Archive for the ‘patches’ Category
Patch Tuesday – Dec. 8, 2009
|
Bulletin ID
|
Bulletin Title
|
Max Severity Rating
|
Vulnerability Impact
|
Restart Requirement
|
Affected Software*
|
|
MS09-069 |
Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392) |
Important |
Denial of Service |
Requires restart |
Microsoft Windows 2000, Windows XP, and Windows Server 2003 |
|
MS09-070 |
Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) |
Important |
Remote Code Execution |
Requires restart |
Microsoft Windows Server 2003 and Windows Server 2008 |
|
MS09-071 |
Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318) |
Critical |
Remote Code Execution |
Requires restart |
Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 |
|
MS09-072 |
Cumulative Security Update for Internet Explorer (976325) |
Critical |
Remote Code Execution |
Requires restart |
Internet Explorer on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 |
|
MS09-073 |
Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) |
Important |
Remote Code Execution |
Requires restart |
Microsoft Windows 2000, Windows XP, Windows Server 2003, Office XP, Office 2003, Works 8.5, and Office Converter Pack |
|
MS09-074 |
Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) |
Critical |
Remote Code Execution |
May require restart |
Microsoft Project 2000, Project 2002, and Project 2003 |
|
* The list of affected software in the summary table is an abstract. To see the full list of affected components please click on the bulletin summary Web page link below and review the “Affected Software” section. |
|||||
=================================
New Security Bulletins
=================================
Microsoft is releasing the following six new security bulletins for newly discovered vulnerabilities:
Bulletin ID: MS09-069
Bulletin Title: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)
Max Severity Rating: Important
Vulnerability Impact: Denial of Service
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000, Windows XP, and Windows Server 2003
——————————–
Bulletin ID: MS09-070
Bulletin Title: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)
Max Severity Rating: Important
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows Server 2003 and Windows Server 2008
——————————–
Bulletin ID: MS09-071
Bulletin Title: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
Max Severity Rating: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008
——————————–
Bulletin ID: MS09-072
Bulletin Title: Cumulative Security Update for Internet Explorer (976325)
Max Severity Rating: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Internet Explorer on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
——————————–
Bulletin ID: MS09-073
Bulletin Title: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
Max Severity Rating: Important
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Office XP, Office 2003, Works 8.5, and Office Converter Pack
——————————–
Bulletin ID: MS09-074
Bulletin Title: Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)
Max Severity Rating: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: May require restart
Affected Software: Microsoft Project 2000, Project 2002, and Project 2003
——————————–
Note: The list of affected software in the summary table above is an abstract. To see the full list of affected components please click on the “Advance Notification Web Page” link below and review the “Affected Software” section.
Summaries for new bulletin(s) may be found at http://www.microsoft.com/technet/security/bulletin/MS09-dec.mspx.
=================================
Malicious Software Removal Tool
=================================
Microsoft is releasing an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Server Update Services (WSUS), Windows Update (WU), and the Download Center. NOTE: this tool will NOT be distributed using Software Update Services (SUS). Information on the Microsoft Windows Malicious Software Removal Tool is available at http://support.microsoft.com/?kbid=890830.
=================================
High Priority Non-Security Updates
=================================
High priority non-security updates Microsoft releases to be available on Microsoft Update (MU), Windows Update (WU), or Windows Server Update Services (WSUS) will be detailed in the KB article found at http://support.microsoft.com/?id=894199.
=================================
New Security Advisories (2)
=================================
In addition to new security bulletins, Microsoft is also releasing two new security advisories on December 08, 2009. Here is an overview:
Identifier: Security Advisory 954157 – Security Enhancements for the Indeo Codec
———————————
Summary: Microsoft is announcing the availability of an update that provides security mitigations to the Indeo codec on supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003. The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code remote code execution when opening specially crafted media content. The update blocks the Indeo codec from being launched in Internet Explorer or Windows Media player. The update also removes the ability for this codec to be loaded when browsing the Internet with any other applications. By only allowing applications to use the Indeo codec when the media content is from the local system or from the intranet zone, and by preventing Internet Explorer and Windows Media Player from launching the codec at all, this update removes the most common remote attack vectors but still allows games or other applications that leverage the codec locally to continue to function.
———————————
Affected Software:
• Microsoft Windows 2000 Service Pack 4
• Windows XP Service Pack 2 and Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
• Windows Server 2003 with SP2 for Itanium-based Systems
———————————
Recommendations: Review Microsoft Security Advisory 954157 for an overview of the issue, details on affected components, workarounds, suggested actions, frequently asked questions (FAQs), and links to additional resources.
———————————
Workarounds: It is possible to disable this codec by deregistering the codec. For directions on how to deregister the codec, see Microsoft Knowledge Base Article 954157.
———————————
Additional Resources:
• Microsoft Security Advisory 954157 – Security Enhancements for the Indeo Codec- http://www.microsoft.com/technet/security/advisory/954157.mspx
• Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/
• Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/
• Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/
________________________________________
Identifier: Security Advisory 974926 – Credential Relaying Attacks on Integrated Windows Authentication
———————————
Summary: This advisory addresses the potential for attacks that affect the handling of credentials using Integrated Windows Authentication (IWA), and the mechanisms Microsoft has made available for customers to help protect against these attacks. In these attacks, an attacker who is able to obtain the user’s authentication credentials while being transferred between a client and a server would be able to reflect these credentials back to a service running on the client, or forward them to another server on which the client has a valid account. This would allow the attacker to gain access to these resources, impersonating the client. Since IWA credentials are hashed, an attacker cannot use this to ascertain the actual username and password. Depending on the scenario and the use of additional attack vectors, an attacker may be able to obtain authentication credentials both inside and outside of the organization’s security perimeter and utilize them to gain inappropriate access to resources. Microsoft is addressing the potential impact of these issues at different levels and wants to make customers aware of the tools that have been made available to address these issues, and the impact of using these tools. This advisory contains information on the different actions Microsoft has taken to improve protection of IWA authentication credentials, and how customers can deploy these safeguards.
———————————
Mitigating Factors:
• In order to relay credentials, an attacker would need to successfully leverage another vulnerability to execute a man-in-the-middle attack, or to convince the victim, using social engineering, to connect to a server under the attacker’s control, for instance by sending a link in a malicious e-mail message.
• Internet Explorer does not automatically send credentials using HTTP to servers hosted in the Internet zone. This reduces the risk that credentials can be forwarded or reflected by an attacker within this zone.
• Inbound traffic must be allowed to the client system for a reflection attack to succeed. The most common attack vector is SMB, as it allows IWA authentication. Hosts behind a firewall that blocks SMB traffic, or hosts that block SMB traffic on a host firewall are not vulnerable to the most common NTLM reflection attacks, which target SMB.
———————————
Recommendations: Review Microsoft Security Advisory 974926 for an overview of the issue, details on affected components, mitigating factors, suggested actions, frequently asked questions (FAQs), and links to additional resources.
———————————
Additional Information:
Q: What versions of Windows are associated with this advisory?
A: Credential forwarding and reflection affects all platforms that have the ability to perform Integrated Windows Authentication. The Extended Protection for Authentication feature is included in Windows 7 and Windows Server 2008 R2, and was made available for Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 in a non-security update released as Microsoft Security Advisory 973811. In order to fully protect authentication credentials, specific applications on these operating systems still need to opt in to the mechanism. The Extended Protection feature is not available for the Microsoft Windows 2000 operating system.
———————————
Additional Resources:
• Microsoft Security Advisory 974926 – Credential Relaying Attacks on Integrated Windows Authentication – http://www.microsoft.com/technet/security/advisory/974926.mspx
• Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/
• Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/
• Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/
=================================
Revised Security Advisory
=================================
Microsoft has updated Security Advisory 973881 – Extended Protection for Authentication – on December 08, 2009.
———————————
Overview of Changes: Security Advisory 973881 was revised to include information about three non-security updates released on December 08, 2009, relating to the Extended Protection for Authentication feature. The three related non-security updates released by Microsoft on December 08, 2009 are:
• Microsoft Knowledge Base Article 971737 contains a non-security update that enables the Windows HTTP Services (WinHTTP) API to opt in to Extended Protection for Authentication.
• Microsoft Knowledge Base Article 970430 contains a non-security update that enables the HTTP Protocol Stack (http.sys) to opt in to Extended Protection for Authentication.
• Microsoft Knowledge Base Article 973917 contains a non-security update that enables Internet Information Services (IIS) to opt in to Extended Protection for Authentication.
———————————
Full Details: http://www.microsoft.com/technet/security/advisory/973881.mspx
=================================
Revised Security Bulletin
=================================
Microsoft has revised Security Bulletin MS08-037 – Vulnerabilities in DNS Could Allow Spoofing (953230) – on December 08, 2009.
———————————
Overview of changes: Microsoft rereleased this security bulletin to reoffer the update for the DNS client on Microsoft Windows 2000 Service Pack 4 (KB951748) to provide strongly random DNS transaction IDs to an additional code path. Unlike the other Windows platforms, on Microsoft Windows 2000, there are two code paths for DNS transactions. The previous update only provided the transaction ID randomization on one of the code paths. The rerelease of this update provides the same transaction ID randomization to the other code path on Microsoft Windows 2000. Customers who have previously installed the update for the DNS Client on Microsoft Windows 2000 Service Pack 4 (951748) need to install the automatically reoffered update. No other updates are affected by this rerelease.
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS08-037.mspx
=================================
Public Security Bulletin Webcast
=================================
Microsoft will host a webcast to address customer questions on these bulletins:
Title: Information about Microsoft December Security Bulletins (Level 200)
Date: Wednesday, December 08, 2009, 11:00 A.M. Pacific Time (U.S. and Canada)
URL: http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407802
=================================
New Bulletin Technical Details
=================================
In the following tables of affected and non-affected software, software editions that are not listed are past their support lifecycle. To determine the support lifecycle for your product and edition, visit the Microsoft Support Lifecycle Web site at http://support.microsoft.com/lifecycle/.
==================================
Microsoft Security Bulletin MS09-069
==================================
Bulletin Title: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)
Executive Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow a denial of service if a remote, authenticated attacker, while communicating through Internet Protocol security (IPsec), sends a specially crafted ISAKMP message to the Local Security Authority Subsystem Service (LSASS) on an affected system. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted requests.
Severity Ratings and Affected Software
This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.
———————————
Vulnerability Identifiers: CVE-2009-3675: Local Security Authority Subsystem Service Resource Exhaustion Vulnerability. Exploitability Rating = 3, Functioning exploit code unlikely. Notes: The vulnerability does not allow remote code execution, only denial of service that a remote, authenticated attacker could attempt to exploit.
———————————
Attack Vectors: A maliciously crafted ISAKMP message while connected and authenticated to an LSASS server over IPSEC.
———————————
Mitigating Factors: Microsoft has not identified any mitigations for this vulnerability.
———————————
Workarounds: Disable the IPSec service.
———————————
Restart Requirement: This update requires a restart.
———————————
Bulletins Replaced by This Update: For Windows 2000: MS06-025
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-069.mspx
==================================
Microsoft Security Bulletin MS09-070
==================================
Bulletin Title: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)
———————————
Executive Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow remote code execution if an attacker sent a specially crafted HTTP request to an ADFS-enabled Web server. An attacker would need to be an authenticated user in order to exploit either of these vulnerabilities.
The security update addresses the vulnerabilities by correcting the validation that ADFS-enabled Web servers apply to request headers submitted by a Web client.
———————————
Severity Ratings and Affected Software: This security update is rated Important for affected releases of Windows Server 2003, Windows Server 2003 x64 Edition, Windows Server 2008, and Windows Server 2008 x64 Edition.
———————————
Vulnerability Identifiers:
• CVE-2009-2508: Single Sign On Spoofing in ADFS Vulnerability. Exploitability Rating = 3, Functioning exploit code unlikely. Notes: The vulnerability does not allow remote code execution, only spoofing.
• CVE-2009-2509. Remote Code Execution in ADFS Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: The vulnerability is only exploitable by an authenticated attacker.
———————————
Attack Vectors:
• A maliciously crafted HTTP request to an ADFS-enabled Web server (CVE-2009-2509).
• The re-use of specific data from the browser’s cache to authenticate against the Web application implementing ADFS single sign-on (CVE-2009-2508).
———————————
Mitigating Factors:
• The attacker must have valid logon credentials to the vulnerable server (CVE-2009-2509).
• An attacker can only impersonate someone whose authentication token they have been able to obtain (CVE-2009-2508).
• An attack is only possible before the session times out on the server (CVE-2009-2508).
• If the Web application uses SSL, the attacker must have access to the victim’s computer to exploit the vulnerability (CVE-2009-2508).
———————————
Workarounds: Microsoft has not identified any workarounds for either of these vulnerabilities.
———————————
Restart Requirement: This update requires a restart.
———————————
Bulletins Replaced by This Update: None
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-070.mspx
=================================
Microsoft Security Bulletin MS09-071
=================================
Bulletin Title: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
———————————
Executive Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if messages received by the Internet Authentication Service server are copied incorrectly into memory when handling PEAP authentication attempts. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. Servers using Internet Authentication Service are only affected when using PEAP with MS-CHAP v2 authentication.The security update addresses the vulnerabilities by correcting the way Internet Authentication Service validates authentication requests by PEAP clients.
———————————
Severity Ratings and Affected Software: This security update is rated Critical for Windows Server 2008 for 32-bit Systems Service Pack 2 and Windows Server 2008 for x64-based Systems Service Pack 2. For all other affected and supported releases of Windows, see the subsection, “Affected and Non-Affected Software”, in the bulletin.
———————————
Vulnerability Identifiers:
• CVE-2009-2505: Internet Authentication Service Memory Corruption Vulnerability. Exploitability Rating = 2, Inconsistent exploit code likely. Notes: Limited possibility for remote code execution. Most likely result is denial of service.
• CVE-2009-3677: MS-CHAP Authentication Bypass Vulnerability. Exploitability Rating = 3, Functioning exploit code unlikely. Notes: The vulnerability does not allow remote code execution, only elevation of privilege due to bypassing of network authentication.
———————————
Attack Vectors:
• An incorrectly formed PEAP authentication request (CVE-2009-2505).
• An incorrectly formed MS-CHAP v2 authentication request (CVE-2009-3677).
———————————
Mitigating Factors: Servers using IAS are only affected if they are configured to use PEAP with MS-CHAP v2 authentication.
———————————
Workarounds: Use an authentication protocol other than PEAP with MS-CHAP v2.
———————————
Restart Requirement: This update requires a restart.
———————————
Bulletins Replaced by This Update: None
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-071.mspx
=================================
Microsoft Security Bulletin MS09-072
=================================
Bulletin Title: Cumulative Security Update for Internet Explorer (976325)
———————————
Executive Summary: This security update resolves four privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. An ActiveX control built with Microsoft Active Template Library (ATL) headers could also allow remote code execution. The security update addresses these vulnerabilities by correcting the control and by modifying the way that Internet Explorer handles objects in memory. This security update also addresses the vulnerability first described in Microsoft Security Advisory 977981.
———————————
Severity Ratings and Affected Software: This security update is rated Critical for all supported releases of Internet Explorer: Internet Explorer 5.01, Internet Explorer 6, Internet Explorer 6 Service Pack 1, Internet Explorer 7 (except when running on supported editions of Windows Server 2003 and Windows Server 2008), and Internet Explorer 8 (except when running on supported editions of Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2). For Internet Explorer 7 and Internet Explorer 8 running on Windows servers as listed, this update is rated Moderate.
———————————
Vulnerability Identifiers:
• CVE-2009-2493: ATL COM Initialization Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: This vulnerability was first addressed in MS09-035.
• CVE-2009-3671: Uninitialized Memory Corruption Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: None.
• CVE-2009-3672: HTML Object Memory Corruption Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: None.
• CVE-2009-3673: Uninitialized Memory Corruption Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: None.
• CVE-2009-3674: Uninitialized Memory Corruption Vulnerability. Exploitability Rating = 1, Consistent exploit code likely. Notes: None.
———————————
Attack Vectors:
• A maliciously crafted Web page
• A maliciously crafted e-mail
———————————
Mitigating Factors:
• Users would have to be persuaded to visit a malicious Web site.
• Exploitation only gains the same user rights as the logged on account.
• By default, all supported versions of Microsoft Outlook and Microsoft Outlook Express open HTML e-mail messages in the Restricted Sites zone.
• By default, IE on Windows 2003 and Windows Server 2008 runs in restricted mode.
———————————
Workarounds
• Set IE security to High for Internet and Intranet zones.
• Configure IE to prompt before running ActiveX and Active Scripting.
———————————
Restart Requirement: This update requires a restart.
———————————
Bulletins Replaced by This Update: MS09-054
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-072.mspx
=================================
Microsoft Security Bulletin MS09-073
=================================
Bulletin Title: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
———————————
Executive Summary: This security update resolves a privately reported vulnerability in Microsoft WordPad and Microsoft Office text converters. The vulnerability could allow remote code execution if a specially crafted Word 97 file is opened in WordPad or Microsoft Office Word. An attacker who successfully exploited this vulnerability could gain the same privileges as the user. Users whose accounts are configured to have fewer privileges on the system could be less impacted than users who operate with administrative privileges. The security update addresses the vulnerability by correcting the way WordPad and the Office Text Converters parse Word 97 documents.
———————————
Severity Ratings and Affected Software: This security update is rated Important for WordPad on all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003. This security update is also rated Important for all supported editions of Microsoft Office Word 2002 and Microsoft Office Word 2003, Microsoft Office Converter Pack, and Microsoft Works 8.5.
———————————
Vulnerability Identifiers: CVE-2009-2506: WordPad and Office Text converter Memory Corruption Vulnerability. Exploitability Rating = 2, Inconsistent exploit code likely. Notes: None
———————————
Attack Vectors: A maliciously crafted Word document
———————————
Mitigating Factors:
• Exploitation only gains the same user rights as the logged on account.
• Users would have to be persuaded to visit a malicious Web site.
• Cannot be exploited automatically through e-mail, because a user must open an attachment that is sent in an e-mail message.
• A Website will prompt to Open, Save, or Cancel before opening a document, unless the user had previously unchecked the option “Always ask before opening this type of file”.
———————————
Workarounds: Disable the WordPad Word 97 converter by restricting access to the converter file.
———————————
Restart Requirement: This update requires a restart.
———————————
Bulletins Replaced by This Update: For Office XP and the Office Converter Pack: MS09-010. For Works 8.5: MS09-024.
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-073.mspx
=================================
Microsoft Security Bulletin MS09-074
=================================
Bulletin Title: Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)
———————————
Executive Summary: This security update resolves a privately reported vulnerability in Microsoft Office Project. The vulnerability could allow remote code execution if a user opens a specially crafted Project file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The update removes the vulnerability by modifying the way that Microsoft Office Project validates memory allocations when opening Project files from disk to memory.
———————————
Severity Ratings and Affected Software: This security update is rated Critical for Microsoft Project 2000 Service Release 1 and rated Important for Microsoft Project 2002 Service Pack 1, and Microsoft Office Project 2003 Service Pack 3.
———————————
Vulnerability Identifiers: CVE-2009-0102: Project Memory Validation Vulnerability. Exploitability Rating = 2, Inconsistent exploit code likely. Notes: None
———————————
Attack Vectors:
• A maliciously crafted Project file
• A maliciously crafted Web page
• A maliciously crafted e-mail attachment
———————————
Mitigating Factors:
• Exploitation only gains the same user rights as the logged on account.
• Cannot be exploited automatically through e-mail, because a user must open an attachment that is sent in an e-mail message.
———————————
Workarounds: Do not open or save Project files that you receive from untrusted sources or that you receive unexpectedly from trusted sources.
———————————
Restart Requirement: This update may require a restart.
———————————
Bulletins Replaced by This Update: MS08-018
———————————
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-074.mspx
=================================
Regarding Information Consistency
=================================
We strive to provide you with accurate information in static (this mail) and dynamic (Web-based) content. Microsoft’s security content posted to the Web is occasionally updated to reflect late-breaking information. If this results in an inconsistency between the information here and the information in Microsoft’s Web-based security content, the information in Microsoft’s Web-based security content is authoritative.
November Security Bulletins
Microsoft is releasing the following six new security bulletins for newly discovered vulnerabilities:
Bulletin ID: MS09-063
Bulletin Title: Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)
Max Severity: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows Vista and Windows Server 2008
——————————–
Bulletin ID: MS09-064
Bulletin Title: Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
Max Severity: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000 Server
——————————–
Bulletin ID: MS09-065
Bulletin Title: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)
Max Severity: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008
——————————–
Bulletin ID: MS09-066
Bulletin Title: Vulnerability in Active Directory Could Allow Denial of Service (973309)
Max Severity: Important
Vulnerability Impact: Denial of Service
Restart Requirement: Requires restart
Affected Software: Microsoft Windows 2000 Server, Windows XP, Windows Server 2003, and Windows Server 2008
——————————–
Bulletin ID: MS09-067
Bulletin Title: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
Max Severity: Important
Vulnerability Impact: Remote Code Execution
Restart Requirement: May require restart
Affected Software: Microsoft Office Excel 2002, Excel 2003, Excel 2007, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format converter for Mac, Excel Viewer, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
——————————–
Bulletin ID: MS09-068
Bulletin Title: Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)
Max Severity: Important
Vulnerability Impact: Remote Code Execution
Restart Requirement: May require restart
Affected Software: Microsoft Office Word 2002, Word 2003, Office 2004 for Mac, Office 2008 for Mac, Open XML File Format converter for Mac, Office Word Viewer, and Office Word Viewer 2003
——————————–
Note: The list of affected software in the summary table is an abstract. To see the full list of affected components please visit the bulletin summary Web page at the link below and navigate to the “Affected Software” section.
Summaries for new bulletin(s) may be found at http://www.microsoft.com/technet/security/bulletin/MS09-nov.mspx.
=================================
Malicious Software Removal Tool
=================================
Microsoft is releasing an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Server Update Services (WSUS), Windows Update (WU), and the Download Center. NOTE: This tool will NOT be distributed using Software Update Services (SUS). Information on the Microsoft Windows Malicious Software Removal Tool is available at http://support.microsoft.com/?kbid=890830.
=================================
High Priority Non-Security Updates
=================================
High priority non-security updates Microsoft releases to be available on Microsoft Update (MU), Windows Update (WU), or Windows Server Update Services (WSUS) will be detailed in the KB article found at http://support.microsoft.com/?id=894199.
=================================
Security Bulletin Major Revisions
=================================
Microsoft has revised Security Bulletin MS09-045 – Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961) – on November 10, 2009.
Overview of changes: Microsoft rereleased this bulletin to add JScript 5.7 on Microsoft Windows 2000 Service Pack 4 as an affected product. Customers who have already installed this update do not need to take any action.
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-045.mspx
________________________________________
Microsoft has revised Security Bulletin MS09-051 – Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682) – on November 10, 2009.
Overview of changes: Microsoft rereleased this bulletin to reoffer the update for Audio Compression Manager on Microsoft Windows 2000 Service Pack 4 to fix a detection issue. This is a detection change only; there were no changes to the binaries. Customers who have successfully updated their systems do not need to reinstall this update.
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-051.mspx
=================================
Public Bulletin Release Webcast
=================================
Microsoft will host a webcast to address customer questions on these bulletins:
Title: Information about Microsoft November Security Bulletins (Level 200)
Date: Wednesday, November 11, 2009, 11:00 A.M. Pacific Time (U.S. and Canada)
URL: http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407490
=================================
New Bulletin Technical Details
=================================
In the following tables of affected and non-affected software, software editions that are not listed are past their support lifecycle. To determine the support lifecycle for your product and edition, visit the Microsoft Support Lifecycle Web site at http://support.microsoft.com/lifecycle/.
Bulletin Identifier: Microsoft Security Bulletin MS09-063
———————-
Bulletin Title: Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)
———————-
Executive Summary: This security update resolves a privately reported vulnerability in the Web Services on Devices Application Programming Interface (WSDAPI) on the Windows operating system. The vulnerability could allow remote code execution if an affected Windows system receives a specially crafted packet. The security update addresses the vulnerability by correcting the processing of headers in WSD messages.
———————-
Severity Ratings and Affected Software: This security update is rated Critical for all supported editions of Windows Vista and Windows Server 2008.
———————-
CVEs and Exploitability Index: CVE-2009-2512 – Web Services on Devices API Memory Corruption Vulnerability
EI = 2 (Inconsistent exploit code likely). Notes: The scenario allows for a possible, limited denial of service attack.
———————-
Attack Vectors: Maliciously crafted network packets
———————-
Mitigating Factors: The vulnerable service is only exposed to incoming connections from the local subnet.
———————-
Restart Requirement: You must restart your system after you apply this security update.
———————-
Removal Information: WUSA.exe does not support uninstall of updates. To uninstall an update installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates and select from the list of updates.
———————-
Bulletins Replaced by This Update: None
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-063.mspx
=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=
~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~
Bulletin Identifier: Microsoft Security Bulletin MS09-064
———————-
Bulletin Title: Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
———————-
Executive Summary: This security update resolves a privately reported vulnerability in Microsoft Windows 2000. The vulnerability could allow remote code execution if an attacker sent a specially crafted network message to a computer running the License Logging Server. An attacker who successfully exploited this vulnerability could take complete control of the system. The security update addresses the vulnerability by changing the way the License Logging service validates a specific field inside the RPC packet.
———————-
Severity Ratings and Affected Software: This security update is rated Critical for Microsoft Windows 2000.
———————-
CVEs and Exploitability Index: CVE-2009-2523 – License Logging Server Heap Overflow Vulnerability
EI = 2 (Inconsistent exploit code likely)
———————-
Attack Vectors: Sending a specially crafted RPC packet.
———————-
Mitigating Factors: Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter.
———————-
Restart Requirement: You must restart your system after you apply this security update.
———————-
Removal Information: Use Add or Remove Programs tool in Control Panel or the Spuninst.exe utility.
———————-
Bulletins Replaced by This Update: None
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-064.mspx
=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=
~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~
Bulletin Identifier: Microsoft Security Bulletin MS09-065
———————-
Bulletin Title: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)
———————-
Executive Summary: This security update resolves several privately reported vulnerabilities in the Windows kernel. The most severe of the vulnerabilities could allow remote code execution if a user viewed content rendered in a specially crafted Embedded OpenType (EOT) font. In a Web-based attack scenario, an attacker would have to host a Web site that contains specially crafted embedded fonts that are used to attempt to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content could contain specially crafted content that could exploit this vulnerability. The security update addresses the vulnerabilities by correcting the method used for validating the argument passed to the system call, validating input passed from user mode through the kernel component of GDI, and correcting the manner in which Windows kernel-mode drivers parse font code.
———————-
Severity Ratings and Affected Software: This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003, and Important for all supported editions of Windows Vista and Windows Server 2008.
———————-
CVEs and Exploitability Index:
• CVE-2009-1127 – Win32k NULL Pointer Dereferencing Vulnerability, EI = 2 (Inconsistent exploit code likely)
• CVE-2009-2513 – Win32k Insufficient Data Validation Vulnerability, EI = 1 (Consistent exploit code likely)
• CVE-2009-2514 – Win32k EOT Parsing Vulnerability, EI = 1 (Consistent exploit code likely)
———————-
Attack Vectors:
• CVE-2009-1127 and CVE-2009-2513: A logon attempt with a legitimate username.
• CVE-2009-2514: A maliciously crafted Office document, Web page, or e-mail attachment.
———————-
Mitigating Factors:
• CVE-2009-1127 and CVE-2009-2513: An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.
• CVE-2009-2514: An attacker would have no way to force users to visit a specially crafted Web site. Cannot be exploited automatically through e-mail because a user must open an attachment that is sent in an e-mail message.
———————-
Restart Requirement: You must restart your system after you apply this security update.
———————-
Removal Information:
• Windows 2000, Windows XP, and Windows Server 2003: Use Add or Remove Programs tool in Control Panel or the Spuninst.exe utility.
• Windows Vista and Windows Server 2008: WUSA.exe does not support uninstall of updates. To uninstall an update installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates and select from the list of updates.
———————-
Bulletins Replaced by This Update: MS09-025
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-065.mspx
=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=
~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~
Bulletin Identifier: Microsoft Security Bulletin MS09-066
———————-
Bulletin Title: Vulnerability in Active Directory Could Allow Denial of Service (973309)
———————-
Executive Summary: This security update resolves a privately reported vulnerability in Active Directory directory service, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow denial of service if stack space was exhausted during execution of certain types of LDAP or LDAPS requests. The security update addresses the vulnerability by changing the way Active Directory, ADAM, and AD LDS process malformed LDAP or LDAPS requests.
———————-
Severity Ratings and Affected Software: This security update is rated Important for Active Directory, ADAM, and AD LDS on all supported editions of Microsoft Windows 2000 Server, Windows XP, Windows Server 2003, and Windows Server 2008.
———————-
CVEs and Exploitability Index: CVE-2009-1928 – LSASS Recursive Stack Overflow Vulnerability
EI = 3 (Functioning exploit code unlikely). Notes: The condition for denial of service exists.
———————-
Attack Vectors: Maliciously crafted network packets
———————-
Mitigating Factors:
• This vulnerability only affects domain controllers and systems configured to run ADAM or AD LDS.
Restart Requirement
You must restart your system after you apply this security update.
———————-
Removal Information:
• Windows 2000 Server, Windows XP, and Windows Server 2003: Use Add or Remove Programs tool in Control Panel or the Spuninst.exe utility.
• Windows Server 2008: WUSA.exe does not support uninstall of updates. To uninstall an update installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates and select from the list of updates.
———————-
Bulletins Replaced by This Update:
• Windows 2000 Server, Windows XP, and Windows Server 2003: MS09-018
• Windows Server 2008: MS08-035
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-066.mspx
=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=
~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~
Bulletin Identifier: Microsoft Security Bulletin MS09-067
———————-
Bulletin Title: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
———————-
Executive Summary: This security update resolves several privately reported vulnerabilities in Microsoft Office Excel. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. The update addresses the vulnerabilities by modifying the way that Excel opens and parses Excel files, and by modifying the way that Excel handles malformed records.
———————-
Severity Ratings and Affected Software: This security update is rated Important for all supported editions of Microsoft Office Excel 2002, Microsoft Office Excel 2003, Microsoft Office Excel 2007, Microsoft Office 2004 for Mac, and Microsoft Office 2008 for Mac; Open XML File Format Converter for Mac; and all supported versions of Microsoft Office Excel Viewer and Microsoft Office Compatibility Pack.
———————-
CVEs and Exploitability Index:
• CVE-2009-3127 – Excel Cache Memory Corruption Vulnerability, EI = 2
• CVE-2009-3128 – Excel SxView Memory Corruption Vulnerability, EI = 2
• CVE-2009-3129 – Excel Featheader Record Memory Corruption Vulnerability, EI = 1
• CVE-2009-3130 – Excel Document Parsing Heap Overflow Vulnerability, EI = 1
• CVE-2009-3131 – Excel Formula Parsing Memory Corruption Vulnerability, EI = 1
• CVE-2009-3132 – Excel Index Parsing Vulnerability, EI = 2
• CVE-2009-3133 – Excel Document Parsing Memory Corruption Vulnerability, EI = 2
• CVE-2009-3134 – Excel Field Sanitization Vulnerability, EI = 2
o EI = 1: Consistent exploit code likely
o EI = 2: Inconsistent exploit code likely
———————-
Attack Vectors:
• A maliciously crafted Excel spreadsheet
• A maliciously crafted e-mail attachment
• A maliciously crafted Web page
———————-
Mitigating Factors:
• An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
• Cannot be exploited automatically through e-mail because a user must open an attachment that is sent in an e-mail message.
———————-
Restart Requirement: Varies depending on which update is installed. See the “Security Update Deployment” section of the bulletin at the link below for more details.
———————-
Removal Information: Varies depending on which update is installed. See the “Security Update Deployment” section of the bulletin at the link below for more details.
———————-
Bulletins Replaced by This Update: MS09-021
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-067.mspx
=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=
~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~=~
Bulletin Identifier: Microsoft Security Bulletin MS09-068
———————-
Bulletin Title: Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)
———————-
Executive Summary: This security update resolves a privately reported vulnerability that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. The security update addresses the vulnerability by modifying the way that Microsoft Office Word opens specially crafted Word files.
———————-
Severity Ratings and Affected Software: This security update is rated Important for all supported editions of Microsoft Office Word 2002 and Microsoft Office Word 2003, Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, Open XML File Format Converter for Mac, and all supported versions of Microsoft Office Word Viewer.
———————-
CVEs and Exploitability Index:
CVE-2009-3135 – Microsoft Office Word File Information Memory Corruption Vulnerability
EI = 1 (Consistent exploit code likely)
———————-
Attack Vectors:
• A maliciously crafted Word document
• A maliciously crafted e-mail attachment
• A maliciously crafted Web page
———————-
Mitigating Factors:
• Users would have to be persuaded to visit a malicious Web site.
• Exploitation only gains the same user rights as the logged on account. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
• Cannot be exploited automatically through e-mail because a user must open an attachment that is sent in an e-mail message.
———————-
Restart Requirement: Varies depending on which update is installed. See the “Security Update Deployment” section of the bulletin at the link below for more details.
———————-
Removal Information: Varies depending on which update is installed. See the “Security Update Deployment” section of the bulletin at the link below for more details.
———————-
Bulletins Replaced by This Update: MS09-027
———————-
Full Details: http://www.microsoft.com/technet/security/bulletin/MS09-068.mspx
Patch Tuesday, October 13
The list of patches are itemized below. If you have automating updating turned on, you might already have the updates. To learn how to turn automatic updating on for your operating system, see Update your PC automatically.
If you do not have automatic updating turned on, or to check whether you need the updates, go to Microsoft Update.
Security updates are also available from the Microsoft Download Center. You can find them most easily by doing a keyword search using the words security update and the month the update was released.
Latest Security Updates
- MS09-050 - addresses a vulnerability in Microsoft Windows (KB 975517)
- MS09-051 - addresses a vulnerability in Windows Media (KB 975682)
- MS09-052 - addresses a vulnerability in Windows Media (KB 974112)
- MS09-053 - addresses a vulnerability in Internet Information Services (IIS) (KB 975254)
- MS09-054 - addresses a vulnerability in Internet Explorer (KB 974455)
- MS09-055 - addresses a vulnerability in Microsoft Windows (KB 973525)
- MS09-056 - addresses a vulnerability in Microsoft Windows (KB 974571)
- MS09-057 - addresses a vulnerability in Indexing Service (KB 969059)
- MS09-058 - addresses a vulnerability in Microsoft Windows (KB 971486)
- MS09-059 - addresses a vulnerability in Microsoft Windows (KB 975467)
- MS09-060 - addresses a vulnerability in Microsoft Office (KB 973965)
- MS09-061 - addresses a vulnerability in Microsoft .NET (KB 974378)
- MS09-062 - addresses a vulnerability in Microsoft Windows (KB 957488)