Skip to main content
MSRC

2008

UPDATE: July 2008 Bulletin Monthly Release - SQL update detection issue

Tuesday, July 08, 2008

Hi, Simon here again – I just wanted to follow up on the SQL update detection issue I mentioned below. We’ve released updated WU/MU detection and an updated WSUS catalog to resolve this issue. Cheers, Simon Release Manager, MSRC July 2008 Monthly Bulletin Release I’m Simon, Release Manager in the MSRC.

Snapshot Viewer ActiveX Control Vulnerability

Monday, July 07, 2008

Hi. Bill here. I want to let you know that we have just posted Microsoft Security Advisory 955179, which contains information regarding active, targeted attacks using a vulnerability in the Snapshot Viewer ActiveX control for Microsoft Access. The Snapshot Viewer enables you to view a report snapshot without having the standard or run-time versions of Microsoft Office Access.

July 2008 Advance Notification

Thursday, July 03, 2008

Hello, Bill here. I wanted to let you know that we just posted our Advance Notification for next week’s bulletin release which will occur on Tuesday, July 8, 2008 around 10 a.m. Pacific Standard Time. It is important to remember that while the information posted below is intended to help with your planning, because it is preliminary information, it is subject to change.

The IE8 XSS Filter

Wednesday, July 02, 2008

Hello, our team and IE have recently collaborated on a new IE8 feature that was announced today – the XSS Filter. Check it out here: http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx This effort demonstrates our commitment to helping our product teams benefit from the knowledge we have gained while defending our products from attack. Stay tuned to our blog for more stories like this in weeks to come…

XSSFilter in Internet Explorer 8.0

Wednesday, July 02, 2008

Hello everyone, this is Robert “RSnake” Hansen. It’s been a while since I’ve talked with the BlueHat folks but only because I’ve been busy behind the scenes working on some cool stuff with the Microsofties. I was pleasantly surprised to hear I am now allowed to talk about one of the things I have helped work on.

Microsoft Windows Server Update Services (WSUS) Blocked from Deploying Security Updates

Monday, June 30, 2008

Hi. Bill here. I want to let you know that we have just posted Microsoft Security Advisory 954960, which contains information regarding deployment Issues with Microsoft Windows Server Update Services (WSUS) version 3.0 and 3.0 Service Pack 1. Under specific conditions, the issue does not let clients detect any updates from a WSUS server on systems with Microsoft Office 2003 installed.

News from FIRST 2008: Driving Security Response Excellence and Innovation

Thursday, June 26, 2008

Hi, Andrew here, Often, when you see me blogging, I’m talking about the important work we do with the researcher community. However, in addition to work with researchers, we’re always looking for ways to foster work with others in the industry and share best practices. As I sit here today at the annual FIRST Conference and think about the future of security response, I’m excited to tell you about ICASI (Industry Consortium for the Advancement of Security on the Internet), a new non-profit organization that will enhance global IT security by proactively driving excellence and innovation in security response.