Today we have released 13 new security bulletins. Please see the details below for more details of the updates and make sure you apply them to your environments where necessary.
| Bulletin ID | Bulletin Title | Max Severity Rating | Vulnerability Impact | Restart Requirement | Affected Software |
| MS10-003 | Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution | Important
| Remote Code Execution | May require restart | Microsoft Office XP, Office 2004 for Mac. |
| MS10-004 | Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution | Important
| Remote Code Execution | May require restart | Microsoft Office PowerPoint 2002, Office PowerPoint 2003, and Office 2004 for Mac. |
| MS10-005 | Vulnerability in Microsoft Paint Could Allow Remote Code Execution | Moderate
| Remote Code Execution | Requires restart | Microsoft Windows 2000, Windows XP, and Windows Server 2003. |
| MS10-006 | Vulnerabilities in SMB Client Could Allow Remote Code Execution | Critical
| Remote Code Execution | Requires restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. |
| MS10-007 | Vulnerability in Windows Shell Handler Could Allow Remote Code Execution | Critical
| Remote Code Execution | Requires restart | Microsoft Windows 2000, Windows XP, and Windows Server 2003. |
| MS10-008 | Cumulative Security Update of ActiveX Kill Bits | Critical
| Remote Code Execution | May require restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. |
| MS10-009 | Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution | Critical
| Remote Code Execution | Requires restart | Microsoft Windows Vista and Windows Server 2008. |
| MS10-010 | Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service | Important
| Denial of Service | Requires restart | Microsoft Windows Server 2008 and Windows Server 2008 R2. |
| MS10-011 | Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege | Important
| Elevation of Privilege | Requires restart | Microsoft Windows 2000, Windows XP, and Windows Server 2003. |
| MS10-012 | Vulnerabilities in SMB Server Could Allow Remote Code Execution | Important
| Remote Code Execution | Requires restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. |
| MS10-013 | Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution | Critical
| Remote Code Execution | Requires restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. |
| MS10-014 | Vulnerability in Kerberos Could Allow Denial of Service | Important
| Denial of Service | Requires restart | Microsoft Windows 2000, Windows Server 2003, and Windows Server 2008. |
| MS10-015 | Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege | Important
| Elevation of Privilege | Requires restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7. |
| |
If you would like a summary of the bulletins please go here.
Microsoft Windows Malicious Software Removal Tool
We are also releasing a new version of the Windows Malicious Software Removal Tool. You can get more details here.
New Security Advisory
Also as part of this month’s security bulletin we are releasing a new security advisory. More details below.
| Identifier | Vulnerability in TLS/SSL Could Allow Spoofing (977377) |
| Summary | Microsoft is investigating public reports of a vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. At this time, Microsoft is not aware of any attacks attempting to exploit the reported vulnerability. As an issue affecting an Internet standard, we recognize that this issue affects multiple vendors. We are working on a coordinated response with our partners in the Internet Consortium for Advancement of Security on the Internet (ICASI). The TLS and SSL protocols are implemented in several Microsoft products, both client and server, and this advisory will be updated as our investigation continues. As part of this security advisory, Microsoft is making available a workaround which enables system administrators to disable TLS and SSL renegotiation functionality. However, as renegotiation is required functionality for some applications, this workaround is not intended for wide implementation and should be tested extensively prior to implementation. Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, depending on customer needs. |
| Affected Software | -
Windows 2000 (All Supported Versions) -
Windows XP (All Supported Versions) -
Windows Server 2003 (All Supported Versions) -
Windows Vista (All Supported Versions) -
Windows Server 2008 (All Supported Versions) -
Windows 7 (All Supported Versions) -
Windows Server 2008 R2 (All Supported Versions) |
| Recommendations | Review Microsoft Security Advisory 977377 for an overview of the issue, details on affected components, mitigating factors, suggested actions, frequently asked questions (FAQs), and links to additional resources. |
| Additional Resources | |
Jeffa
With all the new products that have recently been released it’s a good time to start thinking about updating your
Microsoft Certifications. So to help with that the Microsoft Learning team has introduced Second Shot; which allows you to re-take and exam if you don’t pass it the first time around. And let’s be honest who hasn’t failed an MCP exam at least once? With the Second Shot program you get a second chance to pass the exam. But if you want to take advantage of this offer you are going to have to book and sit your first and exam and (if necessary book the re-take exam by June 30th 2010. The offer applies to all Microsoft Learning exams including IT Pro, Developer, Project Management and Microsoft Dynamics.
To find out more check out the Second Shot website and get your exams booked! Hey you never know you might just do more exams knowing you have a second chance.
And with all these new products new exams are coming out all the time. As an example we have exams on
Windows 7 and
Windows Server 2008 R2 which include all the updates to these two new technologies.
Jeffa
BranchCache, which is new to Windows 7 and Windows Server 2008 R2 is one of my favourite features that allows
organisations to reduce the cost of running branch offices and reduce their complexity. Microsoft IT has deployed BranchCache as part of our Windows 7 rollout and is realizing benefits in WAN utilization. Check out the article below on how we are using this great technology.
Reducing Bandwidth Utilization with Windows 7 and Windows Server 2008 R2 BranchCache
Learn how Microsoft IT uses the BranchCache™ feature available in the Windows® 7 operating system and the Windows Server® 2008 R2 operating system to improve performance and availability to branch offices. Services at the branch office level include file and print management, offline folder redirection, operating system and application distribution, and patch management.
Technical Case Study
Jeffa
I know I’m a bit late with this but I’ve been away for 6 weeks holiday so during this time I missed a bit and I’m just
catching up. Anyway the January Edition of TechNet Magazine is now online and as usual has some great technical information. This issue includes the following highlights:
Plus there is much more as always so make sure you set aside some time to check it out.
Jeffa
This month 6 is the lucky number again. We have 6 updates this month. Please see details of these below.
| Bulletin ID | Bulletin Title | Max Severity Rating | Vulnerability Impact | Restart Requirement | Affected Software |
| MS09-069 | Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service | Important | Denial of Service | Requires Restart | Microsoft Windows 2000, Windows XP, and Windows Server 2003 |
| MS09-070 | Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution | Important | Remote Code Execution | Requires Restart | Microsoft Windows Server 2003 and Windows Server 2008 |
| MS09-071 | Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution | Critical | Remote Code Execution | Requires Restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 |
| MS09-072 | Cumulative Security Update for Internet Explorer | Critical | Remote Code Execution | Requires Restart | Internet Explorer on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 |
| MS09-073 | Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution | Important | Remote Code Execution | Requires Restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Office XP, Office 2003, Works 8.5, and Office Converter Pack |
| MS09-074 | Vulnerability in Microsoft Office Project Could Allow Remote Code Execution | Critical | Remote Code Execution | May Require Restart | Microsoft Project 2000, Project 2002, and Project 2003 |
Summaries of these bulletins can be found here.
A video and a podcast are available on http://edge.TechNet.com that goes through these updates.
December 2009 Security Bulletin Overview In this 8 minute video, Trustworthy Computing provides an overview of the 6 bulletins addressing 12 vulnerabilities.
Security Bulletins for the Regular IT Guy – Dec 09 Podcast Pierre Rowan and Rick Claus describe 6 bulletins in a friendly, informative podcast for customers.
Enjoy!
Jeffa
Are you looking for something cool to hang on your wall at home? You might want to think about the Windows Server 2008 R2 Feature Components Poster! Well you might not get it pass the family so why not download and hang on the wall at work!
This poster provides a visual reference for understanding key technologies in Windows Server 2008 R2. It focuses on Active Directory Domain Services, Hyper-V, Internet Information Services, Remote Desktop Services (including Virtual Desktop Infrastructure (VDI)), BranchCache, and DirectAccess technologies. In addition, updates to core file services and server management are illustrated. Below is a screenshot of what it looks like.
And here is an embed from Microsoft Live Labs Seadragon!
These posters have been around for awhile now and are produced by one of our local guys; Martin Mclean who used to work out of the Microsoft Perth office but now is working for the Windows Server team as a technical writer.
You can download it by clicking the picture above or the link I provided.
Jeffa
Thanks again to the wonderful Mr. Frank I’m using this new tool called Twitter Inserter. Check out my last 50 tweets. Thanks to the author Tod Birdsall for an incredibly effective plug-in!
Follow me on Twitter
Jeffa
With the number of new products that have come out recently it’s a good time to re-visit your Microsoft certification status and get up to date.
To help with this the folks over at Microsoft Learning are running a program until December 31st 2009 where you can get up to 25% certification exams.
We also have what we call Learning Plans which help you become certified in the most notable and correct Microsoft products. If you follow the Career Map you can get a clear picture of where you want to be based on your role and see what certifications you’ll need to do to get there.
So make sure you take up this offer and if you are at a user group or presentation I give in the next month I may have a Microsoft Press book to giveaway! But you have to be there to win.
Jeffa
Over the lest few weeks I’ve been travelling around the place talking about Windows 7 and Windows Server 2008 R2. I always get asked to supply the slides for each session I do so i thought it was time to upload a bunch of these decks because it’s been awhile and as you all know I’ve done quite a lot of sessions over the last little while.
So with please see below for the downloads. And thanks to my 25GB of storage on Windows Live SkyDrive it’s easy to share these.
Windows 7 Slide Decks
Windows Server 2008 R2 Slides
And thanks to a colleague of mine in Melbourne who focuses on System Centre Configuration Manager (SCCM) for this below deck on deploying Windows 7 with System Centre.
Jeffa
This month it’s the lucky number 6 in regards to security updates. Yes we have 6 updates this month to consider for your environments. Details are below.
New Security Bulletins
| Bulletin ID | Bulletin Title | Max Severity | Vulnerability Impact | Restart Requirement | Affected Software |
| MS09-063 | Vulnerability in Web Services on Devices API Could Allow Remote Code Execution | Critical | Remote Code Execution | Requires Restart | Microsoft Windows Vista and Windows Server 2008 |
| MS09-064 | Vulnerability in License Logging Server Could Allow Remote Code Execution | Critical | Remote Code Execution | Requires Restart | Microsoft Windows 2000 Server |
| MS09-065 | Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution | Critical | Remote Code Execution | Requires Restart | Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 |
| MS09-066 | Vulnerability in Active Directory Could Allow Denial of Service | Important | Denial of Service | Requires Restart | Microsoft Windows 2000 Server, Windows XP, Windows Server 2003, and Windows Server 2008 |
| MS09-067 | Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution | Important | Remote Code Execution | May Require Restart | Microsoft Office Excel 2002, Excel 2003, Excel 2007, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format converter for Mac, Excel Viewer, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats |
| MS09-068 | Vulnerability in Microsoft Office Word Could Allow Remote Code Execution | Important | Remote Code Execution | May Require Restart | Microsoft Office Word 2002, Word 2003, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format converter for Mac, Office Word Viewer, and Office Word Viewer 2003 |
If you would like a summary of these bulletins you can find that here.
Microsoft Windows Malicious Software Removal Tool
We are also releasing an updated version of the Windows Malicious Software Removal Tool on WSUS, Windows Update and the Download centre. More information can be found here.
And if you want a nice summary in plain English (well Canadian anyway) head over to the Canada IT Pro Connection and check out this months “Security Bulletins for the regular IT Guy” podcast.
That’s it for this month! Enjoy!
Jeffa
In the recent deployment sessions on Windows 7 you might remember me discussing the importance of planning when deploying a new operating system. Well the Solution Accelerator team would like to announce that the MAP Toolkit 5.0 CTP is now available for download.
The MAP 5.0 CTP includes the following new features:
- Heterogeneous Server Environment Inventory for technologies including Windows Server, Linux, UNIX and VM Ware.
- Ability to determine usage of deployed System Center Configuration Manager, a member of the Core Client Access License Suite.
- Readiness assessment for migration or upgrade to Microsoft Office 2010.
In addition to these new features MAP provides a host of other feature which I outlined in my previous post on MAP 4.0.
Next Steps
Jeffa
This month in TechNet Magazine Online; Windows Server 2008 R2 is featured along with some other good information for deploying Windows 7. Yes Windows 7 is out and is getting a lot of attention. But don’t forget about this important release of Windows Server. Check out the details below!
As always there is heaps of great information in the latest TechNet Magazine. So make sure you set aside to read some of the in depth articles.
Jeffa
Managing storage is something administrators struggle with. I know when I was in Microsoft IT one of the biggest
issues we had was data that was aged and no longer being accessed but still taking up an enormous amount of space. Organisations need to manage data more efficiently and they need to gain insight into their data so they can reduce the cost of storing it, maintaining and managing it. The next frontier for administrators is to be able to manage data based on business value.
Windows Server 2008 R2 introduces the File Classification Infrastructure (FCI) which is a built in solution for file classification that enables manual processes for classifying data to be automated with predefined policies based on the value of that data to the business. FCI’s out of the box functionality provides the ability to define the following:
- Classification Properties
- Automatic Classification – Using these automatic rules FCI can classify files according to the folder in which they are stored or based on the contents of the files.
- Manual Classification – Files can be manually classified based on the file properties interface built into Office system files. When you use this interface FCI will recognize the properties.
- LOB Applications and Scripts – Using an API LOB applications and scripts can set classifications on files
- File Expiration – This is probably going to be the biggest one for organizations. What do you do with
stale or unused data? It’s often a manual task. When I was in IT we used third party tools to scan data that was aged or unused. I remember one scan we did that showed the 75% of the data we had on our file servers had not been touched in 18 months! Yet it was taking an enormous amount of space on our file servers. It was also a convoluted process to analyse this data. Now with FCI administrators can now run scheduled tasks that expire files based on age, location and other classification properties. Administrators can move the files to another location, alert users when data is going to be moved and backup that data in case it needs to be called upon in the future. - SharePoint Integration – FCI integrates with Office SharePoint Server 2007 so any file classification defined for Office files carries through to files uploaded to SharePoint sites.
In addition to what FCI provides in box; perhaps the powerful feature is that FCI is an extensible API which allows ISV’s and developers to build end-to-end solutions based on the FCI architecture. Check out some of the partners that already have solutions in this space.
So I wanted to spend the rest of this post talking about how you install it on Windows Server 2008 R2 and what you can do with it.
Installation
- Installation is easy. The File Classification Infrastructure is installed when you install the File Services role in Windows Server 2008 R2. I’ve done this already on one of my highly available file server virtual machines.
- During the install you will be asked to install role services for for the File Server Role. Make sure you choose the File Server Resource Manager. This will give you the FCI UI plus all the other tools to manage your file servers.
- Once you have the File Services role installed you will see a section under the File Resource Manager called Classification Management. This is where you configure Classification Properties, Classification Rules and run File Management Tasks.
- Next you are going to want to setup some classification properties for your data. In the example below I’ve setup some basic properties to include Business Impact, Expiring Files and Personally Identifiable Information.
- The next thing is to setup Classification Rules which are used to evaluate which values should be assigned to properties for files on the server. For example I’ve setup a Classification Rule that uses the Content Classifier mechanism and the Business Impact Property with a value of Medium. This was defined in classification properties.
To learn more about FCI check out the technical whitepaper, videos on Channel 9 and of course the Storage Team Blog’s post’s on FCI.
Jeffa