February, 2011

  • Advance Notification Service for the February 2011 Security Bulletin Release

    Hello all - Today, as part of our usual monthly bulletin cadence, we are providing our Advance Notification Service for February's security bulletins. This month, we'll release 12 bulletins, three of them rated Critical and nine rated Important, addressing issues in Microsoft Windows, Internet Explorer, Office, Visual Studio, and IIS. 22 issues will be addressed. As part of this month's update, we'll be addressing issues related to two recent Security Advisories, 2490606 (a public vulnerability...
  • Deeper insight into the Security Advisory 967940 update

    Hi! I'm Adam Shostack, a program manager working in TWC Security, and I'd like to talk a bit about today's AutoRun update. Normally, I post over on the SDL blog, but of late I've been doing a lot of work in classifying and quantifying how Windows computers get compromised. One thing that popped from that analysis was the proportion of infected machines with malware that uses Autorun to propagate. You might note that that's a convoluted sentence, and I apologize. Why can't I just say "infected...
  • February 2011 Security Bulletin Release

    Hello all -- Today, as part of our monthly security bulletin release, we have 12 bulletins addressing 22 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and IIS (Internet Information Services). Three bulletins are rated Critical, and these are the bulletins we recommend for priority deployment: o MS11-003 . This bulletin resolves three critical-level and moderate-level vulnerabilities affecting all versions of Internet Explorer. Due to existing mitigations, this bulletin...
  • Q&A from the February 2011 Security Bulletin Webcast

    Hello, Today we published the February Security Bulletin Webcast Questions & Answers page . We fielded 12 questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools. We invite our customers to join us for the next public webcast on Wednesday, March 9th at 11am PST (-8 UTC), when we will go into detail about the March bulletin release and answer questions live on the air. Customers can register to attend at the link below...