Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » MS Out-Of-Band Security Bulletin(s) for December 17, 2008
Search Topic:
Uniqs:
1573
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
best FREE anti-virus, malware, spyware program(s)? »
« Invitation to final beta test of Ad-Aware 2009 edition  
AuthorAll Replies


dp
Premium,MVM
join:2000-12-08
Greensburg, PA
·Verizon Online DSL

MS Out-Of-Band Security Bulletin(s) for December 17, 2008

Microsoft Security Bulletin(s) for December 17, 2008

Published: December 9, 2008 | Updated: December 17, 2008

Note: There may be latency issues due to replication, if the page does not display keep refreshing

Today Microsoft released the following Security Bulletin(s).

Note: »www.microsoft.com/technet/security and »www.microsoft.com/security are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.

Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.

Bulletin Summary:

»www.microsoft.com/technet/securi···dec.mspx

Critical (7)

Microsoft Security Bulletin MS08-071
Vulnerabilities in GDI Could Allow Remote Code Execution (956802)
»www.microsoft.com/technet/securi···071.mspx

Microsoft Security Bulletin MS08-075
Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349)
»www.microsoft.com/technet/securi···075.mspx

Microsoft Security Bulletin MS08-073
Cumulative Security Update for Internet Explorer (958215)
»www.microsoft.com/technet/securi···073.mspx

Microsoft Security Bulletin MS08-078
Security Update for Internet Explorer (960714)
»www.microsoft.com/technet/securi···078.mspx

Microsoft Security Bulletin MS08-070
Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349)
»www.microsoft.com/technet/securi···070.mspx

Microsoft Security Bulletin MS08-072
Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
»www.microsoft.com/technet/securi···072.mspx

Microsoft Security Bulletin MS08-074
Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
»www.microsoft.com/technet/securi···074.mspx

Important (2)

Microsoft Security Bulletin MS08-077
Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
»www.microsoft.com/technet/securi···077.mspx

Microsoft Security Bulletin MS08-076
Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807)
»www.microsoft.com/technet/securi···076.mspx

Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.

If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety 1-866-727-2338. International customers should contact their local subsidiary.

As always, download the updates only from the vendors website - visit Windows Update and Office Update or Microsoft Update websites. You may also get the updates thru Automatic Updates functionality in Windows system.

Security Tool
Find out if you are missing important Microsoft product updates by using MBSA.
--
Microsoft MVP, 2004 - 2008


lilhurricane
16
Premium,Mod
join:2003-01-11
Purple Zone
clubs:
Many thanks, Dp


MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
reply to dp
Thanks dp See Profile.


NICK ADSL UK
Premium,MVM
join:2004-02-22

reply to dp
TechNet Webcast: Information About Microsoft December Out-of-Band Security Bulletin
Event ID: 1032399448


Language(s): English.
Product(s): Security.
Audience(s): IT Professional.


Duration: 60 Minutes
Start Date: Wednesday, December 17, 2008 1:00 PM Pacific Time (US & Canada)



Event Overview


On December 17, 2008, Microsoft will release an out-of-band security bulletin. Join us for a brief overview of the technical details of the security bulletin. The intent of this webcast is to address your concerns. Therefore, most of the webcast is devoted to attendees asking questions about the bulletin and getting answers from our security experts.

Presenters: Christopher Budd, Security Response Communications Lead, Microsoft Corporation, and Adrian Stone, Lead Security Program Manager, Microsoft Corporation


Register Online

Owing to the importance of this update 2 special webcast's will be broadcast so do please register if you wish to get involved. For December the 17th web cast you can register here
»msevents.microsoft.com/CUI/WebCa···yCode=US

And for Thursday the 18th webcast registration can be found here
Start Date: Thursday, December 18, 2008 11:00 AM Pacific Time (US & Canada)
»msevents.microsoft.com/CUI/WebCa···yCode=US
--
Wilders Security Forum Admin
Microsoft MVP - Consumer Security



NICK ADSL UK
Premium,MVM
join:2004-02-22
Many thanks dp for posting


NICK ADSL UK
Premium,MVM
join:2004-02-22

reply to dp
Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB960714)
»www.microsoft.com/downloads/deta···yLang=en

Jrb2
Premium
join:2001-08-31

1 edit
reply to dp
Thanks dp and Nick

PrntRhd

join:2004-11-03
Fairfield, CA
reply to dp
Thanks DP, the MS patch loaded to my primary PC tonight. Required reboot.

GuruGuy

join:2002-12-16
Atlanta, GA
reply to dp
The IE fix came across as "important" in my windows update. Thought it was supposed to be critical.

This was on two vista machines.
--
GuruGuy


Sindows 7

join:2006-09-13
Hope, BC


2 edits
 reply to dp
quote:
Detection and Deployment Tools and Guidance

The Microsoft Baseline Security Analyzer (MBSA) allows administrators to scan local and remote systems for missing security updates

Microsoft Baseline Security Analyzer
The license terms of MBSA 2.0.1 do not expressly list Windows Vista as a supported operating system. However, you may install and use MBSA 2.0.1 according to the MBSA license terms to scan computers that are running a licensed version of Windows Vista.

Microsoft does not support installing MBSA 2.0.1 on computers that run Windows Vista. We recommend that you install MBSA 2.0.1 on a supported operating system. Then, scan Windows Vista-based computers remotely. MBSA 2.0.1 supports the following Windows operating systems:
be nice if your check you system using Vista.


Bondman

join:2001-08-24
Livonia, MI

reply to GuruGuy
I also got this patch as Important for my Vista Laptop. For Windows Server 2008 it was listed as Important on my test server. On my Windows Server 2003 and Windows XP systems it was listed as Critical. Microsoft is also sending its MS Partners an email about this out of bound patch.


Hall
Premium,MVM
join:2000-04-28
Dayton, OH
reply to dp
How reliable is this quick-fix ? I'm always hesitant to apply these rushed patches myself, but I've been affected by this at home and many machines at work have been too.


shearer
Northern Lights
Premium
join:2002-06-18
Toronto, ON
clubs:
reply to dp
I have applied the fix on XP SP2, IE6.
Any proof-of-concept site I can visit to test if IE has been fully secured against this vulnerability?

thanks

ElJay

join:2004-03-17
·Great Works Internet

reply to Hall
said by Hall See Profile :

How reliable is this quick-fix ? I'm always hesitant to apply these rushed patches myself, but I've been affected by this at home and many machines at work have been too.
I know the feeling, but with this one I figured the alternative was worse. I rolled the IE6 patch out to about ten XP SP2 or SP3 boxes and I haven't noticed any problems.
-
Forums » Up and Running » Security » Securitybest FREE anti-virus, malware, spyware program(s)? »
« Invitation to final beta test of Ad-Aware 2009 edition  


Saturday, 13-Mar 12:16:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10.5 years online! © 1999-2010 dslreports.com.
page compression OFF
Most commented news this week
· [136] So, Is This Where Verizon's FiOS Deployment Ends?
· [135] New Comcast TV, Broadband, Phone Price Hikes April First
· [107] The FCC Introduces Their Own Speed Test
· [100] TV Providers Petition FCC for Help in Fee Dispute
· [81] Verizon Wireless: 'All You Can Eat' Has Got To Change
· [76] Researchers Aim To Reduce Copyright Infringement False Positives
· [75] Surprise: AT&T's First Android Isn't Open
· [73] Cablevision And ABC Kiss, Make Up
· [72] OnLive Broadband Game Service To Launch June 17
· [71] Cisco Changes The Universe And Mankind Forever!
Most people now reading
· 10gig blade just crashed. [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Scam]ZML.com Movie Scam Site [Spam, Scam and Phishbusters]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· MagicJack (Error 401) 06/13/09 [MagicJack]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· IPv6 beta [TekSavvy]
· Network DVR delayed Again? [OptimumOnline]
· Magic Jack and Fax machine works great here. [MagicJack]