Microsoft Out-of-Band Security Bulletins for July 2009 Released
Tue, 28/07/09 – 9:53 | No Comment

Microsoft has released two (2) Out-of-Band Security Bulletins addressing vulnerabilities in Internet Explorer and Visual Studio: MS09-034 (Critical) – Cumulative Security Update for Internet Explorer (972260) MS09-035 (Moderate) – Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706) More details in: Microsoft Security Bulletin Summary for IT: http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx Microsoft Security Bulletin Summary for Home Users: http://www.microsoft.com/security/updates/bulletins/200907.aspx Microsoft Security Response Center Blog: http://blogs.technet.com/msrc/ Edit to add:

Read the full story »
Articles

Patch management and related articles.

Bulletins

Microsoft’s monthly security bulletins.

Downloads

Security-related downloads from Microsoft download center.

Exploits

Various exploits seen in the wild.

KB Articles

Microsoft knowledge base articles.

Home » Archive by Category

KB Articles

MS09-035 – Moderate: Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706) – Version:1.0
Tuesday, 28 Jul, 2009 – 1:00 | No Comment

Severity Rating: Moderate – Revision Note: V1.0 (July 28, 2009): Bulletin published.Summary: This security update addresses several privately reported vulnerabilities in the public versions of the Microsoft Active Template Library (ATL) included with Visual Studio. This security update is specifically intended for developers of components and controls. Developers who build and redistribute components and controls using ATL should install the update provided in this bulletin and follow the guidance provided to create, and distribute to their customers, components and controls that are not vulnerable to the vulnerabilities described in this security bulletin.

MS09-034 – Critical: Cumulative Security Update for Internet Explorer (972260) – Version:1.0
Tuesday, 28 Jul, 2009 – 1:00 | No Comment

Severity Rating: Critical – Revision Note: V1.0 (July 28, 2009): Bulletin published.Summary: This security update is being released out of band in conjunction with Microsoft Security Bulletin MS09-035, which describes vulnerabilities in those components and controls that have been developed using vulnerable versions of the Microsoft Active Template Library (ATL).

Microsoft Security Advisory (973882): Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution
Tuesday, 28 Jul, 2009 – 1:00 | No Comment

Revision Note: V1.0 (July 28, 2009): Advisory published.Summary: Security Advisory

An update is available that enables RRAS servers that are running Windows Server 2008 to use the DH-2048 algorithm together with the AES-256 algorithm…
Sunday, 26 Jul, 2009 – 17:53 | No Comment

An update is available that enables RRAS servers that are running Windows Server 2008 to use the DH-2048 algorithm together with the AES-256 algorithm…

Update for Media Center for Windows Vista that resolves logon issues in some extensibility applications
Thursday, 23 Jul, 2009 – 9:22 | No Comment

Update for Media Center for Windows Vista that resolves logon issues in some extensibility applications

Update for Media Center TV Pack for Windows Vista that resolves logon issues in some extensibility applications
Thursday, 23 Jul, 2009 – 9:22 | No Comment

Update for Media Center TV Pack for Windows Vista that resolves logon issues in some extensibility applications

MS09-032 – Critical: Cumulative Security Update of ActiveX Kill Bits (973346) – Version:1.2
Thursday, 23 Jul, 2009 – 1:00 | No Comment

Severity Rating: Critical – Revision Note: V1.2 (July 23, 2009): Clarified the FAQ about Microsoft-specific kill bits contained in this update.Summary: This security update resolves a privately reported vulnerability that is currently being exploited. The vulnerability in Microsoft Video ActiveX Control could allow remote code execution if a user views a specially crafted Web page with Internet Explorer, instantiating the ActiveX control

MS09-016 – Important: Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (961759) – Version:1.2
Thursday, 23 Jul, 2009 – 1:00 | No Comment

Severity Rating: Important – Revision Note: V1.2 (July 23, 2009): Added a link to Microsoft Knowledge Base Article 961759 under Known Issues in the Executive Summary.Summary: This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE). These vulnerabilities could allow denial of service if an attacker sends specially crafted network packets to the affected system, or information disclosure or spoofing if a user clicks on a malicious URL or visits a Web site that contains content controlled by the attacker.

August 2009 cumulative time zone update for Microsoft Windows operating systems
Tuesday, 21 Jul, 2009 – 21:46 | No Comment

August 2009 cumulative time zone update for Microsoft Windows operating systems

E-mail address properties of contacts changed through Exchange Web Services (EWS) are not updated in Outlook or Outlook Web Access (OWA) in Exchange Server 2007 Service Pack 1
Friday, 17 Jul, 2009 – 9:48 | No Comment

E-mail address properties of contacts changed through Exchange Web Services (EWS) are not updated in Outlook or Outlook Web Access (OWA) in Exchange Server 2007 Service Pack 1

Description of Update Rollup 9 for Microsoft Exchange Server 2007 Service Pack 1
Friday, 17 Jul, 2009 – 9:48 | No Comment

Description of Update Rollup 9 for Microsoft Exchange Server 2007 Service Pack 1

An update is available that enables RRAS servers that are running Windows Server 2008 to use the DH-2048 algorithm together with the AES-256 algorithm to negotiate IKE in the L2TP
Wednesday, 15 Jul, 2009 – 10:59 | No Comment

An update is available that enables RRAS servers that are running Windows Server 2008 to use the DH-2048 algorithm together with the AES-256 algorithm to negotiate IKE in the L2TP