Skip to main content
MSRC

Month Archives: April 2010

Security Advisory 983438 Released

Thursday, April 29, 2010

Hello. Today we released Security Advisory 983438, addressing a cross-site scripting (XSS) vulnerability in SharePoint Server 2007 and SharePoint Services 3.0 that could allow Elevation of Privilege (EoP) within the SharePoint site itself. Servers are at reduced risk from Internet Explorer 8 clients, as the Internet Explorer 8 XSS filter helps to mitigate the issue in the internet zone.

Sharepoint XSS issue

Thursday, April 29, 2010

Today we released Security Advisory 983438 informing customers of a cross-site scripting (XSS) vulnerability in SharePoint Server 2007 and SharePoint Services 3.0. Here we would like to give further technical information about this vulnerability. What is the attack vector? The advisory states that the vulnerability could allow Elevation of Privilege (EoP) within the SharePoint site itself.

MS10-025 Re-Release Ready

Tuesday, April 27, 2010

Hi everyone – I’m Carlene Chmaj, new to the Security Response team and here to tell you that the re-release of MS10-025 is available. Again, this only affects those with Windows 2000 Servers in a non-default configuration with Windows Media Services installed. All customers with this configurartion are advised to install this re-released update.

MS10-025 Security Update to be Re-released

Wednesday, April 21, 2010

Hi, MS10-025 is a security update that only affects Windows 2000 Server customers who have installed Windows Media Services (this is a non-default configuration). Today we pulled the update because we found it does not address the underlying issue effectively. We are not aware of any active attacks seeking to exploit this issue and are targeting a re-release of the update for next week.

Guidance on Internet Explorer XSS Filter

Monday, April 19, 2010

The XSS Filter related Blackhat EU presentation discussed a vulnerability that was previously disclosed and addressed in the January security update to Internet Explorer (MS10-002). This attack scenario involved modified HTTP responses, enabling XSS on sites that would not otherwise be vulnerable. An additional update to the IE XSS Filter is currently scheduled for release in June.

Monthly Security Bulletin Webcast Q&A - April 2010

Friday, April 16, 2010

Hosts: Adrian Stone, Senior Security Program Manager Lead Jerry Bryant, Group Manager, Response Communications Website: TechNet/security Chat Topic: April 2010 Security Bulletin Release Date: Tuesday, April 13, 2010 Q: Are the MS10-023 and MS10-028 updates available via Window Server Update Services (WSUS)? They were not listed in KB894199, or as an exception by KB910723?

Software Security == People && Process && Technology

Thursday, April 15, 2010

Mark Curphey here. I run the Subscriptions Engineering Team in Server & Tools Online, where we build complex customer facing web sites like MSDN and TechNet, supporting millions of users. For the last 15 years, I have always held security roles, most recently heading up the Information Security Tools team here at Microsoft, where we were best known for building static code analysis tools and web protection libraries for managed code.