Sign in
MSRC
Tags
ActiveX
advisory
announcements
ANS
Attack
Attack Vector
Autorun
BlueHat Prize
bulletin
Bulletins
Customer Questions
CVD
Defense-in-depth
Emerging Threat
Exploitability
Exploitability Index
IIS
Internet Explorer (IE)
Killbit
Malicious Software (Malware)
Malicious Software Removal Tool (MSRT)
Microsoft Active Protections Program (MAPP)
Microsoft Office
Microsoft Windows
Mitigations
monthly bulletin release
news
november
office
OOB
Pages
Q&A
Responsible Disclosure
Risk Assessment
security
Security Advisory
Security Bulletin
security bulletin release
security bulletin release forefront powerpoint office
Security Bulletin Webcast
Security Bulletins
Security Development Lifecycle (SDL)
Security Update
Security Update Webcast
Security Update Webcast Q & A
Security Update Webcast Q &
September out of band
UAG
Update Tuesday
video
Virus
vulnerability
Webcast
Webcast Q&A
Webcast Q&
Workarounds
Zero-Day Exploit
Browse by Tags
TechNet Blogs
>
MSRC
>
All Tags
>
advisory
Tagged Content List
Blog Post:
Fix it for Security Advisory 2847140 is available
MSRCTeam
We have updated Security Advisory 2847140 to include an easy, one-click Fix it to address the known attack vectors. The Fix it is available to all customers and helps prevent known attacks that leverage the vulnerability to execute code and should not affect your ability to browse the Web. Additionally...
on
8 May 2013
Blog Post:
Microsoft Releases Security Advisory 2847140
MSRCTeam
Today, we released Security Advisory 2847140 regarding an issue that impacts Internet Explorer 8. Internet Explorer 6, 7, 9 and 10 are not affected by the vulnerability. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur...
on
3 May 2013
Blog Post:
Security Advisory 2755801 revised to address Adobe Flash Player issues (Feb. 26, 2013)
MSRCTeam
Today we revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10 on Windows 8. This advisory revision was released in conjunction with Adobe’s update process. Customers who have automatic updates enabled will not need to take any action because protections...
on
26 Feb 2013
Blog Post:
Security Advisory 2755801 revised to address Adobe Flash Player issues (Feb. 7, 2013)
MSRCTeam
Today we revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10 on Windows 8, this revision was released in conjunction with Adobe’s update process. Customers who have automatic updates enabled will not need to take any action because protections will...
on
7 Feb 2013
Blog Post:
Fix it for Security Advisory 2794220 now available
MSRCTeam
We have updated Security Advisory 2749920 to include the Fix it we discussed in Saturday’s blog post . This easy, one-click Fix it is available to everyone and prevents the vulnerability from being used for code execution without affecting your ability to browse the Web. Additionally, applying...
on
31 Dec 2012
Blog Post:
Microsoft Releases Security Advisory 2794220
MSRCTeam
Today, we released Security Advisory 2794220 regarding an issue that impacts Internet Explorer 6, 7, and 8. We are only aware of a very small number of targeted attacks at this time. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically...
on
29 Dec 2012
Blog Post:
It’s That Time of Year, For the December 2012 Bulletin Release
MSRCTeam
Happy holidays! I hope everyone is enjoying the festive season. I like to get my holiday shopping done early, and this year was no exception. In the middle of my holiday shopping last week, as I passed my cash from one store to the next, I was reminded of “Pass-the-Hash.” (My mind does tend...
on
11 Dec 2012
Blog Post:
Security Advisory 2755801 revised to address Adobe Flash Player issues (Nov. 6, 2012)
MSRCTeam
Today, in conjunction with Adobe’s update process, we have revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10. Customers who have automatic updates enabled will not need to take any action because protections will be downloaded and installed automatically...
on
6 Nov 2012
Blog Post:
Security Advisory 2755801 revised to address Adobe Flash Player issues
MSRCTeam
Today we revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10, in conjunction with Adobe’s update process. Customers who have automatic updates enabled will not need to take any action because protections will be downloaded and installed automatically...
on
8 Oct 2012
Blog Post:
Security Advisory 2755801 addresses Adobe Flash Player issues
MSRCTeam
Today we released Security Advisory 2755801 that addresses vulnerabilities in Adobe Flash Player in Internet Explorer 10 on Windows 8. The majority of customers have automatic updates enabled and will not need to take any action because protections will be downloaded and installed automatically. Customers...
on
21 Sep 2012
Blog Post:
Additional information about Internet Explorer and Security Advisory 2757760
MSRCTeam
We will release a Fix it in the next few days to address an issue in Internet Explorer, as outlined in the Security Advisory 2757760 that we released yesterday. While we have only seen a few attempts to exploit the issue, impacting an extremely limited number of people, we are taking this proactive...
on
18 Sep 2012
Blog Post:
Microsoft Releases Security Advisory 2757760
MSRCTeam
Today we released Security Advisory 2757760 to address an issue that affects Internet Explorer 9 and earlier versions if a user views a website hosting malicious code. Internet Explorer 10 is not affected. We have received reports of only a small number of targeted attacks and are working to develop...
on
17 Sep 2012
Blog Post:
August 2012 Bulletin Release
MSRCTeam
Security Advisory 2661254 - Update For Minimum Certificate Key Length Before we get into the details of this month’s bulletin release, let’s take a look at an important change on how Windows deals with certificates that have RSA keys of less than 1024 bits in length. We’ve been talking...
on
14 Aug 2012
Blog Post:
Security Advisory 2737111 released
MSRCTeam
Hello – Today we published Security Advisory 2737111, which provides mitigations and workarounds that will help protect customers from a known vulnerability in one of Oracle’s Outside In libraries, which were updated earlier this month. Microsoft licenses the libraries from Oracle and...
on
24 Jul 2012
Blog Post:
Further insight into Security Advisory 2719615
MSRCTeam
During our regular Update Tuesday bulletin cycle this week, we released Security Advisory 2719615 , which provides guidance concerning a remote code execution issue affecting MSXML Code Services. As part of that Advisory, we've built a Fix it workaround that blocks the potential attack vector in Internet...
on
13 Jun 2012
Blog Post:
Microsoft security updates and the Common Vulnerability Reporting Framework
MSRCTeam
As a part of the Industry Consortium for Advancement of Security on the Internet (ICASI), Microsoft is pleased to present an initial set of monthly security updates – originally released on May 8 – in the consortium’s newly established Common Vulnerability Reporting Framework (CVRF...
on
17 May 2012
Blog Post:
Microsoft releases Security Advisory 2639658
MSRCTeam
Hi everyone, Today we released Security Advisory 2639568 to provide customer guidance for the Windows kernel issue related to the Duqu malware. I would like to provide you information on how to protect your system(s), how we are addressing the issue, and insight into our threat landscape monitoring...
on
3 Nov 2011
Blog Post:
Microsoft releases Security Advisory 2588513
MSRCTeam
Hello. Today we released Security Advisory 2588513 , addressing an information-disclosure issue in SSL (Secure Sockets Layer) 3.0 and TLS (Transport Layer Security) 1.0 to provide guidance for customers. This is an industry-wide issue with limited impact that affects the Internet ecosystem as a whole...
on
26 Sep 2011
Blog Post:
Microsoft Releases Security Advisory 2524375
MSRCTeam
Hello - Today we're releasing Security Advisory 2524375 , to address nine fraudulent digital certificates issued by Comodo Group Inc, a root certificate authority. Comodo has since revoked the digital certificates. This is not a Microsoft security vulnerability; however, one of the certificates potentially...
on
23 Mar 2011
Blog Post:
Advance Notification Service for the March 2011 Security Bulletin Release
MSRCTeam
Hello all -- Today, as part of our usual monthly bulletin cadence, we are providing our Advance Notification Service for March's security bulletins. This month we'll release three bulletins, one of them rated Critical and two rated Important, addressing issues in Microsoft Windows and Office. We'll...
on
3 Mar 2011
Blog Post:
Advance Notification Service for the February 2011 Security Bulletin Release
MSRCTeam
Hello all - Today, as part of our usual monthly bulletin cadence, we are providing our Advance Notification Service for February's security bulletins. This month, we'll release 12 bulletins, three of them rated Critical and nine rated Important, addressing issues in Microsoft Windows, Internet Explorer...
on
3 Feb 2011
Blog Post:
Microsoft releases Security Advisory 2490606
MSRCTeam
Hello - Today we released Security Advisory 2490606 , which addresses a publicly disclosed vulnerability affecting Microsoft Windows Graphics Rendering Engine on Vista, Server 2003, and Windows XP. We are not aware of any affected customers, nor of any active attacks targeting customers. The vulnerability...
on
4 Jan 2011
Blog Post:
Microsoft Releases Security Advisory 2458511
MSRCTeam
Hi everyone, Today we released Security Advisory 2458511 to address a new vulnerability that could impact Internet Explorer users if they visit a website hosting malicious code. As of now, the impact of this vulnerability is extremely limited and we are not aware of any affected customers. The exploit...
on
2 Nov 2010
Blog Post:
Security Advisory 2416728 - Workaround Update
MSRCTeam
Hi everyone - We've updated Microsoft Security Advisory 2416728 to include a step in the workaround requiring the blocking of requests that specify the application error path on the querystring. This can be done using URLScan, a free tool for Internet Information Services (IIS) that can selectively...
on
24 Sep 2010
Blog Post:
Update to Security Advisory 2416728
MSRCTeam
Hi everyone - We've just updated Microsoft Security Advisory 2416728 as we've begun to see limited attacks with the ASP.NET vulnerability. We have added questions and answers and encourage customers to review this information and evaluate it for their environment. We have also added additional...
on
20 Sep 2010
Page 1 of 2 (28 items)
1
2