Sign in
MSRC
Home
About the Team
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
MSRC
>
August, 2006
August, 2006
Connect to Us
RSS for Posts
@msftsecresponse
Security Newsletter
Report a Vulnerability
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecresponse
Monthly Archives
Archives
May 2013
(5)
April 2013
(5)
March 2013
(4)
February 2013
(6)
January 2013
(7)
December 2012
(5)
November 2012
(5)
October 2012
(4)
September 2012
(9)
August 2012
(4)
July 2012
(8)
June 2012
(8)
May 2012
(5)
April 2012
(4)
March 2012
(5)
February 2012
(3)
January 2012
(3)
December 2011
(9)
November 2011
(5)
October 2011
(3)
September 2011
(7)
August 2011
(5)
July 2011
(5)
June 2011
(3)
May 2011
(5)
April 2011
(5)
March 2011
(4)
February 2011
(4)
January 2011
(5)
December 2010
(6)
November 2010
(4)
October 2010
(3)
September 2010
(10)
August 2010
(8)
July 2010
(9)
June 2010
(5)
May 2010
(5)
April 2010
(11)
March 2010
(11)
February 2010
(9)
January 2010
(14)
December 2009
(7)
November 2009
(8)
October 2009
(4)
September 2009
(7)
August 2009
(4)
July 2009
(11)
June 2009
(4)
May 2009
(6)
April 2009
(12)
March 2009
(8)
February 2009
(9)
January 2009
(7)
December 2008
(11)
November 2008
(7)
October 2008
(15)
September 2008
(4)
August 2008
(5)
July 2008
(12)
June 2008
(8)
May 2008
(3)
April 2008
(4)
March 2008
(6)
February 2008
(2)
January 2008
(3)
December 2007
(7)
November 2007
(3)
October 2007
(5)
September 2007
(5)
August 2007
(4)
July 2007
(3)
June 2007
(2)
May 2007
(7)
April 2007
(18)
March 2007
(5)
February 2007
(4)
January 2007
(6)
December 2006
(10)
November 2006
(7)
October 2006
(8)
September 2006
(9)
August 2006
(10)
July 2006
(9)
June 2006
(16)
May 2006
(8)
April 2006
(7)
March 2006
(9)
February 2006
(6)
January 2006
(11)
December 2005
(7)
November 2005
(11)
October 2005
(9)
September 2005
(9)
August 2005
(13)
July 2005
(11)
June 2005
(11)
May 2005
(5)
April 2005
(2)
March 2005
(2)
February 2005
(16)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
MSRC
MS06-040 attack information
Posted
over 7 years ago
by
MSRCTeam
10
Comments
Stepto here. It’s a late, late Saturday night. We’ve been made aware of a recent SANS Internet Storm Center diary post several hours ago regarding an active exploit on MS06-040. We wanted to let you know what we’ve been doing about the situation and what we know. Our AV teams have labeled this Win32/Graweg.A and Win32/Graweg.B and have added detection to http://safety.live.com already as well as our various other offerings such as Windows Onecare. So far, this appears to be an extremely targeted...
MSRC
Today's postponed re-release of MS06-042, and posting of a Security Advisory
Posted
over 7 years ago
by
MSRCTeam
10
Comments
Hi everyone, Stephen Toulouse here. We wanted to provide you with information about the MS06-042 re-release that was scheduled to occur today. As posted on August 15 th , we noted we would be re-releasing MS06-042 today to address a crashing issue that could occur if you are using HTTP 1.1 in combination with Internet Explorer 6.0 SP1. Late last night we discovered an issue that led us to the difficult but necessary decision to not release this update today. Providing the update in its current state...
MSRC
Update about MS06-042 and IE 6.0 SP1
Posted
over 7 years ago
by
MSRCTeam
8
Comments
Hey folks - Mike Reavey here, we've made an update to MS06-042 to let customers know of an issue they might see after applying the update to Internet Explorer 6 Service Pack 1 systems. The issue is limited to IE6SP1 only, and then only when visiting a website that use HTTP 1.1 and compression. Since MS06-042 resolves a number of security vulnerabilities we recommend customers continue to deploy the update, but we do plan to revise *only* the IE6SP1 update and re-release the bulletin with more information...
MSRC
Power Point Zero Day? No.
Posted
over 7 years ago
by
MSRCTeam
5
Comments
Hi, Scott here from the MSRC operations team. I just wanted to drop a few lines to clarify the recent buzz/ activity on a PowerPoint zero day that occured over the weekend. Our investigation has proven thus far that customers who are up to date with Office security updates are NOT affected. Meaning this is NOT a zero day. Malware in the malicious .ppt leverages a previously fixed vulnerability in Microsoft Office to drop the payload. To be attacked and become infected requires a user to...
MSRC
August 2006 Security Update Release
Posted
over 7 years ago
by
MSRCTeam
5
Comments
Hey everyone - Adrian Stone here again, stepping in for Craig Gehre to provide a quick overview of the security updates we've released Today. The full list of the updates released today are below, and, as always, additional information on the specific vulnerabilities resolved with this release are included within each security bulletin. While we always recommend applying any updates rated "Critical" as soon as possible, we are recommending that customers give priority to MS06-040 for testing and...
MSRC
August 2006 Microsoft Monthly Bulletin Release: Day Two Update
Posted
over 7 years ago
by
MSRCTeam
4
Comments
Hi Christopher Budd here, We're into the second day of our August 2006 release and I wanted to check back and let folks know how things are going with this release. It's been about 30 hours since we posted the security updates and I'm happy to be able to say we've had well over 100 million downloads of the update for MS06-040 (that's nearly 3.5 million per hour!!). So our thanks to everyone for working hard and helping us get this out to protect their systems. We're also seeing...
MSRC
An update on Win32/Graweg
Posted
over 7 years ago
by
MSRCTeam
3
Comments
Hey everyone, it’s Adrian . Wanted to drop in and let you know where we are in our investigation of Win32/Graweg. As I’m sure you’ve seen by now on our AV partner sites, this is rated as a low threat and doesn’t at this time replicate automatically from machine to machine. So it’s impact in terms of infection base appears to be extremely small. We’ve updated the security advisory related to MS06-040 . What we know right now is that the attack affects specifically Windows 2000 computers who have not...
MSRC
Monday Update on Graweg
Posted
over 7 years ago
by
MSRCTeam
3
Comments
So I am back to give what I hope is the last update on the recent MS06-040 exploit. By the way, this is Adrian Stone again. As many of you know from the recent posts, and recent Advisory publication we have been working all weekend to stay on top of the Win32/Graweg issue so I thought it would be a good idea to update you with the current status as various enterprises and organizations around the world have come online. We have been seeing activity related to Graweg taper off. From our analysis...
MSRC
MS06-042 Re-released
Posted
over 7 years ago
by
MSRCTeam
2
Comments
Hey folks - Mike Reavey here, I wanted to follow up on our Security Advisory we released on Tuesday about the re-release of MS06-042 for IE 6.0 SP1 customers. We've resolved the issues that delayed the re-release and have released the revised update. The revised update fully resolves the security vulnerability we discussed in the Advisory. We also have resolved the issues that we discovered prior to the planned release on Tuesday. We are now urging IE 6.0 SP1 customers to go ahead and deploy...
MSRC
Advisory with Information on Exploit Code for MS06-040
Posted
over 7 years ago
by
MSRCTeam
Hey folks - Mike Reavey here, providing you with a quick update on MS06-040 . This morning we released Security Advisory 922437 because we're aware of exploit code that has been published on the Internet for the vulnerability that is addressed by Microsoft security bulletin MS06-040 . We've verified that this exploit code can allow remote code to execute on Windows 2000 and Windows XP Service Pack 1 only. In its current state, this code does not affect Windows XP Service Pack 2, Windows Server 2003...
Page 1 of 1 (10 items)