<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Todo es posible, nada es seguro</title><link>http://blogs.technet.com/ksarens/default.aspx</link><description>Todo de seguridad...</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Actualizaciones de Seguridad de Deciembre</title><link>http://blogs.technet.com/ksarens/archive/2008/12/09/actualizaciones-de-seguridad-de-deciembre.aspx</link><pubDate>Wed, 10 Dec 2008 00:50:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3165962</guid><dc:creator>ksarens</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ksarens/comments/3165962.aspx</comments><wfw:commentRss>http://blogs.technet.com/ksarens/commentrss.aspx?PostID=3165962</wfw:commentRss><description>&lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&amp;#161;Nuestras ultimas actualizaciones de Seguridad este A&amp;#241;o! &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2" face="verd"&gt;&amp;#161;Quiero informarse que &lt;/font&gt;&lt;font size="2" face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-deciembre.mspx"&gt;este mes&lt;/a&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt; ya publicamos solas 8 nuevas actualizaciones! :)&lt;/font&gt; &lt;/font&gt;      &lt;p mce_keep="true"&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt; &lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;6 con categor&amp;#237;a Cr&amp;#237;tica y 2 con categor&amp;#237;a Importante &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;/span&gt;  &lt;p&gt;&lt;/p&gt;  &lt;table style="border-bottom: medium none; border-left: medium none; border-collapse: collapse; border-top: medium none; border-right: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class="MsoTableGrid" border="1" cellspacing="0" cellpadding="0" width="755"&gt;&lt;tbody&gt;     &lt;tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1" valign="top" width="74"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-070.mspx"&gt;MS08-070&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="80"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-top: black 1pt solid; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidades en en los archivos extendidos de tiempo de ejecuci&amp;#243;n de Visual Basic 6.0 (controles ActiveX) podr&amp;#237;an permitir la ejecusi&amp;#243;n remota de codigo. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 1"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-071.mspx"&gt;MS08-071&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidad en GDI podr&amp;#237;a permitir la ejecuci&amp;#243;n remota de c&amp;#243;digo &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 2"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-072.mspx"&gt;MS08-072&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidades en los filtros de Microsoft Office podr&amp;#237;an permitir la ejecuci&amp;#243;n remota de c&amp;#243;digo &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-073.mspx"&gt;MS08-073&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Actualizaci&amp;#243;n de seguridad acumulativa para &lt;strong&gt;Internet Explorer&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-074.mspx"&gt;MS08-074&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidades en Microsoft Office Excel podr&amp;#237;an permitir la ejecuci&amp;#243;n remota de c&amp;#243;digo&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-075.mspx"&gt;MS08-075&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Cr&amp;#237;tical&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidades en B&amp;#250;squeda de Windows podr&amp;#237;an permitir la ejecuci&amp;#243;n remota de c&amp;#243;digo&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-076.mspx"&gt;MS08-076&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Importante&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidades en los componentes de Windows Media podr&amp;#237;an permitir la ejecuci&amp;#243;n remota de c&amp;#243;digo&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;       &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="76"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;a target="_blank" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-077.mspx"&gt;MS08-077&lt;/a&gt; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 63.4pt; padding-right: 5.4pt; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" valign="top" width="79"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Importante&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0cm; background-color: transparent; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 446.5pt; padding-right: 5.4pt; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0cm; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" valign="top" width="599"&gt;         &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Vulnerabilidad en Microsoft Office SharePoint Server podr&amp;#237;a provocar la elevaci&amp;#243;n de privilegios&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt; &lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;u&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Detecci&amp;#243;n&lt;/font&gt;&lt;/font&gt;&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;u&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;/font&gt;&lt;/font&gt;          &lt;p mce_keep="true"&gt;&lt;/p&gt;       &lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Para saber si su sistema necesita estas actualizaciones, puede utilizar la herramienta Microsoft Baseline Analyzer (&lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=21134"&gt;MBSA&lt;/a&gt;).         &lt;br /&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Las actualizaciones podr&amp;#237;an requerir el reinicio del equipo. &lt;/font&gt;      &lt;p mce_keep="true"&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;u&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;Atenci&amp;#243;n&lt;/font&gt;&lt;/font&gt;&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt" class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;u&gt;&lt;font size="2"&gt;&lt;font face="verd"&gt;&lt;/font&gt;&lt;/font&gt;          &lt;p mce_keep="true"&gt;&lt;/p&gt;       &lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p mce_keep="true"&gt;&lt;span style="mso-ansi-language: es"&gt;&lt;font size="2"&gt;&lt;/font&gt;      &lt;p mce_keep="true"&gt;Tenemos 2 boletines de Office, quiero informarse que no hay actualizaciones por Office 2003 &lt;strong&gt;SP2&lt;/strong&gt;. El soporte de este v&amp;#233;rsion es terminada desde &lt;a target="_blank" href="http://support.microsoft.com/lifecycle/?LN=es-es&amp;amp;p1=2488&amp;amp;x=11&amp;amp;y=13"&gt;14 Octubre&lt;/a&gt;.&lt;/p&gt;      &lt;p mce_keep="true"&gt;Siempre revisar los detailes de los boletinos para verificar los sistemas operativos y los software afectados.       &lt;br /&gt;&amp;#161;No olvida de instalar las actualizaciones lo antes posible!&lt;/p&gt;      &lt;p mce_keep="true"&gt;&amp;#161;Felices fiestas de Navidad!&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3165962" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ksarens/archive/tags/Seguridad/default.aspx">Seguridad</category><category domain="http://blogs.technet.com/ksarens/archive/tags/Boletines/default.aspx">Boletines</category></item><item><title>Actualizaciones de Seguridad de Noviembre</title><link>http://blogs.technet.com/ksarens/archive/2008/11/13/actualizaciones-de-seguridad-de-noviembre.aspx</link><pubDate>Thu, 13 Nov 2008 13:18:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3152310</guid><dc:creator>ksarens</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ksarens/comments/3152310.aspx</comments><wfw:commentRss>http://blogs.technet.com/ksarens/commentrss.aspx?PostID=3152310</wfw:commentRss><description>&lt;H4&gt;&lt;A href="http://blogs.technet.com/ksarens/archive/2008/07/08/actualizaciones-de-seguridad-de-julio.aspx" mce_href="http://blogs.technet.com/ksarens/archive/2008/07/08/actualizaciones-de-seguridad-de-julio.aspx"&gt;&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;¡Un mes ha pasado ya!&lt;/P&gt;
&lt;P&gt;Este mes (despues el OOB) publicamos 2 nuevas actualizaciones de Seguridad. Una actulizacion Importante y una Crítica.&lt;/P&gt;
&lt;TABLE border=2 cellSpacing=0 cellPadding=2 width=789&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=199&gt;&lt;A target=_blank href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx"&gt;MS08-068&lt;/A&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=586&gt;Vulnerabilidad en SMB podría permitir la ejecución remota de código.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=201&gt;&lt;A target=_blank href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx"&gt;MS08-069&lt;/A&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=586&gt;Vulnerabilidades en servicios XML Core podrían permitir la ejecución remota de código.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;Detección&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;&lt;/U&gt;&lt;/B&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;Para saber si su sistema necesita estas actualizaciones, puede utilizar las herramientas disponibles des Microsoft (WU, MU, MBSA, WSUS, SMS, SCCM). &lt;BR&gt;Las actualizaciones podrían requerir el reinicio del equipo (la actualizacion de SMB require reiniciar el sistema). 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;Atención&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;&lt;/U&gt;&lt;/B&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;B&gt;MS08-068&lt;/B&gt;: Si el ataque existe en un paquete de red, la mejor práctica es de poner un mínimo de servicios disponible en Internet. Cerrando las puertas (inbound) 139 y 445 protegerse de este vulnerabilidad. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;MS08-040:&lt;/B&gt; Puede ser muy díficil de verificar si sus aplicaciones utilisen XML &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3152310" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ksarens/archive/tags/Seguridad/default.aspx">Seguridad</category><category domain="http://blogs.technet.com/ksarens/archive/tags/Boletines/default.aspx">Boletines</category></item><item><title>Actualizaciones de Seguridad de Julio</title><link>http://blogs.technet.com/ksarens/archive/2008/07/08/actualizaciones-de-seguridad-de-julio.aspx</link><pubDate>Tue, 08 Jul 2008 23:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3085794</guid><dc:creator>ksarens</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ksarens/comments/3085794.aspx</comments><wfw:commentRss>http://blogs.technet.com/ksarens/commentrss.aspx?PostID=3085794</wfw:commentRss><description>&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Todo el mundo sabe que cada segundo martes del mes, publicamos nuevas actualizaciones de Seguridad. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2 face=verd&gt;¡Quiero informarse que &lt;/FONT&gt;&lt;A class="" href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-julio.mspx" target=_blank mce_href="http://www.microsoft.com/latam/technet/seguridad/boletines/2008/ms08-julio.mspx"&gt;&lt;FONT size=2 face=verd&gt;este mes&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt; ya publicamos 4 nuevas actualizaciones! 
&lt;P mce_keep="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Todos las actualizaciones&amp;nbsp;son de gravedad &lt;B style="mso-bidi-font-weight: normal"&gt;Importante&lt;/B&gt;. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;/P&gt;&lt;/SPAN&gt;
&lt;TABLE style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none; BORDER-COLLAPSE: collapse; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableGrid border=1 cellSpacing=0 cellPadding=0 class="MsoTableGrid"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; BORDER-TOP: black 1pt solid; PADDING-BOTTOM: 0cm; BORDER-LEFT: black 1pt solid; WIDTH: 63.4pt; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1" class="" vAlign=top width=85&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;MS08-037 &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; BORDER-TOP: black 1pt solid; PADDING-BOTTOM: 0cm; WIDTH: 446.5pt; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" class="" vAlign=top width=595&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Vulnerabilidades en DNS podrían permitir la suplantación &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: black 1pt solid; WIDTH: 63.4pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" class="" vAlign=top width=85&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;MS08-038 &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; PADDING-BOTTOM: 0cm; WIDTH: 446.5pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" class="" vAlign=top width=595&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Vulnerabilidad en Windows Explorer podría permitir la ejecución remota de código &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: black 1pt solid; WIDTH: 63.4pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" class="" vAlign=top width=85&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;MS08-039 &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; PADDING-BOTTOM: 0cm; WIDTH: 446.5pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" class="" vAlign=top width=595&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Vulnerabilidades en Outlook Web Access podrían permitir la elevación de privilegios &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: black 1pt solid; WIDTH: 63.4pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1" class="" vAlign=top width=85&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;MS08-040 &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; PADDING-BOTTOM: 0cm; WIDTH: 446.5pt; BORDER-TOP-COLOR: #f0f0f0; PADDING-TOP: 0cm; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-top-themecolor: text1; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" class="" vAlign=top width=595&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Vulnerabilidades en SQL Server podrían permitir la elevación de privilegios &lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: es"&gt;
&lt;P&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;U&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Detección&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;U&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;
&lt;P mce_keep="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Para saber si su sistema necesita estas actualizaciones, puede utilizar la herramienta Microsoft Baseline Analyzer (MBSA).&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Las actualizaciones podrían requerir el reinicio del equipo. &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;U&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Atención&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;U&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;
&lt;P mce_keep="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN-US&gt;MS08-039&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN-US&gt;: Outlook Web Access Premium &lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;no es afectado&lt;/SPAN&gt;&lt;SPAN lang=EN-US&gt;, solo Outlook Web Access Light. ¿Como &lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;saber&amp;nbsp;si uso&lt;/SPAN&gt;&lt;SPAN lang=EN-US&gt;&amp;nbsp;OWA Light? &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2 face=verd&gt;Cuando su navegador no soporte ActiveX y las opciones de &lt;FONT color=#0000ff&gt;&lt;A class="" href="http://blogs.technet.com/swi/archive/2008/07/08/MS08-039-which-users-are-vulnerable-to-OWA-XSS-vulnerability.aspx" target=_blank mce_href="http://blogs.technet.com/swi/archive/2008/07/08/MS08-039-which-users-are-vulnerable-to-OWA-XSS-vulnerability.aspx"&gt;IFRAME restringida&lt;/A&gt;&lt;/FONT&gt;, solo puede utilizar OWA Light. Puede elegir entre los dos modos de OWA cuando su navegador soporte estas opciones. Para más información: &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/swi/archive/2008/07/08/ms08-040-how-to-spot-potentially-dangerous-mtf-files-crossing-network-boundary.aspx"&gt;&lt;FONT size=2 face=verd&gt;http://blogs.technet.com/swi/archive/2008/07/08/ms08-040-how-to-spot-potentially-dangerous-mtf-files-crossing-network-boundary.aspx&lt;/FONT&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;El actualización es para el servidor de Exchange, pero es el cliente (OWA)&amp;nbsp; el que esta potencialmente&amp;nbsp;en riesgo. &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-ansi-language: es"&gt;MS08-040:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&amp;nbsp;La detección&amp;nbsp;e instalación de esta actualización puede ser complicada. Lea el &lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx"&gt;FAQ&lt;/A&gt; del boletín antes de instalarla.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="mso-ansi-language: es"&gt;&lt;FONT size=2&gt;&lt;FONT face=verd&gt;Por favor, este es mi primero articulo de las actualizaciones de seguridad, si prefiere más información&amp;nbsp;sobre estos&amp;nbsp;artículos, informarme. ¡No es mi intención reemplazar&amp;nbsp;los boletines! &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3085794" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ksarens/archive/tags/Seguridad/default.aspx">Seguridad</category><category domain="http://blogs.technet.com/ksarens/archive/tags/Boletines/default.aspx">Boletines</category></item><item><title>Inyección SQL... esta bajo ataque?</title><link>http://blogs.technet.com/ksarens/archive/2008/06/15/un-ataque-inyecci-n-sql.aspx</link><pubDate>Sun, 15 Jun 2008 23:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3071513</guid><dc:creator>ksarens</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ksarens/comments/3071513.aspx</comments><wfw:commentRss>http://blogs.technet.com/ksarens/commentrss.aspx?PostID=3071513</wfw:commentRss><description>&lt;P&gt;&lt;FONT face=Verdana size=2&gt;Hay muchos sitios y blogs que hablan sobre el tema de inyección SQL. Puede encontrar toda la información en este artículo, y más, en los sitios siguientes:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;El blog de SWI: &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx" mce_href="http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx"&gt;&lt;FONT face=Verdana size=2&gt;http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;El blog de Neil Carpenter: &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx" mce_href="http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx"&gt;&lt;FONT face=Verdana size=2&gt;http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx" mce_href="http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx"&gt;&lt;FONT face=Verdana size=2&gt;http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;La inyección SQL últimamente es un tema que recibe mucha atención.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;La verdad es que no es falta de una explotación de vulnerabilidad de IIS o SQL conocido o 0-day. Hemos recibido muchos casos de inyección SQL y todos son fallos de código ASP/ASPX. A demás, el usuario de SQL utilizando su aplicación ASP no necesita ser un sysadmin.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;En general, la inyección SQL es el resultado de:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Verdana size=2&gt;Validación floja de los datos entrada &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Verdana size=2&gt;Construcción dinámica de las sentencias SQL. &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Verdana size=2&gt;Usuarios de SQL demasiado privilegiados &lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;&lt;FONT face=Verdana size=2&gt;Detección:&lt;/FONT&gt;&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;¡Ya sabemos dos cosas que son muy importantes para revisar y evitar un ataque de inyección SQL!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;· El código ASP/ASPX&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;· Los derechos de usuarios de SQL&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;Al primero, hay que saber si nuestros sitios están o estaban bajo ataque. Por eso, tenemos que analizar los logs de IIS. Hay muchas herramientas de consultas disponibles en Internet por hacer esto, una es LogParser. Podemos ejecutar la siguiente:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;LogParser -i:iisw3c -o:csv "SELECT * INTO suspicious.csv FROM ex*.log WHERE cs-uri-query LIKE '%CAST(%' or cs-uri-query LIKE '%dEcLaRe%'"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;O puede descargar una herramienta que lo hace automáticamente: &lt;/FONT&gt;&lt;A href="http://www.codeplex.com/Release/ProjectReleases.aspx?ProjectName=WSUS&amp;amp;ReleaseId=13436" mce_href="http://www.codeplex.com/Release/ProjectReleases.aspx?ProjectName=WSUS&amp;amp;ReleaseId=13436"&gt;&lt;FONT face=Verdana size=2&gt;http://www.codeplex.com/Release/ProjectReleases.aspx?ProjectName=WSUS&amp;amp;ReleaseId=13436&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;¡Si el log tiene datos, tenemos un problema!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;En caso de inyección SQL que hemos visto últimamente, buscamos por el texto así:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana color=#808080 size=2&gt;DECLARE%20@S%20NVARCHAR(4000);SET%20@S=CAST(0x440045004300...7200%20AS%20NVARCHAR(4000));EXEC(@S);--&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;Verificamos si un &amp;lt;script&amp;gt; tag estaba inyectado en las tablas de la base de datos utilizado con el aplicativo de web. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;&lt;FONT face=verd size=2&gt;Acción:&lt;/FONT&gt;&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;¡Es muy importante cerrar el acceso a nuestro aplicativo de web ahora mismo para proteger la gente quien lo visita! &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;Antes de abrirlo, tenemos que revisar el código ASP/ASPX y el usuario de SQL o contactamos el vendedor del aplicativo de web. El log contiene las páginas web que están utilizando para el ataque. Estas páginas son buenas para empezar de revisar el código. Presta atención que necesitamos revisar todas las páginas ASP/ASPX, no solo aquellas listadas en el log.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;Hay métodos para filtrar inyección SQL utilizando palabras muy conocidas como CAST, DECLARE pero estos métodos solo son temporales y no es seguro que bloqueen todos. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;Para más información: &lt;/FONT&gt;&lt;A href="http://blogs.iis.net/nazim/archive/2008/04/28/filtering-sql-injection-from-classic-asp.aspx" mce_href="http://blogs.iis.net/nazim/archive/2008/04/28/filtering-sql-injection-from-classic-asp.aspx"&gt;&lt;FONT face=verd size=2&gt;http://blogs.iis.net/nazim/archive/2008/04/28/filtering-sql-injection-from-classic-asp.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;Puede encontrar enlaces de los sitios abajo que pueden ayudarle de corregir el código:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;SLQ Injection, ASP.NET, ADO.NET &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/bb671351.aspx" mce_href="http://msdn.microsoft.com/en-us/library/bb671351.aspx"&gt;&lt;FONT face=verd size=2&gt;http://msdn.microsoft.com/en-us/library/bb671351.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;SQL Injection in ASP code (diferente que arriba!) &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc676512.aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc676512.aspx"&gt;&lt;FONT face=verd size=2&gt;http://msdn.microsoft.com/en-us/library/cc676512.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verd size=2&gt;How SQL Injection works &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/ms161953.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms161953.aspx"&gt;&lt;FONT face=verd size=2&gt;http://msdn.microsoft.com/en-us/library/ms161953.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3071513" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ksarens/archive/tags/Seguridad/default.aspx">Seguridad</category><category domain="http://blogs.technet.com/ksarens/archive/tags/SQL+Injection/default.aspx">SQL Injection</category></item></channel></rss>