January, 2010

  • Security Advisory 979352 Released

    Based upon our investigations, we have determined that Internet Explorer was one of the vectors used in targeted and sophisticated attacks against Google and possibly other corporate networks. Today, Microsoft issued guidance to help customers mitigate a Remote Code Execution (RCE) vulnerability in Internet Explorer . Additionally, we are cooperating with Google and other companies, as well as authorities and other industry partners. Microsoft remains committed to taking the appropriate action...
  • Security Advisory 979352 – Going out of Band

    We wanted to provide a quick update on the threat landscape and announce that we will release a security update out-of-band to help protect customers from this vulnerability. Based on our comprehensive monitoring of the threat landscape we continue to see very limited, and in some cases, targeted attacks. To date, the only successful attacks that we are aware of have been against Internet Explorer 6. We continue to recommend customers update to Internet Explorer 8 to benefit from the improved...
  • Further Insight into Security Advisory 979352 and the Threat Landscape

    Hi All, We wanted to provide you some insight into the vulnerability reported in Microsoft Security Advisory 979352 , which is related to our ongoing investigation into the recently publicized attacks against Google and other large corporate networks. We understand that there is a lot of noise about this topic right now and we know that our customers are receiving a lot of information about this situation from a variety of sources, so we want to provide some additional insight. First, we will provide...
  • Bulletin MS10-002 Released

    Hello, Today we released Security Bulletin MS10-002 out-of-band to address vulnerabilities in Internet Explorer. All customers using currently supported versions of Windows and Internet Explorer should apply this update as soon as possible. Once applied, customers are protected against the known attacks that have been widely publicized. For customers using automatic updates, this update will automatically be applied once it is released. I also wanted to clarify some information that we included in...
  • Advance Notification for Out-of-Band Bulletin Release

    Today we issued our Advanced Notification Service (ANS) to advise customers that we will be releasing MS10-002 tomorrow, January 21 st , 2010. We are planning to release the update as close to 10:00 a.m. PST (UTC -8) as possible.  This is a standard cumulative update, accelerated from our regularly scheduled February release, for Internet Explorer with an aggregate severity rating of Critical. It addresses the vulnerability related to recent attacks against Google and small subset of corporations...
  • Security Advisory 979682 Released

    Today we released Security Advisory 979682 to address an Elevation of Privilege (EoP) vulnerability in the Windows kernel, affecting all currently supported versions of 32-bit Windows. 64-bit versions of Windows, including Windows Server 2008 R2, are not affected. The advisory provides customers with actionable guidance to help with protections against exploit of this vulnerability. To exploit this vulnerability, an attacker must already have valid logon credentials and be able to log on to a system...
  • Advisory 979352 Update for Monday January 18

    For today’s update we want to share some insight on the current threat landscape for Security Advisory 979352 , some new resources we have published and the current status on producing a security update. As we’ve previously reported, attacks remain targeted to a very limited number of corporations and are only effective against Internet Explorer 6. We have not seen successful attacks on Internet Explorer 8. We continue to recommend customers update to Internet Explorer 8 to benefit from the...
  • January 2010 Security Bulletin Release

    Summary of Microsoft’s Security Bulletin Release for January 2010 Hi Everyone, We hope that 2010 is off to a good start for you. For our first bulletin release of the New Year, we have one Critical bulletin affecting all versions of Windows. The bulletin, MS10-001 , addresses one vulnerability in the Embedded OpenType Font Engine and is Critical on Windows 2000. For all other versions of Windows, the vulnerability gets a Low rating. We’ve given the bulletin an aggregate rating of “2” on our Exploitability...
  • Advisory 979352 Updated

    Hello, Today we updated Security Advisory 979352 to let customers know that we are aware that exploit code for the vulnerability used in recent attacks against IE 6 users, has now been made public. Information on which versions of Internet Explorer are vulnerable and what customers can do to protect themselves is included in the updated Security Advisory. Our teams are continuing to work on an update and we will take appropriate action to protect customers when the update has met the quality...
  • January 2010 Bulletin Release Advance Notification

    Advance Notification for the January 2010 Security Bulletin Release It may be a new year but here in the Microsoft Security Response Center, it is business as usual. This month we have one bulletin addressing a single vulnerability in Windows. The vulnerability is critical on Windows 2000 and low for all other platforms. Customers with Windows 2000 systems will want to review and deploy this update as soon as possible but, as we will show in our release guidance next week, the Exploitability Index...