<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">The Microsoft Security Response Center (MSRC)</title><subtitle type="html">Working to help protect customers from vulnerabilities in Microsoft software</subtitle><id>http://blogs.technet.com/msrc/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/msrc/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2009-08-14T16:42:53Z</updated><entry><title>Microsoft Security Advisory 977544 Released</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx</id><published>2009-11-13T23:08:00Z</published><updated>2009-11-13T23:08:00Z</updated><content type="html">&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Today we released &lt;A href="http://www.microsoft.com/technet/security/advisory/977544.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/977544.mspx"&gt;&lt;FONT color=#0000ff&gt;Security Advisory 977544&lt;/FONT&gt;&lt;/A&gt; to provide information, including customer guidance, on a publicly reported Denial-of-Service (DoS) vulnerability affecting Server Messaging Block (SMB) Protocol. This vulnerability, in SMBv1 and SMBv2, affects &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Windows 7 and Windows Server 2008 R2. Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and Windows 2000 are not affected.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;I want to be clear that this is a DoS vulnerability &lt;SPAN style="mso-bidi-font-weight: bold"&gt;that is unrelated to&lt;/SPAN&gt; Microsoft Security Bulletin &lt;A href="http://go.microsoft.com/fwlink/?LinkId=163970" mce_href="http://go.microsoft.com/fwlink/?LinkId=163970"&gt;&lt;FONT color=#0000ff&gt;MS09-050&lt;/FONT&gt;&lt;/A&gt; which addressed a remote code execution vulnerability in the SMBv2 protocol. This vulnerability would not allow an attacker to take control or install malware on a user’s system, but could cause the affected system to stop responding until manually restarted.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;We are actively monitoring this situation to keep customers informed and will provide additional guidance as necessary. While we are not currently aware of active attacks, we continue to recommend customers review the mitigations and workarounds detailed in the Security Advisory to protect themselves as we work to develop a comprehensive security update. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;As always, we are working with our &lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;Microsoft Active Protections Program (MAPP)&lt;/A&gt; partners to help&amp;nbsp;provide broader protections for customers and as&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&amp;nbsp;we become aware of new information, we’ll provide additional updates as appropriate through the Security Advisory and the MSRC blog. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;As always, we continue to encourage the responsible disclosure of vulnerabilities to help ensure customers receive high-quality security updates without exposure to malicious attacks. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Thanks,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Mike Reavey&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3293791" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Mitigations" scheme="http://blogs.technet.com/msrc/archive/tags/Mitigations/default.aspx" /><category term="Workarounds" scheme="http://blogs.technet.com/msrc/archive/tags/Workarounds/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>November 2009 Security Bulletin Webcast</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/13/november-2009-security-bulletin-webcast.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/13/november-2009-security-bulletin-webcast.aspx</id><published>2009-11-13T22:29:15Z</published><updated>2009-11-13T22:29:15Z</updated><content type="html">&lt;p&gt;Hello. This is Jerry Bryant letting you know that the &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-november-2009.aspx" target="_blank"&gt;questions and answers&lt;/a&gt; from our November Security Bulletin webcast have been posted and the video from the webcast is below. &lt;/p&gt;  &lt;p&gt;We did not get very many questions this month and the ones we did get covered various topics and were not focused in one particular area. One very good question we received had to do with the Microsoft Word bulletin, &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-068.mspx" target="_blank"&gt;MS09-068&lt;/a&gt;. The user asked if an attack could execute via the Outlook 2007 preview function. This function allows a user to preview certain document types from within Outlook as demonstrated in these screen shots:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3293783/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3293783/original.aspx" width="300" /&gt;&lt;/a&gt;    &lt;br /&gt;Above: what the user sees when clicking on the attached file.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3293784/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3293784/original.aspx" width="300" /&gt;&lt;/a&gt;    &lt;br /&gt;Above: what the user sees after clicking the “Preview file” button.&lt;/p&gt;  &lt;p&gt;The answer to the question is no. The preview option does not offer an attack vector for this vulnerability. &lt;/p&gt;  &lt;p&gt;Here is the video from the webcast where Adrian Stone and I cover the bulletins in detail:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="605"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_320_edge.png, postid=12547" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="353"&gt;More listening and viewing options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/4/5/2/1/msrcnovwebcast09_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Please plan to join us next month for our regularly scheduled Security Bulletin webcast which will be held on December 9 at 11:00 a.m. PDT (UTC -8). You can register now for that webcast at &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407802&amp;amp;culture=en-US" target="_blank"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3293785" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>November 2009 Security Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/10/november-2009-security-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/10/november-2009-security-bulletin-release.aspx</id><published>2009-11-10T16:55:59Z</published><updated>2009-11-10T16:55:59Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for November 2009&lt;/p&gt;  &lt;p&gt;Today, we released &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" target="_blank"&gt;six security bulletins&lt;/a&gt; addressing a total of 15 vulnerabilities. Four affect Windows and Windows Server and two affect Microsoft Office products (Excel and Word). &lt;/p&gt;  &lt;p&gt;As we do every month, we have prepared our Risk &amp;amp; Impact and our Deployment Priority guidance to help customers assess risk to their environments and prioritize the deployment of this month’s updates. Risk &amp;amp; Impact is a snapshot of the cumulative severity and exploitability index ratings for each bulletin. This month, &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx" target="_blank"&gt;MS09-065&lt;/a&gt; is the only bulletin with a critical severity rating and an Exploitability Index rating of 1 (“Consistent Exploit Code Likely”). This bulletin provides updates for three vulnerabilities in Windows Kernel-Mode Drivers. We recommend customers prioritize and deploy this update immediately.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3292868/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3292868/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;To better demonstrate the affected products and important aspects of &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx" target="_blank"&gt;MS09-065&lt;/a&gt;, I am including a more detailed overview slide (below). As you can see, only one of the three vulnerabilities (CVE-2009-2514) is critical. That vulnerability only affects Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 (it does not affect Windows Vista or Windows Server 2008 so if you are using either of these platforms, you can lower the deployment priority to a two). The vulnerability was publicly disclosed and could be used to create a malicious web page which could potentially exploit vulnerable systems just by visiting the website. The other two vulnerabilities are Elevation of Privilege (EoP) which would require the attacker to have valid logon credentials in order to be able to exploit. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3292875/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3292875/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The following deployment priority guidance is based on a combination of severity rating, exploitability index rating, available mitigations and workarounds and range of affected products. All customers should perform their own prioritization assessment as each environment is different and other factors may apply. Microsoft recommends that all security updates be deployed as soon as possible.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3292871/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3292871/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;· &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-063.mspx" target="_blank"&gt;MS09-063&lt;/a&gt; affects Windows Vista and Windows Server 2008. There is a potential for unauthenticated remote code execution (RCE) but only from the local subnet. Attacks cannot originate from outside of the network. This mitigation along with the exploitability index rating of 2 lowers the deployment priority. Obviously, this is still a critical bulletin so customers should deploy as soon as possible.&lt;/p&gt;  &lt;p&gt;· &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx" target="_blank"&gt;MS09-064&lt;/a&gt; affects only Windows 2000 Server SP4. This one also has the potential for unauthenticated RCE between systems running the License Logging Service. This service is enabled by default on Windows 2000 Server so this deployment priority should be moved up for customers who have Windows 2000 servers on public-facing networks.&lt;/p&gt;  &lt;p&gt;· &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-067.mspx" target="_blank"&gt;MS09-067&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-068.mspx" target="_blank"&gt;MS09-068&lt;/a&gt; both have similar attack vectors. A user would have to open a maliciously crafted Excel or Word file developed to exploit these vulnerabilities. Users of Office XP or later will be prompted to Open, Save, or Cancel before opening a document. These mitigations lower the severity and deployment priority. However, users should never open file attachments they receive in emails from unknown sources and should always question attachments from known sources if they are unexpected.&lt;/p&gt;  &lt;p&gt;Adrian Stone from the Microsoft Security Response Center (MSRC) and I give a brief overview of this month’s bulletin release in the video below.&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="647"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_320_edge.png, postid=12416" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="395"&gt;More listening and viewing options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/6/1/4/2/1/n09msrcvover_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;For more in-depth technical detail on &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-063.mspx"&gt;MS09-063&lt;/a&gt;, &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx"&gt;MS09-064&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx"&gt;MS09-065&lt;/a&gt;, please visit our Security Research &amp;amp; Defense team blog at &lt;a href="http://blogs.technet.com/srd"&gt;this link&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;We also re-released MS09-045 and MS09-051. The former was re-released to add detection for users who may be running JScript 5.7 on Windows 2000 Service Pack 4 machines and the latter is a re-release of the update for Audio Compression Manager on Microsoft Windows 2000 Service Pack 4 to fix a detection issue. &lt;/p&gt;  &lt;p&gt;As always, we encourage all customers to join us for our live security bulletin webcast which we conduct every month after release. Adrian and I will go in to detail on each bulletin and, along with a room full of subject matter experts, answer all of your questions live. So if you can, please join us tomorrow, Nov 11 at 11:00 a.m. PDT (UTC -8). You can register for the webcast at &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;The last item I want to mention this month is that the Microsoft Malware Protection Center (MMPC) team has added &lt;a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3aWin32%2fFakeVimes"&gt;Win32/fakevimes&lt;/a&gt; and &lt;a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3aWin32%2fPrivacyCenter"&gt;Win32/privacycenter&lt;/a&gt; to the Windows Malicious Software Removal Tool (MSRT) this month. Please check their &lt;a href="http://blogs.technet.com/mmpc"&gt;blog post&lt;/a&gt; for more information.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292865" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Microsoft Windows" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Windows/default.aspx" /><category term="Microsoft Office" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Office/default.aspx" /><category term="Attack Vector" scheme="http://blogs.technet.com/msrc/archive/tags/Attack+Vector/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Risk Assessment" scheme="http://blogs.technet.com/msrc/archive/tags/Risk+Assessment/default.aspx" /></entry><entry><title>November 2009 Bulletin Release Advance Notification </title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/05/november-2009-bulletin-release-advance-notification.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/05/november-2009-bulletin-release-advance-notification.aspx</id><published>2009-11-05T16:12:00Z</published><updated>2009-11-05T16:12:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; for the November 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;To help customers plan and prioritize for this month’s security updates, &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;we wanted to let you know that we will be releasing 6 bulletins (three critical and three important) addressing 15 vulnerabilities, affecting Windows and Microsoft Office products. Customers should plan a restart for the Windows bulletins. The Office bulletins may not require a restart if the components being updated are not in use. More information about the upcoming security updates can be found on the TechNet Web site.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;The target release day is next Tuesday Nov. 10 at 10:00 a.m. PST (UTC -8). At that time we will post more detailed information about the bulletins here and on our &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/srd" mce_href="http://blogs.technet.com/srd"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Security Research &amp;amp; Defense (SRD) blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;. We will also include our Risk and Impact guidance, our Deployment Priority guidance, and an overview video discussing these materials. For more detailed information concerning the upcoming bulletins, please review the ANS page &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;As always, Adrian Stone and I will be hosting a webcast to cover the bulletins in greater detail the day after bulletins release. So please join us on Wednesday Nov. 11 at 11:00 a.m. PST (UTC -8) and bring any questions you have about the bulletins. We will have a room full of subject matter experts on hand to answer them. To register for the webcast, please follow this &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;link&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3291742" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Microsoft Office" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Office/default.aspx" /></entry><entry><title>Update released for MS09-054</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/11/02/update-released-for-ms09-054.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/11/02/update-released-for-ms09-054.aspx</id><published>2009-11-02T22:01:00Z</published><updated>2009-11-02T22:01:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Today we released an update &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;that addresses two issues with &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; that a limited number customers reported to us through our Customer Service and Support (CSS) group. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;These two issues can affect the proper display of web pages. For additional details, please refer to Microsoft Knowledge Base article&amp;nbsp;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Security update &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; was released as part of the October Security Bulletin Release cycle and protects against the vulnerabilities outlined in the bulletin. Also, we’re not currently aware of any attempts to attack the vulnerabilities. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;While the number of customers affected by these two issues is limited, after working both with affected customers and our CSS group, we feel the best thing for all customers is to proactively provide this update as widely as possible to help prevent other customers from encountering the issues outlined in the KB.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Because of this, we plan to release this update through the same broad release channels as the original security update, &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;. Customers will see &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;offered by default through Windows Update, Microsoft Update, and Automatic Updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Customers who have applied &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;should go ahead and apply &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;. Customers who have not yet applied &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;should apply both &lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;and &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;There’s more information on the update and the issues it addresses in Microsoft Knowledge Base article &lt;A href="http://support.microsoft.com/kb/976749" target=_blank mce_href="http://support.microsoft.com/kb/976749"&gt;&lt;FONT size=3 face=Calibri&gt;976749&lt;/FONT&gt;&lt;/A&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thanks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Christopher&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3290929" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>October 2009 Security Bulletin Webcast Questions and Answers</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/20/october-2009-security-bulletin-webcast-questions-and-answers.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/20/october-2009-security-bulletin-webcast-questions-and-answers.aspx</id><published>2009-10-20T21:23:09Z</published><updated>2009-10-20T21:23:09Z</updated><content type="html">&lt;p&gt;Hi everyone. We have posted the questions and answers from the security bulletin webcast we conducted on October 14 at &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-october-2009.aspx"&gt;this link&lt;/a&gt;. It was clear from all of the questions concerning MS09-062 (the GDI+ update) that there is some confusion on how to apply the update when you have a combination of SQL Server and Windows 2000 clients. &lt;/p&gt;  &lt;p&gt;To clarify what the bulletin states, if you do not have any Windows 2000 SP4 clients on your network then you do not need to apply the SQL Server update that corresponds to the version of SQL Server you are running. In this case, you would only need to apply the update for the client operating systems on your network. This is because on platforms newer than Windows 2000 SP4, the operating system will use its own version of the affected component (gdiplus.dll) rather than the one distributed by the RSClientPrint ActiveX control through SQL Server Reporting Services. &lt;/p&gt;  &lt;p&gt;In the video below, Adrian Stone and I go in to details on each bulletin to cover the vulnerabilities, affected platforms, attack vectors, and mitigations:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="566"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_320_edge.png, postid=11522" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="314"&gt;More listening and viewing options:         &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/2/5/1/1/octmsrcvidwebcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt;&lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Next month we will host our live security bulletin webcast on November 11 at 11:00 am Pacific time (UTC -7). To register for that webcast, please follow &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407490&amp;amp;culture=en-US"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3287979" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast Q &amp;amp; A" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/default.aspx" /><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /></entry><entry><title>October 2009 Security Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx</id><published>2009-10-13T17:05:34Z</published><updated>2009-10-13T17:05:34Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for October 2009&lt;/p&gt;  &lt;p&gt;This month, we released &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;13 new bulletins&lt;/a&gt; which address 33 vulnerabilities in Windows, Internet Explorer and Microsoft Office. Since we published this information in our advance notification (ANS) last Thursday, we have been asked “is this the most bulletins Microsoft has ever released”? The short answer to that question is yes. However, we have, on several occasions, released between 10 and 12 bulletins so this is business as usual. All of our updates go through extensive quality testing and when they reach the bar for broad distribution, we schedule them for release. &lt;/p&gt;  &lt;p&gt;As we noted in the ANS last week, two of the updates address open Security Advisories. &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-050.mspx"&gt;MS09-050&lt;/a&gt; addresses the SMBv2 issue in &lt;a href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;Security Advisory 975497&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-053.mspx"&gt;MS09-053&lt;/a&gt; addresses the IIS issue discussed in &lt;a href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;Security Advisory 975191&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Another issue being addressed this month that has received some public attention has to do with security certificates used for authentication. The vulnerabilities being addressed by Security Bulletin &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-056.mspx"&gt;MS09-056&lt;/a&gt; could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. We are aware that a rogue certificate was distributed in a public forum but we are not aware of any attempts to use this to attack users. &lt;/p&gt;  &lt;p&gt;Below is the severity summary and exploitability index for the 13 new bulletins. We also refer to this as the overall risk and impact summary. As you can see, eight of the bulletins have a rating of Critical. Of those eight, six have an exploitability index rating of 1, which means we believe it is highly likely that we will see exploit code in the wild within the first 30 days from the date of release. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286577/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;To help with deployment planning, we started publishing our guidance (beginning last month) on which bulletins should be considered first for deployment. Obviously one size does not fit all and each customer will need to consider their own unique situations in addition to this guidance. Our approach is to take a combination of the severity, the exploitability index rating, the range of products affected, and potential mitigations to group these in to a priority 1, 2 or 3. Our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense&lt;/a&gt; team, who represent some of the best security researchers in the world, play a key role in this every month as well. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3286578/original.aspx" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Most of this month’s updates require a restart, so please refer to the bulletins when you’re planning your deployment to ensure you’re fully protected. We want to specifically note that MS09-050 requires a restart but will not prompt you to do so if you install the update manually. &lt;/p&gt;  &lt;p&gt;As we do every month, Adrian Stone and I provide a high-level overview of this month’s bulletin release in the following video:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="554"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_320_edge.png, postid=11402" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="302"&gt;Other listening and viewing options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;This month we are also re-releasing &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx"&gt;MS08-069, vulnerability in Microsoft XML Core Services could allow remote code execution (955218)&lt;/a&gt; to add detection for Windows 7 and Windows Server 2008 R2. This component does not ship with these platforms but many applications install it in order to use its functionality.&lt;/p&gt;  &lt;p&gt;Finally, you may also notice a change in the severity rating since the advance notification for several versions of Windows in the .NET bulletin (&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx"&gt;MS09-061&lt;/a&gt;). We have elevated the severity of these products from Important to Critical. We do not typically make changes after the advance notification goes out but during our ongoing investigation to protect customers, we determined that this was the appropriate rating for these products when certain versions of the .NET Framework are installed on them. &lt;/p&gt;  &lt;p&gt;We encourage all customers to join us tomorrow when Adrian and I will go in to detail on each bulletin and, along with a room full of subject matter experts, answer all of your questions live. So if you can, please join us at 11:00 a.m. PDT (UTC -7). You can register for the webcast at &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;this link&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;Update – Resource links:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx" target="_blank"&gt;Assessing the risk of the October security bulletins&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx" target="_blank"&gt;MS09-051: A note on the affected platforms&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx" target="_blank"&gt;MS09-050: Exploit timeline for SMB2 RCE vulnerability&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx" target="_blank"&gt;MS09-054: Extra info on the attack surface for the IE security bulletin&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx" target="_blank"&gt;MS09-061: More information about the .NET security bulletin&lt;/a&gt; – Security Research &amp;amp; Defense blog &lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx" target="_blank"&gt;Scanti-ly Clad – Another Rogue Stripped by MSRT&lt;/a&gt; – Microsoft Malware Protection Center blog &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Update (10/13) Changed the number of vulnerabilities addressed to 33 from 34. CVE-2009-2493 was counted in both MS09-055 and MS09-060. &lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3286576" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="ActiveX" scheme="http://blogs.technet.com/msrc/archive/tags/ActiveX/default.aspx" /><category term="Killbit" scheme="http://blogs.technet.com/msrc/archive/tags/Killbit/default.aspx" /><category term="Microsoft Windows" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Windows/default.aspx" /><category term="Microsoft Office" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Office/default.aspx" /><category term="Attack Vector" scheme="http://blogs.technet.com/msrc/archive/tags/Attack+Vector/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Malicious Software Removal Tool (MSRT)" scheme="http://blogs.technet.com/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/default.aspx" /><category term="Responsible Disclosure " scheme="http://blogs.technet.com/msrc/archive/tags/Responsible+Disclosure+/default.aspx" /><category term="Risk Assessment" scheme="http://blogs.technet.com/msrc/archive/tags/Risk+Assessment/default.aspx" /></entry><entry><title>October 2009 Bulletin Release Advance Notification</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/10/08/october-2009-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/10/08/october-2009-bulletin-release.aspx</id><published>2009-10-08T16:23:00Z</published><updated>2009-10-08T16:23:00Z</updated><content type="html">&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; for the October 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;For October we are releasing 13 bulletins (eight critical and five important), addressing 34 vulnerabilities, affecting Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools, and SQL Server. Most of these updates require a restart so please factor that into your deployment planning. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Among the updates this month, we are closing out two current security advisories:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975497.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;&lt;FONT face=Calibri size=3&gt;Vulnerabilities in SMB Could Allow Remote Code Execution (975497)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT face=Calibri size=3&gt;Vulnerabilities in the FTP Service in Internet Information Services (975191)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Usually we do not go into this level of detail in the advance notification but we felt that it is important guidance so customers can plan accordingly and deploy these updates as soon as possible.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The target to release the October security updates is next Tuesday Oct. 13 at 10:00 a.m. PDT (UTC -8). Check back here at that time for a more detailed overview of the updates (including an overview video), our risk and impact summary and our deployment prioritization guide. More information about the upcoming security updates can be found &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-oct.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; in&amp;nbsp;the ANS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;After you have had a chance to read through the bulletins, please join us for a live webcast on Wednesday Oct. 14 at 11:00 a.m. PDT (UTC -7) and get answers to any questions you might have. To register, just follow &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;this link.&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3285484" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /></entry><entry><title>September 2009 Security Bulletin Webcast Video and Customer Q and A</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/11/september-2009-security-bulletin-webcast-video-and-customer-q-and-a.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/11/september-2009-security-bulletin-webcast-video-and-customer-q-and-a.aspx</id><published>2009-09-12T01:11:39Z</published><updated>2009-09-12T01:11:39Z</updated><content type="html">&lt;p&gt;In the September 2009 security bulletin webcast, it was clear that customers had a lot of concerns about &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; as almost half the questions we answered were on that topic. &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-september-2009.aspx"&gt;The questions and answers from the session are now posted here on the blog&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;As we mentioned in the webcast, The &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; bulletin has been updated to call out Windows XP in the affected products list with a severity rating of low for the two Denial-of-Service vulnerabilities (the third, Remote Code Execution vulnerability, does not affect XP). As stated in the bulletin, in the default configuration, Windows XP is not affected by any of the issues addressed by the bulletin. However, we heard from enterprise customers that custom configurations that put XP in a vulnerable state are in use so we updated the bulletin for clarity. Does this mean there will be an update for Windows XP? No and I will use the text from the bulletin to explain why:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;strong&gt;If Windows XP is listed as an affected product, why is Microsoft not issuing an update for it?        &lt;br /&gt;&lt;/strong&gt;By default, Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows XP Professional x64 Edition Service Pack 2 do not have a listening service configured in the client firewall and are therefore not affected by this vulnerability. Windows XP Service Pack 2 and later operating systems include a stateful host firewall that provides protection for computers against incoming traffic from the Internet or from neighboring network devices on a private network. The impact of a denial of service attack is that a system would become unresponsive due to memory consumption. However, a successful attack requires a &lt;u&gt;sustained flood&lt;/u&gt; of specially crafted TCP packets, and the system will recover once the flood ceases. This makes the severity rating Low for Windows XP. Windows XP is not affected by CVE-2009-1925. Customers running Windows XP are at reduced risk, and Microsoft recommends they use the firewall included with the operating system, or a network firewall, to block access to the affected ports and limit the attack surface from untrusted networks.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Concerning &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; and Windows 2000, the scenario is very similar to Windows XP in that an attack requires a sustained flood of specially crafted TCP packets and the system will recover once the flood stops. Keeping Windows 2000 servers behind a NAT or reverse proxy can help to reduce risk.&lt;/p&gt;  &lt;p&gt;In the last blog post I called out &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt; as the highest priorities for deployment and while MS09-048 has received a lot of attention, we want to continue to stress getting those updates installed to all users. &lt;/p&gt;  &lt;p&gt;This month we are leaving the Q and A out of the video because we have &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-september-2009.aspx"&gt;posted those questions to the blog&lt;/a&gt; and to keep the overall duration of the video down. If you like it this way or if you prefer us to leave that portion in, head over to the &lt;a href="http://edge.technet.com/Media/MSRC-Monthly-Security-Bulletin-Webcast-September-2009/"&gt;TechNet Edge site&lt;/a&gt; where we host the videos and leave your feedback there. &lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="614"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/8/4/8/msrcsept09webcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_320_edge.png, postid=8482" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="362"&gt;More listening and viewing options:         &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/8/4/8/msrcsept09webcast_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt;&lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/8/4/8/msrcsept09webcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt;&lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Following the webcast we got feedback that folks liked the new deployment priority slide as well as the new detail slides for each bulletin. We appreciate the feedback and will keep looking for ways to improve the content. &lt;/p&gt;  &lt;p&gt;Please plan on joining us for our next regularly scheduled webcast on October 13 at 11:00 a.m&lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407488&amp;amp;culture=en-US"&gt;. Click HERE to register&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3280657" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Update Webcast Q &amp;amp; A" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast+Q+_2600_amp_3B00_+A/default.aspx" /><category term="video" scheme="http://blogs.technet.com/msrc/archive/tags/video/default.aspx" /><category term="Security Update Webcast" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update+Webcast/default.aspx" /><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Attack Vector" scheme="http://blogs.technet.com/msrc/archive/tags/Attack+Vector/default.aspx" /><category term="Exploitability Index" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability+Index/default.aspx" /><category term="Exploitability" scheme="http://blogs.technet.com/msrc/archive/tags/Exploitability/default.aspx" /><category term="Malicious Software Removal Tool (MSRT)" scheme="http://blogs.technet.com/msrc/archive/tags/Malicious+Software+Removal+Tool+_2800_MSRT_2900_/default.aspx" /></entry><entry><title>Microsoft Security Advisory 975497 Released</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/08/microsoft-security-advisory-975497-released.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/08/microsoft-security-advisory-975497-released.aspx</id><published>2009-09-09T02:35:00Z</published><updated>2009-09-09T02:35:00Z</updated><content type="html">&lt;FONT face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;We’ve just released Microsoft released Security &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975497.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;&lt;FONT color=#0000ff size=3&gt;Advisory 975497&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; that provides information about a new, irresponsibly reported vulnerability in SMB 2.0. Our investigation has shown that Windows Vista, Windows Server 2008 and Windows 7 RC are affected by this vulnerability. Windows 7 RTM, Windows Server 2008 R2, Windows XP and Windows 2000 are not affected by this vulnerability. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;The Security Advisory outlines steps that Windows Vista and Windows Server 2008 customers can take to help protect themselves while we work on a security update for this issue.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;As always, we’ve provided information through &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT color=#0000ff size=3&gt;Microsoft Active Protections Program (MAPP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt; as well as the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank mce_href="http://www.microsoft.com/security/msra/default.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT color=#0000ff size=3&gt;Microsoft Security Response Alliance (MSRA)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt; that they can use to help provide broader protections to customers. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;We will update you through our security advisory and the MSRC Weblog as we have new information.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Christopher&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279917" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>September 2009 Security Bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/08/september-2009-security-bulletin-release.aspx</id><published>2009-09-08T20:50:47Z</published><updated>2009-09-08T20:50:47Z</updated><content type="html">&lt;p&gt;Summary of Microsoft’s Security Bulletin Release for September 2009&lt;/p&gt;  &lt;p&gt;Hello again,&lt;/p&gt;  &lt;p&gt;This month we released five critical bulletins to address vulnerabilities in Windows and protect customers from two types of threats:&lt;/p&gt;  &lt;p&gt;1. Browser based attacks where websites hosting malicious code attempt to compromise visitors. This includes &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt;, &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-046.mspx"&gt;MS09-046&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;2. Network based scenarios where attackers attempt Remote Code Execution (RCE) or Denial-of-Service (DoS) type attacks. This includes &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-049.mspx"&gt;MS09-049&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;For this set of bulletins, we consider the first category to be the biggest threat to customers overall as reflected in our Severity and Exploitability Index slide where we present a high level, aggregate view of each bulletin:&lt;/p&gt; &lt;a href="http://blogs.technet.com/photos/msrcteam/images/3279846/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3279846/original.aspx" width="500" /&gt;&lt;/a&gt;   &lt;p&gt;We also refer to the slide above as our risk and impact assessment. The risk of exploitation combined with the impact of the vulnerability should help customers prioritize these bulletins for deployment. To provide further guidance in this area, this month we are providing a new deployment prioritization assessment. As noted on the slide below, there are several factors that we used to determine the priority. However, there are many other potential variables that may be unique to your environment so we recommend each customer perform their own assessment and install all security updates as soon as possible.&lt;/p&gt; &lt;a href="http://blogs.technet.com/photos/msrcteam/images/3279847/original.aspx" target="_blank"&gt;&lt;img border="0" src="http://blogs.technet.com/photos/msrcteam/images/3279847/original.aspx" width="500" /&gt;&lt;/a&gt;   &lt;p&gt;As you can see, we give &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;MS09-045&lt;/a&gt; and &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-047.mspx"&gt;MS09-047&lt;/a&gt; the highest deployment priority mainly due to these being browse and own attack scenarios and a high exploitability index rating. Exploits for MS09-047 can also be created through specially crafted files such as ASF and MP3 audio files. These files could then be sent via email. &lt;/p&gt;  &lt;p&gt;Concerning &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-046.mspx"&gt;MS09-046&lt;/a&gt;, our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense&lt;/a&gt; (SRD) team has determined that reliable exploit code would be difficult to produce hence the lower exploitability index rating. In this case and with MS09-045, users with Internet Explorer 8.0 are at reduced risk due to the protections provided by Date Execution Prevention (&lt;a href="http://windowshelp.microsoft.com/Windows/en-US/Help/186de3d0-01af-4d4c-981d-674637d2f4bf1033.mspx"&gt;DEP&lt;/a&gt;). Also, while this is an ActiveX control update, it is not related to the ATL issue discussed in &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;security advisory 973882&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;The wireless update provided in &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-049.mspx"&gt;MS09-049&lt;/a&gt; addresses an issue with the Wireless AutoConfig Service in both Windows Vista and Windows Server 2008. We consider this one hard to exploit due to the work that has gone in to hardening the Windows Heap Manager. The SRD blog has a &lt;a href="http://blogs.technet.com/srd/archive/2009/08/04/preventing-the-exploitation-of-user-mode-heap-corruption-vulnerabilities.aspx"&gt;great write up&lt;/a&gt; on this.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;MS09-048&lt;/a&gt; contains updates for three vulnerabilities. One of those is a Remote Code Execution vulnerability affecting only Windows Vista and Windows Server 2008. We think this one would be difficult to produce reliable exploit code for as well. The SRD team did a &lt;a href="http://blogs.technet.com/srd" target="_blank"&gt;write up&lt;/a&gt; on this one to provide additional details so I recommend reading it. The other two vulnerabilities are both Denial-of-Service issues and I want to point out that while Windows 2000 is affected by these, an update is not being provided. This is because the architecture to protect TCP/IP properly does not exist in Windows 2000. Customers on this platform who cannot update their systems to Windows Server 2003 or 2008 will need to carefully monitor their networks and assure that firewall best practices are followed.&lt;/p&gt;  &lt;p&gt;Also, we re-released &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx"&gt;MS09-037&lt;/a&gt;. This bulletin for vulnerabilities in the Active Template Library (ATL), affecting components that shipped with Windows, was originally released in August 2009. In our ongoing investigation into the ATL issue, we identified a related vulnerable control so this bulletin has been updated to include it. This additional update affects users of Windows XP Media Center 2005 and Windows Vista systems. It is important to note that to date, we have not seen any new controls being used in active attacks. The Video ActiveX control that was under limited exploitation and which drove our out of band update in July, is still the only one we have seen used in attacks. Please refer to &lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt; for the latest information and guidance from our investigation.&lt;/p&gt;  &lt;p&gt;In this month’s overview video, Adrian Stone and I discuss the severity and exploitability index slide and the new deployment priority slide in a little more detail:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="541"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/4/7/msrcs09v3_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_320_edge.png, postid=7467" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="289"&gt;More viewing and listening options:          &lt;br /&gt;          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/4/7/msrcs09v3_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/4/7/msrcs09v3_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Please join Adrian and I for a live webcast tomorrow, Wednesday Sept. 9 at 11:00 a.m. PDT (UTC -7) where we will go in to detail on each bulletin and answer all of your questions, with the help of a room full of subject matter experts. &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;Go here to register &amp;gt;&amp;gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In this post I also want to provide some clarity on Windows 7 and Windows Server 2008 R2. After the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx"&gt;Advance Notification&lt;/a&gt; went out last Thursday, we saw speculation that these new products may be affected because they were not specifically listed. To be clear, Windows 7 and Windows Server 2008 R2 are not affected by any of the September security updates. Since the date these products were released to manufacturing (July 09), they have been part of our standard security update process. As such, they would have been called out in the ANS if they were affected. &lt;/p&gt;  &lt;p&gt;Finally, we are not addressing the IIS/FTP vulnerability announced in &lt;a href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;Security Advisory 975191&lt;/a&gt; with this month’s security bulletin release. Our teams are still working on an update for this issue and we encourage customers to review the advisory for the most current guidance on this issue.&lt;/p&gt;  &lt;p&gt;That’s it for this month. If you cannot join us for the webcast tomorrow, come back to the blog Friday afternoon as we will be posting the webcast video and Q&amp;amp;A from the session.&lt;/p&gt;  &lt;p&gt;Thanks!&lt;/p&gt;  &lt;p&gt;Jerry Bryant&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights.*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279860" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry><entry><title>Microsoft Security Advisory 975191 Revised</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/03/microsoft-security-advisory-975191-revised.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/03/microsoft-security-advisory-975191-revised.aspx</id><published>2009-09-04T08:50:00Z</published><updated>2009-09-04T08:50:00Z</updated><content type="html">&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Hi Everyone,&lt;BR&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Today we updated &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;Security Advisory &lt;/SPAN&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;975191&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&amp;nbsp;as we are now seeing limited attacks.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Additionally, a new proof of concept published allowing for Denial of Service (DoS) attacks on Windows XP and Windows Server 2003 with read access to the File Transfer Protocol (FTP) service. This does not require Write access.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also, a new POC allowing DoS was disclosed this afternoon that affects the version of FTP 6 which shipped with Windows Vista and Windows Server 2008.&amp;nbsp; Customers should be aware that the Download Center has FTP 7.5 available for Windows Vista and Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: PMingLiU; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;The initial vulnerability was not responsibly disclosed to Microsoft, which has led to limited, active attacks putting customers at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft recommends customers review and implement the workarounds provided in the Advisory under the &lt;SPAN style="mso-bidi-font-weight: bold"&gt;Workaround&lt;/SPAN&gt; section.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;More information on suggested actions can be found in &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Arial"&gt;&lt;A href="http://support.microsoft.com/kb/975191"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Knowledge Base Article 975191&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;While these workarounds do not completely mitigate the threat of DoS, &lt;SPAN style="mso-bidi-font-style: italic"&gt;we’re currently investigating the issue as part of our &lt;/SPAN&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" target=_blank&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-style: italic"&gt;&lt;FONT size=3&gt;Software Security Incident Response Process (SSIRP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-style: italic"&gt;&lt;FONT size=3&gt;&amp;nbsp;and working to develop a security update.&amp;nbsp; This update will be released once it reaches an appropriate level of quality for broad distribution.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-style: italic"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Additionally, we are actively working with partners in our &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Active Protections Program (MAPP)&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; as well as the &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Microsoft Security Response Alliance (MSRA)&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; to share information that they can use to provide broader protections to customers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;For more technical details on the advisory, please see what our colleagues have written on Microsoft’s Internet Information Services (IIS) blog here: &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://blogs.iis.net/"&gt;&lt;SPAN style="COLOR: blue"&gt;Microsoft IIS Blog&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;. As always, be sure to check back here on the Microsoft Security Response Center (MSRC) blog or in the &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;advisory&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; for any additional information or updates that develop.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Thank you,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Alan Wallace&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="COLOR: blue; mso-fareast-font-family: PMingLiU; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-language: ZH-TW"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3279110" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Active Protections Program (MAPP)" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>September 2009 bulletin Release</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/02/september-2009-bulletin-release.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/02/september-2009-bulletin-release.aspx</id><published>2009-09-03T05:27:00Z</published><updated>2009-09-03T05:27:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Advance Notification&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; for the September 2009 Security Bulletin Release&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This month we will be releasing 5 security bulletins, all affecting Windows, and all with an aggregate severity rating of critical. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;As always, the target for release is the second Tuesday of the month at 10:00 a.m. PDT (UTC -8). Please check back here at that time as we will be posting our risk and impact assessment, a new deployment prioritization table and an overview video. Also, we encourage you to join us live on Wednesday September 9 at 11:00 a.m. (UTC -7) for our regular security bulletin webcast where we will cover the bulletins in greater detail and answer questions. &lt;/FONT&gt;&lt;A href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US" mce_href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Click here to register&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;If the files being updated are in use at the time of installation then these updates would require a restart. Otherwise, they would not. For information on the reasons you may be prompted to restart the system, see &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?id=887012" mce_href="http://support.microsoft.com/?id=887012"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Knowledge Base Article 887012&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In related news, you will note that the ANS does not specify an update for the Internet Information Services FTP service vulnerability for which we released &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;security advisory 975191&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on Tuesday of this week. As noted in an &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx" mce_href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;earlier blog post&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;, we have spun up our &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" mce_href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;SSIRP (Software Security Incident Response Process) process&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to address this issue and our teams are working hard to produce an update. Please keep an eye on the advisory for more information and if you are not already, please subscribe to our &lt;/FONT&gt;&lt;A href="https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizard.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&amp;amp;lcid=1033" mce_href="https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizard.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&amp;amp;lcid=1033"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;comprehensive alerts&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to receive updates by email. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;On a final note, I want to highlight our new &lt;/FONT&gt;&lt;A href="http://go.microsoft.com/?linkid=9673472" mce_href="http://go.microsoft.com/?linkid=9673472"&gt;&lt;FONT size=3 face=Calibri&gt;Microsoft Security Update Guide&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; which was written to help IT professionals better understand and use Microsoft security update release information, processes, communications, and tools – and how to manage organizational risk and develop a repeatable, effective deployment mechanism for security updates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Jerry Bryant&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278834" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Bulletin" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Bulletin/default.aspx" /><category term="Security Update" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Update/default.aspx" /><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Windows" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Windows/default.aspx" /></entry><entry><title>Microsoft Security Advisory 975191 Released</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/09/01/microsoft-security-advisory-975191-released.aspx</id><published>2009-09-02T01:24:00Z</published><updated>2009-09-02T01:24:00Z</updated><content type="html">&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Hi Everyone,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;This is Alan Wallace, senior communications manager for our security response communications team.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Today, Microsoft released &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;FONT color=#0000ff&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;Security Advisory &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;975191&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-weight: bold"&gt;, to provide customer guidance and protection from a &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;vulnerability that could allow remote code execution on affected systems running the FTP service in Microsoft Internet Information Services (IIS) 5.0, 5.1 and 6.0, and connected to the Internet.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;While we have seen detailed exploit code published on the Internet for this vulnerability, we are &lt;SPAN style="mso-bidi-font-weight: bold"&gt;not&lt;/SPAN&gt; currently aware of active attacks &lt;SPAN style="mso-bidi-font-weight: bold"&gt;that use&lt;/SPAN&gt; this exploit code or of customer impact.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;This vulnerability was not responsibly disclosed to Microsoft and may put customers at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;We’re currently investigating the issue as part of our &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx" target=_blank mce_href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Software Security Incident Response Process (SSIRP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;and working to develop a security update.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This update will be released once it reaches an appropriate level of quality for broad distribution.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 8pt 0in 0pt" class=Para&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Affected products include Windows 2000, Windows XP, and &lt;SPAN class=MsoCommentReference&gt;&lt;SPAN style="mso-ansi-font-size: 11.0pt; mso-bidi-font-size: 11.0pt"&gt;W&lt;/SPAN&gt;&lt;/SPAN&gt;indows Server 2003.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Microsoft &lt;SPAN style="mso-bidi-font-family: Calibri"&gt;recommends customers review and implement the workarounds provided in the Advisory under the &lt;B&gt;Workaround&lt;/B&gt; section.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;More information on suggested actions can be found in &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/975191" mce_href="http://support.microsoft.com/kb/975191"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Knowledge Base Article 975191&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;Additionally, we are actively working with partners in our &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" mce_href="http://www.microsoft.com/security/msrc/mapp/overview.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Active Protections Program (MAPP)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt; as well as the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/security/msra/default.mspx" target=_blank mce_href="http://www.microsoft.com/security/msra/default.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Microsoft Security Response Alliance (MSRA)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; to share information that they can use to provide broader protections to customers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;For more technical details on the advisory, please see what our colleagues have written over on the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/srd" target=_blank mce_href="http://blogs.technet.com/srd"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Security Research and Defense blog&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3 face=Calibri&gt;As always, be sure to check back here on the MSRC blog or in the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/975191.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/975191.mspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;advisory&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; for any additional information or updates that develop.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thank you,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'"&gt;Alan&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="COLOR: blue; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoPlainText&gt;&lt;SPAN style="FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*This posting is provided "AS IS" with no warranties, and confers no rights*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoPlainText&gt;&lt;SPAN style="FONT-SIZE: 11pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278582" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author><category term="Security Advisory" scheme="http://blogs.technet.com/msrc/archive/tags/Security+Advisory/default.aspx" /><category term="Microsoft Active Protections Program (MAPP)" scheme="http://blogs.technet.com/msrc/archive/tags/Microsoft+Active+Protections+Program+_2800_MAPP_2900_/default.aspx" /><category term="Zero-Day Exploit" scheme="http://blogs.technet.com/msrc/archive/tags/Zero-Day+Exploit/default.aspx" /></entry><entry><title>August 2009 Security Bulletin Webcast Video and Customer Q and A</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx" /><id>http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx</id><published>2009-08-15T02:42:53Z</published><updated>2009-08-15T02:42:53Z</updated><content type="html">&lt;p&gt;As we do every month on the Wednesday following our standard second Tuesday security bulletin release, we conducted a live webcast where Adrian Stone and myself went through the bulletins in detail and then answered customer questions with the help of several subject matter experts (SMEs).&lt;/p&gt;  &lt;p&gt;It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;Security Advisory 972890&lt;/a&gt;: This advisory was released in response to active attacks against the Microsoft Video ActiveX Control in order to provide guidance and mitigations (including a &lt;a href="http://support.microsoft.com/fixit#tab0"&gt;Microsoft Fix it&lt;/a&gt; solution) to customers while we worked towards an update for the underlying issue. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx"&gt;MS09-032 – Cumulative Update of ActiveX Kill Bits (973346)&lt;/a&gt;: This bulletin provided an official kill bit update to replace the Microsoft Fix it solution provided by Security Advisory 972890. The update addresses additional kill bits and is also available through Microsoft update technologies such as Windows Update, Microsoft Update, and Windows Software Update Services (WSUS). This kill bit blocked the ability to instantiate the Microsoft Video ActiveX Control in Internet Explorer to mitigate against known attacks. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx"&gt;MS09-034 – Cumulative Security Update for Internet Explorer (972260)&lt;/a&gt;: This bulletin provided a defense-in-depth update that helps mitigate known attack vectors within Internet Explorer. To be clear, Internet Explorer is not vulnerable to these attacks but the vulnerable components can be reached through Internet Explorer. Installing this update mitigates that threat. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx"&gt;MS09-035 – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)&lt;/a&gt;: This update is specifically geared towards developers of components and controls who use ATL. The update addresses the underlying issue in our Visual Studio development tools. Developers who use ATL should install this update and recompile their components and controls following the guidance in this &lt;a href="http://go.microsoft.com/?linkid=9674481"&gt;MSDN article&lt;/a&gt;. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-037.mspx"&gt;MS09-037 – Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)&lt;/a&gt;: This bulletin provides updates for vulnerable components and controls that shipped with Windows products. These are Microsoft components and controls were built using ATL. Among the updates in this bulletin is a binary level update that addresses the vulnerability in the Microsoft Video ActiveX Control that has seen some active attacks. So we previously released a kill bit update to provide immediate protection for customers and are addressing the underlying vulnerability with this update. &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/973882.mspx"&gt;Security Advisory 973882&lt;/a&gt;: This advisory provides information on our ongoing investigation in to the ATL issue and serves as a single source for all related information. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.&lt;/p&gt;  &lt;p&gt;Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for. Please review the text version of the &lt;a href="http://blogs.technet.com/msrc/pages/monthly-security-bulletin-webcast-q-a-august-2009.aspx"&gt;Q&amp;amp;A here&amp;gt;&amp;gt;&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Here is the video of the webcast that includes the bulletin by bulletin presentation and the complete Q&amp;amp;A session:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="541"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_09.xap" /&gt; &lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png, postid=5067" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="289"&gt;More viewing and listening options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_large_edge.png"&gt;Large Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_small_edge.png"&gt;Small Preview Image (PNG)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/7/6/0/5/msrcaugblwebcast_s_edge.wmv"&gt;Streaming WMV (512kbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/7/6/0/5/msrcaugblwebcast_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Please plan to join us for the next regularly scheduled webcast on September 9, 2009 at 11:00 a.m. (UTC-7) where we will again cover any new bulletins and address your questions in real time. &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032407486&amp;amp;culture=en-US"&gt;Click here to register &amp;gt;&amp;gt;&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Finally, please visit our &lt;a href="http://blogs.technet.com/srd"&gt;Security Research &amp;amp; Defense blog&lt;/a&gt; where you will find some great deep dive articles full of analysis and guidance on these and many other security issues. You may also find our new &lt;a href="http://www.microsoft.com/mscorp/twc/blogs/default.mspx"&gt;blog aggregator&lt;/a&gt; useful for getting a consolidated view of all of our Trustworthy Computing blogs. &lt;/p&gt;  &lt;p&gt;Thanks, &lt;/p&gt;  &lt;p&gt;Jerry Bryant &lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273699" width="1" height="1"&gt;</content><author><name>MSRCTEAM</name><uri>http://blogs.technet.com/members/MSRCTEAM.aspx</uri></author></entry></feed>