Gestern war Dienstag. Und zwar der zweite Dienstag im Monat: Patch Tuesday. Auch in diesem Monat sind wieder einige sicherheitsrelevante Hotfixes veröffentlicht worden, die wie üblich auf den TechNet-Seiten beschrieben sind. Diesmal sind das:

Bulletin ID

Vulnerability Title

MS09-069

Local Security Authority Subsystem Service Resource Exhaustion Vulnerability

MS09-070

Single Sign On Spoofing in ADFS Vulnerability

MS09-070

Remote Code Execution in ADFS Vulnerability

MS09-071

Internet Authentication Service Memory Corruption Vulnerability

MS09-071

MS-CHAP Authentication Bypass Vulnerability

MS09-072

ATL COM Initialization Vulnerability

MS09-072

Uninitialized Memory Corruption Vulnerability

MS09-072

HTML Object Memory Corruption Vulnerability

MS09-072

Uninitialized Memory Corruption Vulnerability

MS09-072

Uninitialized Memory Corruption Vulnerability

MS09-073

WordPad and Office Text converter Memory Corruption Vulnerability

MS09-074

Project Memory Validation Vulnerability

 

Es gibt jedoch noch weitere Informationsquellen, die ich Ihnen empfehlen möchte:

    1. Use plain English terms and every day language that any Technical professional can understand – minimize “corporate speak”.
    2. Breakdown each Security Bulletin with summary information first followed by more details as to the impact an IT Pro would face.
    3. Outline mitigation factors in case patches couldn’t be tested or applied in a timely fashion
    4. Keep it top 20 minutes OR LESS. This one is critical – Keep It Simple, repeatable and get out of the IT Pros way to get on with their day.
    5. Have fun!

Mit freundlichen Grüßen!

 

Ralf M. Schnell