Skip to main content
MSRC

MSRC

Update on Security Advisory 2269637

Tuesday, August 31, 2010

Hi everyone, Since we released Security Advisory 2269637 on August 23, we’ve continued to conduct an investigation not only into our own affected products, but also into how we can best help to protect customers given DLL preloading also affects some third-party applications. We’d like to provide an update on our investigation.

Microsoft Security Advisory 2269637 Released

Saturday, August 21, 2010

Overview Today we released MicrosoftSecurity Advisory 2269637. This is different from other Microsoft Security Advisories because it’s not talking about specific vulnerabilities in Microsoft products. Rather, this is our official guidance in response to security research that has outlined a new, remote vector for a well-known class of vulnerabilities, known as DLL preloading or “binary planting” attacks.

August 2010 Webcast and QA

Thursday, August 12, 2010

Hello, Today we published the Questions & Answers from the August 2010 Security Bulleting webcast. We answered a total of 17 questions concerning the March bulletins and open Security Advisories. No particular themes emerged from the questions but there were some good ones so please review them. The video covers the core part of the presentation Adrian Stone and I gave during the webcast.

August 2010 Security Bulletin Release

Tuesday, August 10, 2010

Hello all. As part of our usual cycle of monthly updates, today Microsoft is releasing 14 security bulletins, addressing 34 vulnerabilities. Eight of those bulletins have a Critical severity rating, and we consider four of those to be high-priority deployments: MS10-052 This bulletin resolves a privately reported vulnerability in Microsoft’s MPEG Layer-3 audio codecs.

Update on the publicly disclosed Win32k.sys EoP Vulnerability

Tuesday, August 10, 2010

Hi everyone, Yesterday we tweeted to let customers know that we were investigating a publicly disclosed vulnerability in the Windows Kernel-mode drivers (win32k.sys) affecting all supported operating systems. We are not aware of attacks that try to use the reported vulnerability or of any customer impact at this time. Today we have more information, as well as a planned course of action.

August 2010 Bulletin Release Advance Notification

Thursday, August 05, 2010

Hello; I’m Angela Gunn and I’m new to the Response Communications team. Today we’re releasing our advance notification for the August security bulletin release, which is scheduled for Tuesday, August 10. This month’s release is composed of 14 bulletins addressing 34 vulnerabilities in Windows, Microsoft Office, Internet Explorer, SQLMSXML, and Silverlight.

August 2010 Out-of-Band Security Release Webcast Q&A

Tuesday, August 03, 2010

Hello - During today’s webcast our team of technical experts answered over fifty questions regarding the August 2010 Out-of-Band Security Release update questions. Click hereto review the entire list of questions and answers from today’s Out-of-Band webcast Q&A page. Also, here is the link to the Q&A index page for your review - in case you wanted to view any of the past 12 webcast Q&A’s.

MS10-046 Released Out-of-Band Today

Monday, August 02, 2010

Hello, As we announced on Friday, today we released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. This security update addresses a vulnerability in the handling of shortcuts that affects all currently supported versions of Windows XP, Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2. As our colleagues over in the MMPC have noted, several families of malware have been attempting to attack this vulnerability.

Out of Band Release to address Microsoft Security Advisory 2286198

Thursday, July 29, 2010

Today we’re announcing plans to release a security update to address the vulnerability discussed in Security Advisory 2286198 on Monday, August 2, 2010 at or around 10 AM PDT. We are releasing the bulletin as we’ve completed the required testing and the update has achieved the appropriate quality bar for broad distribution to customers.

Community-Based Defense: Looking Outward, Moving Forward

Wednesday, July 28, 2010

Two years ago, in front of a standing-room only crowd here at Black Hat, we introduced three new information sharing programs as well as the concept of Community-Based Defense. The underlying concept shared by all three programs was simple-collaboration will be key to preventing and defending against online crime going forward; no one company, individual or technology can do it alone.