Sign in
MSRC
Home
About the Team
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
MSRC
>
May, 2006
May, 2006
Connect to Us
RSS for Posts
@msftsecresponse
Security Newsletter
Report a Vulnerability
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecresponse
Monthly Archives
Archives
May 2013
(5)
April 2013
(5)
March 2013
(4)
February 2013
(6)
January 2013
(7)
December 2012
(5)
November 2012
(5)
October 2012
(4)
September 2012
(9)
August 2012
(4)
July 2012
(8)
June 2012
(8)
May 2012
(5)
April 2012
(4)
March 2012
(5)
February 2012
(3)
January 2012
(3)
December 2011
(9)
November 2011
(5)
October 2011
(3)
September 2011
(7)
August 2011
(5)
July 2011
(5)
June 2011
(3)
May 2011
(5)
April 2011
(5)
March 2011
(4)
February 2011
(4)
January 2011
(5)
December 2010
(6)
November 2010
(4)
October 2010
(3)
September 2010
(10)
August 2010
(8)
July 2010
(9)
June 2010
(5)
May 2010
(5)
April 2010
(11)
March 2010
(11)
February 2010
(9)
January 2010
(14)
December 2009
(7)
November 2009
(8)
October 2009
(4)
September 2009
(7)
August 2009
(4)
July 2009
(11)
June 2009
(4)
May 2009
(6)
April 2009
(12)
March 2009
(8)
February 2009
(9)
January 2009
(7)
December 2008
(11)
November 2008
(7)
October 2008
(15)
September 2008
(4)
August 2008
(5)
July 2008
(12)
June 2008
(8)
May 2008
(3)
April 2008
(4)
March 2008
(6)
February 2008
(2)
January 2008
(3)
December 2007
(7)
November 2007
(3)
October 2007
(5)
September 2007
(5)
August 2007
(4)
July 2007
(3)
June 2007
(2)
May 2007
(7)
April 2007
(18)
March 2007
(5)
February 2007
(4)
January 2007
(6)
December 2006
(10)
November 2006
(7)
October 2006
(8)
September 2006
(9)
August 2006
(10)
July 2006
(9)
June 2006
(16)
May 2006
(8)
April 2006
(7)
March 2006
(9)
February 2006
(6)
January 2006
(11)
December 2005
(7)
November 2005
(11)
October 2005
(9)
September 2005
(9)
August 2005
(13)
July 2005
(11)
June 2005
(11)
May 2005
(5)
April 2005
(2)
March 2005
(2)
February 2005
(16)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
MSRC
Incorrect reports of a new Windows 2000 SMB vulnerability
Posted
over 7 years ago
by
stepto
Hey everyone. Stephen Toulouse here. There has been a bit of a flurry of activity here in Redmond this morning when we noticed a couple of people releasing information about an SMB vulnerability in Windows 2000. We just want to let everyone know that we've investigated this claim and found the vulnerability being discussed is fixed by MS05-011, a security update released almost 16 months ago. We contacted our partners on this and made sure they understood this is not new. What *is* new is that...
MSRC
Advisory posted on the recent Word vulnerability.
Posted
over 7 years ago
by
stepto
59
Comments
Hi everyone, Stephen Toulouse here again. Just wanted to make you aware that we have reached the point in our investigation of the limited attacks trying to use the Word vulnerability that provided us with enough information to develop some stronger workarounds and mitigations. We've posted all that into a new security advisory: http://www.microsoft.com/technet/security/advisory/919637.mspx Just to reiterate, this information is of course just a place holder while we are working on the update...
MSRC
A quick check-in on the Word vulnerability
Posted
over 7 years ago
by
stepto
Hi everyone, Stephen Toulouse here again. I wanted to catch you up on where we’re at with our investigation of the Word vulnerability. First off on the vulnerability itself: I want to reiterate we’re hard at work on an update. The attack vector here is Word documents attached to an email or otherwise delivered to a user’s computer. The user would have to open it first for anything to happen. That information isn’t meant to say the issue isn’t serious, it’s just meant to clearly denote the scope...
MSRC
Reports of a new vulnerability in Microsoft Word
Posted
over 7 years ago
by
stepto
1
Comments
Hi everyone, Stephen Toulouse here. We've been made aware of a new vulnerability in Microsoft Word XP and Word 2003. Customers using the Word viewer to view documents are not impacted. Yesterday we recieved a report that a customer had been subjected to a very targeted attack using this vulnerability. Here's what we know: In order for this attack to be carried out, a user must first open a malicious Word document attached to an e-mail or otherwise provided to them by an attacker. (note that opening...
MSRC
New Article: Ten Principles of Microsoft Patch Management
Posted
over 7 years ago
by
stepto
Hello, This is Christopher Budd. I wanted to take a moment and let folks know that this month's IT Pro Security newsletter has an article that I hope will be helpful for those of you who manage security updates. It's called Ten Principles of Microsoft Patch Management and in it I try o outline not so much the "how" of patch management but rather more of the "why" behind what we do. Over the years, I've found many questions that customers have around bulletins and security updates are best...
MSRC
Detection Changes for MS06-020 on WU/MU/AU and Text Corrections for MS06-019 for WSUS/SMS
Posted
over 7 years ago
by
stepto
This is Craig Gehre and there are two things I wanted to let you know about. Some of you may have been getting install errors on the Flash update, MS06-020, we released on Tuesday. You would have seen these install failure errors on Windows Update, Microsoft Update, or on your system via Automatic Update. There is nothing wrong with the update itself. What was happening is that we were offering the update to newer versions of Flash, which did not need the update, in addition to the systems that did...
MSRC
May 2006 Bulletin Release
Posted
over 7 years ago
by
stepto
Say heh? I have to be honest. I’ve been in the MSRC now for a while, seen a lot of “interesting” things happen around here and it is a bit of a trip to look at our list of bulletins we shipped today and see the words Flash, Adobe, and Macromedia in the titles. Different to say the least. Anyways, below are links to the bulletins we release today. Fairly light release and the detection/deployment story is fairly smooth. Microsoft Update and WSUS will offer you everything we released this month...
MSRC
May 2006 Advance Notification
Posted
over 7 years ago
by
stepto
Good afternoon, This is Christopher Budd. I wanted to take a moment and let you know that we've posted our regular Monthly Advanced Notification for the upcoming bulletin release. As a reminder, this month, our regularly scheduled monthly bulletin release is slated for Tuesday, 9 May 2006 with a target time of 10 AM Pacific Time. A quick reminder too that 10 AM is a target time and not a hard and fast deadline. This month, we are planning 3 bulletins. One for Microsoft Exchange and two for...
Page 1 of 1 (8 items)