February 2010 Bulletin Release Advance Notification

SGT Oddball

Active member
Pro User
Local time
1:44 AM
Messages
650
Location
Lost in France
Today we released February bulletin information through our Advance Notification Service (ANS). This month, we will be releasing 13 bulletins - five rated Critical, seven rated Important, and one rated Moderate - addressing 26 vulnerabilities. Eleven of the bulletins affect Windows and the remaining two affect Office. More information about the upcoming security updates can be found on the Advance Notification Service (ANS) webpage.

As we started to do in December, we want to give customers a peek at what our deployment guidance will be next Tuesday. This month, we will be giving four of the bulletins a deployment priority rating of 1. In the ANS, those are bulletins 1, 2, 3, and 6. We recommend that customers test and deploy all security updates as soon as possible but you should prioritize these first.

To further help customers prioritize, I have pulled the Windows information from the ANS into a summary table so depending on the version you are running, you can see how many bulletins you need to prepare for:

Version

Critical

Important

Moderate

Low

Total

Windows 2000

5

3

1

0

9

Windows XP

5

2

1

0

8

Windows Server 2003

4

3

2

0

9

Windows Vista

3

3

0

0

6

Windows Server 2008

3

4

0

1

8

Windows 7

3

2

0

0

5

Windows Server 2008 R2

3

1

0

1

5

 



The Office related bulletins are both rated Important and would require user action to be exploited (usually in the form of convincing a user to open a specially crafted file). The vulnerabilities only affect older versions of Office so customers on Office 2007 or Office 2008 for Mac will have not actions this month.

We encourage customers to upgrade to the latest versions of both Windows and Office. As this bulletin release shows, the latest versions are less impacted overall due to the improved security protections built in to these products.

I also want to give a summary of the three open Security Advisories so customers know what to expect on Tuesday:

·             Advisory 980088, Vulnerability in Internet Explorer Could Allow Information Disclosure: this advisory was released yesterday (Feb 3). We do not have an update for this issue planned for the normal February bulletin release. However, this vulnerability only affects versions of windows older than Vista in their default configuration, and there is a “Fix It” available so customers in non-default configurations can protect themselves.

·             Advisory 979682, Vulnerability in Windows Kernel Could Allow Elevation of Privilege: we are on track to release an update for this issue next Tuesday.

·             Advisory 977544, Vulnerability in SMB Could Allow Denial of Service: we are still working on an update for this issue so it will not be addressed in the February bulletins. As a reminder, this issue cannot be used to allow an attacker to take control of a system remotely, but instead results in a system becoming unresponsive due to resource consumption.

We are not aware of any attacks on these vulnerabilities and continue to encourage customers to implement the mitigations and workarounds outlined in the advisories.

Last month I started including important information about Windows versions that are reaching the end of their product lifecycle. Customers using these versions should consider upgrading before support for these products end as, once they do, we will no longer provide security updates:


  • Windows XP Service Pack 2 will no longer be supported as of July 13, 2010. Many customers are still on this version, so we encourage upgrading to Service Pack 3 or to Windows 7 as soon as possible.
  • Windows Vista RTM will no longer be supported as of April 13, 2010. Service Pack 1 will still be supported until July 12, 2011 but we recommend customers update to Service Pack 2 or Windows 7 at this time.
  • Extended support for Windows 2000 will also be retired on July 13, 2010. At that time, we will no longer provide security or any other updates for Windows 2000.
Finally, please plan to join Adrian Stone and myself next week for our regular live webcast where we will go in to detail on each bulletin to give you even more information and guidance:

Date: Wednesday, Feb 10
Time: 11:00 a.m. PST (UTC -8)
Registration:
http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032427679

Hope to see you there!

Jerry Bryant
Sr. Security Communications Manager – Lead


*This posting is provided "AS IS" with no warranties, and confers no rights.*

 



aggbug.aspx

More...
 

My Computer My Computer

At a glance

NT4Cyrix 2338 MegVoodoo
OS
NT4
CPU
Cyrix 233
Motherboard
Jetway
Memory
8 Meg
Graphics Card(s)
Voodoo
Sound Card
SB16
Monitor(s) Displays
14" CRT
Screen Resolution
800x600
Hard Drives
40meg
Keyboard
Yes
Mouse
Yes
Internet Speed
56k
Thanks for the information.
 

My Computer My Computer

At a glance

Vista Ult64, Win7600Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS4096 MB DDR3-SDRAMATI Radeon HD 3870 Series x2 Crossfired
Computer Manufacturer/Model Number
Self Build 64bit
OS
Vista Ult64, Win7600
CPU
Intel Core 2 Quad Q6600 @ 2400 MHz 64bit OS
Motherboard
Asus P5E3 Deluxe WiFi @p 64 bit OS
Memory
4096 MB DDR3-SDRAM
Graphics Card(s)
ATI Radeon HD 3870 Series x2 Crossfired
Sound Card
Realtek on board
Monitor(s) Displays
Samsung SyncMaster - 23 inches
Screen Resolution
1680x1050 pixels at 60 Hz in True Colors
Hard Drives
Hitachi (250 GB)/Samsung 750 GB. /Barracuda 160 GB.
My Book 1 TB external..
PSU
Cooler Master 1000w
Case
Cooler Master Cosmos 1000.
Cooling
Fans and fresh air,
Keyboard
Wireless
Mouse
Wireless
Internet Speed
Never fast enough
Other Info
I use a Magnum.
Thanks "Big Guy". :D
 

My Computer My Computer

At a glance

Win 7 Pro x64, VM Win XP, Win7 Pro Sandbox, K...AMD Athlon(tm) II X4 640 @ 3.0 Gbz12GB 1066MHz DDR3 SDRAM - 2x4GB, 2x2GBATI Radeon HD 4350 HD Graphics/Audio with 512MB
Computer Manufacturer/Model Number
HP Pavilion a4302f
OS
Win 7 Pro x64, VM Win XP, Win7 Pro Sandbox, Kubuntu 11
CPU
AMD Athlon(tm) II X4 640 @ 3.0 Gbz
Memory
12GB 1066MHz DDR3 SDRAM - 2x4GB, 2x2GB
Graphics Card(s)
ATI Radeon HD 4350 HD Graphics/Audio with 512MB
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
1. Dell 23" SP2307, 2. Mitsublishi 40" HDTV, Hannspree 25"
Screen Resolution
1. 2048x1152, 2. 1920-1080, 3. 1920x1200
Hard Drives
Int: 1 120 Gig SSD i
1 - 2.5" 500 USB External HDD
1 -1 Tb USB External HDD
Case
Mid Tower
Cooling
Standard Fans - 5 fans (very quiet)
Keyboard
Microsoft Wireless 2000
Mouse
Microsoft Wireless Mouse 5000
Internet Speed
10 Mbit (realistically 500 Kbit - 1.2 Mbit)
Other Info
Speakers - Bose Desktop (Excellent Sound)
1 external CD|DVD\Blue-ray Recorders/Players (Sony)

My Computer My Computer

At a glance

Win 7 Ultimate 64-bit. SP1.Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6...8 DDR 3 RAM. 1066MHZATI 1024 MB. DDR3. Radeon HD5650
Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
Back
Top