<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">The Microsoft Security Response Center (MSRC)</title><subtitle type="html">Working to help protect customers from vulnerabilities in Microsoft software</subtitle><id>http://blogs.technet.com/msrc/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/msrc/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2009-07-29T16:51:00Z</updated><entry><title>November 2009 Bulletin Release Advance Notification </title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/05/november-2009-bulletin-release-advance-notification.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/05/november-2009-bulletin-release-advance-notification.aspx</id><published>2009-11-05T16:12:00Z</published><updated>2009-11-05T16:12:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; for the November 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;To help customers plan and prioritize for this month’s security updates, &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;we wanted to let you know that we will be releasing 6 bulletins (three critical and three important) addressing 15 vulnerabilities, affecting Windows and Microsoft Office products. Customers should plan a restart for the Windows bulletins. The Office bulletins may not require a restart if the components being updated are not in use. More information about the upcoming security updates can be found on the TechNet Web site.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;The target release day is next Tuesday Nov. 10 at 10:00 a.m. PST (UTC -8). At that time we will post more detailed information about the bulletins here and on our &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/srd" mce_href="http://blogs.technet.com/srd"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Security Research &amp;amp; Defense (SRD) blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;. We will also include our Risk and Impact guidance, our Deployment Priority guidance, and an overview video discussing these materials. For more detailed information concerning the upcoming bulletins, please review the ANS page &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;As always, Adrian Stone and I will be hosting a webcast to cover the bulletins in greater detail the day after bulletins release. So please join us on Wednesday Nov. 11 at 11:00 a.m. PST (UTC -8) and bring any questions you have about the bulletins. We will have a room full of subject matter experts on hand to answer them. To register for the webcast, please follow this &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;link&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3291742" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Microsoft Office" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Office/default.aspx" /></entry><entry><title>Update released for MS09-054</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/02/update-released-for-ms09-054.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/02/update-released-for-ms09-054.aspx</id><published>2009-11-02T22:01:00Z</published><updated>2009-11-02T22:01:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Today we released an update &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;that addresses two issues with &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; that a limited number customers reported to us through our Customer Service and Support (CSS) group. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;These two issues can affect the proper display of web pages. For additional details, please refer to Microsoft Knowledge Base article&amp;nbsp;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Security update &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; was released as part of the October Security Bulletin Release cycle and protects against the vulnerabilities outlined in the bulletin. Also, we’re not currently aware of any attempts to attack the vulnerabilities. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;While the number of customers affected by these two issues is limited, after working both with affected customers and our CSS group, we feel the best thing for all customers is to proactively provide this update as widely as possible to help prevent other customers from encountering the issues outlined in the KB.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Because of this, we plan to release this update through the same broad release channels as the original security update, &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;. Customers will see &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;offered by default through Windows Update, Microsoft Update, and Automatic Updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Customers who have applied &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;should go ahead and apply &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;. Customers who have not yet applied &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;should apply both &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;and &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;There’s more information on the update and the issues it addresses in Microsoft Knowledge Base article &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thanks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Christopher&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3290929" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>October 2009 Security Bulletin Webcast Questions and Answers</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/20/october-2009-security-bulletin-webcast-questions-and-answers.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/20/october-2009-security-bulletin-webcast-questions-and-answers.aspx</id><published>2009-10-20T21:23:09Z</published><updated>2009-10-20T21:23:09Z</updated><content type="html">&lt;p&gt;Hi everyone. We have posted the questions and answers from the security bulletin webcast we conducted on October 14 at &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-october-2009.aspx"&gt;this link&lt;/a&gt;. It was clear from all of the questions concerning MS09-062 (the GDI+ update) that there is some confusion on how to apply the update when you have a combination of SQL Server and Windows 2000 clients. &lt;/p&gt;  &lt;p&gt;To clarify what the bulletin states, if you do not have any Windows 2000 SP4 clients on your network then you do not need to apply the SQL Server update that corresponds to the version of SQL Server you are running. In this case, you would only need to apply the update for the client operating systems on your network. This is because on platforms newer than Windows 2000 SP4, the operating system will use its own version of the affected component (gdiplus.dll) rather than the one distributed by the RSClientPrint ActiveX control through SQL Server Reporting Services. &lt;/p&gt;  &lt;p&gt;In the video below, Adrian Stone and I go in to details on each bulletin to cover the vulnerabilities, affected platforms, attack vectors, and mitigations:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="566"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_320_edge.png, postid=11522" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="314"&gt;More listening and viewing options:         &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt;&lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Next month we will host our live security bulletin webcast on November 11 at 11:00 am Pacific time (UTC -7). To register for that webcast, please follow &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3287979" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast Q &amp;amp; A" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/default.aspx" /><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /></entry><entry><title>October 2009 Security Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx</id><published>2009-10-13T17:05:34Z</published><updated>2009-10-13T17:05:34Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for October 2009&lt;/p&gt;  &lt;p&gt;This month, we released &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;13 new bulletins&lt;/a&gt; which address 33 vulnerabilities in Windows, Internet Explorer and Microsoft Office. Since we published this information in our advance notification (ANS) last Thursday, we have been asked “is this the most bulletins Microsoft has ever released”? The short answer to that question is yes. However, we have, on several occasions, released between 10 and 12 bulletins so this is business as usual. All of our updates go through extensive quality testing and when they reach the bar for broad distribution, we schedule them for release. &lt;/p&gt;  &lt;p&gt;As we noted in the ANS last week, two of the updates address open Security Advisories. &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx"&gt;MS09-050&lt;/a&gt; addresses the SMBv2 issue in &lt;a href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;Security Advisory 975497&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-053.mspx"&gt;MS09-053&lt;/a&gt; addresses the IIS issue discussed in &lt;a href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;Security Advisory 975191&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Another issue being addressed this month that has received some public attention has to do with security certificates used for authentication. The vulnerabilities being addressed by Security Bulletin &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx"&gt;MS09-056&lt;/a&gt; could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. We are aware that a rogue certificate was distributed in a public forum but we are not aware of any attempts to use this to attack users. &lt;/p&gt;  &lt;p&gt;Below is the severity summary and exploitability index for the 13 new bulletins. We also refer to this as the overall risk and impact summary. As you can see, eight of the bulletins have a rating of Critical. Of those eight, six have an exploitability index rating of 1, which means we believe it is highly likely that we will see exploit code in the wild within the first 30 days from the date of release. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;To help with deployment planning, we started publishing our guidance (beginning last month) on which bulletins should be considered first for deployment. Obviously one size does not fit all and each customer will need to consider their own unique situations in addition to this guidance. Our approach is to take a combination of the severity, the exploitability index rating, the range of products affected, and potential mitigations to group these in to a priority 1, 2 or 3. Our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense&lt;/a&gt; team, who represent some of the best security researchers in the world, play a key role in this every month as well. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Most of this month’s updates require a restart, so please refer to the bulletins when you’re planning your deployment to ensure you’re fully protected. We want to specifically note that MS09-050 requires a restart but will not prompt you to do so if you install the update manually. &lt;/p&gt;  &lt;p&gt;As we do every month, Adrian Stone and I provide a high-level overview of this month’s bulletin release in the following video:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="554"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_320_edge.png, postid=11402" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="302"&gt;Other listening and viewing options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;This month we are also re-releasing &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx"&gt;MS08-069, vulnerability in Microsoft XML Core Services could allow remote code execution (955218)&lt;/a&gt; to add detection for Windows 7 and Windows Server 2008 R2. This component does not ship with these platforms but many applications install it in order to use its functionality.&lt;/p&gt;  &lt;p&gt;Finally, you may also notice a change in the severity rating since the advance notification for several versions of Windows in the .NET bulletin (&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx"&gt;MS09-061&lt;/a&gt;). We have elevated the severity of these products from Important to Critical. We do not typically make changes after the advance notification goes out but during our ongoing investigation to protect customers, we determined that this was the appropriate rating for these products when certain versions of the .NET Framework are installed on them. &lt;/p&gt;  &lt;p&gt;We encourage all customers to join us tomorrow when Adrian and I will go in to detail on each bulletin and, along with a room full of subject matter experts, answer all of your questions live. So if you can, please join us at 11:00 a.m. PDT (UTC -7). You can register for the webcast at &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;Update – Resource links:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx" target="_blank"&gt;Assessing the risk of the October security bulletins&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx" target="_blank"&gt;MS09-051: A note on the affected platforms&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx" target="_blank"&gt;MS09-050: Exploit timeline for SMB2 RCE vulnerability&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx" target="_blank"&gt;MS09-054: Extra info on the attack surface for the IE security bulletin&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx" target="_blank"&gt;MS09-061: More information about the .NET security bulletin&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx" target="_blank"&gt;Scanti-ly Clad – Another Rogue Stripped by MSRT&lt;/a&gt; – Microsoft Malware Protection Center blog &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Update (10/13) Changed the number of vulnerabilities addressed to 33 from 34. CVE-2009-2493 was counted in both MS09-055 and MS09-060. &lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3286576" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="ActiveX" scheme="http://blogs.technet.com/msrc/archive/tags/ActiveX/default.aspx" /><category term="Killbit" scheme="http://blogs.technet.com/msrc/archive/tags/Killbit/default.aspx" /><category term="Microsoft Windows" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Windows/default.aspx" /><category term="Microsoft Office" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Office/default.aspx" /><category term="Attack Vector" scheme="http://blogs.technet.com/msrc/archive/tags/Attack+Vector/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Malicious Software Removal Tool (MSRT)" scheme="http://blogs.technet.com/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/default.aspx" /><category term="Responsible Disclosure " scheme="http://blogs.technet.com/msrc/archive/tags/Responsible+Disclosure+/default.aspx" /><category term="Risk Assessment" scheme="http://blogs.technet.com/msrc/archive/tags/Risk+Assessment/default.aspx" /></entry><entry><title>October 2009 Bulletin Release Advance Notification</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/08/october-2009-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/08/october-2009-bulletin-release.aspx</id><published>2009-10-08T16:23:00Z</published><updated>2009-10-08T16:23:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; for the October 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;For October we are releasing 13 bulletins (eight critical and five important), addressing 34 vulnerabilities, affecting Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools, and SQL Server. Most of these updates require a restart so please factor that into your deployment planning. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Among the updates this month, we are closing out two current security advisories:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975497.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;&lt;FONT face=Calibri size=3&gt;Vulnerabilities in SMB Could Allow Remote Code Execution (975497)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT face=Calibri size=3&gt;Vulnerabilities in the FTP Service in Internet Information Services (975191)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Usually we do not go into this level of detail in the advance notification but we felt that it is important guidance so customers can plan accordingly and deploy these updates as soon as possible.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The target to release the October security updates is next Tuesday Oct. 13 at 10:00 a.m. PDT (UTC -8). Check back here at that time for a more detailed overview of the updates (including an overview video), our risk and impact summary and our deployment prioritization guide. More information about the upcoming security updates can be found &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; in&amp;nbsp;the ANS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;After you have had a chance to read through the bulletins, please join us for a live webcast on Wednesday Oct. 14 at 11:00 a.m. PDT (UTC -7) and get answers to any questions you might have. To register, just follow &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;this link.&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3285484" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /></entry><entry><title>September 2009 Security Bulletin Webcast Video and Customer Q and A</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/11/september-2009-security-bulletin-webcast-video-and-customer-q-and-a.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/11/september-2009-security-bulletin-webcast-video-and-customer-q-and-a.aspx</id><published>2009-09-12T01:11:39Z</published><updated>2009-09-12T01:11:39Z</updated><content type="html">&lt;p&gt;In the September 2009 security bulletin webcast, it was clear that customers had a lot of concerns about &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; as almost half the questions we answered were on that topic. &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-september-2009.aspx"&gt;The questions and answers from the session are now posted here on the blog&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;As we mentioned in the webcast, The &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; bulletin has been updated to call out Windows XP in the affected products list with a severity rating of low for the two Denial-of-Service vulnerabilities (the third, Remote Code Execution vulnerability, does not affect XP). As stated in the bulletin, in the default configuration, Windows XP is not affected by any of the issues addressed by the bulletin. However, we heard from enterprise customers that custom configurations that put XP in a vulnerable state are in use so we updated the bulletin for clarity. Does this mean there will be an update for Windows XP? No and I will use the text from the bulletin to explain why:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;strong&gt;If Windows XP is listed as an affected product, why is Microsoft not issuing an update for it?        &lt;br /&gt;&lt;/strong&gt;By default, Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows XP Professional x64 Edition Service Pack 2 do not have a listening service configured in the client firewall and are therefore not affected by this vulnerability. Windows XP Service Pack 2 and later operating systems include a stateful host firewall that provides protection for computers against incoming traffic from the Internet or from neighboring network devices on a private network. The impact of a denial of service attack is that a system would become unresponsive due to memory consumption. However, a successful attack requires a &lt;u&gt;sustained flood&lt;/u&gt; of specially crafted TCP packets, and the system will recover once the flood ceases. This makes the severity rating Low for Windows XP. Windows XP is not affected by CVE-2009-1925. Customers running Windows XP are at reduced risk, and Microsoft recommends they use the firewall included with the operating system, or a network firewall, to block access to the affected ports and limit the attack surface from untrusted networks.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Concerning &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; and Windows 2000, the scenario is very similar to Windows XP in that an attack requires a sustained flood of specially crafted TCP packets and the system will recover once the flood stops. Keeping Windows 2000 servers behind a NAT or reverse proxy can help to reduce risk.&lt;/p&gt;  &lt;p&gt;In the last blog post I called out &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt; as the highest priorities for deployment and while MS09-048 has received a lot of attention, we want to continue to stress getting those updates installed to all users. &lt;/p&gt;  &lt;p&gt;This month we are leaving the Q and A out of the video because we have &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-september-2009.aspx"&gt;posted those questions to the blog&lt;/a&gt; and to keep the overall duration of the video down. If you like it this way or if you prefer us to leave that portion in, head over to the &lt;a href="http://edge.technet.com/Media/MSRC-Monthly-Security-Bulletin-Webcast-September-2009/"&gt;TechNet Edge site&lt;/a&gt; where we host the videos and leave your feedback there. &lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="614"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/8/4/8/msrcsept09webcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_320_edge.png, postid=8482" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="362"&gt;More listening and viewing options:         &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/8/4/8/msrcsept09webcast_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt;&lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Following the webcast we got feedback that folks liked the new deployment priority slide as well as the new detail slides for each bulletin. We appreciate the feedback and will keep looking for ways to improve the content. &lt;/p&gt;  &lt;p&gt;Please plan on joining us for our next regularly scheduled webcast on October 13 at 11:00 a.m&lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;. Click HERE to register&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3280657" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast Q &amp;amp; A" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/default.aspx" /><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Attack Vector" scheme="http://blogs.technet.com/msrc/archive/tags/Attack+Vector/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Malicious Software Removal Tool (MSRT)" scheme="http://blogs.technet.com/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/default.aspx" /></entry><entry><title>Microsoft Security Advisory 975497 Released</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/08/microsoft-security-advisory-975497-released.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/08/microsoft-security-advisory-975497-released.aspx</id><published>2009-09-09T02:35:00Z</published><updated>2009-09-09T02:35:00Z</updated><content type="html">&lt;FONT face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;We’ve just released Microsoft released Security &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975497.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;&lt;FONT color=#0000ff size=3&gt;Advisory 975497&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; that provides information about a new, irresponsibly reported vulnerability in SMB 2.0. Our investigation has shown that Windows Vista, Windows Server 2008 and Windows 7 RC are affected by this vulnerability. Windows 7 RTM, Windows Server 2008 R2, Windows XP and Windows 2000 are not affected by this vulnerability. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;The Security Advisory outlines steps that Windows Vista and Windows Server 2008 customers can take to help protect themselves while we work on a security update for this issue.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;As always, we’ve provided information through &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT color=#0000ff size=3&gt;Microsoft Active Protections Program (MAPP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt; as well as the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank mce_href="http://www.microsoft.com/security/msra/default.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT color=#0000ff size=3&gt;Microsoft Security Response Alliance (MSRA)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt; that they can use to help provide broader protections to customers. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;We will update you through our security advisory and the MSRC Weblog as we have new information.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Christopher&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279917" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>September 2009 Security Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx</id><published>2009-09-08T20:50:47Z</published><updated>2009-09-08T20:50:47Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for September 2009&lt;/p&gt;  &lt;p&gt;Hello again,&lt;/p&gt;  &lt;p&gt;This month we released five critical bulletins to address vulnerabilities in Windows and protect customers from two types of threats:&lt;/p&gt;  &lt;p&gt;1. Browser based attacks where websites hosting malicious code attempt to compromise visitors. This includes &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt;, &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-046.mspx"&gt;MS09-046&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;2. Network based scenarios where attackers attempt Remote Code Execution (RCE) or Denial-of-Service (DoS) type attacks. This includes &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-049.mspx"&gt;MS09-049&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;For this set of bulletins, we consider the first category to be the biggest threat to customers overall as reflected in our Severity and Exploitability Index slide where we present a high level, aggregate view of each bulletin:&lt;/p&gt; &lt;a href="http://blogs.technet.com/photos/msrcteam/images/3279846/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3279846/original.aspx" width="500" /&gt;&lt;/a&gt;   &lt;p&gt;We also refer to the slide above as our risk and impact assessment. The risk of exploitation combined with the impact of the vulnerability should help customers prioritize these bulletins for deployment. To provide further guidance in this area, this month we are providing a new deployment prioritization assessment. As noted on the slide below, there are several factors that we used to determine the priority. However, there are many other potential variables that may be unique to your environment so we recommend each customer perform their own assessment and install all security updates as soon as possible.&lt;/p&gt; &lt;a href="http://blogs.technet.com/photos/msrcteam/images/3279847/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3279847/original.aspx" width="500" /&gt;&lt;/a&gt;   &lt;p&gt;As you can see, we give &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt; the highest deployment priority mainly due to these being browse and own attack scenarios and a high exploitability index rating. Exploits for MS09-047 can also be created through specially crafted files such as ASF and MP3 audio files. These files could then be sent via email. &lt;/p&gt;  &lt;p&gt;Concerning &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-046.mspx"&gt;MS09-046&lt;/a&gt;, our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense&lt;/a&gt; (SRD) team has determined that reliable exploit code would be difficult to produce hence the lower exploitability index rating. In this case and with MS09-045, users with Internet Explorer 8.0 are at reduced risk due to the protections provided by Date Execution Prevention (&lt;a href="http://windowshelp.microsoft.com/Windows/en-US/Help/186de3d0-01af-4d4c-981d-674637d2f4bf1033.mspx"&gt;DEP&lt;/a&gt;). Also, while this is an ActiveX control update, it is not related to the ATL issue discussed in &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;security advisory 973882&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;The wireless update provided in &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-049.mspx"&gt;MS09-049&lt;/a&gt; addresses an issue with the Wireless AutoConfig Service in both Windows Vista and Windows Server 2008. We consider this one hard to exploit due to the work that has gone in to hardening the Windows Heap Manager. The SRD blog has a &lt;a href="http://blogs.technet.com/srd/archive/2009/08/04/preventing-the-exploitation-of-user-mode-heap-corruption-vulnerabilities.aspx"&gt;great write up&lt;/a&gt; on this.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; contains updates for three vulnerabilities. One of those is a Remote Code Execution vulnerability affecting only Windows Vista and Windows Server 2008. We think this one would be difficult to produce reliable exploit code for as well. The SRD team did a &lt;a href="http://blogs.technet.com/srd" target="_blank"&gt;write up&lt;/a&gt; on this one to provide additional details so I recommend reading it. The other two vulnerabilities are both Denial-of-Service issues and I want to point out that while Windows 2000 is affected by these, an update is not being provided. This is because the architecture to protect TCP/IP properly does not exist in Windows 2000. Customers on this platform who cannot update their systems to Windows Server 2003 or 2008 will need to carefully monitor their networks and assure that firewall best practices are followed.&lt;/p&gt;  &lt;p&gt;Also, we re-released &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx"&gt;MS09-037&lt;/a&gt;. This bulletin for vulnerabilities in the Active Template Library (ATL), affecting components that shipped with Windows, was originally released in August 2009. In our ongoing investigation into the ATL issue, we identified a related vulnerable control so this bulletin has been updated to include it. This additional update affects users of Windows XP Media Center 2005 and Windows Vista systems. It is important to note that to date, we have not seen any new controls being used in active attacks. The Video ActiveX control that was under limited exploitation and which drove our out of band update in July, is still the only one we have seen used in attacks. Please refer to &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt; for the latest information and guidance from our investigation.&lt;/p&gt;  &lt;p&gt;In this month’s overview video, Adrian Stone and I discuss the severity and exploitability index slide and the new deployment priority slide in a little more detail:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="541"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/4/7/msrcs09v3_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_320_edge.png, postid=7467" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="289"&gt;More viewing and listening options:          &lt;br /&gt;          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/4/7/msrcs09v3_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Please join Adrian and I for a live webcast tomorrow, Wednesday Sept. 9 at 11:00 a.m. PDT (UTC -7) where we will go in to detail on each bulletin and answer all of your questions, with the help of a room full of subject matter experts. &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;Go here to register &amp;gt;&amp;gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In this post I also want to provide some clarity on Windows 7 and Windows Server 2008 R2. After the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx"&gt;Advance Notification&lt;/a&gt; went out last Thursday, we saw speculation that these new products may be affected because they were not specifically listed. To be clear, Windows 7 and Windows Server 2008 R2 are not affected by any of the September security updates. Since the date these products were released to manufacturing (July 09), they have been part of our standard security update process. As such, they would have been called out in the ANS if they were affected. &lt;/p&gt;  &lt;p&gt;Finally, we are not addressing the IIS/FTP vulnerability announced in &lt;a href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;Security Advisory 975191&lt;/a&gt; with this month’s security bulletin release. Our teams are still working on an update for this issue and we encourage customers to review the advisory for the most current guidance on this issue.&lt;/p&gt;  &lt;p&gt;That’s it for this month. If you cannot join us for the webcast tomorrow, come back to the blog Friday afternoon as we will be posting the webcast video and Q&amp;amp;A from the session.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights.*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279860" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>Microsoft Security Advisory 975191 Revised</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/03/microsoft-security-advisory-975191-revised.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/03/microsoft-security-advisory-975191-revised.aspx</id><published>2009-09-04T08:50:00Z</published><updated>2009-09-04T08:50:00Z</updated><content type="html">&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Hi Everyone,&lt;BR&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Today we updated &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Security Advisory &lt;/SPAN&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;975191&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&amp;nbsp;as we are now seeing limited attacks.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Additionally, a new proof of concept published allowing for Denial of Service (DoS) attacks on Windows XP and Windows Server 2003 with read access to the File Transfer Protocol (FTP) service. This does not require Write access.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also, a new POC allowing DoS was disclosed this afternoon that affects the version of FTP 6 which shipped with Windows Vista and Windows Server 2008.&amp;nbsp; Customers should be aware that the Download Center has FTP 7.5 available for Windows Vista and Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: PMingLiU; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;The initial vulnerability was not responsibly disclosed to Microsoft, which has led to limited, active attacks putting customers at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft recommends customers review and implement the workarounds provided in the Advisory under the &lt;SPAN style="mso-bidi-font-weight: bold"&gt;Workaround&lt;/SPAN&gt; section.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;More information on suggested actions can be found in &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Arial"&gt;&lt;A href="http://support.microsoft.com/kb/975191"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Knowledge Base Article 975191&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;While these workarounds do not completely mitigate the threat of DoS, &lt;SPAN style="mso-bidi-font-style: italic"&gt;we’re currently investigating the issue as part of our &lt;/SPAN&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" target=_blank&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-style: italic"&gt;&lt;FONT size=3&gt;Software Security Incident Response Process (SSIRP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-style: italic"&gt;&lt;FONT size=3&gt;&amp;nbsp;and working to develop a security update.&amp;nbsp; This update will be released once it reaches an appropriate level of quality for broad distribution.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-style: italic"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Additionally, we are actively working with partners in our &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Active Protections Program (MAPP)&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; as well as the &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Security Response Alliance (MSRA)&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; to share information that they can use to provide broader protections to customers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;For more technical details on the advisory, please see what our colleagues have written on Microsoft’s Internet Information Services (IIS) blog here: &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://blogs.iis.net/"&gt;&lt;SPAN style="COLOR: blue"&gt;Microsoft IIS Blog&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;. As always, be sure to check back here on the Microsoft Security Response Center (MSRC) blog or in the &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;advisory&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; for any additional information or updates that develop.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Thank you,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Alan Wallace&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="COLOR: blue; mso-fareast-font-family: PMingLiU; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279110" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Active Protections Program (MAPP)" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>September 2009 bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/02/september-2009-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/02/september-2009-bulletin-release.aspx</id><published>2009-09-03T05:27:00Z</published><updated>2009-09-03T05:27:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; for the September 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This month we will be releasing 5 security bulletins, all affecting Windows, and all with an aggregate severity rating of critical. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;As always, the target for release is the second Tuesday of the month at 10:00 a.m. PDT (UTC -8). Please check back here at that time as we will be posting our risk and impact assessment, a new deployment prioritization table and an overview video. Also, we encourage you to join us live on Wednesday September 9 at 11:00 a.m. (UTC -7) for our regular security bulletin webcast where we will cover the bulletins in greater detail and answer questions. &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Click here to register&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;If the files being updated are in use at the time of installation then these updates would require a restart. Otherwise, they would not. For information on the reasons you may be prompted to restart the system, see &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?id=887012" mce_href="http://support.microsoft.com/?id=887012"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Knowledge Base Article 887012&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In related news, you will note that the ANS does not specify an update for the Internet Information Services FTP service vulnerability for which we released &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;security advisory 975191&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on Tuesday of this week. As noted in an &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx" mce_href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;earlier blog post&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;, we have spun up our &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" mce_href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;SSIRP (Software Security Incident Response Process) process&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to address this issue and our teams are working hard to produce an update. Please keep an eye on the advisory for more information and if you are not already, please subscribe to our &lt;/FONT&gt;&lt;A href="https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizard.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&amp;amp;lcid=1033" mce_href="https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizard.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&amp;amp;lcid=1033"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;comprehensive alerts&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to receive updates by email. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;On a final note, I want to highlight our new &lt;/FONT&gt;&lt;A href="http://go.microsoft.com/?linkid=9673472" mce_href="http://go.microsoft.com/?linkid=9673472"&gt;&lt;FONT size=3 face=Calibri&gt;Microsoft Security Update Guide&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; which was written to help IT professionals better understand and use Microsoft security update release information, processes, communications, and tools – and how to manage organizational risk and develop a repeatable, effective deployment mechanism for security updates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278834" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Windows" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Windows/default.aspx" /></entry><entry><title>Microsoft Security Advisory 975191 Released</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx</id><published>2009-09-02T01:24:00Z</published><updated>2009-09-02T01:24:00Z</updated><content type="html">&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Hi Everyone,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;This is Alan Wallace, senior communications manager for our security response communications team.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Today, Microsoft released &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT color=#0000ff&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;Security Advisory &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;975191&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;, to provide customer guidance and protection from a &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;vulnerability that could allow remote code execution on affected systems running the FTP service in Microsoft Internet Information Services (IIS) 5.0, 5.1 and 6.0, and connected to the Internet.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;While we have seen detailed exploit code published on the Internet for this vulnerability, we are &lt;SPAN style="mso-bidi-font-weight: bold"&gt;not&lt;/SPAN&gt; currently aware of active attacks &lt;SPAN style="mso-bidi-font-weight: bold"&gt;that use&lt;/SPAN&gt; this exploit code or of customer impact.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;This vulnerability was not responsibly disclosed to Microsoft and may put customers at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;We’re currently investigating the issue as part of our &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" target=_blank mce_href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Software Security Incident Response Process (SSIRP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;and working to develop a security update.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This update will be released once it reaches an appropriate level of quality for broad distribution.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Affected products include Windows 2000, Windows XP, and &lt;SPAN class=MsoCommentReference&gt;&lt;SPAN style="mso-ansi-font-size: 11.0pt; mso-bidi-font-size: 11.0pt"&gt;W&lt;/SPAN&gt;&lt;/SPAN&gt;indows Server 2003.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Microsoft &lt;SPAN style="mso-bidi-font-family: Calibri"&gt;recommends customers review and implement the workarounds provided in the Advisory under the &lt;B&gt;Workaround&lt;/B&gt; section.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;More information on suggested actions can be found in &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/975191" mce_href="http://support.microsoft.com/kb/975191"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Knowledge Base Article 975191&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;Additionally, we are actively working with partners in our &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Active Protections Program (MAPP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt; as well as the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank mce_href="http://www.microsoft.com/security/msra/default.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Security Response Alliance (MSRA)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; to share information that they can use to provide broader protections to customers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;For more technical details on the advisory, please see what our colleagues have written over on the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/srd" target=_blank mce_href="http://blogs.technet.com/srd"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Security Research and Defense blog&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;As always, be sure to check back here on the MSRC blog or in the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;advisory&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; for any additional information or updates that develop.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thank you,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;Alan&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoPlainText&gt;&lt;SPAN style="FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoPlainText&gt;&lt;SPAN style="FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278582" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Active Protections Program (MAPP)" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>August 2009 Security Bulletin Webcast Video and Customer Q and A</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx</id><published>2009-08-15T02:42:53Z</published><updated>2009-08-15T02:42:53Z</updated><content type="html">&lt;p&gt;As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).&lt;/p&gt;  &lt;p&gt;It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;Security Advisory 972890&lt;/a&gt;: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a &lt;a href="http://support.microsoft.com/fixit#tab0"&gt;Microsoft Fix it&lt;/a&gt; solution) to customers while we worked towards an update for the underlying issue. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx"&gt;MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)&lt;/a&gt;: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx"&gt;MS09-034 – Cumulative Security Update for Internet Explorer (972260)&lt;/a&gt;: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx"&gt;MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)&lt;/a&gt;: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this &lt;a href="http://go.microsoft.com/?linkid=9674481"&gt;MSDN article&lt;/a&gt;. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx"&gt;MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)&lt;/a&gt;: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt;: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.&lt;/p&gt;  &lt;p&gt;Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx"&gt;Q&amp;amp;A here&amp;gt;&amp;gt;&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&amp;amp;A session:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="541"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png, postid=5067" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="289"&gt;More viewing and listening options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png"&gt;Large Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png"&gt;Small Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;Click here to register &amp;gt;&amp;gt;&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Finally, please visit our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense blog&lt;/a&gt; where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new &lt;a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx"&gt;blog aggregator&lt;/a&gt; useful for getting a consolidated view of all of our Trustworthy Computing blogs. &lt;/p&gt;  &lt;p&gt;Thanks, &lt;/p&gt;  &lt;p&gt;Jerry Bryant &lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>August 2009 Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx</id><published>2009-08-11T20:00:36Z</published><updated>2009-08-11T20:00:36Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for August 2009&lt;/p&gt;  &lt;p&gt;Hi everyone,&lt;/p&gt;  &lt;p&gt;This month, we released nine security bulletins. Five of those are rated Critical and four have an aggregate severity rating of Important. Of the nine updates, eight affect Windows and the last one affects Office Web Components (OWC). It is also important to note that five of the six critical updates also have an Exploitability Index rating of “1” which means that we could expect there to be consistent, reliable code in the wild seeking to exploit one or more of these vulnerabilities within the first 30 days from release. The chart below shows the aggregate severity summary and exploitability index ratings for all nine bulletins. This overview chart should guide you in prioritizing this month’s updates in order to protect your systems efficiently and effectively.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" target="_blank"&gt;&lt;img src="http://blogs.technet.com/photos/msrcteam/images/3272462/original.aspx" width="500" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Of particular note in this release is &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx"&gt;MS09-037&lt;/a&gt; which is an update for Microsoft Active Template Library (ATL). Among the five updates in this bulletin is a binary level update for the Microsoft Video ActiveX Control. As you may recall, we originally released &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;Security Advisory 972890&lt;/a&gt; on July 6 in response to an active attack against this component and subsequently released Security Bulletin &lt;a href="http://go.microsoft.com/fwlink/?LinkId=157386"&gt;MS09-032&lt;/a&gt; to supply an official kill bit update (rather than the temporary Microsoft Fix it supplied with the advisory). All of the included vulnerabilities were privately reported, have a critical severity and are rated “1” on our exploitability index. We encourage you to deploy this update as soon as possible. We will be updating &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt; to include a reference to this bulletin as it relates to ATL. &lt;/p&gt;  &lt;p&gt;Another of the updates I would like to draw your attention to is &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx"&gt;MS09-043&lt;/a&gt;, which addresses the Office Web Components vulnerability discussed in &lt;a href="http://www.microsoft.com/technet/security/advisory/973472.mspx"&gt;Security Advisory 973472&lt;/a&gt;. We strongly encourage customers to review and deploy this bulletin if applicable given that we have seen exploitation in the wild. Even though this update addresses an ActiveX control issue, it is unrelated to the ATL issue we discuss in &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;If you are running a WINS server on either Windows 2000 or Windows Server 2003 then I would also call your attention to &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx"&gt;MS09-039&lt;/a&gt; as this one has the potential for an un-authenticated, self-replicating attack across the network. Installing the update will protect your systems should any attacks be developed to exploit the vulnerabilities addressed in this update but at this time, we are not aware of any exploit code in the wild.&lt;/p&gt;  &lt;p&gt;In the video below, Adrian Stone and I provide an overview of this month’s release and discuss the updates above in a little more detail. For even greater detail on all nine bulletins, please join us tomorrow, August 12 at 11:00 a.m. (UTC-7) for our monthly bulletin webcast where we will also address your questions concerning these updates. &lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Click HERE to register &amp;gt;&amp;gt;&lt;/a&gt;&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="2" width="544" border="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/0/0/5/msrcaug09itov_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_large_edge.png, postid=5003" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="292"&gt;More viewing and listening options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_large_edge.png"&gt;Large Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_small_edge.png"&gt;Small Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/3/0/0/5/msrcaug09itov_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://mschnlnine.vo.llnwd.net/d1/edge/3/0/0/5/msrcaug09itov_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;We are also re-releasing two bulletins this month:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-029.mspx"&gt;MS09-029&lt;/a&gt; to address a print spooler issue on various Windows platforms that could cause the print spooler to stop responding in certain scenarios. Please see &lt;a href="http://support.microsoft.com/kb/961371"&gt;Knowledge Base article 961371&lt;/a&gt; for details. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx"&gt;MS09-035&lt;/a&gt; to offer new updates for Visual Studio 2005 SP1, Visual Studio 2008 and Visual Studio 2008 SP1. The new security updates are for developers who use Visual Studio to create components and controls for mobile applications using ATL for Smart Devices. All Visual Studio developers should install these new updates so that they can use Visual Studio to create components and controls that are not vulnerable to the reported issues. For more information on this known issue, see &lt;a href="http://support.microsoft.com/kb/969706"&gt;Knowledge Base Article 969706&lt;/a&gt;. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To close this month’s blog post, I would encourage systems administrators and application developers to read through &lt;a href="http://www.microsoft.com/technet/security/advisory/973811.mspx"&gt;Security Advisory 973811&lt;/a&gt; which was also released today. This is a non-security update that enables new protection technology that can be used to enhance the protection of credentials when authenticating network connections. &lt;/p&gt;  &lt;p&gt;As always, please check the &lt;a href="http://blogs.technet.com/srd"&gt;Security Research and Defense blog&lt;/a&gt; for additional technical information on these updates and we hope to see you at the webcast tomorrow.&lt;/p&gt;  &lt;p&gt;Thanks,&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272463" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="ActiveX" scheme="http://blogs.technet.com/msrc/archive/tags/ActiveX/default.aspx" /><category term="Internet Explorer (IE)" scheme="http://blogs.technet.com/msrc/archive/tags/Internet+Explorer+_2800_IE_2900_/default.aspx" /><category term="Attack" scheme="http://blogs.technet.com/msrc/archive/tags/Attack/default.aspx" /><category term="Defense-in-depth" scheme="http://blogs.technet.com/msrc/archive/tags/Defense-in-depth/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Risk Assessment" scheme="http://blogs.technet.com/msrc/archive/tags/Risk+Assessment/default.aspx" /></entry><entry><title>August 2009 Advance Notification</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/08/06/august-2009-advance-notification.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/08/06/august-2009-advance-notification.aspx</id><published>2009-08-06T20:07:00Z</published><updated>2009-08-06T20:07:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-aug.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-aug.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Advance Notification&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt; for the August 2009 Security Bulletin Release&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;In this month’s Advance Notification we are making customers aware that next Tuesday August 11&lt;SUP&gt;th&lt;/SUP&gt; we plan to release 9 security bulletins at approximately 10:00 a.m. PDT (UTC -8). Those bulletins consist of:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;8 bulletins affecting Windows four of which are rated critical and&amp;nbsp;four are rated as important.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;One of the critical Windows bulletins also affects Client for Mac.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;One of the important Windows bulletins also affects the .NET Framework.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;One critical bulletin affecting Microsoft Office, Microsoft Visual Studio, Microsoft ISA Server and Microsoft BizTalk Server. This update addresses the issue discussed in security advisory &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/973472.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/973472.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;973472&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;Concerning restart requirements, all of the updates for Windows will require a restart except one (this is the update also affecting the .NET Framework). The Office related bulletin may require a restart if the binaries being updated are in use. To reduce your chances of requiring a restart, please see &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://support.microsoft.com/kb/887012" mce_href="http://support.microsoft.com/kb/887012"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;Knowledge Base article 887012&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;On release day, look for additional information on both this blog and the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/srd" mce_href="http://blogs.technet.com/srd"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;Security Research and Defense blog&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;. &amp;nbsp;If you have questions or would like more information about this month’s release, please plan to attend our regularly scheduled security bulletin webcast on Wednesday, August 12, 2009, at 11:00 a.m. PDT (UTC –7). &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US" mce_href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407484&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Click HERE to register&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thanks!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Jerry Bryant&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Update 8/7/2009: corrected the number of critical and important Windows bulletins to four each.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3271229" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /></entry><entry><title>Security Bulletin Webcast Questions and Answers – Out-Of-Band July 2009</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/07/29/security-bulletin-webcast-questions-and-answers-out-of-band-july-2009.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/07/29/security-bulletin-webcast-questions-and-answers-out-of-band-july-2009.aspx</id><published>2009-07-30T02:51:00Z</published><updated>2009-07-30T02:51:00Z</updated><content type="html">&lt;SPAN lang=EN style="mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&lt;FONT face=Calibri&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Hi,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;In conjunction with the Microsoft July 2009 Out-of-Band Bulletin release, we conducted two public webcasts to assist customers. During these webcasts, we were able to address 60 questions in the time allotted. The questions centered primarily on &lt;SPAN style="COLOR: blue"&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx"&gt;&lt;FONT color=#0000ff&gt;MS09-034&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;: the Internet Explorer Cumulative Update Bulletin and &lt;SPAN style="COLOR: blue"&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx"&gt;&lt;FONT color=#0000ff&gt;MS09-035&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;: the Visual Studio Bulletin. We also addressed questions regarding the &lt;/SPAN&gt;&lt;SPAN style="COLOR: blue"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/973882.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT color=#0000ff&gt;Microsoft Security Advisory 973882&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; and the ATL issues as a whole. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Here is the link to the full Q&amp;amp;A so you can see all of the answers that were provided for these great questions:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="http://blogs.technet.com/msrc/pages/security-bulletin-webcast-q-a-oob-july-2009.aspx" mce_href="http://blogs.technet.com/msrc/pages/security-bulletin-webcast-q-a-oob-july-2009.aspx"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;http://blogs.technet.com/msrc/pages/security-bulletin-webcast-q-a-oob-july-2009.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Also, here is the link to the Q&amp;amp;A index page in case you want to view previous months:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;A href="http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx" mce_href="http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;As always, customers experiencing issues installing any of the updates this month should contact our Customer Service and Support group:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Customers in the U.S. and Canada can receive technical support from Microsoft Customer Support Services at 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit the &lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/ms955707.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms955707.aspx"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT color=#0000ff&gt;International Support Web site&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Thanks!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;Al Brown&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights.*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3269208" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry></feed>