespread impact...
MSRC
Security advisory posted, and RSA thoughts.
Posted
over 7 years ago
by
stepto
Hi everyone, Stepto here. (I'm giving up on the "Stephen Toulouse here" after many people I met at RSA greeted me as "Stepto", but as a side note since I created the blog under "Stepto" please remember that posts made by individuals on the MSRC are made by themselves and not me.) I wanted to check in real quick and make everyone aware of a security advisory that we have posted for a recent update to Internet Explorer that is not security related, but we still wanted to make sure people were aware...
MSRC
March 2006 Advanced Notification
Posted
over 7 years ago
by
stepto
Hey folks, Mike Reavey here, I wanted to take a quick second to make sure everyone saw the Advance Notification for the Security Bulletin release for March. This coming Tuesday, the 14th, we’re planning to release two security bulletins, and they are being released for Windows for Office. The maximum total severity rating for this month is Critical, so please update systems as soon as possible when they are available on Tuesday. The updates can be deployed and detected with MBSA, Microsoft Update...
MSRC
March 2006 Bulletin Release
Posted
over 7 years ago
by
stepto
‘I want my two… bulletins’. For some reason an unrelenting paperboy’s quest for two dollars seems to echo in my mind today. It seems so small yet it is so important. Well today the MSRC released two new bulletins. One for Office and the other for Windows, more info below. The Windows one addresses an issue you may have been following via our advisories, 914457. BTW, this is Craig Gehre, the Release Manager for the MSRC (Don’t you get sick of team blogs saying "Jane here, blah blah blah…"?). We also...
MSRC
Publicly disclosed vulnerability in Internet Explorer
Posted
over 7 years ago
by
stepto
Hi everyone, Lennart Wistrand here. You may have heard about an IE crashing vulnerability that was unfortunately publicly posted before the weekend. We just wanted to make a quick note here that, as always, we’re investigating it. So far we’ve determined that visiting a page that exploits it could cause IE to fail. We’re going to continue to look into this but remind you that safe browsing practices can help here, like only visiting trusted websites, etc. If you think you might be impacted though...
MSRC
New publicly disclosed vulnerability in Internet Explorer
Posted
over 7 years ago
by
stepto
Hi, It’s Lennart again. Wanted to let you know that today we saw another public posting around a vulnerability in Internet Explorer. This one is different than the crash bug I wrote about earlier. The public posting speaks about createTextRange() and a way that this could be utilized to get code to run when visiting a specially crafted Web page. We’re still investigating, but we have confirmed this vulnerability and I am writing a Microsoft Security Advisory on this. But we wanted to make sure customers...
MSRC
Recent exploits regarding the Internet Explorer HTML handling vulnerability.
Posted
over 7 years ago
by
stepto
Hi everyone, Stepto here. Today the MSRC became aware of public reports of attacks on some PC users utilizing the vulnerability that Lennart posted about in Internet Explorer . Here's what we know. The attacks are limited in scope for now and are being carried out by malicious Web sites exploiting a vulnerability in the method by which Internet Explorer handles HTML rendering. To be clear, and as our advisory states, the vulnerability affects currently supported versions of Windows 2000, Windows...
MSRC
Update regarding recent Internet Explorer attacks
Posted
over 7 years ago
by
stepto
Hi gang, Stepto here again. The MSRC in combination with our internal and external partner teams have been working through the weekend looking at the recent attacks involving the IE vulnerability I mentioned previously. So far we’re still seeing only limited attacks. But our anti-malware team, as always, is on the case and has uploaded removal information for the attacks to date to Windows Live Safety Center . I want to reiterate that the IE team has the update in process right now and if warranted...
MSRC
Third party solutions to the Internet Explorer CreateTextRange vulnerability
Posted
over 7 years ago
by
stepto
Hi everyone, Mike Reavey here. I wanted to make everyone aware of some recent developments regarding the “Create TextRange” IE vulnerability. First off we're still not seeing increased spread of attacks, and in fact have been very active in taking down sites as they come up with law enforcement. But attacks are still occurring so we certainly still recommend up to date AV software and our safe browsing guidance while we work on the update, and have updated the security advisory with a list of VIA...
Page 1 of 1 (9 items)