Thu, 2/07/09 – 14:03 | No Comment

MS03-011 * MS02-069 * MS02-052 * MS02-013 * MS00-081 * MS00-075 * MS00-059 * MS00-011 * MS99-045 * MS99-031 Bulletin Information: * MS03-011 - http://www. microsoft .com/technet/ security / bulletin /ms03-011.mspx - Reason for Revision: V2.0 …

Read the full story »
Articles

Patch management and related articles.

Bulletins

Microsoft’s monthly security bulletins.

Downloads

Security-related downloads from Microsoft download center.

Exploits

Various exploits seen in the wild.

KB Articles

Microsoft knowledge base articles.

Home » Archive by Tags

Articles tagged with: revision-note

MS09-002 - Critical: Cumulative Security Update for Internet Explorer (961260) - Version:1.1
Monday, 16 Feb, 2009 – 0:00 | No Comment

Severity Rating: Critical - Revision Note: V1.1 (February 16, 2009): Added a link to Microsoft Knowledge Base Article 961260 under Known Issues in the Executive Summary.Summary: This security update resolves two privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.

MS08-070 - Critical: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349) - Version:1.2
Wednesday, 11 Feb, 2009 – 0:00 | No Comment

Severity Rating: Critical - Revision Note: V1.2 (February 11, 2009): Clarified the class IDs for two ActiveX controls. First, listed a second class ID in the workaround, “Prevent Windows Common AVI ActiveX Control from running in Internet Explorer,” for CVE-2008-4255

Microsoft Security Bulletin Summary for February 2009
Tuesday, 10 Feb, 2009 – 0:00 | No Comment

Revision Note: Bulletin Summary published.Summary: This bulletin summary lists security bulletins released for February 2009.

MS09-005 - Important: Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634) - Version:1.0
Tuesday, 10 Feb, 2009 – 0:00 | No Comment

Severity Rating: Important - Revision Note: Bulletin published.Summary: This security update resolves three privately reported vulnerabilities in Microsoft Office Visio that could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights

MS09-004 - Important: Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420) - Version:1.0
Tuesday, 10 Feb, 2009 – 0:00 | No Comment

Severity Rating: Important - Revision Note: Bulletin published.Summary: This security update resolves a privately reported vulnerability in Microsoft SQL Server.

MS08-074 – Critical: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070) - Version:2.0
Wednesday, 28 Jan, 2009 – 0:00 | No Comment

Severity Rating: Critical - Revision Note: V2.0 (January 28, 2009): Added a footnote to the Affected Software table and two entries to the section, Frequently Asked Questions (FAQ) Related to this Security Update, pertaining to security updates KB958437 and KB958439 for supported versions of Microsoft Office Excel 2007.

MS08-040 – Important: Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203) - Version:1.7
Wednesday, 21 Jan, 2009 – 0:00 | No Comment

Severity Rating: Important - Revision Note: V1.7 (January 21, 2009): Listed Microsoft SQL Server 2000 Desktop Engine (MSDE 2000) Service Pack 3a, a component of Application Center 2000 Service Pack 2, as non-affected software.Summary: This security update resolves four privately disclosed vulnerabilities. The more serious of the vulnerabilities could allow an attacker to run code and to take complete control of an affected system. An authenticated attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.

Microsoft Security Bulletin Summary for January 2009
Tuesday, 13 Jan, 2009 – 0:00 | No Comment

Revision Note: Bulletin Summary published.Summary: This bulletin summary lists security bulletins released for January 2009.

Microsoft Security Advisory (961509): Research proves feasibility of collision attacks against MD5
Tuesday, 30 Dec, 2008 – 0:00 | No Comment

Revision Note: Advisory publishedSummary: Microsoft is aware that research was published at a security conference proving a successful attack against X.509 digital certificates signed using the MD5 hashing algorithm. This attack method would allow an attacker to generate additional digital certificates with different content that have the same digital signature as an original certificate. The MD5 algorithm had previously shown a vulnerability, but a practical attack had not yet been demonstrated.

Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution
Tuesday, 30 Dec, 2008 – 0:00 | No Comment

Revision Note: December 30, 2008: Changed the CVE Reference in the Overview section to CVE-2008-5416.Summary: Microsoft is investigating new public reports of a vulnerability that could allow remote code execution on systems with supported editions of Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2000 Desktop Engine (WMSDE), and Windows Internal Database (WYukon). Systems with Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 Service Pack 3, and Microsoft SQL Server 2008 are not affected by this issue.

MS08-078 - Critical: Security Update for Internet Explorer (960714) - Version:1.1
Thursday, 18 Dec, 2008 – 0:00 | No Comment

Severity Rating: Critical - Revision Note: V1.1 (December 18, 2008): Added unaffected server core notation for Windows Server 2008 for 32-bit Systems and Windows Server 2008 for x64-based Systems.

MS08-069 – Critical: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218) - Version:1.2
Wednesday, 17 Dec, 2008 – 0:00 | No Comment

Severity Rating: Critical - Revision Note: V1.2 (December 17, 2008): Added log file entries in the Security Update Deployment section Reference table for Microsoft XML Core Services 6.0 when installed on Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2, Windows Server 2003 x64 Edition, and Windows Server 2003 x64 Edition Service Pack 2.Summary: This security update resolves several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer.