Skip to main content
MSRC

Microsoft Security Response Center Blog

Latest on security update for Microsoft Security Advisory 935423

Sunday, April 01, 2007

Hello everyone, this is Christopher Budd. We have some new information tonight on the status of the security update that we’re working on that addresses the vulnerability in Windows Animated Cursor Handling. From our ongoing monitoring of the situation, we can say that over this weekend attacks against this vulnerability have increased somewhat.

Microsoft Security Advisory 935423 and Windows Server 2003 SP2

Saturday, March 31, 2007

Hello everyone, this is Christopher Budd. As I noted yesterday, we have teams doing ongoing investigation and research around the technical issues for the vulnerability in Windows Animated Cursor Handling. Today, we’ve made an update to the advisory with additional information from that ongoing work. We’ve added information regarding Windows 2003 Service Pack 2 in the “Related Software” section to note that these versions are affected by the issue as well.

Update on Microsoft Security Advisory 935423

Friday, March 30, 2007

Hello everyone, This is Christopher Budd. We’ve gotten some questions from customers around the security advisory that we released yesterday, Microsoft Security Advisory (935423). Specifically, we’ve been getting questions about: · When we learned about the vulnerability · When we learned about the attack · What we’re doing to help protect customers

Microsoft Security Advisory 935423 Posted

Thursday, March 29, 2007

Hey everyone this is Adrian Stone, I wanted to let people know that we have just posted Microsoft Security Advisory (935423). This advisory addresses new public reports of very limited attacks against a newly reported vulnerability in Microsoft Windows Animated cursor handling. We’ve activated our Software Security Incident Response Process (SSIRP) and there are few items worth noting:

March 2007 Bulletin Release Day

Tuesday, March 13, 2007

Hello, this is Christopher Budd, Since it’s the second Tuesday for March, I wanted to go ahead and make a short posting to confirm what we announced last Thursday: we are not releasing any security updates today. We are releasing an update to the Malicious Software Removal Tool today: this month’s update removes Win32/Alureon and you can download the tool at www.

March 2007 Advance Notification

Thursday, March 08, 2007

Hello, This is Christopher Budd and it’s the Thursday before the Second Tuesday for March 2007. As we do each month at this time, we’ve posted our Advance Notification for the upcoming security bulletin release. For the month of March 2007, we will not be releasing any new security updates on March 13, 2007.

Microsoft Security Advisory 933052 Published

Wednesday, February 14, 2007

Hey everyone this is Alexandra Huft, Very briefly, I wanted to let you know that we’ve posted a new advisory on a new Word issue. We’ve posted Microsoft Security Advisory (933052) that details a vulnerability that affects Word 2000 and Word 2002. We’ve activated our Software Security Incident Response Process (SSIRP) and we are aware of We are aware of very limited, targeted attacks attempting to exploit this.

February 2007 Bulletin Release

Tuesday, February 13, 2007

Hi Everyone! This is Tami Gallupe. I’m one of the new release managers here with the MSRC. I and my colleague Simon are taking over the release mantle from Craig Gehre here, so you’ll be hearing from us now with information about our releases. For my first post, I wanted to go ahead and let you know about February’s bulletin release.

February 2007 Advance Notification

Thursday, February 08, 2007

Hello, This is Christopher Budd and it’s the Thursday before the Second Tuesday for February 2007. As we do each month at this time, we’ve posted our Advance Notification for the upcoming security bulletin release. I did want to note that this month, the Thursday before the Second Tuesday is actually the second Thursday of the month.

Microsoft Security Advisory 932553 Posted

Friday, February 02, 2007

Hey everyone this is Alexandra Huft, I wanted to let people know about a new issue that we’ve activated our Software Security Incident Response Process (SSIRP) for: we have some information we can share from the investigation so far and I wanted to share it with you. We just posted Microsoft Security Advisory (932553).