The Microsoft Security Response Center (MSRC)

Working to help protect customers from vulnerabilities in Microsoft software

Browse by Tags

  • Blog Post: Microsoft security updates and the Common Vulnerability Reporting Framework

    As a part of the Industry Consortium for Advancement of Security on the Internet (ICASI), Microsoft is pleased to present an initial set of monthly security updates – originally released on May 8 – in the consortium’s newly established Common Vulnerability Reporting Framework (CVRF...
  • Blog Post: Advanced Notification for out-of-band release to address Security Advisory 2659883

    Hello, Today we’re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in Security Advisory 2659883 . The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST. The bulletin has a severity rating of Critical...
  • Blog Post: Microsoft releases Security Advisory 2641690, updates Untrusted Certificate Store

    Hi everyone, As a follow-up to Friday’s blog post , today we released Security Advisory 2641690 to notify customers that we revoked the trust of DigiCert Sdn.Bhd in an update that moves two Intermediate Certificate Authorities (CA) certificates to the Microsoft Untrusted Certificate Store. ...
  • Blog Post: Microsoft releases Security Advisory 2639658

    Hi everyone, Today we released Security Advisory 2639568 to provide customer guidance for the Windows kernel issue related to the Duqu malware. I would like to provide you information on how to protect your system(s), how we are addressing the issue, and insight into our threat landscape monitoring...
  • Blog Post: Microsoft releases Security Advisory 2588513

    Hello. Today we released Security Advisory 2588513 , addressing an information-disclosure issue in SSL (Secure Sockets Layer) 3.0 and TLS (Transport Layer Security) 1.0 to provide guidance for customers. This is an industry-wide issue with limited impact that affects the Internet ecosystem as a whole...
  • Blog Post: Advance Notification Service for the February 2011 Security Bulletin Release

    Hello all - Today, as part of our usual monthly bulletin cadence, we are providing our Advance Notification Service for February's security bulletins. This month, we'll release 12 bulletins, three of them rated Critical and nine rated Important, addressing issues in Microsoft Windows, Internet Explorer...
  • Blog Post: Microsoft releases Security Advisory 2501696

    Hello. Today we're releasing Security Advisory 2501696 , which describes a publicly disclosed scripting vulnerability affecting all versions of Microsoft Windows. The main impact of the vulnerability is unintended information disclosure. We're aware of published information and proof-of-concept...
  • Blog Post: Microsoft Releases Security Advisory 2488013

    Hello, Today we released Security Advisory 2488013 to address a public vulnerability that could affect customers using Internet Explorer 6, 7 and 8 if they visit a website hosting malicious code. Currently the impact of this vulnerability is limited and we are not aware of any affected customers or...
  • Blog Post: December 2010 Advance Notification Service is released

    Hi everyone. Mike Reavey from the MSRC here. Today we're releasing our Advance Notification Service for the December 2010 security bulletin release. As we do every month, we've given information about the coming December release and provided links to detailed information so you can plan your deployment...
  • Blog Post: Microsoft Releases Security Advisory 2458511

    Hi everyone, Today we released Security Advisory 2458511 to address a new vulnerability that could impact Internet Explorer users if they visit a website hosting malicious code. As of now, the impact of this vulnerability is extremely limited and we are not aware of any affected customers. The exploit...
  • Blog Post: Q&A from the September 2010 Out-of-Band Security Release webcast

    Hello, Below you will find the webcast we conducted earlier this week as part of the MS10-070 Security Update which was released Out-of-Band. We have also published the questions and answers from that webcast and linked them here . The response for this webcast was amazing; however, due to time...
  • Blog Post: Update to Security Advisory 2416728

    Hi everyone - We've just updated Microsoft Security Advisory 2416728 as we've begun to see limited attacks with the ASP.NET vulnerability. We have added questions and answers and encourage customers to review this information and evaluate it for their environment. We have also added additional...
  • Blog Post: Security Advisory 2416728 Released

    Hi everyone, Today we released Security Advisory 2416728 describing a publicly disclosed vulnerability in ASP.NET that affects all versions of the .NET Framework. At this time we are not aware of any attacks using this vulnerability and we encourage customers to review the advisory for mitigations...
  • Blog Post: September 2010 Security Bulletin Release

    Hi everyone, With this month's bulletin release, I want to highlight the great work done through our partnerships in the Microsoft Active Protections Program (MAPP). MAPP represents our commitment to community based defense and a shared sense of responsibility to help protect the computing ecosystem...
  • Blog Post: Update on Security Advisory 2269637

    Hi everyone, Since we released Security Advisory 2269637 on August 23, we've continued to conduct an investigation not only into our own affected products, but also into how we can best help to protect customers given DLL preloading also affects some third-party applications. We'd like to provide...
  • Blog Post: August 2010 Webcast and QA

    Hello, Today we published the Questions & Answers from the August 2010 Security Bulleting webcast . We answered a total of 17 questions concerning the March bulletins and open Security Advisories. No particular themes emerged from the questions but there were some good ones so please review them...
  • Blog Post: Security Advisory 2286198 Updated

    We've just updated Microsoft Security Advisory 2286198 to let customers know that we now have an automated "Fix It" available to implement the workaround we first outlined in our original posting on Friday, July 16, 2010. More information is available in the KB article 2286198 , but in summary running...
  • Blog Post: July 2010 Security Bulletin Release

    Hi everyone. As part of our usual monthly update cycle, today Microsoft is releasing four security bulletins to address five vulnerabilities in Windows and Microsoft Office. MS10-042 resolves a publicly disclosed and actively exploited vulnerability discussed in Security Advisory 2219475 . The update...
  • Blog Post: Security Advisory 2219475 Released

    Hello - We have released Security Advisory 2219475 , addressing the vulnerability in the Windows Help and Support Center function in Windows XP and Windows Server 2003. We are not aware of any active attacks at this time. Customers running Windows Vista, Windows 7, Windows Server 2008 and Windows...
  • Blog Post: Windows Help Vulnerability Disclosure

    Hello, We are aware of a publicly disclosed vulnerability affecting Windows XP and Windows Server 2003. We are not aware of any current exploitation of this issue and customers running Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2, are not vulnerable to this issue, or at...
  • Blog Post: June 2010 Security Bulletin Release

    Hi everyone, Today, as part of our regular monthly security bulletin release cycle, we released 10 bulletins to address 34 total vulnerabilities in Windows, Microsoft Office (including SharePoint), Internet Explorer (IE), Internet Information Services (IIS), and the .NET Framework. Only three of these...
  • Blog Post: Security Advisory 983438 Released

    Hello. Today we released Security Advisory 983438 , addressing a cross-site scripting (XSS) vulnerability in SharePoint Server 2007 and SharePoint Services 3.0 that could allow Elevation of Privilege (EoP) within the SharePoint site itself. Servers are at reduced risk from Internet Explorer 8 clients...
  • Blog Post: April 2010 Bulletin Release Advance Notification

    Hi everyone, Our ANS (Advance Notification Service) went out today informing customers that next Tuesday we will release 11 bulletins addressing 25 vulnerabilities in Windows, Microsoft Office, and Microsoft Exchange. We recommend that customers review the ANS summary page and prepare to test and...
  • Blog Post: Out-of-Band Security Bulletin Webcast Q&A - March 30, 2010

    Hosts: Adrian Stone, Senior Security Program Manager Lead Jerry Bryant, Group Manager, Response Communications Website: TechNet/security Chat Topic: March 2010 Out-of-Band Security Bulletin Date: Tuesday, March 30, 2010 Q: CVE-2010-0483 , like CVE-2010-0806 , is a remote code executable...
  • Blog Post: Security Bulletin MS10-018 Released

    Hi everyone, Today we released MS10-018 out-of-band due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in Security Advisory 981374 . I want to reiterate that Internet Explorer 8 is not affected by this issue so customers using this version...
Page 1 of 3 (53 items) 123