Microsoft Alerts

AplusWebMaster

New member
Advisor Team
FYI...

Microsoft Security Advisory (2718704)
Unauthorized Digital Certificates Could Allow Spoofing
- https://technet.microsoft.com/en-us/security/advisory/2718704
June 03, 2012 - "Microsoft is aware of active attacks using unauthorized digital certificates derived from a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported releases of Microsoft Windows. Microsoft is providing an update for all supported releases of Microsoft Windows. The update revokes the trust of the following intermediate CA certificates:
• Microsoft Enforced Licensing Intermediate PCA (2 certificates)
• Microsoft Enforced Licensing Registration Authority CA (SHA1)
Recommendation. For supported releases of Microsoft Windows, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service..."
* http://support.microsoft.com/kb/2718704

- https://blogs.technet.com/b/msrc/ar...ecurity-advisory-2718704.aspx?Redirected=true
3 Jun 2012 - "We recently became aware of a complex piece of targeted malware known as 'Flame' and immediately began examining the issue. As many reports assert, Flame has been used in highly sophisticated and targeted attacks and, as a result, the vast majority of customers are not at risk. Additionally, most antivirus products will detect and remove this malware. That said, our investigation has discovered some techniques used by this malware that could also be leveraged by less sophisticated attackers to launch more widespread attacks..."

- https://blogs.technet.com/b/srd/arc...rusted-certificate-store.aspx?Redirected=true
3 Jun 2012 - "... we released Security Advisory 2718704*, notifying customers that unauthorized digital certificates have been found that chain up to a Microsoft sub-certification authority issued under the Microsoft Root Authority... we encourage all customers to apply the officially tested update to add the proper certificates to the Untrusted Certificate Store... Components of the Flame malware were signed with a certificate that chained up to the Microsoft Enforced Licensing Intermediate PCA certificate authority, and ultimately, to the Microsoft Root Authority. This code-signing certificate came by way of the Terminal Server Licensing Service that we operate to issue certificates to customers for ancillary PKI-based functions in their enterprise. Such a certificate could (without this update being applied) also allow attackers to sign code that validates as having been produced by Microsoft.
Conclusion: We recommend that all customers apply this update."

- http://support.microsoft.com/kb/894199
Last Review: June 4, 2012 - Revision: 129.0
___

- http://www.securitytracker.com/id/1027114
Jun 4 2012
... Unauthorized digital certificates derived from these certificate authorities are being actively used in attacks.
Windows Mobile 6.x and Windows Phone 7 and 7.5 are also affected.
Impact: A remote user may be able to spoof code signing signatures.
Solution: The vendor has issued a fix (KB2718704), available via automatic update...

>> https://www.f-secure.com/weblog/archives/00002377.html
June 4, 2012
___

Microsoft Security Advisory (2718704)
- http://atlas.arbor.net/briefs/index#-2141289419
Severity: Extreme Severity
Published: Monday, June 04, 2012 20:39
This security vulnerability is high risk and should be looked at ASAP by security teams.
Analysis: Due to the risks involved, multiple sources suggest that this issue be mitigated as soon as possible. The vulnerability has already been used in the Flame malware, which has been around for a few years. How many other potential adversaries have found and are leveraging the same security hole for their purposes is an open question.
Source: http://technet.microsoft.com/en-us/security/advisory/2718704

Source: https://isc.sans.edu/diary.html?storyid=13366
Last Updated: 2012-06-05 ...(Version: 4)

Source: http://www.wired.com/threatlevel/2012/06/internet-security-fail/
June 1, 2012 Mikko Hypponen, Chief Research Officer - F-Secure

:fear::fear:
 
Last edited:
WSUS and Windows update hardening

FYI...

WSUS and Windows update hardening

- http://blogs.technet.com/b/wsus/archive/2012/06/08/further-hardening-of-wsus-now-available.aspx
8 Jun 2012
- http://blogs.technet.com/b/mu/archive/2012/06/06/update-to-windows-update-wsus-coming-this-week.aspx
June 8, 2012 - Revision: 2.2
- http://blogs.technet.com/b/configmg.../further-hardening-of-wsus-now-available.aspx
8 Jun 2012

... and:

- http://support.microsoft.com/kb/2720211
Last Review: June 8, 2012 - Revision: 2.2
- http://support.microsoft.com/kb/894199
Last Review: June 8, 2012 - Revision: 131.0
___

An update for Windows Server Update Services 3.0 Service Pack 2 is available
- http://support.microsoft.com/kb/2720211
Last Review: June 11, 2012 - Revision: 5.0

:fear: :fear: :spider:
 
Last edited:
MS Security Bulletin Summary - June 2012

FYI...

Ref: http://technet.microsoft.com/en-us/security/bulletin

- https://technet.microsoft.com/en-us/security/bulletin/ms12-jun
June 12, 2012 - "This bulletin summary lists security bulletins released for June 2012...
(Total of -7-)

Critical -3-

Microsoft Security Bulletin MS12-036 - Critical
Vulnerability in Remote Desktop Could Allow Remote Code Execution (2685939)
- https://technet.microsoft.com/en-us/security/bulletin/MS12-036
Critical - Remote Code Execution - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-037 - Critical
Cumulative Security Update for Internet Explorer (2699988)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-037
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer

Microsoft Security Bulletin MS12-038 - Critical
Vulnerability in .NET Framework Could Allow Remote Code Execution (2706726)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-038
Critical - Remote Code Execution - May require restart Microsoft Windows, Microsoft .NET Framework

Important -4-


Microsoft Security Bulletin MS12-039 - Important
Vulnerabilities in Lync Could Allow Remote Code Execution (2707956)
- https://technet.microsoft.com/en-us/security/bulletin/MS12-039
Important - Remote Code Execution - May require restart - Microsoft Lync

Microsoft Security Bulletin MS12-040 - Important
Vulnerability in Microsoft Dynamics AX Enterprise Portal Could Allow Elevation of Privilege (2709100)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-040
Important - Elevation of Privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-041 - Important
Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2709162)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-041
Important - Elevation of Privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-042 - Important
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2711167)
- https://technet.microsoft.com/en-us/security/bulletin/MS12-042
Important - Elevation of Privilege - Requires restart - Microsoft Windows

___

Certificate Trust List update...
- https://blogs.technet.com/b/msrc/ar...-the-june-2012-bulletins.aspx?Redirected=true
12 Jun 2012
RSA keys under 1024 bits are blocked
- https://blogs.technet.com/b/pki/arc...er-1024-bits-are-blocked.aspx?Redirected=true
11 Jun 2012

Bulletin deployment priority
- https://blogs.technet.com/cfs-files...es/00-00-00-45-71/2604.June-2012-Priority.png

Severity and exploitability index
- https://blogs.technet.com/cfs-files...es/00-00-00-45-71/8737.June-2012-Severity.png
___

Microsoft Security Advisory (2719615)
Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2719615
June 12, 2012
0-day... CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1889 - 9.3 (HIGH)
> http://support.microsoft.com/kb/2719615#FixItForMe

Microsoft Security Advisory (2269637)
Insecure Library Loading Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2269637
• V16.0 (June 12, 2012) - "... Updates relating to Insecure Library Loading section: MS12-039..."
___

ISC Analysis
- https://isc.sans.edu/diary.html?storyid=13453
Last Updated: 2012-06-12 17:45:41 UTC
___

MSRT
- http://support.microsoft.com/?kbid=890830
June 12, 2012 - Revision: 103.0
(Recent additions)
- http://www.microsoft.com/security/pc-security/malware-families.aspx
... added this release...
• Cleaman
• Kuluoz

Download:
- http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=16
File Name: Windows-KB890830-V4.9.exe - 15.5 MB
- https://www.microsoft.com/download/en/details.aspx?id=9905
x64 version of MSRT:
File Name: Windows-KB890830-x64-V4.9.exe - 16.1 MB

.
 
Last edited:
MS Security Advisories 2012.06.12

FYI...

Microsoft Security Advisory (2719615)
Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2719615
June 12, 2012
0-day... CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1889 - 9.3 (HIGH)
> http://support.microsoft.com/kb/2719615#FixItForMe

- https://secunia.com/advisories/49456/
Release Date: 2012-06-12
Criticality level: Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Workaround
... vulnerability is reportedly being actively exploited.
Solution: Apply Microsoft Fix it solution.
Reported as a 0-day.
Original Advisory: Microsoft:
http://technet.microsoft.com/en-us/security/advisory/2719615

- http://googleonlinesecurity.blogspot.com/2012/06/microsoft-xml-vulnerability-under.html
June 12, 2012 - "... attacks are being distributed both via malicious web pages intended for Internet Explorer users and through Office documents. Users running Windows XP up to and including Windows 7 are known to be vulnerable..."
___

Microsoft Security Advisory (2269637)
Insecure Library Loading Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2269637
• V16.0 (June 12, 2012) - "... Updates relating to Insecure Library Loading section: MS12-039..."
___

An automatic updater of revoked certificates is available for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
- http://support.microsoft.com/kb/2677070
Last Review: June 13, 2012 - Revision: 2.0

> https://blogs.technet.com/b/pki/arc...hy-certificates-and-keys.aspx?Redirected=true
___

> http://forums.spybot.info/showpost.php?p=426868&postcount=25

:fear::fear:
 
Last edited:
MS Security Advisory updates 2012.06.13...

FYI...

Further insight into Security Advisory 2719615
- https://blogs.technet.com/b/msrc/ar...ecurity-advisory-2719615.aspx?Redirected=true
13 Jun 2012 - "During our regular Update Tuesday bulletin cycle this week, we released Security Advisory 2719615*, which provides guidance concerning a remote code execution issue affecting MSXML Code Services. As part of that Advisory, we've built a Fix it workaround that blocks the potential attack vector in Internet Explorer. Fix its are a labor-saving mechanism that helps protect customers from a specific issue in advance of a comprehensive security update. We encourage customers to read more about SA2716915's one-click, no-reboot-required Fix it in an in-depth post on the SRD blog**."
* http://technet.microsoft.com/en-us/security/advisory/2719615

** http://blogs.technet.com/b/srd/archive/2012/06/13/msxml-fix-it-before-fixing-it.aspx

Microsoft Security Advisory (2718704)
Unauthorized Digital Certificates Could Allow Spoofing
- https://technet.microsoft.com/en-us/security/advisory/2718704
"... update revokes the trust of the following intermediate CA certificates:
Microsoft Enforced Licensing Intermediate PCA (2 certificates)
Microsoft Enforced Licensing Registration Authority CA (SHA1) ..."
• V1.1 (June 13, 2012): Advisory revised to notify customers that Windows Mobile 6.x, Windows Phone 7, and Windows Phone 7.5 devices are not affected by the issue.

:fear::fear:
 
FixIt NOW - 0-day XML Core Services...

FYI...

FixIt NOW - 0-day XML Core Services...
> https://isc.sans.edu/diary.html?storyid=13489
Last Updated: 2012-06-16 15:58:47 UTC - "... metasploit module (public release) for this vulnerability. Users are encouraged to patch*..."

* http://support.microsoft.com/kb/2719615#FixItForMe
June 12, 2012 - Revision: 3.0

> http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1889 - 9.3 (HIGH)

- https://secunia.com/advisories/49456/
Last Update: 2012-06-22
Criticality level: Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Workaround
... vulnerability is currently being actively exploited...

- http://h-online.com/-1619732
18 June 2012

- https://www.us-cert.gov/current/#microsoft_releases_security_advisory_for5
updated June 25, 2012

- http://nakedsecurity.sophos.com/201...nerability-included-in-blackhole-exploit-kit/
June 29, 2012 - "... CVE-2012-1889 exploiting code very similar to that published to Metasploit was seen within the landing page of a Blackhole exploit kit..."

:fear::fear: :sad:
 
Last edited:
MS12-034 FixIt...

FYI...

MS12-034: Description of the security update for CVE-2012-0181 in Windows XP and Windows Server 2003
- http://support.microsoft.com/kb/2686509#FixItForMeAlways
Last Review: June 19, 2012 - Revision: 4.0 - "... If you receive the "0x8007F0F4" error when you try to install this security update, check to see if the %windir%\FaultyKeyboard.log file was created on the computer...
Known issues with this security update: In some scenarios, the %windir%\FaultyKeyboard.log file might not have been created on your computer. If the file was not created, follow these steps: To fix this problem automatically, click the Fix it button or link. Then click Run in the File Download dialog box, and follow the steps in the Fix it wizard..."

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0181 - 10.0 (HIGH)

:sad::fear:
 
Last edited:
MS12-037 exploit in-the-wild

FYI...

MS12-037 exploit in-the-wild
- http://nakedsecurity.sophos.com/201...ability-being-actively-exploited-in-the-wild/
June 19, 2012 - "A critical Internet Explorer vulnerability, announced and patched by Microsoft in June's Patch Tuesday, is being exploited in the wild. The vulnerability is CVE-2012-1875*... patched in MS12-037**... Cunningly-crafted JavaScript code - which can be embedded in a web page to foist the exploit on unsuspecting vistors - is circulating freely on the internet. Also, the Metasploit exploitation framework now has a plug-in module which will generate malicious JavaScript for you on-the-fly to help you automate an attack... response is easy: if you haven't patched already, do so right away..."
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1875 - 9.3 (HIGH)

Cumulative Security Update for Internet Explorer (2699988) - Critical
** https://technet.microsoft.com/en-us/security/bulletin/ms12-037
June 12, 2012

- http://www.symantec.com/connect/blogs/cve-2012-1875-wild-part-2-internet-explorer-gets-stumped
19 Jun 2012

- http://atlas.arbor.net/briefs/index#-1257954642
Severity: Elevated Severity
Source: http://www.symantec.com/connect/blogs/cve-2012-1875-exploited-wild-part-1-trojannaid
18 Jun 2012
___

- https://www.us-cert.gov/cas/techalerts/TA12-174A.html
June 22, 2012
> http://support.microsoft.com/kb/2686509#FixItForMeAlways

:mad::sad:
 
Last edited:
IE9 may stop responding ...

FYI...

IE9 may stop responding if DFX Audio Enhancer is installed
- http://support.microsoft.com/kb/2727797/
Last Review: June 22, 2012 - Revision: 2.0 ...
"Consider the following scenario:
You are running Windows Internet Explorer 9.
DFX Audio Enhancer version 10 is installed on the computer.
The following security update is installed on the computer:
2699988 MS12-037: Cumulative Security Update for Internet Explorer: June 12, 2012
In this scenario, Windows Internet Explorer 9 may stop responding, or "hang."
CAUSE: This issue occurs because of an incompatibility with an earlier version of DFX Audio Enhancer...
For more information about how to obtain the latest version of DFX, go to the following third-party webpage:
- http://www.fxsound.com/dfx/index.php ..."

:fear: :sad:
 
Update for Windows Update ...

FYI...

Update for Windows Update ...
- http://h-online.com/-1624979
25 June 2012 - "Microsoft has released an unscheduled, non-patch day update for Windows to update the Windows Update function itself. However, according to reports from readers, the Windows Update Agent update does -not- always run smoothly... Users who run Windows Update are confronted with a message which says that an update for Windows Update needs to be installed before the system can check for other updates. On some computers, clicking the "Install Updates" button results in a failed installation with error code 80070057 or 8007041B. On heise Security's test Windows 7 computer, repeatedly attempting the update (click on "Check for updates" on the left) did eventually result in the update being successfully applied. Microsoft has provided a "Fix it" tool* for more stubborn cases in Knowledge Base Article 949104**. The update in question upgrades the Windows Update Agent from version 7.4.7600.226 to 7.6.7600.256 ..."
* Direct download: http://go.microsoft.com/?linkid=9767096

** http://support.microsoft.com/kb/949104

:sad: :fear:
 
MS June cumulative updates have been released

FYI...

MS June cumulative updates have been released
- https://blogs.technet.com/b/the_mic...dates-have-been-released.aspx?Redirected=true
28 Jun 2012

2007 Office system cumulative update for June 2012
For Excel 2007: http://support.microsoft.com/kb/2712234 ...
June 26, 2012 - "The cumulative update packages for June 2012 contain the latest hotfixes for the 2007 Microsoft Office system and for the 2007 Office servers..."

Office 2010 cumulative update for June 2012
For Excel 2010: http://support.microsoft.com/kb/2712235 ...
June 28, 2012 - "The cumulative update packages for June 2012 contain the latest hotfixes for the Microsoft Office 2010 system and for the Office 2010 servers..."

:fear:
 
.NET 4 updates can take longer than expected

FYI...

Installing updates for the Microsoft .NET Framework 4 can take longer than expected
- http://support.microsoft.com/kb/2570538/en-us?sd=rss&spid=548#fixit4me
Last Review: July 3, 2012 - Rev: 4.0
... CAUSE: Updates to the .NET Framework 4 require a complete regeneration of the Native Image Cache, a very time-consuming operation. For some computers, an interaction with previously installed Native Images may cause Native Image regeneration to take much longer than expected. Although this issue only affects setup times, the effect can be several minutes to tens of minutes. Computers that have more Native Images installed will see longer generation times...
To fix this problem automatically, click the Fix it button or link. Then click Run in the File Download dialog box, and follow the steps in the Fix it wizard...

- http://support.microsoft.com/kb/2570538/en-us?sd=rss&spid=548#appliesto
APPLIES TO Microsoft .NET Framework 4

:fear:
 
MS Security Bulletin Summary - July 2012

FYI...

- https://technet.microsoft.com/en-us/security/bulletin/ms12-jul
July 10, 2012 - "This bulletin summary lists security bulletins released for July 2012...
(Total of -9-)

Critical - 3

Microsoft Security Bulletin MS12-043 - Critical
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-043
Critical - Remote Code Execution - May require restart - Microsoft Windows, Microsoft Office, Microsoft Developer Tools, Microsoft Server Software

Microsoft Security Bulletin MS12-044 - Critical
Cumulative Security Update for Internet Explorer (2719177)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-044
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer

Microsoft Security Bulletin MS12-045 - Critical
Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution (2698365)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-045
Critical - Remote Code Execution - May require restart - Microsoft Windows

Important - 6

Microsoft Security Bulletin MS12-046 - Important
Vulnerability in Visual Basic for Applications Could Allow Remote Code Execution (2707960)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-046
Important - Remote Code Execution - May require restart - Microsoft Office, Microsoft Developer Tools

Microsoft Security Bulletin MS12-047 - Important
Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2718523)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-047
Important - Elevation of Privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-048 - Important
Vulnerability in Windows Shell Could Allow Remote Code Execution (2691442)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-048
Important - Remote Code Execution - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-049 - Important
Vulnerability in TLS Could Allow Information Disclosure (2655992)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-049
Important - Information Disclosure - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-050 - Important
Vulnerabilities in SharePoint Could Allow Elevation of Privilege (2695502)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-050
Important - Elevation of Privilege - May require restart - Microsoft Office, Microsoft Server Software

Microsoft Security Bulletin MS12-051 - Important
Vulnerability in Microsoft Office for Mac Could Allow Elevation of Privilege (2721015)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-051
Important - Elevation of Privilege - Does not require restart - Microsoft Office
___

- https://blogs.technet.com/b/msrc/ar...-the-july-2012-bulletins.aspx?Redirected=true
10 Jul 2012

Bulletin Deployment Priority
- https://blogs.technet.com/cfs-files...logFiles/00-00-00-45-71/3755.July-2012-DP.png

Severity and Exploitability Index
- https://blogs.technet.com/cfs-files...logFiles/00-00-00-45-71/5826.July-2012-XI.png
___

ISC Analysis
- https://isc.sans.edu/diary.html?storyid=13642
Last Updated: 2012-07-10 18:30:31 UTC
___

- https://secunia.com/advisories/49456/ - MS12-043
- https://secunia.com/advisories/45690/ - MS12-044
- https://secunia.com/advisories/49743/ - MS12-045
- https://secunia.com/advisories/49800/ - MS12-046
- https://secunia.com/advisories/49200/ - MS12-047
- https://secunia.com/advisories/49873/ - MS12-048
- https://secunia.com/advisories/49874/ - MS12-049
- https://secunia.com/advisories/49877/ - MS12-050
- https://secunia.com/advisories/49875/ - MS12-050
- https://secunia.com/advisories/49876/ - MS12-051
___

MSRT
- http://support.microsoft.com/?kbid=890830
July 10, 2012 - Revision: 106.0

Download:
- http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=16
File Name: Windows-KB890830-V4.10.exe - 15.6 MB
- https://www.microsoft.com/download/en/details.aspx?id=9905
x64 version of MSRT:
File Name: Windows-KB890830-x64-V4.10.exe - 16.3 MB

.
 
Last edited:
MS Security Advisories - 2012.07.10 ...

FYI...

MS Security Advisories - 2012.07.10 ...

Microsoft Security Advisory (2728973)
Unauthorized Digital Certificates Could Allow Spoofing
- https://technet.microsoft.com/en-us/security/advisory/2728973
July 10, 2012

- https://blogs.technet.com/b/msrc/ar...-the-july-2012-bulletins.aspx?Redirected=true
July 10, 2012 - "... we’ve chosen to -deprecate- the Windows Gadget Gallery effective immediately, and to provide a Fix it to help sysadmins disable Gadgets and the Sidebar across their enterprises..."
Microsoft Security Advisory (2719662)
Vulnerabilities in Gadgets Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2719662
July 10, 2012 - "... Applying the automated Microsoft Fix It* solution described in Microsoft Knowledge Base Article 2719662 disables the Windows Sidebar experience and all Gadget functionality..."
* http://support.microsoft.com/kb/2719662#FixItForMe
Last Review: July 13, 2012 - Revision: 2.0

- https://isc.sans.edu/diary.html?storyid=13651
Last Updated: 2012-07-10 22:10:12 UTC - "... insecure gadgets allow random code to be executed with the rights of the logged on user..."

Microsoft Security Advisory (2719615)
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2719615
Published: Tuesday, June 12, 2012 | Updated: Tuesday, July 10, 2012
"... We have issued MS12-043 to address this issue..."
- http://support.microsoft.com/kb/2722479#FixItForMe
July 10, 2012
Fix it solution for MSXML version 5 - Microsoft Fix it 50908
> http://go.microsoft.com/?linkid=9813081

Microsoft Security Advisory (2269637)
Insecure Library Loading Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2269637
July 10, 2012 - v17.0: Added the following Microsoft Security Bulletin to the Updates relating to Insecure Library Loading section: MS12-046

> http://forums.spybot.info/showpost.php?p=427982&postcount=37

:fear::spider:
 
Last edited:
Win7 SP1 Browser Choice errors ...

FYI...

Win7 SP1 Browser Choice errors ...
- https://www.microsoft.com/en-us/news/press/2012/Jul12/07-17statement.aspx
July 17, 2012 - "Under a December 2009 decision of the European Commission, Microsoft is required to display a “Browser Choice Screen” (BCS) on Windows PCs in Europe where Internet Explorer is the default browser. We have fallen short in our responsibility to do this. Due to a technical error, we missed delivering the BCS software to PCs that came with the service pack 1 update to Windows 7. The BCS software has been delivered as it should have been to PCs running the original version of Windows 7, as well as the relevant versions of Windows XP and Windows Vista. However, while we believed when we filed our most recent compliance report in December 2011 that we were distributing the BCS software to all relevant PCs as required, we learned recently that we’ve missed serving the BCS software to the roughly 28 million PCs running Windows 7 SP1. While we have taken immediate steps to remedy this problem, we deeply regret that this error occurred and we apologize for it. The Commission recently told us that it had received reports that the BCS was not being displayed on some PCs. Upon investigating the matter, we learned of the error... the engineering team responsible for maintenance of this code did not realize that it needed to update the detection logic for the BCS software when Windows 7 SP1 was released last year. As a result of this error, new PCs with Windows 7 SP1 did not receive the BCS software as they should have. Since most computer users run earlier versions of Windows, we estimate that the BCS software was properly distributed to about 90% of the PCs that should have received it. We recognize, however, that our obligation was to distribute the BCS to every PC that should have received it. Therefore, we have moved as quickly as we can to address the error and to provide a full accounting of it to the Commission."

- http://thenextweb.com/microsoft/201...ot-snafu-promises-fix-by-the-end-of-the-week/
"... 28 million PCs in question... Distribution of the fix started on July 3rd..."

What is the Browser Choice update?
- http://support.microsoft.com/kb/976002

.
 
MS advisory - Oracle Outside In libraries

FYI...

Microsoft Security Advisory (2737111)
Vulnerabilities in Microsoft Exchange and FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution
- https://technet.microsoft.com/en-us/security/advisory/2737111
July 24, 2012 - "Microsoft is investigating new public reports of vulnerabilities in third-party code, Oracle Outside In libraries, that affect Microsoft Exchange Server 2007, Microsoft Exchange Server 2010, and FAST Search Server 2010 for SharePoint, which ship that component. Customers that apply the workarounds described in this advisory are not exposed to the vulnerabilities described in Oracle Critical Patch Update Advisory - July 2012. The vulnerabilities exist due to the way that files are parsed by the third-party, Oracle Outside In libraries. In the most severe case of Microsoft Exchange Server 2007 and Microsoft Exchange Server 2010, it is possible under certain conditions for the vulnerabilities to allow an attacker to take control of the server process that is parsing a specially crafted file. An attacker could then install programs; view, change, or delete data; or take any other action that the server process has access to do. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers..."
• V1.1 (July 25, 2012): Revised the workaround titles for clarity. There were no changes to the workaround steps.

More info...
- https://blogs.technet.com/b/srd/arc...ecurity-advisory-2737111.aspx?Redirected=true
24 Jul 2012

Microsoft Exchange Server...
- https://secunia.com/advisories/50019/
Release Date: 2012-07-25
Criticality level: Highly critical
Impact: DoS, System access
Where: From remote...
... more information: https://secunia.com/advisories/49936/
Solution: ... vendor recommends to apply workarounds... see the vendor's advisory...
Original Advisory: Microsoft: http://technet.microsoft.com/en-us/security/advisory/2737111

Microsoft SharePoint and FAST Search Server vuln...
- https://secunia.com/advisories/50049/
Release Date: 2012-07-25
Criticality level: Moderately critical
Impact: DoS, System access
Where: From remote...
... more information: https://secunia.com/advisories/49936/
Solution: ... vendor recommends to apply workarounds... see the vendor's advisory...
Original Advisory: Microsoft: http://technet.microsoft.com/en-us/security/advisory/2737111
___

- http://www.kb.cert.org/vuls/id/118913
Last revised: 27 Jul 2012 - "... used by a variety of applications, including Microsoft Exchange, Oracle Fusion Middleware, Guidance Encase Forensics, AccessData FTK, and Novell Groupwise. Outside In 8.3.7.77 and earlier fail to properly handle multiple file types when the data is malformed..."

Vendor Information for VU#118913
- http://www.kb.cert.org/vuls/byvendor?searchview&Query=FIELD+Reference=118913&SearchOrder=4

- http://h-online.com/-1653568
26 July 2012

Oracle Outside In Advisory ...
- http://atlas.arbor.net/briefs/index#101557049
Severity: Elevated Severity
Published: Thursday, July 19, 2012 21:19
The Oracle Outside In library is used by many other applications and has multiple security holes in it's parsing routines. Patches are available.
Analysis: Security holes in such a library are good news for the attackers, who have multiple targets to choose from. Defenders should patch ASAP. Of the 15 vulnerable vendors, heavyweights such as Microsoft, IBM and Cisco appear along with others. It is a positive development that this security hole was found by a Google security researcher instead of a cyber-criminal.
Source: http://www.kb.cert.org/vuls/id/118913

.
 
Last edited:
MS Support phases ending in the next 2 years

FYI...

> https://blogs.technet.com/b/mrsnrub...ding-in-the-next-2-years.aspx?Redirected=true
5 Aug 2012

July 13th 2013 (2013-07-13)
Windows Server 2008
- enters extended support
- will receive only security/GDR updates
- extended support end July 10th 2018 (2018-07-10)
- last service pack was SP2
- ref: Microsoft Product Lifecycle Search
___

April 8th 2014 (2014-04-08)
Windows XP
- end of support
- no more updates for this product
- includes XP x64 Edition
- last service pack for x86 was SP3
- last service pack for x64 was SP2
- ref: Microsoft Product Lifecycle Search
- ref: End of Support

Office 2003
- end of support
- no more updates for this product
- ref: End of Support

.
 
MS Security Bulletin Summary - August 2012

FYI...

- https://technet.microsoft.com/en-us/security/bulletin/ms12-aug
August 14, 2012 - "This bulletin summary lists security bulletins released for August 2012...
(Total of -9-)

Critical -5-

Microsoft Security Bulletin MS12-052 - Critical
Cumulative Security Update for Internet Explorer (2722913)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-052
Critical - Remote Code Execution - Requires restart - Microsoft Windows, Internet Explorer

Microsoft Security Bulletin MS12-053 - Critical
Vulnerability in Remote Desktop Could Allow Remote Code Execution (2723135
- https://technet.microsoft.com/en-us/security/bulletin/ms12-053
Critical - Remote Code Execution - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-054 - Critical
Vulnerabilities in Windows Networking Components Could Allow Remote Code Execution (2733594)
- https://www.microsoft.com/technet/security/bulletin/MS12-054
Critical - Remote Code Execution - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-060 - Critical
Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-060
Critical - Remote Code Execution - May require restart - Microsoft Office, Microsoft SQL Server, Microsoft Server Software, Microsoft Developer Tools
- http://support.microsoft.com/kb/2708437
Last Review: August 14, 2012 - Revision: 1.3

Microsoft Security Bulletin MS12-058 - Critical
Vulnerabilities in Microsoft Exchange Server WebReady Document Viewing Could Allow Remote Code Execution (2740358)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-058
Critical - Remote Code Execution - Does not require restart - Microsoft Exchange Server

Important -4-

Microsoft Security Bulletin MS12-055 - Important
Vulnerability in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2731847)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-055
Important - Elevation of Privilege - Requires restart - Microsoft Windows

Microsoft Security Bulletin MS12-056 - Important
Vulnerability in JScript and VBScript Engines Could Allow Remote Code Execution (2706045)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-056
Important - Remote Code Execution - May require restart - Microsoft Windows

Microsoft Security Bulletin MS12-057 - Important
Vulnerability in Microsoft Office Could Allow Remote Code Execution (2731879)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-057
Important - Remote Code Execution - May require restart - Microsoft Office

Microsoft Security Bulletin MS12-059 - Important
Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2733918)
- https://technet.microsoft.com/en-us/security/bulletin/ms12-059
Important - Remote Code Execution - May require restart - Microsoft Office
___

Bulletin Deployment Priority
- https://blogs.technet.com/cfs-files...eblogfiles/00-00-00-45-71/4812.Deployment.png

Severity and Exploitability Index
- https://blogs.technet.com/cfs-files.../00-00-00-45-71/4846.August-2012-Severity.png

August 2012 Bulletin Release
- https://blogs.technet.com/b/msrc/ar...st-2012-security-updates.aspx?Redirected=true
14 Aug 2012 - "... MS12-060... We’re aware of limited, targeted attacks attempting to exploit this vulnerability..."
___

- https://secunia.com/advisories/50237/ - MS12-052
- https://secunia.com/advisories/50244/ - MS12-053
- https://secunia.com/advisories/50245/ - MS12-054
- https://secunia.com/advisories/50236/ - MS12-055
- https://secunia.com/advisories/50243/ - MS12-056
- https://secunia.com/advisories/50251/ - MS12-057
- https://secunia.com/advisories/50019/ - MS12-058
- https://secunia.com/advisories/50228/ - MS12-059
- https://secunia.com/advisories/50247/ - MS12-060
___

Update Rollup 4 for Exchange 2010 SP2
- https://blogs.technet.com/b/exchang...ange-2010-service-pack-2.aspx?Redirected=true
14 Aug 2012 - "... On August 13th 2012, the Exchange CXP team released Update Rollup 4 for Exchange Server 2010 SP2 to the Download Center. This update contains a number of customer reported and internally found issues. See KB 2706690* Description of Update Rollup 4 for Exchange Server 2010 Service Pack 2 for more details...
* http://support.microsoft.com/kb/2706690
August 14, 2012 - Revision: 1.0
Applies to:
Microsoft Exchange Server 2010 Service Pack 2, when used with:
Microsoft Exchange Server 2010 Enterprise
Microsoft Exchange Server 2010 Standard
- https://isc.sans.edu/diary.html?storyid=13900#comment
"... apparently we're all getting that rollup whether we want it or not...
posted by GrumpySysAdmin, Wed Aug 15 2012, 21:37"
__

Update Rollup 8 for Exchange 2007 SP3
- https://blogs.technet.com/b/exchang...ange-2007-service-pack-3.aspx?Redirected=true
14 Aug 2012 - "On August 13th 2012, the Exchange CXP team released Update Rollup 8 for Exchange Server 2007 SP3 to the Download Center... See KB 2734323* Description of Update Rollup 8 for Exchange Server 2007 Service Pack 3..."
* http://support.microsoft.com/kb/2734323
Last Review: August 14, 2012 - Revision: 1.0
Applies to: Microsoft Exchange Server 2007 Service Pack 3, when used with:
Microsoft Exchange Server 2007 Enterprise Edition
Microsoft Exchange Server 2007 Standard Edition
___

MSRT
- http://support.microsoft.com/?kbid=890830
August 14, 2012 - Revision: 108.0
- http://www.microsoft.com/security/pc-security/malware-families.aspx
Updated: Aug 14, 2012 - "... added in this release...
• Bafruz
• Matsnu ..."
- https://blogs.technet.com/b/mmpc/ar...t-s-the-buzz-with-bafruz.aspx?Redirected=true
14 Aug 2012

Download:
- http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=16
File Name: Windows-KB890830-V4.11.exe - 15.7 MB
- https://www.microsoft.com/download/en/details.aspx?id=9905
x64 version of MSRT:
File Name: Windows-KB890830-x64-V4.11.exe - 16.3 MB
___

ISC Analysis
- https://isc.sans.edu/diary.html?storyid=13900
Last Updated: 2012-08-14 18:32:51 UTC

.
 
Last edited:
Back
Top