Sign in
MSRC
Home
About the Team
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
MSRC
>
December, 2006
December, 2006
Connect to Us
RSS for Posts
@msftsecresponse
Security Newsletter
Report a Vulnerability
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecresponse
Monthly Archives
Archives
May 2013
(5)
April 2013
(5)
March 2013
(4)
February 2013
(6)
January 2013
(7)
December 2012
(5)
November 2012
(5)
October 2012
(4)
September 2012
(9)
August 2012
(4)
July 2012
(8)
June 2012
(8)
May 2012
(5)
April 2012
(4)
March 2012
(5)
February 2012
(3)
January 2012
(3)
December 2011
(9)
November 2011
(5)
October 2011
(3)
September 2011
(7)
August 2011
(5)
July 2011
(5)
June 2011
(3)
May 2011
(5)
April 2011
(5)
March 2011
(4)
February 2011
(4)
January 2011
(5)
December 2010
(6)
November 2010
(4)
October 2010
(3)
September 2010
(10)
August 2010
(8)
July 2010
(9)
June 2010
(5)
May 2010
(5)
April 2010
(11)
March 2010
(11)
February 2010
(9)
January 2010
(14)
December 2009
(7)
November 2009
(8)
October 2009
(4)
September 2009
(7)
August 2009
(4)
July 2009
(11)
June 2009
(4)
May 2009
(6)
April 2009
(12)
March 2009
(8)
February 2009
(9)
January 2009
(7)
December 2008
(11)
November 2008
(7)
October 2008
(15)
September 2008
(4)
August 2008
(5)
July 2008
(12)
June 2008
(8)
May 2008
(3)
April 2008
(4)
March 2008
(6)
February 2008
(2)
January 2008
(3)
December 2007
(7)
November 2007
(3)
October 2007
(5)
September 2007
(5)
August 2007
(4)
July 2007
(3)
June 2007
(2)
May 2007
(7)
April 2007
(18)
March 2007
(5)
February 2007
(4)
January 2007
(6)
December 2006
(10)
November 2006
(7)
October 2006
(8)
September 2006
(9)
August 2006
(10)
July 2006
(9)
June 2006
(16)
May 2006
(8)
April 2006
(7)
March 2006
(9)
February 2006
(6)
January 2006
(11)
December 2005
(7)
November 2005
(11)
October 2005
(9)
September 2005
(9)
August 2005
(13)
July 2005
(11)
June 2005
(11)
May 2005
(5)
April 2005
(2)
March 2005
(2)
February 2005
(16)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
MSRC
New Report of A Word Zero Day
Posted
over 7 years ago
by
MSRCTeam
13
Comments
Hi All, Scott Deacon here, well a busy week extends into a busy weekend for the MSRC!! We are investigating reports of another new vulnerability in Microsoft Word – initial investigation has shown that this is a different issue to that reported in Microsoft Security Advisory 929433 . Our initial investigation has discovered that Word 2000, Word 2002, Word 2003 and the Word Viewer 2003 are affected, but Word 2007 is NOT affected by the vulnerability. From the initial reports and...
MSRC
New report of a Windows vulnerability
Posted
over 7 years ago
by
MSRCTeam
9
Comments
Hi everyone, As usual the holiday season is a busy time for everyone including those of us here in the MSRC. I hope that everyone has finished their holiday shopping so they can enjoy the long weekend. This is Mike Reavey by the way in case anyone was wondering. Aside from discussing the holidays, the reason I am dropping in on the blog is that right now we are closely monitoring developments related to a public posting of proof of concept code targeting an issue with the Client Server Run...
MSRC
What “very limited, targeted attacks” Means
Posted
over 7 years ago
by
MSRCTeam
7
Comments
Hi, this is Christopher Budd. We’ve gotten some question from customers about what we mean when we say we’re aware of “very limited, targeted attacks” in a security advisory. I wanted to take a moment and help give some clarity. When we talk about “very limited, targeted attacks” we specifically mean this in contrast to attacks that affect a broad number of customers randomly. Unlike these broad, random attacks, these very limited, targeted attacks are carried out against a very small number...
MSRC
December 2006 Advanced Notification
Posted
over 7 years ago
by
MSRCTeam
3
Comments
Hello, This is Christopher Budd and I'm posting here today to let you know that we've posted our Advanced Notification for the December 2006 Microsoft Monthly Security Bulletin Release. Next Tuesday, on December 12, 2006 at approximately 10:00 am PT we are slated to release six new security bulletins: Five Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security...
MSRC
Update on Current Word Vulnerability Reports
Posted
over 7 years ago
by
MSRCTeam
3
Comments
Hey everyone, Alexandra Huft here. I wanted to try and summarize/clarify for everyone the three current Word Zero-Day issues that have been reported to Microsoft. First, I wanted everyone to know that we’re actively investigating and monitoring all of these issues through our Software Security Incident Response Process and we are working on developing and testing security updates for the three issues, which we’ll release as part of our release process once they’ve reached an appropriate level...
MSRC
Update on accidental posting of pre-release security updates for Office for Mac
Posted
over 7 years ago
by
MSRCTeam
3
Comments
We wanted to follow up with Office for Mac users on what to do if you installed the pre-release security updates released on Tuesday. Because the Office for Mac update that was erroneously released had additional, non-security fixes, the Office for Mac team would like to distribute a new update to its customers that includes all the fixes unrelated to security. We are planning to release the new update by the end of next week. Customers who downloaded the pre-release security update for Office...
MSRC
December 2006 Monthly Security Bulletin Release
Posted
over 7 years ago
by
MSRCTeam
2
Comments
Hello, this is Christopher Budd. I wanted to let you know that as part of our standard monthly bulletin release process we’ve released our security bulletins for December 2006. · Microsoft Windows ( MS06-072 ) · maximum severity rating of Critical · vulnerabilities could allow an attacker to remotely take complete control of an affected system. · Microsoft Visual Studios 2005 ( MS06-073 ) · maximum severity rating of Critical · vulnerabilities could allow an attacker...
MSRC
Information on accidental posting of pre-release security updates for Office for Mac
Posted
over 7 years ago
by
MSRCTeam
2
Comments
We’ve seen some question s from customers about some security updates that posted for a while today for Office for Mac that they didn’t see any security bulletins for. I wanted to let you know that these weren’t security updates related to this month’s release or the two Word issues we’ve written about in Security Advisory 929433 and on our weblog : those investigations are still underway and we’ll release updates for those issues once we’ve met the appropriate quality bar. The updates posted...
MSRC
Public Proof of Concept Code for ASX File Format Isssue
Posted
over 7 years ago
by
MSRCTeam
2
Comments
Hey everyone this is Alexandra Huft I wanted to let you know that we’re aware of proof-of-concept code published publicly affecting Windows Media ASX file format. We are currently investigating this report. We are not currently aware of attempts to exploit this vulnerability. The ASX file format is an XML-based media file format which is processed by Windows Media Player. An attacker could construct a malformed ASX file and use it to cause Media Player to overrun a heap-allocated buffer...
MSRC
Microsoft Security Advisory (929433) Posted
Posted
over 7 years ago
by
MSRCTeam
2
Comments
Hey everyone this is Alexandra Huft I wanted to let people know that we just posted Microsoft Security Advisory (929433) which involves Microsoft Word. We are currently investigating a report of a proof of concept which may allow an attacker to execute code on a user’s machine by convincing them to open a specially-crafted Word document. We are aware of limited attacks attempting to use the vulnerability reported. I will keep everyone up to date as new or additional information becomes...
Page 1 of 1 (10 items)