<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MSRC</title><link>http://blogs.technet.com/b/msrc/</link><description /><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>June 2013 Security Bulletin Webcast, Q&amp;A, and Slide Deck</title><link>http://blogs.technet.com/b/msrc/archive/2013/06/14/june-2013-security-bulletin-webcast-q-amp-a-and-slide-deck.aspx</link><pubDate>Fri, 14 Jun 2013 22:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3579028</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Today we&amp;rsquo;re publishing the &lt;a href="http://blogs.technet.com/b/msrc/p/june-2013-security-bulletin-q-a.aspx"&gt;&lt;span style="color: #0000ff;"&gt;June 2013 Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/span&gt;&lt;/a&gt;.&amp;nbsp; We fielded three questions during the webcast, with specific questions focusing primarily on Windows Print Spooler (&lt;a href="http://technet.microsoft.com/security/bulletin/ms13-050"&gt;&lt;span style="color: #0000ff;"&gt;MS13-050&lt;/span&gt;&lt;/a&gt;), Microsoft Office (&lt;a href="http://technet.microsoft.com/security/bulletin/ms13-051"&gt;&lt;span style="color: #0000ff;"&gt;MS13-051&lt;/span&gt;&lt;/a&gt;), and the security advisory addressing digital certificates (&lt;a href="http://technet.microsoft.com/security/advisory/2854544"&gt;&lt;span style="color: #0000ff;"&gt;SA2854544&lt;/span&gt;&lt;/a&gt;). There was one question we were unable to field on the air which we&amp;nbsp;answered on the Q&amp;amp;A page.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, July 10, 2013, at 11 a.m. PDT (UTC -7), when we will go into detail about the July bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend the webcast at the link below:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date: Wednesday, July 10, 2013&lt;br /&gt; Time: 11:00 a.m. PDT (UTC -7) &lt;br /&gt; Register: &lt;/strong&gt;&lt;strong&gt;TBD &lt;/strong&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACYMQAA7BsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADUAZgAzAGIAZQAyADMAZAAtADQAZQA5ADcALQA0AGIAOABmAC0AOQA4AGMANAAtADYANABiADQANgBiAGIAYQBiAGIAZgBiACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA1AGYAMwBiAGUAMgAzAGQALQA0AGUAOQA3AC0ANABiADgAZgAtADkAOABjADQALQA2ADQAYgA0ADYAYgBiAGEAYgBiAGYAYgAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" type="application/x-silverlight-2" width="480" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=5f3be23d-4e97-4b8f-98c4-64b46bbabbfb,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=5f3be23d-4e97-4b8f-98c4-64b46bbabbfb,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0000ff;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;br /&gt; Group Manager, Response Communications&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3579028" width="1" height="1"&gt;</description><enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-03-57-90-28/June-2013-Security-Bulletin-Webcast-_2D00_-FINAL-_2D00_-Customer-Ready.pptx" length="1869921" type="application/octet-stream" /><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/">Malicious Software Removal Tool (MSRT)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast+Q_2600_amp_3B00_A/">Webcast Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/monthly+bulletin+release/">monthly bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/advisory/">advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/office/">office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security+bulletin+release/">security bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast/">Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Q_2600_amp_3B00_A/">Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin+Webcast/">Security Bulletin Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Customer+Questions/">Customer Questions</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>Improved cryptography infrastructure and the June 2013 bulletins</title><link>http://blogs.technet.com/b/msrc/archive/2013/06/11/improved-cryptography-and-the-june-2013-bulletins.aspx</link><pubDate>Tue, 11 Jun 2013 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3577548</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-size: small;"&gt;It was just over one year ago, May 28, 2012, to be exact, that I transitioned from running active MSRC cases and writing bulletins to my current role managing software security incidents. A lot has changed in that year&lt;em&gt; - &lt;/em&gt;and I&amp;rsquo;ve dealt with some interesting issues during my tenure&lt;em&gt; - &lt;/em&gt;but our goal of providing the best customer protections possible remains a constant. For example, in June 2012, we introduced a new &lt;/span&gt;&lt;a href="http://blogs.technet.com/b/pki/archive/2012/06/12/announcing-the-automated-updater-of-untrustworthy-certificates-and-keys.aspx"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;feature&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; to automatically update the Certificate Trust List (CTL), allowing us to quickly move untrusted or compromised certificates to the CTL without customer interaction. Since this feature works by checking for new updates over the internet, enterprises that filter this type of network traffic are not able to take full advantage of this feature.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Today we are building on that functionality by releasing an update, in the form of &lt;a href="http://technet.microsoft.com/en-us/security/advisory/2854544"&gt;&lt;span style="color: #0563c1;"&gt;Security Advisory 2854544&lt;/span&gt;&lt;/a&gt;, which gives enterprises more options for managing their private public key infrastructure (PKI) environments. This functionality, initially built into Windows 8, Windows Server 2012 and Windows RT, is now available for Windows Vista through Windows 7. Over the coming months, we&amp;rsquo;ll be rolling out additional updates to this advisory&lt;em&gt; - &lt;/em&gt;all aimed at bolstering Windows&amp;rsquo; cryptography and certificate-handling infrastructure. Our efforts here aren&amp;rsquo;t in response to any specific incident; it&amp;rsquo;s the continuing evolution of how we handle digital certificates to ensure the safest possible computing environment for our customers. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Speaking of safer computing, let&amp;rsquo;s talk about the five bulletins we released today - one Critical and four Important, addressing 23 vulnerabilities in Microsoft Windows, Office and Internet Explorer. For those who need to prioritize deployment, we recommend focusing on MS13-047 and MS13-051 first. As always, customers should deploy all security updates as soon as possible. Our Bulletin Deployment Priority guidance is below to further assist in deployment planning (click for larger view). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;MS13-047 | Cumulative Security Update for Internet Explorer&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: small;"&gt;This security update resolves 19 issues in Internet Explorer that could allow remote code execution if a customer views a specially crafted Web page using the browser. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. This security update is rated Critical for all versions of Internet Explorer, on all supported releases of Microsoft Windows. These issues were privately disclosed and we have not detected any attacks or customer impact.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;MS13-051 | Vulnerability in Microsoft Office Could Allow Remote Code Execution&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: small;"&gt;This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Office document using an affected version of Microsoft Office software, or previews or opens a specially crafted email message in Outlook while using Microsoft Word as the email reader. This issue is rated Important for Microsoft Office 2003 and Office for Mac 2011. While details about this issue were privately disclosed, we are aware of limited, targeted attacks that attempt to exploit this vulnerability.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Watch the bulletin overview video below for a brief summary of today&amp;rsquo;s releases.&lt;/span&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA8hsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAL4CAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGYAYwA3ADIAMgA2ADkAZQAtAGUAMQAzAGYALQA0ADYANgAyAC0AYQAzAGYAZgAtADIANwAwADAAMABkADgAOQA2ADMAMQA2AAoALABBAHUAdABvAHAAbABhAHkAPQBGAGEAbABzAGUALABTAGgAbwB3AE0AYQByAGsAZQB0AGkAbgBnAE8AdgBlAHIAbABhAHkAPQB0AHIAdQBlACwATQBpAHMAYwBDAG8AbgB0AHIAbwBsAHMAPQBGAHUAbABsAFMAYwByAGUAZQBuADsARABlAHQAYQBjAGgAZQBkACwAUwBoAG8AdwBNAGUAbgB1AD0AdAByAHUAZQAsAFQAYQBiAHMAPQBFAG0AYgBlAGQAOwBFAG0AYQBpAGwAOwBTAGgAYQByAGUAOwBJAG4AZgBvADsALABTAGgAbwB3AEMAYQBwAHQAaQBvAG4APQBmAGEAbABzAGUALABBAGcAZQBHAGEAdABlAD0AVAByAHUAZQAsAEEAZwBlAEcAYQB0AGUARABhAHkATQBvAG4AdABoAFkAZQBhAHIATwByAGQAZQByAD0ATQBEAFkALABWAGkAZABlAG8AVQByAGwAPQBoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGUAbgAtAHUAcwAvAHMAaABvAHcAYwBhAHMAZQAvAGQAZQB0AGEAaQBsAHMALgBhAHMAcAB4AD8AdQB1AGkAZAA9AGYAYwA3ADIAMgA2ADkAZQAtAGUAMQAzAGYALQA0ADYANgAyAC0AYQAzAGYAZgAtADIANwAwADAAMABkADgAOQA2ADMAMQA2AAoALABNAG8AZABlAD0AUABsAGEAeQBlAHIAAAAAAAAAAAAAAP//AAD//wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" type="application/x-silverlight-2" width="480" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=fc72269e-e13f-4662-a3ff-27000d896316
,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=fc72269e-e13f-4662-a3ff-27000d896316
,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;Our Bulletin Deployment Priority graph provides an overview of this month&amp;rsquo;s priority releases&lt;br /&gt;(click for larger view).&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8080.June-2013-DP-Slide.PNG"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8080.June-2013-DP-Slide.PNG" alt="" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;Our risk and impact graph shows an aggregate view of this month&amp;rsquo;s Severity and Exploitability Index &lt;br /&gt;(click for larger view).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="font-size: small;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/1512.June-2013-XI-and-Severity.PNG"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/1512.June-2013-XI-and-Severity.PNG" alt="" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For more information about this month&amp;rsquo;s security updates, visit the &lt;/span&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-jun"&gt;Microsoft Bulletin Summary Web page&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Andrew Gross and I will host the monthly bulletin webcast, scheduled for Wednesday, June 12, 2013, at 11 a.m. PDT. I invite you to register &lt;/span&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032538733&amp;amp;Culture=en-US"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;, and tune in to learn more about this month&amp;rsquo;s security bulletins and advisories. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For all the latest information, you can also follow the MSRC team on Twitter at &lt;/span&gt;&lt;a href="http://www.twitter.com/msftsecresponse"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;@MSFTSecResponse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;I look forward to hearing your questions about this month&amp;rsquo;s release in our webcast tomorrow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Thank you,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;Group Manager, Response Communications&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; Microsoft Trustworthy Computing&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3577548" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>Advanced Notification Service for the June 2013 Security Bulletin Release</title><link>http://blogs.technet.com/b/msrc/archive/2013/06/06/advanced-notification-service-for-the-june-2013-security-bulletin-release.aspx</link><pubDate>Thu, 06 Jun 2013 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3577021</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-size: small;"&gt;Today we&amp;rsquo;re providing Advance Notification of five bulletins for release on Tuesday, June 11, 2013. This release brings one Critical- and four Important-class bulletins. The Critical-rated bulletin addresses issues in Internet Explorer, and the Important-rated bulletins address issues in Microsoft Windows and Office.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;We will publish the bulletins on the second Tuesday of the month, at approximately 10 a.m. PT. Please revisit this blog at that time for our official risk and impact analysis, along with deployment guidance and a brief video overview of the month&amp;rsquo;s highlights. Until then, you should review the &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-jun"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;ANS Summary Page&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; for more information and prepare for bulletin testing and deployment as soon as possible, to help ensure a smooth update process.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For the latest information, follow the MSRC team on Twitter at &lt;/span&gt;&lt;a href="https://twitter.com/msftsecresponse"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;@MSFTSecResponse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Thank you,&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;Group Manager&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;Microsoft Trustworthy Computing&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3577021" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/ANS/">ANS</category></item><item><title>May 2013 Security Bulletin Webcast, Q&amp;A, and Slide Deck</title><link>http://blogs.technet.com/b/msrc/archive/2013/05/17/may-2013-security-bulletin-webcast-q-amp-a-and-slide-deck.aspx</link><pubDate>Fri, 17 May 2013 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3573411</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;For those who couldn&amp;rsquo;t attend the live webcast, today we&amp;rsquo;re publishing the &lt;a href="http://blogs.technet.com/b/msrc/p/may-2013-security-bulletin-q-a.aspx"&gt;&lt;span style="color: #0000ff;"&gt;May 2013 Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/span&gt;&lt;/a&gt;.&amp;nbsp; We fielded 13 questions on various topics during the webcast, with specific bulletin questions focusing primarily on Internet Explorer (&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-037"&gt;&lt;span style="color: #0000ff;"&gt;MS13-037&lt;/span&gt;&lt;/a&gt; and &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-038"&gt;&lt;span style="color: #0000ff;"&gt;MS13-038&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #0000ff;"&gt;&lt;span style="text-decoration: underline;"&gt;)&lt;/span&gt; &lt;span style="color: #000000;"&gt;and Visio&lt;/span&gt;&lt;/span&gt; (&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-044"&gt;&lt;span style="color: #0000ff;"&gt;MS13-044&lt;/span&gt;&lt;/a&gt;).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, June 12, 2013, at 11 a.m. PDT (UTC -7), when we will go into detail about the June bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend the webcast at the link below:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date: Wednesday, June 12, 2013&lt;br /&gt; Time: 11:00 a.m. PDT (UTC -7) &lt;br /&gt; Register: &lt;/strong&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032538733&amp;amp;Culture=en-US"&gt;&lt;strong&gt;&lt;span style="color: #0000ff;"&gt;Attendee Registration &lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACYMQAA7BsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADgAMwBhAGEANgAyADYANgAtAGEAOQBkAGQALQA0AGIAMgA4AC0AYgA4AGUAYQAtADcAZABhAGEAYgA2AGIAYgA2ADcAZABlACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQA4ADMAYQBhADYAMgA2ADYALQBhADkAZABkAC0ANABiADIAOAAtAGIAOABlAGEALQA3AGQAYQBhAGIANgBiAGIANgA3AGQAZQAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" type="application/x-silverlight-2" width="480" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=83aa6266-a9dd-4b28-b8ea-7daab6bb67de,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=83aa6266-a9dd-4b28-b8ea-7daab6bb67de,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0000ff;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;br /&gt; Group Manager, Response Communications&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3573411" width="1" height="1"&gt;</description><enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-03-57-34-11/May-2013-Security-Bulletin-Webcast-_2D00_-Final-_2D00_-Customer-Ready.pptx" length="1947809" type="application/octet-stream" /><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/">Security Update Webcast Q &amp;amp; A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update+Webcast/">Security Update Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Killbit/">Killbit</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/">Malicious Software Removal Tool (MSRT)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast+Q_2600_amp_3B00_A/">Webcast Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/monthly+bulletin+release/">monthly bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast/">Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Q_2600_amp_3B00_A/">Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin+Webcast/">Security Bulletin Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>Microsoft Customer Protections for May 2013</title><link>http://blogs.technet.com/b/msrc/archive/2013/05/14/microsoft-customer-protections-for-may-2013.aspx</link><pubDate>Tue, 14 May 2013 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3572472</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-size: small;"&gt;Today, we are releasing 10 bulletins, addressing 33 vulnerabilities in Microsoft products. Before we get into the details, we wanted to first let our enterprise customers know about a change in how we&amp;rsquo;re communicating technical details within our security advisories. Starting today, customers will be able to clearly identify key security updates within advisories. For further details, please visit &lt;a href="http://support.microsoft.com/kb/2849195"&gt;Knowledge Base article&amp;nbsp;2849195&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Let&amp;rsquo;s talk about the updates that we released today. Ten bulletins were released, two Critical and eight Important, addressing 33 vulnerabilities in Internet Explorer, Microsoft Windows, Microsoft Office, Server and Tools, and .NET Framework. For those who need to prioritize deployment, we recommend focusing on MS13-037, MS13-038 and MS13-039 first. As always, customers should deploy all security updates as soon as possible. Our Bulletin Deployment Priority guidance is below to further assist in deployment planning (click for larger view).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;MS13-037 | Cumulative Security Update for Internet Explorer&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: small;"&gt;This security update resolves 11 issues in Internet Explorer that could allow remote code execution if a customer views a specially crafted Web page using the browser. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current administrator. This security update is rated Critical for all versions of Internet Explorer, on all supported releases of Microsoft Windows. These issues were privately disclosed and we have not detected any attacks or customer impact.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;MS13-038 | Security Update for Internet Explorer&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: small;"&gt;This security update permanently addresses the Internet Explorer 8 issue described in &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/advisory/2847140"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Security Advisory 2847140&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; to help ensure customers are protected. This security update is rated Critical for Internet Explorer 8 on Windows clients and Moderate for Internet Explorer 8 on Windows servers.&amp;nbsp; There is no severity rating for Internet Explorer 9. This issue was publicly disclosed and there are limited known targeted attacks.&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;MS13-039 | Vulnerability in HTTP.sys Could Allow Denial of Service&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size: small;"&gt;This security update resolves one issue in Microsoft Windows that could allow denial of service if an attacker sends a specially crafted HTTP packet to an affected Windows server or client. The security update is rated Important for supported editions of Windows 8 and Windows Server 2012. This issue was privately disclosed and we have not detected any attacks or customer impact.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Watch the bulletin overview video below for a brief summary of today&amp;rsquo;s releases.&lt;/span&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA8hsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAL4CAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9ADMAZgBkAGQANQA5ADQANAAtADEAMwAyADMALQA0ADYAOAA3AC0AYgBiAGIAOAAtADEAZgBhADIAZQAyAGIAOQA1ADkAMABmAAoALABBAHUAdABvAHAAbABhAHkAPQBGAGEAbABzAGUALABTAGgAbwB3AE0AYQByAGsAZQB0AGkAbgBnAE8AdgBlAHIAbABhAHkAPQB0AHIAdQBlACwATQBpAHMAYwBDAG8AbgB0AHIAbwBsAHMAPQBGAHUAbABsAFMAYwByAGUAZQBuADsARABlAHQAYQBjAGgAZQBkACwAUwBoAG8AdwBNAGUAbgB1AD0AdAByAHUAZQAsAFQAYQBiAHMAPQBFAG0AYgBlAGQAOwBFAG0AYQBpAGwAOwBTAGgAYQByAGUAOwBJAG4AZgBvADsALABTAGgAbwB3AEMAYQBwAHQAaQBvAG4APQBmAGEAbABzAGUALABBAGcAZQBHAGEAdABlAD0AVAByAHUAZQAsAEEAZwBlAEcAYQB0AGUARABhAHkATQBvAG4AdABoAFkAZQBhAHIATwByAGQAZQByAD0ATQBEAFkALABWAGkAZABlAG8AVQByAGwAPQBoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGUAbgAtAHUAcwAvAHMAaABvAHcAYwBhAHMAZQAvAGQAZQB0AGEAaQBsAHMALgBhAHMAcAB4AD8AdQB1AGkAZAA9ADMAZgBkAGQANQA5ADQANAAtADEAMwAyADMALQA0ADYAOAA3AC0AYgBiAGIAOAAtADEAZgBhADIAZQAyAGIAOQA1ADkAMABmAAoALABNAG8AZABlAD0AUABsAGEAeQBlAHIAAAAAAAAAAAAAAP//AAD//wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" type="application/x-silverlight-2" width="480" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=3fdd5944-1323-4687-bbb8-1fa2e2b9590f
,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=3fdd5944-1323-4687-bbb8-1fa2e2b9590f
,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;p&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8787.Deployment-Priority.png"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/8787.Deployment-Priority.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Our risk and impact graph shows an aggregate view of this month&amp;rsquo;s Severity and Exploitability Index &lt;br /&gt;(click for larger view). &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/6685.Severity-and-Exploitability-Index.png"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/6685.Severity-and-Exploitability-Index.png" alt="" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For more information about this month&amp;rsquo;s security updates, visit the &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Microsoft Bulletin Summary Web page&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Jonathan Ness and I will host the monthly technical webcast, scheduled for Wednesday, May 15, 2013, at 11 a.m. PT. I invite you to register &lt;/span&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032538728&amp;amp;Culture=en-US"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;, and tune in to learn more about the May Security Bulletins and Advisories.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For the latest information, you can also follow the MSRC team on Twitter at &lt;/span&gt;&lt;a href="http://www.twitter.com/msftsecresponse"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;@MSFTSecResponse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;I look forward to hearing your questions about today&amp;rsquo;s release in our webcast tomorrow.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Thank you,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;Group Manager, Response Communications&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;Microsoft Trustworthy Computing&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3572472" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin+Webcast/">Security Bulletin Webcast</category></item><item><title>Advance Notification Service for the May 2013 Security Bulletin Release</title><link>http://blogs.technet.com/b/msrc/archive/2013/05/09/advance-notification-service-for-the-may-2013-security-bulletin-release.aspx</link><pubDate>Thu, 09 May 2013 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3571523</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span style="font-size: small;"&gt;Today we&amp;rsquo;re providing Advance Notification of 10 bulletins for release on Tuesday, May 14, 2013. This release brings two Critical and eight Important-class bulletins, which address 33 unique vulnerabilities. The Critical-rated bulletins address issues in Microsoft Windows and Internet Explorer. Of note, we are working to have the Internet Explorer Security Update address the issue described in &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/advisory/2847140"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Security Advisory 2847140&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;, supplementing the currently available Fix it.&amp;nbsp; The Important-rated bulletins address issues in Microsoft Windows, Microsoft Office, Server and Tools, and .NET Framework.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;As always, we will publish the bulletins on the second Tuesday of the month, at approximately 10 a.m. PST. Please revisit this blog at that time for our official risk and impact analysis, along with deployment guidance and a brief video overview of the month&amp;rsquo;s highlights. Until then, you should review the &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;ANS Summary Page&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; for more information and prepare for bulleting testing and deployment as soon as possible to help ensure a smooth update process.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;For the latest information, you can also follow the MSRC team on Twitter at &lt;/span&gt;&lt;a href="https://twitter.com/msftsecresponse"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;@MSFTSecResponse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;Thank you,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0563c1; font-size: small;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;Group Manager&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;Microsoft Trustworthy Computing&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3571523" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/ANS/">ANS</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletins/">Security Bulletins</category></item><item><title>Fix it for Security Advisory 2847140 is available</title><link>http://blogs.technet.com/b/msrc/archive/2013/05/08/fix-it-for-security-advisory-2847140-is-available.aspx</link><pubDate>Wed, 08 May 2013 23:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3571443</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;We have updated &lt;a title="Security Advisory 2847140" href="http://technet.microsoft.com/security/advisory/2847140"&gt;Security Advisory 2847140&lt;/a&gt; to include an easy, one-click Fix it to address the known attack vectors. The Fix it is available to all customers and helps prevent known attacks that leverage the vulnerability to execute code and should not affect your ability to browse the Web. Additionally, applying the Fix it does not require a reboot. We encourage all customers using Internet Explorer 8 to apply this Fix it to help protect their systems. Internet Explorer 6, 7, 9 and 10 are not affected.&lt;/p&gt;
&lt;p&gt;The Fix it is an effort to help protect as many customers as possible, as quickly as possible. We continue to work on a security update to address this issue and we&amp;rsquo;re closely monitoring the threat landscape. Tomorrow, please visit our monthly &lt;a title="Advance Notification Service (ANS) blog" href="http://blogs.technet.com/b/msrc/"&gt;Advance Notification Service (ANS) blog&lt;/a&gt; for details on the Security Updates being released in May&amp;rsquo;s Security Bulletin cycle.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;br /&gt;&lt;a title="Dustin Childs" href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;Dustin Childs&lt;/a&gt;&lt;br /&gt;Group Manager, Response Communications&lt;br /&gt;Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3571443" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/advisory/">advisory</category></item><item><title>Microsoft Releases Security Advisory 2847140</title><link>http://blogs.technet.com/b/msrc/archive/2013/05/03/microsoft-releases-security-advisory-2847140.aspx</link><pubDate>Sat, 04 May 2013 02:15:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3570713</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Today, we released &lt;a title="Security Advisory 2847140" href="http://technet.microsoft.com/en-us/security/advisory/2847140"&gt;Security Advisory 2847140&lt;/a&gt; regarding an issue that impacts Internet Explorer 8. Internet Explorer 6, 7, 9 and 10 are not affected by the vulnerability. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message.&lt;/p&gt;
&lt;p&gt;Internet Explorer 9 and 10 are not affected by this issue, so &lt;a title="upgrading" href="http://windows.microsoft.com/en-US/internet-explorer/download-ie"&gt;upgrading&lt;/a&gt; to these versions will help protect you from this issue.&lt;/p&gt;
&lt;p&gt;While we are actively working to develop a security update to address this issue, we encourage customers using affected versions of Internet Explorer to deploy the following workarounds and mitigations included in the advisory to help protect themselves:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones&lt;/strong&gt;&lt;br /&gt;This will help &lt;strong&gt;prevent exploitation&lt;/strong&gt; but may &lt;strong&gt;affect usability&lt;/strong&gt;; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones&lt;br /&gt;&lt;/strong&gt;This will help &lt;strong&gt;prevent exploitation&lt;/strong&gt; but can &lt;strong&gt;affect usability&lt;/strong&gt;, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We also always encourage people to follow the "Protect Your Computer" guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. We also encourage folks to exercise caution when visiting websites and avoid clicking suspicious links, or opening email messages from unfamiliar senders. Additional information can be found at &lt;a href="http://www.microsoft.com/protect"&gt;www.microsoft.com/protect&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We are monitoring the threat landscape very closely and will continue to take appropriate action to help protect customers.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;br /&gt;&lt;a title="Dustin Childs" href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;Dustin Childs&lt;/a&gt;&lt;br /&gt;Group Manager, Response Communications&lt;br /&gt;Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3570713" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Advisory/">Security Advisory</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/advisory/">advisory</category></item><item><title>New update available for MS13-036</title><link>http://blogs.technet.com/b/msrc/archive/2013/04/23/new-update-available-for-ms13-036.aspx</link><pubDate>Tue, 23 Apr 2013 17:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3568559</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p style="text-align: right;"&gt;&amp;nbsp;&lt;a title="Portuguese (Brazil)" href="http://blogs.technet.com/b/msrc/p/kb2840149-released_portugues-brasil.aspx"&gt;Portuguese (Brazil)&lt;/a&gt;, &lt;a title="Русский" href="http://blogs.technet.com/b/msrc/p/kb2840149-released_russian.aspx"&gt;Русский&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Today we released a new update to replace KB2823324, which was originally made available through &lt;a title="MS13-036" href="http://technet.microsoft.com/en-us/security/bulletin/ms13-036"&gt;MS13-036&lt;/a&gt;.&amp;nbsp;As we &lt;a title="previously discussed" href="http://blogs.technet.com/b/msrc/archive/2013/04/11/kb2839011-released-to-address-security-bulletin-update-issue.aspx"&gt;previously discussed&lt;/a&gt;, we stopped distributing this update when we learned some customers were having issues. The new update, &lt;a title="KB2840149" href="http://support.microsoft.com/kb/2840149"&gt;KB2840149&lt;/a&gt;, still addresses the Moderate security issue described in MS13-036, and should not cause these issues. If you have automatic updates enabled, you won&amp;rsquo;t need to take any actions. For those manually updating, we encourage you to apply this update at your earliest convenience.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt;&lt;a title="Dustin Childs" href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;Dustin Childs&lt;/a&gt;&lt;br /&gt;Group Manager, Response Communications&lt;br /&gt;Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3568559" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update/">Security Update</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/bulletin/">bulletin</category></item><item><title>April 2013 Security Bulletin Webcast, Q&amp;A, and Slide Deck</title><link>http://blogs.technet.com/b/msrc/archive/2013/04/16/april-2013-security-bulletin-webcast-q-amp-a-and-slide-deck.aspx</link><pubDate>Tue, 16 Apr 2013 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3566566</guid><dc:creator>MSRCTeam</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Today we&amp;rsquo;re publishing the &lt;a href="http://blogs.technet.com/b/msrc/p/april-2013-security-bulletin-q-a.aspx"&gt;&lt;span style="color: #0000ff;"&gt;April 2013 Security Bulletin Webcast Questions &amp;amp; Answers page&lt;/span&gt;&lt;/a&gt;.&amp;nbsp; We fielded nine questions during the webcast, with almost half of those focused on &lt;span style="color: #000000;"&gt;the Remote Desktop Client bulletin&lt;/span&gt; (&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-024"&gt;&lt;span style="color: #0000ff;"&gt;MS13-024&lt;/span&gt;&lt;/a&gt;).&amp;nbsp; One question that was not answered on air has been included on the Q&amp;amp;A page.&lt;/p&gt;
&lt;p&gt;We invite our customers to join us for the next public webcast on Wednesday, May 15, 2013, at 11 a.m. PDT (UTC -7), when we will go into detail about the May bulletin release and answer questions live on the air.&lt;/p&gt;
&lt;p&gt;Customers can register to attend the webcast at the link below:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Date: Wednesday, May 15, 2013&lt;br /&gt; Time: 11:00 a.m. PDT (UTC -7) &lt;br /&gt; Register: &lt;/strong&gt;&lt;a href="https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032538728&amp;amp;culture=en-us"&gt;&lt;strong&gt;&lt;span style="color: #0000ff;"&gt;Attendee Registration &lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div style="width: 480px; height: 270px;"&gt;&lt;object data="data:application/x-oleobject;base64,QfXq3+HzJEysrJnDBxUISgAJAACcMQAA6BsAABQAAAAjAEYARgAwADAAMAAwADAAMAAAAAAAAAAAAAAAAAAAAI4AAABoAHQAdABwADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAGcAbABvAGIAYQBsAC8AZQBuAC0AdQBzAC8AcwBoAG8AdwBjAGEAcwBlAC8AUgBpAGMAaABNAGUAZABpAGEALwBwAGwAYQB5AGUAcgAtAGUAbgAuAHgAYQBwAAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALoCAABDAHUAbAB0AHUAcgBlAD0AZQBuAC0AdQBzACwAVQB1AGkAZAA9AGIAYgBlAGQANwAzADQANgAtADUAYgBkADQALQA0ADIAOQBmAC0AYgAwADQAZgAtADkANgAwADQAOQA4ADQAMwBkAGUAMgAwACwAQQB1AHQAbwBwAGwAYQB5AD0ARgBhAGwAcwBlACwAUwBoAG8AdwBNAGEAcgBrAGUAdABpAG4AZwBPAHYAZQByAGwAYQB5AD0AdAByAHUAZQAsAE0AaQBzAGMAQwBvAG4AdAByAG8AbABzAD0ARgB1AGwAbABTAGMAcgBlAGUAbgA7AEQAZQB0AGEAYwBoAGUAZAAsAFMAaABvAHcATQBlAG4AdQA9AHQAcgB1AGUALABUAGEAYgBzAD0ARQBtAGIAZQBkADsARQBtAGEAaQBsADsAUwBoAGEAcgBlADsASQBuAGYAbwA7ACwAUwBoAG8AdwBDAGEAcAB0AGkAbwBuAD0AZgBhAGwAcwBlACwAQQBnAGUARwBhAHQAZQA9AFQAcgB1AGUALABBAGcAZQBHAGEAdABlAEQAYQB5AE0AbwBuAHQAaABZAGUAYQByAE8AcgBkAGUAcgA9AE0ARABZACwAVgBpAGQAZQBvAFUAcgBsAD0AaAB0AHQAcAA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBlAG4ALQB1AHMALwBzAGgAbwB3AGMAYQBzAGUALwBkAGUAdABhAGkAbABzAC4AYQBzAHAAeAA/AHUAdQBpAGQAPQBiAGIAZQBkADcAMwA0ADYALQA1AGIAZAA0AC0ANAAyADkAZgAtAGIAMAA0AGYALQA5ADYAMAA0ADkAOAA0ADMAZABlADIAMAAsAE0AbwBkAGUAPQBQAGwAYQB5AGUAcgAAAAAAAAAAAAAA//8AAP//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==" type="application/x-silverlight-2" width="480" height="270"&gt;&lt;param name="source" value="http://www.microsoft.com/global/en-us/showcase/RichMedia/player-en.xap" /&gt;&lt;param name="initParams" value="Culture=en-us,Uuid=bbed7346-5bd4-429f-b04f-96049843de20,Autoplay=False,ShowMarketingOverlay=true,MiscControls=FullScreen;Detached,ShowMenu=true,Tabs=Embed;Email;Share;Info;,ShowCaption=false,AgeGate=True,AgeGateDayMonthYearOrder=MDY,VideoUrl=http://www.microsoft.com/en-us/showcase/details.aspx?uuid=bbed7346-5bd4-429f-b04f-96049843de20,Mode=Player" /&gt;&lt;param name="enableHtmlAccess" value="true" /&gt;&lt;param name="allowHtmlPopupwindow" value="true" /&gt;&lt;param name="background" value="#FF000000" /&gt;&lt;/object&gt;&lt;/div&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/msrc/about.aspx#Dustin_Childs"&gt;&lt;span style="color: #0000ff;"&gt;Dustin Childs&lt;/span&gt;&lt;/a&gt;&lt;br /&gt; Group Manager, Response Communications&lt;br /&gt; Microsoft Trustworthy Computing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3566566" width="1" height="1"&gt;</description><enclosure url="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-03-56-65-66/April-2013-Security-Bulletin-Webcast-_2D00_-Final-_2D00_-Customer-Ready.pptx" length="1965690" type="application/octet-stream" /><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/">Security Update Webcast Q &amp;amp; A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Update+Webcast/">Security Update Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin/">Security Bulletin</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Windows/">Microsoft Windows</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Microsoft+Office/">Microsoft Office</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast+Q_2600_amp_3B00_A/">Webcast Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/monthly+bulletin+release/">monthly bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/security+bulletin+release/">security bulletin release</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Webcast/">Webcast</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Bulletins/">Bulletins</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Q_2600_amp_3B00_A/">Q&amp;amp;A</category><category domain="http://blogs.technet.com/b/msrc/archive/tags/Security+Bulletin+Webcast/">Security Bulletin Webcast</category></item></channel></rss>