<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MSRC</title><link>http://blogs.technet.com/b/msrc/</link><description /><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Microsoft security updates and the Common Vulnerability Reporting Framework</title><link>http://blogs.technet.com/b/msrc/archive/2012/05/17/microsoft-security-updates-and-the-common-vulnerability-reporting-framework.aspx</link><pubDate>Thu, 17 May 2012 22:09:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3498570</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;As a part of the Industry Consortium for Advancement of Security on the Internet (ICASI), Microsoft is pleased to present an initial set of monthly security updates &amp;ndash; originally released on May 8 &amp;ndash; in the consortium&amp;rsquo;s newly established Common Vulnerability Reporting Framework (CVRF) format, &lt;a href="https://connect.microsoft.com/"&gt;for your examination and feedback&lt;/a&gt;. Today, ICASI released version 1.1 of its CVRF &amp;ndash; a markup system designed to make security bulletins and advisories machine readable in an industry-standard fashion.&lt;/p&gt;
&lt;p&gt;Even though many vendors have followed Microsoft&amp;rsquo;s lead in providing comprehensive security updates to customers, the formats vendors use vary. CVRF provides the entire industry with a way to share and present data in a coordinated and structured manner.&lt;/p&gt;
&lt;p&gt;CVRF is free for anyone to examine and use. The goal is to build a data-markup framework that can be used by anyone publishing or examining security update information on the Internet.&lt;/p&gt;
&lt;p&gt;CVRF is a work in process. For many customers, a machine-readable markup framework for security releases might not be a pressing need. For instance, home-computer users or small businesses may choose to install security updates automatically. However, many business customers spend time &amp;ldquo;copying and pasting&amp;rdquo; our security bulletin content into their risk management systems, spreadsheets and corporate notification emails manually as part of their IT security compliance and remediation task list.&lt;/p&gt;
&lt;p&gt;For these customers, this machine-readable format may enable more efficiency and automation. Faster and more efficient guidance for these customers means they can more quickly ensure protection, which is always our goal. For those that do not require automation, we will continue to offer our bulletins in the current format. For those customers looking to automate and streamline their security-management process, or for those who are simply curious to see what happens when vendors from around the industry roll up their sleeves and work to make the update process better, visit the Connect portal to read more about CVRF, and to examine CVRF-formatted bulletins. Visit &lt;a href="https://connect.microsoft.com/"&gt;https://connect.microsoft.com/&lt;/a&gt;&amp;nbsp;and click SIGN IN in the upper right-hand corner to sign in with your Windows Live ID. Once you are signed in and are looking at the home page, use the invitation code &amp;ldquo;cvrf-9BK8-6W2T&amp;rdquo; (without quotes) to join the program, or visit &lt;a href="https://connect.microsoft.com/site1098/InvitationUse.aspx?ProgramID=7665&amp;amp;InvitationID=cvrf-9BK8-6W2T"&gt;https://connect.microsoft.com/site1098/InvitationUse.aspx?ProgramID=7665&amp;amp;InvitationID=cvrf-9BK8-6W2T&lt;/a&gt; directly.&lt;/p&gt;
&lt;p&gt;Your feedback will be relayed to the ICASI working group of which Microsoft is a member. Together we&amp;rsquo;ll continue to make CVRF a truly robust, collaborative standard throughout the Internet ecosystem.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Update:&lt;/b&gt; If you would like to find out more information about the CVRF standard, please join the CVRF working group webinar on Tuesday, 30 May at noon EDT. They will provide an overview of CVRF v1.1 and showcase the improvements in this latest revision. You can register at &lt;a href="http://register.webcastgroup.com/L4/?wid=0557685978"&gt;http://register.webcastgroup.com/L4/?wid=0557685978&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Mike Reavey &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Senior Director, MSRC&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3498570" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update/">Security Update</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/monthly+bulletin+release/">monthly bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/vulnerability/">vulnerability</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/advisory/">advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security+bulletin+release/">security bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Update+Tuesday/">Update Tuesday</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>May 2012 Security Bulletin Webcast, Slide Deck, and Q&amp;A</title><link>http://blogs.technet.com/b/msrc/archive/2012/05/11/may-2012-security-bulletin-webcast-slide-deck-and-q-amp-a.aspx</link><pubDate>Fri, 11 May 2012 19:33:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3497542</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/may-2012-security-bulletin-q-a.aspx"&gt; May Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;, and the &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71-Slide_5F00_Decks/7220.May-2012-Security-Bulletin-Webcast-_2D00_-Final-_2D00_-Customer-Ready.pptx"&gt;May 2012 Security Bulletin Release Webcast slide deck&lt;/a&gt;. During the webcast, we fielded 8 questions on various topics, including bulletins released, deployment tools, and update detection tools.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, June 13 at 11am PDT (UTC -7), when we will go into detail about the June bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, June 13, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499671&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADEAYgA0AGUAMAAxADUANQAtADIAMgA1ADIALQA0ADQAZgAxAC0AYQBmADkAYgAtADYAZAAwAGEANwBhADAANgBmADkANgA2ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQAxAGIANABlADAAMQA1ADUALQAyADIANQAyAC0ANAA0AGYAMQAtAGEAZgA5AGIALQA2AGQAMABhADcAYQAwADYAZgA5ADYANgAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=1b4e0155-2252-44f1-af9b-6d0a7a06f966,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=1b4e0155-2252-44f1-af9b-6d0a7a06f966,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Yunsun Wee&lt;br /&gt; Director&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3497542" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Update+Tuesday/">Update Tuesday</category></item><item><title>Bulletin Management Process and the May 2012 Bulletins</title><link>http://blogs.technet.com/b/msrc/archive/2012/05/08/bulletin-management-process-and-the-may-2012-bulletins.aspx</link><pubDate>Tue, 08 May 2012 17:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3496751</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Have you ever wondered why bulletins group particular issues together? Or one set of products and not another? Well today Jonathan Ness has posted an insightful &lt;a href="http://blogs.technet.com/b/srd/"&gt;Security Research &amp;amp; Defense (SRD) blog&lt;/a&gt; discussing some of the nuances and packaging decisions that went into MS12-034. This is a particularly interesting case to dive into and will give readers a better appreciation for the bulletin management process here at Microsoft.&lt;/p&gt;
&lt;p&gt;For Update Tuesday we&amp;rsquo;re releasing seven security bulletins &amp;ndash; three Critical-class and four Important &amp;ndash; addressing 23 issues in Microsoft Windows, Office, Silverlight, and the .NET Framework. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing on the following two critical updates first:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;MS12-034 (Microsoft Office, Windows, .NET Framework, and Silverlight)&lt;/b&gt;: This security update addresses 10 issues affecting a cross section from Microsoft Windows , Office, Silverlight, and the Microsoft .NET Framework. The maximum severity for these issues is Critical and could result in remote code execution. To ensure protection all updates from this bulletin must be applied. We recommend that customers read through the bulletin information concerning MS12-034 and apply it as soon as possible.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;MS12-029 (Microsoft Word)&lt;/b&gt;: This security update addresses one Critical issue affecting Microsoft Office that could result in remote code execution. Attack vectors for this issue include maliciously crafted websites and email. We recommend that customers read through the bulletin information concerning MS12-029 and apply it as soon as possible.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Please watch the video below for details about this month's bulletins:&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADkAYQA0ADMAMQBlADAANAAtADMAMgBmADkALQA0ADcAZABlAC0AYQBiADMAZgAtAGQAMQBjADQAYwBjAGUANgA1ADcANQA1ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA5AGEANAAzADEAZQAwADQALQAzADIAZgA5AC0ANAA3AGQAZQAtAGEAYgAzAGYALQBkADEAYwA0AGMAYwBlADYANQA3ADUANQAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=9a431e04-32f9-47de-ab3f-d1c4cce65755,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=9a431e04-32f9-47de-ab3f-d1c4cce65755,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/2112.20120508_5F00_Deployment_5F00_Priority_5F00_Slide.PNG"&gt; &lt;img alt="Deployment Priority" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/2112.20120508_5F00_Deployment_5F00_Priority_5F00_Slide.PNG" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/2671.20120508_5F00_Exploitability_5F00_Index_5F00_Slide.PNG"&gt; &lt;img alt="Exploitability Index" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/2671.20120508_5F00_Exploitability_5F00_Index_5F00_Slide.PNG" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can find more information about this month's security updates on the &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may"&gt;Microsoft Security Bulletin Summary web page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Per our usual process, we&amp;rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Dustin Childs. I invite you to tune in and learn more about the May security bulletins, as well as other announcements made today. The webcast is scheduled for Wednesday, May 9, at 11 A.M. PDT. &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499667&amp;amp;Culture=en-US"&gt;Click here to register.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Yunsun Wee&lt;br /&gt; Director&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3496751" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Update+Tuesday/">Update Tuesday</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>MAPP Update: Taking Action to Decrease Risk of Information Disclosure</title><link>http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx</link><pubDate>Thu, 03 May 2012 17:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3495905</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;During our investigation into the disclosure of confidential data shared with our Microsoft Active Protections Program (MAPP) partners, we determined that a member of the MAPP program, Hangzhou DPTech Technologies Co., Ltd., had breached our non-disclosure agreement (NDA). Microsoft takes breaches of our NDAs very seriously and has removed this partner from the MAPP Program.&lt;/p&gt;
&lt;p&gt;Additionally, starting with our May release, we strengthened existing controls and took actions to better protect our information. We believe that these enhancements will better protect our information, while furthering customer protection by aiding partners developing active protections. For an in-depth look at how MAPP provides a critical head-start to defenders, while working to minimize risk, please read &lt;a href="http://blogs.technet.com/b/ecostrat/archive/2012/05/03/inside-the-mapp-program.aspx"&gt;this blog&lt;/a&gt; by the MAPP team.&lt;/p&gt;
&lt;p&gt;Yunsun Wee &lt;br /&gt; Director &lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3495905" width="1" height="1"&gt;</description></item><item><title>Advanced Notification Service for May 2012 Security Bulletin Release</title><link>http://blogs.technet.com/b/msrc/archive/2012/05/03/advanced-notification-service-for-may-2012-security-bulletin-release.aspx</link><pubDate>Thu, 03 May 2012 17:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3495900</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we&amp;rsquo;re releasing our &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may"&gt;advance notification&lt;/a&gt; for the May security bulletin release, which is scheduled for Tuesday, May 8. This month&amp;rsquo;s release includes 7 bulletins addressing 23 vulnerabilities in Microsoft Windows, Office, Silverlight, and .NET Framework. All 7 bulletins will be released on Tuesday, May 8 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.&lt;/p&gt;
&lt;p&gt;As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.&lt;/p&gt;
&lt;p&gt;Please join Dustin Childs and Pete Voss for a public webcast on Wednesday. They&amp;rsquo;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Date:&lt;/b&gt; Wednesday, May 9, 2012 &lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499667&amp;amp;Culture=en-US"&gt;Click Here To Register&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Yunsun Wee &lt;br /&gt; Director &lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3495900" width="1" height="1"&gt;</description></item><item><title>April 2012 Security Bulletin Webcast and Q&amp;A</title><link>http://blogs.technet.com/b/msrc/archive/2012/04/13/april-2012-security-bulletin-webcast-and-q-amp-a.aspx</link><pubDate>Fri, 13 Apr 2012 21:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3492129</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/april-2012-security-bulletin-q-a.aspx"&gt; April Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;,&amp;nbsp;and the &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71-Slide_5F00_Decks/8867.April-2012_5F00_Security_5F00_Bulletin_5F00_Webcast.pptx"&gt;slide deck&lt;/a&gt; presented in the webcast. We fielded 15 questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, May 9 at 11am PDT (UTC -7), when we will go into detail about the May bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, May 9, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499667&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADgAYwAwADAAYwBiAGMAOAAtADYAYQAzADUALQA0ADIANwA0AC0AOABhAGEAMQAtADEAMQBmAGUAZAA2ADUANgAwAGYANwBiACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA4AGMAMAAwAGMAYgBjADgALQA2AGEAMwA1AC0ANAAyADcANAAtADgAYQBhADEALQAxADEAZgBlAGQANgA1ADYAMABmADcAYgAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=8c00cbc8-6a35-4274-8aa1-11fed6560f7b,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=8c00cbc8-6a35-4274-8aa1-11fed6560f7b,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Pete Voss&lt;br /&gt; Senior Response Communications Manager&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3492129" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Update+Tuesday/">Update Tuesday</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Customer+Questions/">Customer Questions</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>Windows XP and Office 2003 countdown to end of support, and the April 2012 bulletins</title><link>http://blogs.technet.com/b/msrc/archive/2012/04/10/windows-xp-and-office-2003-countdown-to-end-of-support-and-the-april-2012-bulletins.aspx</link><pubDate>Tue, 10 Apr 2012 17:02:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3491308</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;As you know, today is Update Tuesday. Before I go into the bulletin details, however, I wanted to let you know that today we&amp;rsquo;re notifying customers that &lt;a href="http://windowsteamblog.com/windows/b/business/archive/2012/04/09/upgrade-today-two-year-countdown-to-end-of-support-for-windows-xp-and-office-2003.aspx"&gt;Windows XP and Office 2003 will go out of support in April 2014&lt;/a&gt;.&amp;nbsp;We understand that&amp;nbsp;preparing to deploy the latest versions of Windows and Office may take time for some organizations, and we encourage all customers to upgrade to the latest operating system to help protect your systems.&lt;/p&gt;
&lt;p&gt;Now, on to the updates. If you&amp;rsquo;re running Automatic Updates you&amp;rsquo;re automatically protected from the issues addressed this month, and for those of you who test and deploy your updates, we&amp;rsquo;ve offered some details and guidance below.&lt;/p&gt;
&lt;p&gt;As I previously mentioned in the &lt;a href="http://blogs.technet.com/b/msrc/archive/2012/04/05/advance-notification-service-for-april-2012-security-bulletin-release.aspx"&gt;Advance Notification Service blog post&lt;/a&gt; on Thursday, today we are releasing six security bulletins, four of which are rated Critical in severity, and two Important.&lt;/p&gt;
&lt;p&gt;These bulletins will increase protection by addressing 11 CVEs. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on these Critical updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;MS12-027 (Windows Common Controls)&lt;/b&gt;: This security update resolves a CVE in the MSCOMCTL.OCX ActiveX control, which could allow remote code execution if a user visits a website containing specially crafted content designed to exploit the vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;MS12-023 (Internet Explorer)&lt;/b&gt;: This security update resolves five CVEs in Internet Explorer, which could allow a third party to gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In the video below, Yunsun Wee discusses this month's bulletins in further detail.&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADAAZgAxADAANgBhADEAYQAtADAAOQA1ADUALQA0ADQAYQA4AC0AYQA0ADYANwAtAGQAMAA1AGQAMAAyAGMAYgBjADUAZQA0ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQAwAGYAMQAwADYAYQAxAGEALQAwADkANQA1AC0ANAA0AGEAOAAtAGEANAA2ADcALQBkADAANQBkADAAMgBjAGIAYwA1AGUANAAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=0f106a1a-0955-44a8-a467-d05d02cbc5e4,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=0f106a1a-0955-44a8-a467-d05d02cbc5e4,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/7220.April-2012-Overview-Slides_5F00_Dep_5F00_Prio.png"&gt; &lt;img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/7220.April-2012-Overview-Slides_5F00_Dep_5F00_Prio.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8715.April-2012-Overview-Slides_5F00_Sev_5F00_XI.png"&gt; &lt;img alt="Deployment Priority" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8715.April-2012-Overview-Slides_5F00_Sev_5F00_XI.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can find more information about this month's security updates on the Microsoft Security Bulletin Summary web page.&lt;/p&gt;
&lt;p&gt;Jonathan Ness from the MSRC will join me Wednesday for a webcast. Please tune in and learn more about the April security bulletins, as well as other announcements made today. The webcast is scheduled for Wednesday, April 11, at 11 A.M. PDT. &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499650&amp;amp;Culture=en-US"&gt;Click here to register.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Pete Voss&lt;br /&gt; Sr. Response Communications Manager&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3491308" width="1" height="1"&gt;</description></item><item><title>Advance Notification Service for April 2012 security bulletin release</title><link>http://blogs.technet.com/b/msrc/archive/2012/04/05/advance-notification-service-for-april-2012-security-bulletin-release.aspx</link><pubDate>Thu, 05 Apr 2012 17:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3490571</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we&amp;rsquo;re releasing our &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr"&gt;advance notification&lt;/a&gt; for the April security bulletin release, which is scheduled for Tuesday, April 10. This month&amp;rsquo;s release includes 6 bulletins addressing&amp;nbsp;11 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Forefront UAG, and .NET Framework. All 6 bulletins will be released on Tuesday, April 10 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.&lt;/p&gt;
&lt;p&gt;As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.&lt;/p&gt;
&lt;p&gt;Jonathan Ness will join me for a public webcast on Wednesday. During the webcast, we will go into detail about the bulletins and answer questions live on the air. See below for registration information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Date:&lt;/b&gt; Wednesday, April 11, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499650&amp;amp;Culture=en-US"&gt;Click Here To Register&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Pete Voss &lt;br /&gt; Sr. Response Communications Manager&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3490571" width="1" height="1"&gt;</description></item><item><title>BlueHat Prize: And now the fun begins</title><link>http://blogs.technet.com/b/msrc/archive/2012/04/03/bluehat-prize-and-now-the-fun-begins.aspx</link><pubDate>Wed, 04 Apr 2012 01:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3490202</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;The entry window for the first annual BlueHat Prize closed at 11:59pm PDT on April 1. We've been eagerly awaiting a final entry count from the contest organizers, and senior security strategist Katie Moussouris has just &lt;a href="http://blogs.technet.com/b/ecostrat/archive/2012/04/04/bluehat-prize-entries-the-final-tally-is.aspx"&gt;posted that tally&lt;/a&gt; on the EcoStrat blog. Congratulations to all participants and good luck to the BlueHat Prize Board, which finds itself eyebrow-deep in exciting new defensive-security ideas as the competition judging process begins.&lt;/p&gt;
&lt;p&gt;Angela Gunn&lt;br /&gt;Trustworthy Computing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3490202" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/BlueHat+Prize/">BlueHat Prize</category></item><item><title>6...5...4...3...2...</title><link>http://blogs.technet.com/b/msrc/archive/2012/03/26/6-5-4-3-2.aspx</link><pubDate>Mon, 26 Mar 2012 19:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3488663</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Nearly nine months after we announced the first annual &lt;a href="http://www.bluehatprize.com/"&gt;BlueHat Prize&lt;/a&gt; competition for innovations in defensive security technologies, we&amp;rsquo;re just days away from the submission deadline. On the &lt;a href="http://blogs.technet.com/b/ecostrat/archive/2012/03/26/peace-games-bluehat-prize-update-and-countdown.aspx"&gt;EcoStrat blog&lt;/a&gt; today, Senior Security Strategist Katie Moussouris gives a glimpse into the frantic final days of the competition period. If you&amp;rsquo;re working on your own entry (deadline April 1!) or simply wondering how the race for &amp;ldquo;mad loot&amp;rdquo; is shaping up, be sure to check out her post.&lt;/p&gt;
&lt;p&gt;Angela Gunn&lt;br /&gt;Trustworthy Computing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3488663" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/BlueHat+Prize/">BlueHat Prize</category></item><item><title>March 2012 Security Bulletin Webcast and Q&amp;A </title><link>http://blogs.technet.com/b/msrc/archive/2012/03/16/march-2012-security-bulletin-webcast-and-q-amp-a.aspx</link><pubDate>Fri, 16 Mar 2012 23:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3487198</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/march-2012-security-bulletin-q-a.aspx"&gt; March Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;. During the webcast, we fielded twelve questions focusing on &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020"&gt;MS12-020&lt;/a&gt; (aka &amp;ldquo;the RDP update&amp;rdquo;). Two additional questions for &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-022"&gt;MS12-022&lt;/a&gt; regarding Microsoft Expression Design were answered after the webcast. All questions are included on the Q&amp;amp;A page.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, April 11, 2012 at 11am PDT (UTC -7), when we will go into detail about the April bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, April 11, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499650&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGMAZAAxADQAMgA4AGUANwAtADkAMAA0ADgALQA0AGUAMwAzAC0AYgBmAGIAOQAtADIAZAA0AGYAOAAwADgAZQA1AGQAZgBlACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQBjAGQAMQA0ADIAOABlADcALQA5ADAANAA4AC0ANABlADMAMwAtAGIAZgBiADkALQAyAGQANABmADgAMAA4AGUANQBkAGYAZQAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=cd1428e7-9048-4e33-bfb9-2d4f808e5dfe,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=cd1428e7-9048-4e33-bfb9-2d4f808e5dfe,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3487198" width="1" height="1"&gt;</description></item><item><title>Proof-of-Concept Code available for MS12-020</title><link>http://blogs.technet.com/b/msrc/archive/2012/03/16/proof-of-concept-code-available-for-ms12-020.aspx</link><pubDate>Fri, 16 Mar 2012 20:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3487174</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;On March 15, we became aware of public proof-of-concept code that results in denial of service for the issue addressed by&amp;nbsp;&lt;a title="http://technet.microsoft.com/en-us/security/bulletin/ms12-020" href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020"&gt;MS12-020&lt;/a&gt;, which we released Tuesday.&lt;/p&gt;
&lt;p&gt;We continue to watch the threat landscape and we are not aware of public proof-of-concept code that results in remote code execution.&lt;/p&gt;
&lt;p&gt;We recommend customers deploy MS12-020 as soon as possible, as this security update protects against attempts to exploit CVE-2012-0002. Additionally we have offered a &lt;a href="http://blogs.technet.com/b/srd/archive/2012/03/13/cve-2012-0002-a-closer-look-at-ms12-020-s-critical-issue.aspx"&gt;one-click Fix It&lt;/a&gt; to help mitigate risk for those customers who need time to test the update before deploying it.&lt;/p&gt;
&lt;p&gt;The details of the proof-of-concept code appear to match the vulnerability information shared with Microsoft Active Protections Program (MAPP) partners. Microsoft is actively investigating the disclosure of these details and will take the necessary actions to protect customers and ensure that confidential information we share is protected pursuant to our contracts and program requirements.&lt;/p&gt;
&lt;p&gt;Customers who have deployed MS12-020 are protected from attempts to exploit CVE-2012-0002.&lt;/p&gt;
&lt;p&gt;Consistent with the charter of the MAPP program, we released details related to the vulnerabilities addressed in MS12-020 to MAPP partners under a strict Non-Disclosure Agreement in advance of releasing the security bulletin. Security software partners use this type of information to build enhanced customer protections that, in many cases, provide customers with more time to make optimal deployment decisions for their environments. More information about the MAPP program can be found here: &lt;a title="http://www.microsoft.com/security/msrc/whatwedo/securitycollaboration.aspx" href="http://www.microsoft.com/security/msrc/whatwedo/securitycollaboration.aspx"&gt;http://www.microsoft.com/security/msrc/whatwedo/securitycollaboration.aspx&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt;Yunsun Wee&lt;br /&gt;Director, Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3487174" width="1" height="1"&gt;</description></item><item><title>Strength, flexibility and the March 2012 security bulletins</title><link>http://blogs.technet.com/b/msrc/archive/2012/03/13/strength-flexibility-and-the-march-2012-security-bulletins.aspx</link><pubDate>Tue, 13 Mar 2012 16:48:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3486444</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello. Today we&amp;rsquo;re releasing six security bulletins &amp;ndash; one Critical-class, four Important and one Moderate &amp;ndash; addressing seven issues in Microsoft Windows, Visual Studio, and Expression Design. We recommend that customers focus on MS12-020, our sole critical-class bulletin, as the March deployment priority. A little about MS12-020:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;MS12-020 (Windows)&lt;/b&gt;: This bulletin addresses one Critical-class issue and one Moderate-class issue in Remote Desktop Protocol (RDP). Both issues were cooperatively disclosed to Microsoft and we know of no active exploitation in the wild. The Critical-class issue applies to a fairly specific subset of systems &amp;ndash; those running RDP &amp;ndash; and is less problematic for those systems with Network Level Authentication (NLA) enabled. That said, we strongly recommend that customers examine and prepare to apply this bulletin as soon as possible. The Critical-class issue could allow a would-be attacker to achieve remote code execution on a machine running RDP (a non-default configuration); if the machine does not have NLA enabled, the attacker would not require authentication for RCE access.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We understand that our customers need time to evaluate and test all bulletins before applying them. To provide for a bit of scheduling flexibility, we&amp;rsquo;re offering a one-click, no-reboot Fix it that enables Network-Level Authentication, an effective mitigation for this issue. It applies to Vista, Server 2008, Win7 and Server 2008R2 systems, and you can read all about it &lt;a href="http://blogs.technet.com/b/srd/archive/2012/03/13/cve-2012-0002-a-closer-look-at-ms12-020-s-critical-issue.aspx"&gt;on the SRD blog&lt;/a&gt;. We&amp;rsquo;re pleased that the circumstances around this issue -- well-understood, not under active attack, easy-to-apply mitigation &amp;ndash; give us the chance to provide both strength and flexibility as customers go about their update routines.&lt;/p&gt;
&lt;p&gt;In the video below, Yunsun Wee discusses this month's bulletins, including MS12-020, in further detail.&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADEAYwBjAGYAYgAzAGMAYgAtADQAYwBmADYALQA0ADAAOAAyAC0AYQBjAGMANQAtADgANwBlAGYAMAA0ADEANgA2AGEANQA2ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQAxAGMAYwBmAGIAMwBjAGIALQA0AGMAZgA2AC0ANAAwADgAMgAtAGEAYwBjADUALQA4ADcAZQBmADAANAAxADYANgBhADUANgAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=1ccfb3cb-4cf6-4082-acc5-87ef04166a56,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=1ccfb3cb-4cf6-4082-acc5-87ef04166a56,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Below is this month&amp;rsquo;s deployment priority guidance, to further assist customers in their deployment planning (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5734.March-2012-Deployment-2.png"&gt; &lt;img alt="Deployment Priority" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/5734.March-2012-Deployment-2.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Our risk and impact graph shows an aggregate view of March&amp;rsquo;s severity and exploitability index (click for larger view). Note that MS12-019&amp;nbsp;does not receive an XI rating.&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4705.March-2012-Server_2D00_XI-1.png"&gt; &lt;img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4705.March-2012-Server_2D00_XI-1.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can find more information about this month's security updates on the Microsoft Security Bulletin Summary web page.&lt;/p&gt;
&lt;p&gt;Per our usual process we&amp;rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Dustin Childs. They&amp;rsquo;ll talk through the March bulletins, discuss changes on the horizon for Technet, and answer any further questions about the NLA Fix it. The webcast is scheduled for tomorrow, March 14, 2012, at 11 a.m. PDT. &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499508&amp;amp;culture=en-us"&gt;Click here to register&lt;/a&gt;, and as always we look forward to taking your questions live during the webcast.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3486444" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update/">Security Update</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security+bulletin+release/">security bulletin release</category></item><item><title>March 2012 ANS</title><link>http://blogs.technet.com/b/msrc/archive/2012/03/08/march-2012-ans.aspx</link><pubDate>Thu, 08 Mar 2012 18:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3485542</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello. Today we&amp;rsquo;re releasing our &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar"&gt;advance notification&lt;/a&gt; for the March security bulletin release, which is scheduled for Tuesday, March 13. This month&amp;rsquo;s release includes six bulletins addressing seven vulnerabilities in Microsoft Windows, Visual Studio, and Expression Design. As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ll release all six bulletins on Tuesday, March 13 at approximately 10 a.m. PDT. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.&lt;/p&gt;
&lt;p&gt;On Wednesday, please join Dustin Childs and Pete Voss for our regular bulletin-overview webcast. They&amp;rsquo;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Date:&lt;/b&gt; Wednesday, March 14&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -7)&lt;br /&gt; &lt;b&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499508&amp;amp;culture=en-us"&gt;Click Here To Register&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn &lt;br /&gt; Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3485542" width="1" height="1"&gt;</description></item><item><title>February 2012 Security Bulletin Webcast and Q&amp;A</title><link>http://blogs.technet.com/b/msrc/archive/2012/02/17/february-2012-security-bulletin-webcast-and-q-amp-a.aspx</link><pubDate>Fri, 17 Feb 2012 18:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3481634</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/february-2012-security-bulletin-q-a.aspx"&gt; February Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;. We fielded ten questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools. Many of the questions centered on the .Net/Silverlight update &lt;a href="http://blogs.technet.com/b/msrc/p/february-2012-security-bulletin-q-a.aspx"&gt;MS12-016&lt;/a&gt;. &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71-Slide_5F00_Decks/5736.February_5F00_2012_5F00_Security_5F00_Bulletin_5F00_Webcast.pptx"&gt;Click here&lt;/a&gt; to access the slide deck that appears in the webcast.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, March 14 at 11am PST (UTC -7), when we will go into detail about the March bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, March 14, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PST (UTC -7)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499508&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGMAYQBhADQANwBkADAANwAtAGEAMAAyAGEALQA0AGYAYwA2AC0AOAA2ADMAYQAtADAAMgAxADkAZQBmAGMANAAxADEAZQA0ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQBjAGEAYQA0ADcAZAAwADcALQBhADAAMgBhAC0ANABmAGMANgAtADgANgAzAGEALQAwADIAMQA5AGUAZgBjADQAMQAxAGUANAAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=caa47d07-a02a-4fc6-863a-0219efc411e4,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=caa47d07-a02a-4fc6-863a-0219efc411e4,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3481634" width="1" height="1"&gt;</description></item><item><title>MSRC looks back at ten years, and the February 2012 bulletins</title><link>http://blogs.technet.com/b/msrc/archive/2012/02/14/msrc-looks-back-at-ten-years-and-the-february-2012-bulletins.aspx</link><pubDate>Tue, 14 Feb 2012 18:05:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3480903</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Ever wondered where Update Tuesday bulletins come from, or what it&amp;rsquo;s like around Microsoft when a serious information-security situation arises? Or wondered who precisely is responsible for getting your monthly bulletin releases out the door?&lt;/p&gt;
&lt;p&gt;Update Tuesday, which brings us here today, is one of the most prominent results of that famous Bill Gates memo that put security at the center of Microsoft&amp;rsquo;s development and support efforts -- just over 10 years ago. We Trustworthy Computing folk tend to look more to the future than to the past, but on the 10-year anniversary a few of us sat down to talk about incident response, the security ecosystem, and how Microsoft collaborates with the industry:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MSRC senior security program manager &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=e4e900e5-40b6-4d1d-9a7c-f48acf2bbcb9"&gt;Dustin Childs&lt;/a&gt; explains why, in MSRC, &amp;ldquo;the second-Tuesday cycle is what we live for&amp;rdquo; and gives a glimpse at how the Microsoft response process handled MS08-067 &amp;ndash; the case that became Conficker.&lt;/li&gt;
&lt;li&gt;MSRC senior director &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=e0e1c74e-83b6-4fa1-942f-d4d95633eaaf"&gt;Mike Reavey&lt;/a&gt; on never making the same hard decision twice in incident response.&lt;/li&gt;
&lt;li&gt;MSRC security program manager &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=bdeee68c-174d-405b-a318-a9a0c47a1356"&gt;Leigh Honeywell &lt;/a&gt;on coming to Microsoft from the open-source community and becoming an Internet firefighter.&lt;/li&gt;
&lt;li&gt;EcoStrat senior security strategist &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=63f124aa-58b1-405e-a4b3-a6c2981b5846"&gt;Katie Moussouris&lt;/a&gt; on the crucial need to reach out to researchers, and the process of convincing Microsoft to pay out a quarter of a million dollars in the BlueHat Prize.&lt;/li&gt;
&lt;li&gt;EcoStrat senior security manager &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=6b14aebc-1765-43d6-8c94-d7d897b4b2c0"&gt;Maarten van Horenbeeck&lt;/a&gt; on how keeping trusted industry partners in the loop on bulletins and advisories protects the entire ecosystem&amp;hellip;quietly.&lt;/li&gt;
&lt;li&gt;And, for a look at how we appear to a longtime observer, we set up a Skype chat with tech evangelist &lt;a href="http://www.microsoft.com/en-us/showcase/details.aspx?uuid=b3995313-24d9-4f34-b2f7-2b3cb1e20253"&gt;Ryan Naraine&lt;/a&gt; to get his perspective on how our process affects the broader ecosystem.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Meanwhile, as I previously mentioned in the &lt;a href="http://blogs.technet.com/b/msrc/archive/2012/02/09/ans-for-february-2012-and-some-notes-on-sdl.aspx"&gt;Advance Notification Service blog post&lt;/a&gt; on Thursday, today we are releasing nine security bulletins. Four of those are rated Critical in severity, with the remaining five classified as Important.&lt;/p&gt;
&lt;p&gt;The bulletins will address 21 vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on two critical updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;MS12-010 (Internet Explorer)&lt;/b&gt;: Cumulative Security Update for Internet Explorer. This bulletin addresses two Critical, one Important and one Moderate issues affecting all versions of Internet Explorer. The most severe of these could allow for remote code execution, if an attacker were to convince a user to visit a maliciously constructed Web page. All of these issues were cooperatively disclosed to Microsoft, and we know of no active exploitation in the wild. We recommend that customers read through the bulletin information concerning MS12-010 and apply it as soon as possible.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;MS12-013 (C Runtime Library)&lt;/b&gt;: Vulnerabilities in C Run-Time Library Could Allow Remote Code Execution. This bulletin addresses an issue that could arise if a would-be attacker sent a malicious media file to a targeted user, or convinced the user to visit a Web page hosting such a file. The issue was cooperatively disclosed to Microsoft, and we know of no active exploitation in the wild. As with MS12-010, though, we recommend that customers read through the bulletin information and apply it as soon as possible.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In this video, Yunsun Wee discusses this month's bulletins in further detail.&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADEAZABhAGEAOQBhADYAYwAtAGEAZAAyADUALQA0AGYANwAzAC0AYQAxAGMAZgAtADAANAA4ADEAMwBlADAAOABiADUAZgA0ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQAxAGQAYQBhADkAYQA2AGMALQBhAGQAMgA1AC0ANABmADcAMwAtAGEAMQBjAGYALQAwADQAOAAxADMAZQAwADgAYgA1AGYANAAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=1daa9a6c-ad25-4f73-a1cf-04813e08b5f4,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=1daa9a6c-ad25-4f73-a1cf-04813e08b5f4,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Below is this month&amp;rsquo;s deployment priority guidance, to further assist customers in their deployment planning (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/6646.February-2012-Deployment.png"&gt; &lt;img alt="Deployment Priority" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/6646.February-2012-Deployment.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Our risk and impact graph shows an aggregate view of February&amp;rsquo;s severity and exploitability index (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/1134.February-2012-XI.png"&gt; &lt;img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/1134.February-2012-XI.png" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can find more information about this month's security updates on the &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb"&gt;Microsoft Security Bulletin Summary web page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As usual, our colleagues in SRD have prepared blog posts that delve more deeply into technical aspects of this month&amp;rsquo;s releases. In addition to a chart delving into &lt;a href="http://blogs.technet.com/b/srd/archive/2012/02/14/assessing-risk-for-the-february-2012-security-updates.aspx"&gt;this month&amp;rsquo;s deployment priorities&lt;/a&gt;, SRD unpacks &lt;a href="http://blogs.technet.com/b/srd/archive/2012/02/14/ms12-013-more-information-about-the-msvcrt-dll-issue.aspx"&gt;the details&lt;/a&gt; of MS12-013 and takes a &lt;a href="http://blogs.technet.com/b/srd/archive/2012/02/14/ms12-014-indeo-a-blast-from-the-past.aspx"&gt;longer look&lt;/a&gt; at MS12-014, which touches Indeo &amp;ndash; a multimedia codec predating no small percentage of the people reading this sentence.&lt;/p&gt;
&lt;p&gt;Per our usual process we&amp;rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Jonathan Ness. They&amp;rsquo;ll talk over the February bulletins, discuss changes on the horizon for Technet, and answer some questions we&amp;rsquo;ve been receiving about the support lifecycle for Vista. The webcast is scheduled for tomorrow, February 15, 2012, at 11 A.M. PST. &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499501&amp;amp;culture=en-us"&gt;Click here to register&lt;/a&gt;, and as always we look forward to taking your questions live during the webcast.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing.&lt;/p&gt;
&lt;script type="text/javascript" src="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx/&amp;rdquo;http:/technet.microsoft.com/en-us/videoembed/update-tuesday-overview&amp;rdquo;"&gt;&lt;/script&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3480903" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update/">Security Update</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/monthly+bulletin+release/">monthly bulletin release</category></item><item><title>ANS for February 2012, and some notes on SDL</title><link>http://blogs.technet.com/b/msrc/archive/2012/02/09/ans-for-february-2012-and-some-notes-on-sdl.aspx</link><pubDate>Thu, 09 Feb 2012 18:03:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3479986</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello. Today we&amp;rsquo;re releasing our &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb"&gt;advance notification&lt;/a&gt; for the February security bulletin release, which is scheduled for Tuesday, February 14. This month&amp;rsquo;s release includes nine bulletins addressing 21 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and .NET/Silverlight. As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ll release all nine bulletins on Tuesday, February 14 at approximately 10 a.m. PST. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.&lt;/p&gt;
&lt;p&gt;Here at MSRC we know that over the years, information on Microsoft&amp;rsquo;s Security Development Lifecycle system has been downloaded over 850,000 times so far. (Happy coding, everyone!) As part of our look back over the first ten years of Trustworthy Computing, our friends in the SDL program &lt;a href="http://blogs.msdn.com/b/sdl/archive/2012/01/12/trustworthy-computing-s-10-year-milestone-reflecting-on-humble-beginnings.aspx"&gt;caught up with&lt;/a&gt; Steve Lipner, our senior director of security engineering strategy, and asked him how his team made &lt;a href="http://www.microsoft.com/Presspass/Features/2012/jan12/GatesMemo.mspx"&gt;that famous Bill Gates memo&lt;/a&gt; the law of the land at Microsoft. Of course, the SDL is a living process and continues to change and grow. For information on what&amp;rsquo;s ahead, including news about our brand-new Security Development Conference, take a look at &amp;lt;&amp;gt;a href="http://blogs.technet.com/b/security/archive/2012/02/01/security-development-lifecycle-a-living-process.aspx"?Tim Rains&amp;rsquo; post on the Security Blog. Perhaps some of us will see you in DC in May?&lt;/p&gt;
&lt;p&gt;In the meantime, please join Jonathan Ness and Pete Voss for our regular webcast on Wednesday. They&amp;rsquo;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Date:&lt;/b&gt; Wednesday, February 15&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PST (UTC -8)&lt;br /&gt; &lt;b&gt;&lt;a href="https://msevents.microsoft.com/cui/EventDetail.aspx?EventID=1032499501&amp;amp;culture=en-US"&gt;Click Here To Register&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn &lt;br /&gt; Trustworthy Computing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3479986" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/ANS/">ANS</category></item><item><title>January 2012 Security Bulletin Webcast Q&amp;A</title><link>http://blogs.technet.com/b/msrc/archive/2012/01/12/january-2012-security-bulletin-webcast-q-amp-a.aspx</link><pubDate>Fri, 13 Jan 2012 00:49:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475246</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/january-2012-security-bulletin-q-a.aspx"&gt; January Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;. We fielded nine questions on various topics during the &lt;a href="http://technet.microsoft.com/en-us/edge/january-2012-security-bulletin-webcasts"&gt;webcast&lt;/a&gt;, including bulletins released, deployment tools, and update detection tools. There were two questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&amp;amp;A page. &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71-Slide_5F00_Decks/2630.January_5F00_2012_5F00_Security_5F00_Bulletin_5F00_Webcast.pptx"&gt;Click here&lt;/a&gt; to access the slide deck that&amp;nbsp;appears in the webcast.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, February 15 at 11am PST (UTC -8), when we will go into detail about the February bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, February 15, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PST (UTC -8)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499501&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADUANAA0AGYAMQA5AGIANAAtADQAMABlADYALQA0ADAAYQBhAC0AOQBlAGMAMgAtADAANwA0ADQAYQA3ADQAOQA4AGEANgA3ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA1ADQANABmADEAOQBiADQALQA0ADAAZQA2AC0ANAAwAGEAYQAtADkAZQBjADIALQAwADcANAA0AGEANwA0ADkAOABhADYANwAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=544f19b4-40e6-40aa-9ec2-0744a7498a67,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=544f19b4-40e6-40aa-9ec2-0744a7498a67,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475246" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin+Webcast/">Security Bulletin Webcast</category></item><item><title>January 2012 Security Bulletins Released</title><link>http://blogs.technet.com/b/msrc/archive/2012/01/10/january-2012-security-bulletins-released.aspx</link><pubDate>Tue, 10 Jan 2012 18:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474774</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello. As I previously mentioned in the &lt;a href="http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx"&gt;Advance Notification Service blog post&lt;/a&gt; on Thursday, today we are releasing seven security bulletins, one of which is rated Critical in severity, with the remaining six classified as Important.&lt;/p&gt;
&lt;p&gt;These bulletins will address eight vulnerabilities in Microsoft products. Customers should plan to install all of these updates as soon as possible. For those who must prioritize deployment, we recommend focusing first on the sole critical update:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;MS12-004 (Windows Media Player)&lt;/b&gt;: Vulnerabilities in Windows Media Player Could Cause Remote Code Execution. This bulletin &amp;ndash; the only one in January&amp;rsquo;s set to include multiple CVEs &amp;ndash; addresses two issues that could arise if a would-be attacker sent a malicious MIDI or DirectShow file to a targeted user. Both of these issues were cooperatively disclosed to Microsoft, and we know of no active exploitation in the wild. Still, we recommend that customers read through the bulletin information concerning MS12-004 and apply it as soon as possible.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In the video below, Pete Voss discusses this month's bulletins in further detail.&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADcAYQBkAGEAYgBjAGMAZAAtADEANQBlADkALQA0AGMAMQA1AC0AYQA5ADAANAAtAGMAYgA0AGIANwBiAGQAMgAxADkANwBkACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA3AGEAZABhAGIAYwBjAGQALQAxADUAZQA5AC0ANABjADEANQAtAGEAOQAwADQALQBjAGIANABiADcAYgBkADIAMQA5ADcAZAAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=7adabccd-15e9-4c15-a904-cb4b7bd2197d,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=7adabccd-15e9-4c15-a904-cb4b7bd2197d,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;As always, we recommend that customers deploy all security updates as soon as possible. Below is our deployment priority guidance to further assist customers in their deployment planning (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG"&gt; &lt;img alt="Deployment Priority" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4527.20120110_5F00_Deployment_5F00_Priority.PNG" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Our risk and impact graph shows an aggregate view of this month's severity and exploitability index (click for larger view).&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;&lt;span class="style1"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG"&gt; &lt;img alt="Exploitability Index" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/4048.20120110_5F00_Severity_5F00_and_5F00_XI.PNG" width="500" height="281" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can find more information about this month's security updates on the &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan"&gt;Microsoft Security Bulletin Summary web page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As you may remember, last month we announced a bulletin addressing the SSL issue we described in Security Advisory 2588513. Days before release, we noted a compatibility problem that might have affected certain users of third-party products, and decided to hold that bulletin until we could complete further investigation. We&amp;rsquo;re-releasing that bulletin today as MS12-006; we&amp;rsquo;re also providing further information and guidance to customers with a Knowledge Base article and a Fix-it that will be useful in certain installation circumstances.&lt;/p&gt;
&lt;p&gt;As usual, our colleagues in SRD have prepared blog posts that delve more deeply into technical details of this month&amp;rsquo;s releases. In addition to a discussion of this month&amp;rsquo;s deployment priorities, SRD has a post examining some of the finer points of MS12-001, which addresses an Important-class issue affecting the SafeSEH security mitigation, and an overview of the aforementioned MS12-004.&lt;/p&gt;
&lt;p&gt;Per our usual process, we&amp;rsquo;ll offer the monthly technical webcast on Wednesday, hosted by Pete Voss and Dustin Childs. I invite you to tune in and learn more about the January security bulletins, as well as other announcements made today. The webcast is scheduled for tomorrow, January 11, 2012, at 11 A.M. PST. &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;amp;Culture=en-US"&gt;Click here to register.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn&lt;br /&gt; Trustworthy Computing.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474774" width="1" height="1"&gt;</description></item><item><title>January 2012 ANS is released</title><link>http://blogs.technet.com/b/msrc/archive/2012/01/05/january-12-ans-is-released.aspx</link><pubDate>Thu, 05 Jan 2012 17:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474114</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello. Today we&amp;rsquo;re releasing our &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan"&gt;advance notification&lt;/a&gt; for the January security bulletin release, which is scheduled for Tuesday, January 10. This month&amp;rsquo;s release includes seven bulletins addressing eight vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software. As always, we recommend that customers review the ANS summary page for more information and prepare for the testing and deployment of these bulletins as soon as possible.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ll release all seven bulletins on Tuesday, January 10 at approximately 10 a.m. PST. Revisit this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.&lt;/p&gt;
&lt;p&gt;In addition, eagle-eyed readers of the summary page will notice an unusual vulnerability classification, &amp;ldquo;Security Feature Bypass,&amp;rdquo; for one of our Important-severity bulletins. SFB-class issues in themselves can&amp;rsquo;t be leveraged by an attacker; rather, a would-be attacker would use them to facilitate use of another exploit. For those interested in learning more, we expect the SRD blog to publish a detailed analysis of the matter on Tuesday.&lt;/p&gt;
&lt;p&gt;Please join Dustin Childs and Pete Voss for a webcast on Wednesday. They&amp;rsquo;ll go into detail about the bulletins and answer questions live on the air. See below for registration information.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Date:&lt;/b&gt; Wednesday, January 11&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PST (UTC -8)&lt;br /&gt; &lt;b&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;amp;Culture=en-US"&gt;Click Here To Register&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Angela Gunn &lt;br /&gt; Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474114" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/ANS/">ANS</category></item><item><title>December 2011 Out-Of-Band Bulletin Release: Q&amp;A and Webcast</title><link>http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-bulletin-release-q-amp-a-and-webcast.aspx</link><pubDate>Fri, 30 Dec 2011 23:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3473499</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/p/december-2011-oob-security-bulletin-q-a.aspx"&gt; December 2011 Out-of-Band Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;. We fielded 41 questions on the subject of &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"&gt;MS11-100 &lt;/a&gt;. There were four questions during the webcast that we were unable to answer and we have included those questions and answers on the Q&amp;amp;A page.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast scheduled for Wednesday, January 11, 2012 at 11 a.m. PST (UTC -8), when we will go into detail about the January 2012 bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, January 11, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PDT (UTC -8)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Pete Voss&lt;br /&gt; Sr. Response Communications Manager&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;
&lt;script type="text/javascript" src="http://technet.microsoft.com/en-us/videoembed/out-of-band-security-bulletin-webcast"&gt;&lt;/script&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3473499" width="1" height="1"&gt;</description></item><item><title>Microsoft releases MS11-100 for Security Advisory 2659883</title><link>http://blogs.technet.com/b/msrc/archive/2011/12/29/microsoft-releases-ms11-100-for-security-advisory-2659883.aspx</link><pubDate>Thu, 29 Dec 2011 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3473283</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we released Security Update &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100"&gt;MS11-100&lt;/a&gt; to address the issue described in &lt;a href="http://technet.microsoft.com/en-us/security/advisory/2659883"&gt;Security Advisory 2659883&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The security update has a severity rating of Critical and resolves a publicly disclosed remote unauthenticated Denial of Service issue in ASP.NET versions 1.1 and above on all supported versions of .NET Framework. Of note, the new method of hash collision attacks used to exploit this vulnerability is an industry-wide issue affecting various Web platforms, including ASP.NET.&lt;/p&gt;
&lt;p&gt;While we have seen no attacks attempting to exploit this vulnerability, we encourage affected customers to test and deploy the update as soon as possible. Consumers are not vulnerable unless they are running a Web server from their computer. More technical details can be found at the &lt;a href="http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx"&gt;Security Research &amp;amp; Defense Blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For all the latest information, you can also follow the MSRC team on Twitter at &lt;a href="http://www.twitter.com/msftsecresponse"&gt;@MSFTSecResponse&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Dave Forstrom&lt;br /&gt; Director&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3473283" width="1" height="1"&gt;</description></item><item><title> Advanced Notification for out-of-band release to address Security Advisory 2659883</title><link>http://blogs.technet.com/b/msrc/archive/2011/12/28/advanced-notification-for-out-of-band-release-to-address-security-advisory-2659883.aspx</link><pubDate>Thu, 29 Dec 2011 03:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3473183</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Hello,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Today we&amp;rsquo;re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in &lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/advisory/2659883"&gt;&lt;span style="color: #0000ff; font-family: Calibri; font-size: small;" size="3" face="Calibri" color="#0000ff"&gt;Security Advisory 2659883&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;.&lt;/span&gt;&lt;/span&gt; The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;The bulletin has a severity rating of Critical and addresses a publicly disclosed vulnerability in ASP.NET that affects all versions of the .NET Framework. While we&amp;rsquo;re currently unaware of any attacks targeting ASP.NET, we encourage all customers to test and deploy the update when it is available. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;We will also hold a special edition webcast on Thursday, December 29 at 1 p.m. PST. Click &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032502798&amp;amp;Culture=en-US" target="_blank"&gt;here&lt;/a&gt; to register.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;" size="3" face="Calibri"&gt;For all the latest information, you can also follow the MSRC team on Twitter at &lt;/span&gt;&lt;a href="https://twitter.com/#!/msftsecresponse"&gt;&lt;span style="color: #0000ff; font-family: Calibri; font-size: small;" size="3" face="Calibri" color="#0000ff"&gt;@MSFTSecResponse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri; font-size: small;" size="3" face="Calibri"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Thanks,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Dave Forstrom&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Director&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="3"&gt;&lt;span style="font-family: Calibri;" face="Calibri"&gt;Microsoft Trustworthy Computing&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3473183" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/OOB/">OOB</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/ANS/">ANS</category></item><item><title>Microsoft releases Security Advisory 2659883, offers workaround for industry-wide issue</title><link>http://blogs.technet.com/b/msrc/archive/2011/12/28/microsoft-releases-security-advisory-2659883-offers-workaround-for-industry-wide-issue.aspx</link><pubDate>Wed, 28 Dec 2011 12:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3473097</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published &lt;a href="http://technet.microsoft.com/en-us/security/advisory/2659883"&gt;Security Advisory 2659883&lt;/a&gt; to provide a workaround to help protect ASP.NET customers from a publicly disclosed vulnerability that affects various Web platforms industry-wide. We are not aware of any attacks using this vulnerability, which affects all supported versions of .NET Framework, however we recommend customers use the mitigation and workaround described in the Advisory to help protect sites against this new method to exploit hash tables.&lt;/p&gt;
&lt;p&gt;Our teams are working around the clock worldwide to develop a security update of appropriate quality to address this issue. Meanwhile, our Security Research &amp;amp; Defense team has written&lt;a href="http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx"&gt; a blog post&lt;/a&gt; to explain how to know if you are vulnerable and detect exploitation, as well as background on the workaround. We are also working closely with our &lt;a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx"&gt;Microsoft Active Protections Program (MAPP)&lt;/a&gt; to help our partners build protections when and where possible. We will continue to update customers with new information as it becomes available.&lt;/p&gt;
&lt;p&gt;For all the latest information, you can also follow the MSRC team on Twitter at &lt;a href="https://twitter.com/#!/msftsecresponse"&gt;@MSFTSecResponse.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Dave Forstrom&lt;br /&gt; Director&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3473097" width="1" height="1"&gt;</description></item><item><title>December 2011 Bulletin Release Q&amp;A and Slide Deck</title><link>http://blogs.technet.com/b/msrc/archive/2011/12/19/december-2011-bulletin-release-q-amp-a-and-slide-deck.aspx</link><pubDate>Mon, 19 Dec 2011 18:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3472029</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Today we published the &lt;a href="http://blogs.technet.com/b/msrc/archive/2011/12/15/december-2011-security-bulletin-webcast-q-amp-a.aspx"&gt; December Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/a&gt;. We fielded six questions on various topics during the webcast, including bulletins released, deployment tools, and update detection tools.&lt;/p&gt;
&lt;p&gt;For more details on this month&amp;rsquo;s bulletins, click here to &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/3058.December-2011-Webcast-Deck_5F00_FINAL.pptx"&gt;view the slide deck&lt;/a&gt; used in the webcast. See below to view the webcast.&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA5xsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGMANAA3AGMAMwA2ADIAMQAtAGEAMQBlADYALQA0ADAANQAyAC0AOABhAGQAZAAtADAAZgA0AGUANABhADYAOQA2AGYANgA5ACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQBjADQANwBjADMANgAyADEALQBhADEAZQA2AC0ANAAwADUAMgAtADgAYQBkAGQALQAwAGYANABlADQAYQA2ADkANgBmADYAOQAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" width="480" type="application/x-silverlight-2" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=c47c3621-a1e6-4052-8add-0f4e4a696f69,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=c47c3621-a1e6-4052-8add-0f4e4a696f69,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, January 11, 2012 at 11am PST (UTC -8), when we will go into detail about the January bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend at the link below:&lt;br /&gt; &lt;b&gt;Date:&lt;/b&gt; Wednesday, January 11, 2012&lt;br /&gt; &lt;b&gt;Time:&lt;/b&gt; 11:00 a.m. PST (UTC -8)&lt;br /&gt; &lt;b&gt;Register:&lt;/b&gt; &lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032499498&amp;amp;Culture=en-US"&gt;Attendee Registration&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt; Jerry Bryant&lt;br /&gt; Group Manager, Response Communications&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3472029" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast+Q_2600_amp_3B00_A/">Webcast Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Q_2600_amp_3B00_A/">Q&amp;amp;A</category></item></channel></rss>
