October, 2008

  • Microsoft out-of-band Security Bulletin (MS08-067) Webcast Q&A

    Register now for the November 2008 Security Bulletin Webcast Security Bulletin Webcast Q&A Index Hosts: Christopher Budd, Security Response Communications Lead Adrian Stone, Lead Security Program Manager (MSRC) Website: TechNet/security Chat Topic: Microsoft out-of-band Security Bulletin (MS08-067) TechNet Webcast Date: Thursday, October 23, 2008 and Friday, October 24, 2008 Note: The below questions were submitted from webcast attendees and are not necessarily in the order...
  • MS08-067 Released

    Hi, This is Christopher Budd. Following up on my post from last night, I wanted to let you know that we’ve released MS08-067 today. This security update resolves a vulnerability in the Server service that affects all currently supported versions of Windows. Windows XP and older versions are rated as “Critical” while Windows Vista and newer versions are rated as “Important”. Because the vulnerability is potentially wormable on those older versions of Windows, we’re encouraging customers to test...
  • Advance Notification for Out-of-Band Release

    Hello this is Christopher Budd, I wanted to let you know that we’ve just posted an Advance Notification for an out-of-band bulletin release. We plan to release one Windows security bulletin with a maximum severity of Critical; scheduled for a target time of 10:00 a.m. PT on Thursday Oct. 23, 2008. A restart will be required. We have scheduled a special webcast to cover this release. This will also be on Thursday at 1 p.m. PT. You can register for it here . Thanks Christopher *This...
  • Microsoft Security E-mail Spoofs with Malware

    Hi t his is Christopher Budd, We received some questions from customers about an e-mail that’s circulating that claims to be a security e-mail from Microsoft. The e-mail comes with an attached executable, which it claims is the latest security update, and encourages the recipient to run the attached executable so they can be safe. While malicious e-mails posing as Microsoft security notifications with attached malware aren’t new (we’ve seen this problem for several years) this particular...
  • Update on MS08-067

    Hello everyone, This is Christopher Budd once again. As I said in my last post , we aren’t done when we release an update. Our response teams are constantly watching the situation around the world to understand as much as possible what’s going on with things like the threat environment and the state of security update deployments. Based on some of our latest situation reports I wanted to provide you with an update as of this morning. You’ve told us it’s helpful for you to have this information...
  • Microsoft Security Advisory 958963

    Hey folks, Mike Reavey here, It’s been almost five days since we originally released MS08-067 , and our tracking shows that security deployments remain strong. We’re also still unaware of any application compatibility issues with this update. Like we’ve said, we’re continuing to watch the threat environment. Yesterday , we said that our analysis of public exploit code that was available showed it would always result in a denial of service. Today, we’ve identified the public availability of...
  • Additional Microsoft Security Bulletin Webcasts and Information Available for MS08-067

    Hi All, Mike Reavey, here. Just wanted to let you know that based on customer feedback, w e have set up two additional Security Bulletin Webcasts related to this o ut - of -b and release. Details are below: · For the Thursday , 10/23/08 , 5:00 PM Webcast , c ustomers can register at: http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032394183&Culture=en-US · For the Friday , 10/24/08 , 11:00 AM Webcast , c ustomers can register at: http://msevents.microsoft.com/CUI...
  • Update on MS08-067 and Microsoft Security Advisory 958963

    Hi, this is Christopher Budd. As we go into the weekend I wanted to take a moment and give you an update on the latest information around MS08-067 and Microsoft Security Advisory 958963 . Essentially there is no new information to report. We’ve seen no significant changes in the threat landscape since our posting of Microsoft Security Advisory 958963 on Monday. We continue to see strong, rapid and wide deployments of the security update worldwide. We also still have no reports of issues with the...
  • Out-Of-Band Security Bulletin Webcast Questions and Answers - MS08-067

    Hi, On Thursday, October 23, 2008, Microsoft released an Out-Of-Band Security Bulletin (MS08-067). To meet the customer demand for information relating to this release, Microsoft conducted three customer webcasts. Two of these webcasts were conducted on Thursday, October 23 rd and the other on Friday, October 24 th . The link below will direct you to a collection of all questions answered during the three webcasts. Here is the link to the full Q&A so you can see all of the answers...
  • October 2008 Advanced Notification

    Hello, Bill here. I wanted to let you know that we just posted our Advance Notification for next week’s bulletin release which will occur on Tuesday, Oct. 14, 2008 around 10 a.m. Pacific Standard Time. It is important to remember that while the information posted below is intended to help with your planning, because it is preliminary information, it is subject to change. As part of our regularly scheduled bulletin release, we’re currently planning to release: · Four Microsoft Security...