Skip to main content
MSRC

Security

Microsoft Releases Security Advisory 2847140

Friday, May 03, 2013

Today, we released Security Advisory 2847140 regarding an issue that impacts Internet Explorer 8. Internet Explorer 6, 7, 9 and 10 are not affected by the vulnerability. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message.

New update available for MS13-036

Tuesday, April 23, 2013

Portuguese (Brazil), Русский Today we released a new update to replace KB2823324, which was originally made available through MS13-036. As we previously discussed, we stopped distributing this update when we learned some customers were having issues. The new update, KB2840149, still addresses the Moderate security issue described in MS13-036, and should not cause these issues.

Security Advisory 2755801 revised to address Adobe Flash Player issues (Feb. 26, 2013)

Tuesday, February 26, 2013

Today we revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10 on Windows 8. This advisory revision was released in conjunction with Adobe’s update process. Customers who have automatic updates enabled will not need to take any action because protections will be downloaded and installed automatically.

Security Advisory 2755801 revised to address Adobe Flash Player issues (Feb. 7, 2013)

Thursday, February 07, 2013

Today we revised Security Advisory 2755801 to address issues in Adobe Flash Player in Internet Explorer 10 on Windows 8, this revision was released in conjunction with Adobe’s update process. Customers who have automatic updates enabled will not need to take any action because protections will be downloaded and installed automatically.

January 2013 Security Bulletin Webcast, Q&A, and Slide Deck

Friday, January 11, 2013

Today we’re publishing the January2013 Security Bulletin Webcast Questions & Answers page. During the webcast, we fielded 12 questions focusing primarily on the Print Spooler (MS12-001) and .NET Framework (MS13-004) updates. All questions are included on the Q&A page. We invite our customers to join us for the next scheduled webcast on Wednesday, February 13th at 11 a.

Microsoft Releases Security Advisory 2794220

Saturday, December 29, 2012

Today, we released Security Advisory 2794220 regarding an issue that impacts Internet Explorer 6, 7, and 8. We are only aware of a very small number of targeted attacks at this time. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message.

Verifying update hashes

Tuesday, November 13, 2012

Some of you may have noticed us improving our defense-in-depth practices for bulletins by supplying sha1 and sha2 hashes in the Knowledge Base (KB) articles. This has been most visible in the KB with the addition of the “File hash information” section, but it is also noted in the Frequently Asked Questions (FAQ) section of each bulletin for convenience.

Advance Notification Service for November 2012 Security Bulletin Release

Thursday, November 08, 2012

Today, we’re providing advance notification for six bulletins to help protect customers against 19 CVEs. The four Critical-rated updates will address 13 vulnerabilities in Microsoft Windows, Internet Explorer and the .NET Framework. One bulletin rated Important will address four vulnerabilities in Microsoft Office and finally, one Moderate update will address two issues in Microsoft Windows.