Microsoft has released latest Security Updates that fixes critical vulnerabilities in Windows, Internet Explorer, MS Word and a number of other programs.It contains  14 bulletins covering 34 serious security vulnerabilities in Internet Explorer, Microsoft Windows, Microsoft Office, Silverlight, Microsoft XML Core Services and Server Message Block.Eight of the bulletins are rated “critical” because of the risk of remote code execution attacks.  The other six are rated “important.”

Critical Updates:

•MS10-052:  Resolves vulnerability in Microsoft's MPEG Layer-3 audio codecs.
•MS10-055:  Fxes a hole in Windows Media Player's Cinepak Codec .
•MS10-056:  Resolves four flaws in Microsoft Office.
•MS10-060: Plugs two holes that could allow remote code execution, in Microsoft .Net Framework and Microsoft Silverlight

 

8-12-2010 06-43-15

Full details  available here :Microsoft Security Bulletin Summary for August 2010 and Assessing the risk of the August security updates

Microsoft  released  three critical security bulletins on Tuesday, plugging ten security patches covering a massive number of vulnerabilities, including a single Office patch that takes out fourteen bugs,those  fixing 34 vulnerabilities affecting all supported versions of Windows, Office XP, Office 2003 and 2007.

6-9-2010 07-21-02

Details here:-

 

6-9-2010 06-53-19

Security Patches

MS10-032/KB979559 - Important (2000, XP, 2003, Vista, 7, 2008, 2008 R2)

MS10-033/KB979902 - Critical (2000, XP, Vista, 7, 2003, 2008, 2008 R2)

MS10-034/KB980195 - Critical (2000, XP, Vista, 7)/Moderate (2003, 2008, 2008 R2)

MS10-035/KB982381 - Critical (2000, XP, Vista, 7, 2003, 2008, 2008 R2)

MS10-036/KB983235 - Important (Office XP, Office 2003, Office 2007)

MS10-037/KB980218 - Important (2000, XP, Vista, 7, 2003, 2008, 2008 R2)

MS10-038/KB2027452 - Important (Office XP, Office 2003, Office 2007, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format Converter for Mac, Excel Viewer, Office Compatibility Pack for Office 2007 File Formats)

MS10-039/KB980218 - Important (InfoPath 2003, InfoPath 2007, Office SharePoint Server 2007, Windows SharePoint Services 2.0

Desktop / Server MS10-040/KB982666 - Important (Vista, 7, 2003, 2008, 2008 R2)

MS10-041/KB981343 - Important (2000, XP, Vista, 7, 2003, 2008, 2008 R2)

Microsoft’s summary of the June releases can be found here

How many occasions you have to leave your computer, after a format, to download the Windows updates you had before it?Is there a solution?Try Autopatcher .It was one of the first software based services that allowed Windows users to download all released service packs and patches for their operating system and Microsoft Office. The service had been in troubles in the past thanks to an disagreement with Microsoft. They did come back from that and have changed the way AutoPatcher operates.

The main benefit of using AutoPatcher is that it will download all patches that have been released to the local computer system with the option to install them afterwards. This means that the patches can be installed while the computer is offline. It also means that the patches can be distributed to other computer systems to patch those as well.

3-11-2010 17-08-53

Using AutoPatcher is really easy.After downloading you’ll have to extract the file’s contents in order to run AutoPatcher.It will display a list of all available release packages that can be downloaded to the local computer system.If you want to burn AutoPatcher on a CD (so it can run directly off the CD), just burn the contents of the folder in which you extracted the contents of the file you downloaded. It  has now been updated to support Windows 7. The biggest benefit of AutoPatcher is that it is able to effortlessly install multiple updates in a batch without requiring repeated user intervention.

In addition to downloading updates for Windows 7, the program is able to download updates for Windows XP, 2003/2008 Server and Vista (32 and 64 bit), Microsoft Office XP, 2003 and 2007. NET Framework, DirectX, Java and Adobe Reader .

Download: AutoPatcher  |1.07 MB

Microsoft issued 13 security bulletins for February's Patch Tuesday, patching a total of 26 vulnerabilities in a massive update Feb. 9.Five of the vulnerabilities are rated "Critical," seven are marked as "Important," and the last one is classified as "Moderate." .

2-10-2010 17-52-03 

The seventeen-year-old Windows vulnerability that came to light last month will be patched, but the Internet Explorer flaw discovered this week will not.

Further reading: Microsoft Security Bulletin  February 2010 –Summary

Breakdown of the some of the more notable issues being addressed here

Microsoft's  Patch Tuesday (08-12-2009) fix will solve a reported twelve security flaws.Among the critical patches, two affect Windows, and there is one each that addresses issues in Word, Excel, Visual Basic, and Internet Explorer.Three of the six bulletins will be rated “critical”.

 

The patches will fix security holes in:

  • Internet Explorer 5, 6, 7 & 8
  • Windows 2000 Service Pack 4
  • Windows XP Service Pack 2 & 3
  • Windows Vista Service Pack 1 & 2
  • Windows Server 2003 Service Pack 2
  • Windows Server 2008 Systems Service Pack 2
  • Office XP Service Pack 3
  • Office 2003 Service Pack 3

 

12-9-2009 06-43-59

 

For more details visit Microsoft Security Bulletin Summary for December 2009

Security Patches

KB974392

MS09-070

KB974318

KB976325

KB975539

KB967183

KB954157

KB976138

Other Updates

KB954157

KB970430 

KB971737 

KB973917

Microsoft  released six bulletins  for July  on Tuesday,three of the vulnerabilities are rated "Critical," and the other three are marked as "Important.".All of the Critical vulnerabilities earned their rating through a remote code execution impact, meaning a hacker could potentially gain control of an infected machine.

 

They are:

  • MS09-029: This covers two  vulnerabilities in the Microsoft Windows component, Embedded OpenType  Font Engine. The vulnerabilities could allow remote code execution.   Rated  “critical” for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, AntiPhishingShieldand Windows Server 2008.
  • MS09-028:  This update fixes three separate vulnerabilities in Microsoft DirectShow. The vulnerabilities could allow remote code execution if a user opened a specially crafted QuickTime media file.
  • MS09-032: This security update resolves a privately reported vulnerability in Microsoft Video ActiveX Control. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer that uses the ActiveX control.  This rated “critical”for all supported editions of Windows XP and “moderate” for all supported editions of Windows Server 2003.

Three other bulletins were issued to cover a solitary bug  in Microsoft Virtual PC and Microsoft Virtual Server; a privilege escalation issue in Microsoft Internet Security and Acceleration (ISA) Server 2006; and a remote code execution hole in Microsoft Office Publisher.

More details here :http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx

The software you are using today likely has security holes that nobody has discovered yet.If you don't keep up with the latest software, you will eventually get hacked.A patch is a small piece of software designed to fix problems with or update a computer program or its supporting data.

Most major software companies will periodically release patches, , that correct very specific problems in their software programs.Most of the  patches are free to download andSparksSpace the majority of them are now simply downloaded from the Internet .A fair percentage of these patches help to address problems, but a poorly composed software patch may actually create new problems.It is very important to keep yourself apprised of security updates to all of the software on your machine. The easiest way to do this is to check the software vendor or developer's website on a regular basis or to join a mailing list that keeps users informed about security vulnerabilities and updates.

 

The following types of software are most likely to contain a security vulnerability

 

  • Operating Systems - Windows, Macintosh, UNIX/Linux, etc.
  • Server Software - Web servers, Mail servers, FTP servers, Database servers, etc.
  • Web Browsers - Internet Explorer, Netscape, Safari, Mozilla FireFox, Chrome etc.
  • Email Clients - Outlook, Outlook Express, Eudora, Netscape, Mozilla, etc.
  • Peer-to-Peer File Sharing software - BitComet, BitLord, BitTorrent, FlashGet, G3 Torrent,KTorrent, LimeWire,QTorrent, rTorrent, Shareaza,Kazaa, Gnutella, eDonkey, etc.

When a patch is released it is important to install it, as it may improve security or fix a compromising bug that previously slipped through. Be sure you download the patch from a reliable source, such as the software's website.

 

Useful Links

 

Related Reading :

Eight security bulletins were released by Microsoft on Tuesday, April 14, 2009, five of  which are rated critical. They affect IE (MS09-014), Excel (MS09-009), WordPad and Office Text Converters (MS09-010), ISA Server and Forefront (MS09-016), a whole bunch more...

4-15-2009 6-06-20 AM

 

Microsoft’s summary of the April releases can be found here: Critical Bulletins

Microsoft ,Tuesday released three security bulletins with fixes for vulnerabilities affecting millions of Windows OS users.

 

windows-logo

 

  • MS09-006/KB958690 — Critical (XP, Vista, 2000, 2003, 2008):. Provides cover for three newly discovered and privately reported vulnerabilities in Windows. This particular bug allows attackers to remotely execute code via a specially crafted EMF or WMF image. You should install this patch immediately. These vulnerabilities affect all versions of Windows, including Vista and Windows Server 2008.
  • MS09-007/KB960225 — Important (XP, Vista, 2000, 2003, 2008): This bulletin includes a patch for a solitary vulnerability in Windows, which could allow spoofing if an attacker gains access to the certificate used by the end user for authentication. To exploit this bug, the attacker needs access to the certificate that the end user has for authentication, which is why it is lowered to “Important.” This is not the worst bug in history, but you will want to install this patch when convenient. This affects 32-bit and 64-bit versions of Windows, including Server Core.
  • MS09-008/KB961063/KB961064 – Important (2000, 2003, 2008): The DNS and WINS servers in Windows Server have a vulnerability that could allow someone to mess with the lookups; from there, all sorts of mischief can occur, such as swapping google.com to some undesirable Web site. Install this patch on any server running DNS or WINS that an attacker might have access to. This affects 32-bit and 64-bit versions of Windows Server, including Server Core.

Windows users should treat the “critical” bulletin with the highest possible priority.

fix

 

Microsoft dropped a monster Patch Tuesday release with fixes for at least 28 vulnerabilities affecting Windows, Office, Internet Explorer, Visual Basic Active Controls and Windows Media Player.Of the 28 flaws, 23 carry a “critical” rating.

sparkspace

 

 

Here are the raw details on all the patches:

  • MS08-070 (critical; 6 vulnerabilities fixed): This update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls), which could allow remote code execution if a user browsed a Web site that contains specially crafted content.
  • MS08-071 (critical; 2 vulnerabities fixed): This update resolves two privately reported vulnerability in Windows, which could allow remote code execution if a user opens a specially crafted WMF image file.
  • MS08-072 (critical; 8 vulnerabilities): This update resolves eight privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Word or Rich Text Format (RTF) file.
  • MS08-073 (critical; 4 vulnerabilities fixed): This update resolves four privately reported vulnerabilities in Internet Explorer, which could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
  • MS08-074 (critical; 3 vulnerabilities): This update resolves three privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Excel file.
  • MS08-075 (critical; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution if a user opens and saves a specially crafted saved-search file within Windows Explorer or if a user clicks a specially crafted search URL.
  • MS08-076 (important; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution.
  • MS08-077 (important; 1 vulnerability): This update resolves one privately reported vulnerability in Microsoft Office SharePoint, which could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack could result in denial of service or information disclosure.

Patch Tuesday Release

Microsoft’s scheduled batch of patches for November fixes at least four documented vulnerabilities affecting Windows, Internet Explorer and Office users.

vista-patch-bandaid-sp1

The updates apply to users running all supported versions of Windows (including Vista and Windows Server 2008) and most versions of Microsoft Office

Details available here

The first critical  update cover the risk of remote code execution attacks ,if a Windows user is simply tricked into browsing to a rigged Web page with Internet Explorer

Microsoft Security Bulletin MS08-069

The second update  provides cover for a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. Exploit code for this flaw is currently available on the Internet.

Microsoft Security Bulletin MS08-068

Microsoft Corp. fixed a critical bug in its Windows operating system Thursday, saying that it is being exploited by online criminals and could eventually be used in a widespread "worm" attack.Microsoft says it found evidence two weeks ago of an RPC attack that can potentially infect Windows machines.Microsoft  issued urgently this critical patch ahead of regularly scheduled  November updates(the second Tuesday of each month).

                      security vista-patch-bandaid-sp1

"It is possible that this vulnerability could be used in the crafting of a wormable exploit. If successfully exploited, an attacker could then install programs or view, change, or delete data; or create new accounts with full user rights," Microsoft said in the  Microsoft Security Bulletin MS08-067 released Thursday morning.The company also will reveal more details about the patch in a special Webcast.

Windows Server 2003, 2000, and XP (even with Service Pack 2 or 3 installed) are particularly vulnerable.I would highly recommend applying this patch as soon as possible, either by visiting Windows Update or enabling Automatic Updates.

• Windows 2000 with Service Pack 4 patch download
• Windows XP with Service Pack 2 or 3 patch download
• Windows XP 64-bit Edition patch download
• Windows Server 2003 with Service Pack 1 or 2 patch download
• Windows Server 2003 64-bit Edition patch download
• Windows Vista with or without Service Pack 1 patch download
• Windows Vista 64-bit Edition with or without Service Pack 1 patch download
• Windows Server 2008 32-bit Edition patch download
• Windows Server 2008 64-bit Edition patch download

For more information please read security bulletin MS08-067