Sign in
MSRC
Tags
ActiveX
advisory
announcements
ANS
Attack
Attack Vector
Autorun
BlueHat Prize
bulletin
Bulletins
Customer Questions
CVD
Defense-in-depth
Emerging Threat
Exploitability
Exploitability Index
IIS
Internet Explorer (IE)
Killbit
Malicious Software (Malware)
Malicious Software Removal Tool (MSRT)
Microsoft Active Protections Program (MAPP)
Microsoft Office
Microsoft Windows
Mitigations
monthly bulletin release
news
november
office
OOB
Pages
Q&A
Responsible Disclosure
Risk Assessment
security
Security Advisory
Security Bulletin
security bulletin release
security bulletin release forefront powerpoint office
Security Bulletin Webcast
Security Bulletins
Security Development Lifecycle (SDL)
Security Update
Security Update Webcast
Security Update Webcast Q & A
Security Update Webcast Q &
September out of band
UAG
Update Tuesday
video
Virus
vulnerability
Webcast
Webcast Q&A
Webcast Q&
Workarounds
Zero-Day Exploit
Browse by Tags
TechNet Blogs
>
MSRC
>
All Tags
>
risk assessment
Tagged Content List
Blog Post:
Announcing the Microsoft Security Update Guide, Second Edition
MSRCTeam
Hi all -- We're pleased to announce the release of the new Microsoft Security Update Guide, Second Edition . Fully revised and updated from the first edition, which was released in 2009, this edition focuses on best practices for prioritizing and testing security updates before deployment within your...
on
4 Apr 2011
Blog Post:
June 2010 Security Bulletin Release
MSRCTeam
Hi everyone, Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these...
on
8 Jun 2010
Blog Post:
Security Advisory 983438 Released
MSRCTeam
Hello. Today we released Security Advisory 983438 , addressing a cross-site scripting (XSS) vulnerability in SharePoint Server 2007 and SharePoint Services 3.0 that could allow Elevation of Privilege (EoP) within the SharePoint site itself. Servers are at reduced risk from Internet Explorer 8 clients...
on
29 Apr 2010
Blog Post:
Update on MS10-025
MSRCTeam
I wanted to give customers an update on the status of MS10-025 . First, I want to reiterate that this issue affects only Windows 2000 Servers in a non-default configuration: Windows Media Services needs to be installed. Customers who do not have Windows Media Services installed are not affected and were...
on
23 Apr 2010
Blog Post:
MS10-025 Security Update to be Re-released
MSRCTeam
Hi, MS10-025 is a security update that only affects Windows 2000 Server customers who have installed Windows Media Services (this is a non-default configuration). Today we pulled the update because we found it does not address the underlying issue effectively. We are not aware of any active attacks...
on
21 Apr 2010
Blog Post:
Guidance on Internet Explorer XSS Filter
MSRCTeam
The XSS Filter related Blackhat EU presentation discussed a vulnerability that was previously disclosed and addressed in the January security update to Internet Explorer ( MS10-002 ). This attack scenario involved modified HTTP responses, enabling XSS on sites that would not otherwise be vulnerable....
on
19 Apr 2010
Blog Post:
Security Advisory 979352 – Going out of Band
MSRCTeam
We wanted to provide a quick update on the threat landscape and announce that we will release a security update out-of-band to help protect customers from this vulnerability. Based on our comprehensive monitoring of the threat landscape we continue to see very limited, and in some cases, targeted...
on
19 Jan 2010
Blog Post:
January 2010 Security Bulletin Release
MSRCTeam
Summary of Microsoft’s Security Bulletin Release for January 2010 Hi Everyone, We hope that 2010 is off to a good start for you. For our first bulletin release of the New Year, we have one Critical bulletin affecting all versions of Windows. The bulletin, MS10-001 , addresses one vulnerability in the...
on
12 Jan 2010
Blog Post:
New Reports of a Vulnerability in IIS
MSRCTeam
Hi everyone, On Dec. 23 we were made aware of a new claim of a vulnerability in Internet Information Services (IIS). We are still investigating this issue and are not aware of any active attacks but wanted to let customers know that our initial assessment shows that the IIS web server must be in a non...
on
27 Dec 2009
Blog Post:
November 2009 Security Bulletin Release
MSRCTeam
Summary of Microsoft’s Security Bulletin Release for November 2009 Today, we released six security bulletins addressing a total of 15 vulnerabilities. Four affect Windows and Windows Server and two affect Microsoft Office products (Excel and Word). As we do every month, we have prepared our Risk &...
on
10 Nov 2009
Blog Post:
October 2009 Security Bulletin Release
MSRCTeam
Summary of Microsoft’s Security Bulletin Release for October 2009 This month, we released 13 new bulletins which address 33 vulnerabilities in Windows, Internet Explorer and Microsoft Office. Since we published this information in our advance notification (ANS) last Thursday, we have been asked “is this...
on
13 Oct 2009
Blog Post:
August 2009 Bulletin Release
MSRCTeam
Summary of Microsoft’s Security Bulletin Release for August 2009 Hi everyone, This month, we released nine security bulletins. Five of those are rated Critical and four have an aggregate severity rating of Important. Of the nine updates, eight affect Windows and the last one affects Office Web Components...
on
11 Aug 2009
Page 1 of 1 (12 items)