 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Windows Enterprise Desktop &#187; MS09-022</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/tag/ms09-022/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop</link>
	<description></description>
	<lastBuildDate>Fri, 17 May 2013 15:52:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>More on Patch Tuesday, July 2009</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/more-on-patch-tuesday-july-2009/</link>
		<comments>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/more-on-patch-tuesday-july-2009/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 13:51:57 +0000</pubDate>
		<dc:creator>Ed Tittel</dc:creator>
				<category><![CDATA[Microsoft Patch Tuesday]]></category>
		<category><![CDATA[Microsoft security updates]]></category>
		<category><![CDATA[MS09-022]]></category>
		<category><![CDATA[MS09-028]]></category>
		<category><![CDATA[MS09-029]]></category>
		<category><![CDATA[MS09-030]]></category>
		<category><![CDATA[MS09-031]]></category>
		<category><![CDATA[MS09-032]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=402</guid>
		<description><![CDATA[OK, so today is Wednesday, so that means Patch Tuesday has now come and gone, and the finalized version of the Security Bulletin Summary for July 2009 is now available. In addition to six updates, there&#8217;s also an updated version of the Windows Malicious Software Removal tool included amidst this month&#8217;s offerings. The following table [...]]]></description>
				<content:encoded><![CDATA[<p>OK, so today is Wednesday, so that means Patch Tuesday has now come and gone, and the finalized version of the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-jul.mspx" target="_blank">Security Bulletin Summary for July 2009 </a>is now available. In addition to six updates, there&#8217;s also an updated version of the Windows Malicious Software Removal tool included amidst this month&#8217;s offerings. The following table provides some details on the security-related patches and updates, with links to their underlying individual security bulletins.</p>
<table border="1" cellspacing="4" cellpadding="4">
<thead>
<tr>
<th>Bulletin ID</th>
<th>Rating</th>
<th>Target</th>
<th>Remarks</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkID=139788" target="_blank">MS09-023</a></td>
<td>Critical</td>
<td>Microsoft Windows</td>
<td>2 privately reported remote code execution items in the Windows Embedded OpenType (EOT) Font Engine</td>
</tr>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=152887" target="_blank">MS09-028</a></td>
<td>Critical</td>
<td>Microsoft Windows</td>
<td>2 vulnerabilities (1 public, 2 private) in Microsoft DirectShow; opening a specially formatted QuickTime media file can lead to remote execution</td>
</tr>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=157386" target="_blank">MS09-032</a></td>
<td>Critical</td>
<td>Microsoft Windows</td>
<td>Resolves privately reported vulnerability already being exploited in the MS Video ActiveX control; could lead to remote execution upon viewing a specially crafted Web page in IE with a malicious ActiveX control</td>
</tr>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=153891" target="_blank">MS09-033</a></td>
<td>Important</td>
<td>Virtual PC Virtual Server</td>
<td>Privately reported vulnerability allows arbitrary code to be executed, or complete control taken for an affected guest OS</td>
</tr>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=154993" target="_blank">MS09-031</a></td>
<td>Important</td>
<td>ISA Server 2006</td>
<td>Privately reported vulnerability could allow elevation of privilege upon successful impersonation of administrative account on ISA server configured for Radius One time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation</td>
</tr>
<tr>
<td><a href="http://go.microsoft.com/fwlink/?LinkID=147424" target="_blank">MS09-030</a></td>
<td>Important</td>
<td>Microsoft Office Publisher</td>
<td>Privately reported vulnerability could allow remote code execution if a user opens a specially crafted Publisher file; could lead to complete control over affected system.</td>
</tr>
</tbody>
</table>
<p>The critical Windows related items will probably need to be addressed as soon as possible; the other important items may or may not apply to all enterprise situations, but will surely apply to some. For those outfits, the possibility of remote code execution or outright system takeover suggests that they, too, should be addressed quickly.</p>
<p>FWIW, I was able to download and install all these patches on several Vista systems late last night/early this morning without any difficulties. Alas, the same is not true for an optional update to one of my systems Realtek 8111B PCIe GBE Ethernet controller: after three attempts to install same, I&#8217;m still scratching my head and wondering why it won&#8217;t work. And wouldn&#8217;t you know it: the Realtek Web site doesn&#8217;t have an update newer than May 2009, while this one is dated for earlier in July. Sigh.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/more-on-patch-tuesday-july-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday June09: A Real Whopper!</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-june09-a-real-whopper/</link>
		<comments>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-june09-a-real-whopper/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 16:43:49 +0000</pubDate>
		<dc:creator>Ed Tittel</dc:creator>
				<category><![CDATA[Enterprise Vista]]></category>
		<category><![CDATA[enterprise Vista desktop]]></category>
		<category><![CDATA[MS09-018]]></category>
		<category><![CDATA[MS09-019]]></category>
		<category><![CDATA[MS09-020]]></category>
		<category><![CDATA[MS09-021]]></category>
		<category><![CDATA[MS09-022]]></category>
		<category><![CDATA[MS09-023]]></category>
		<category><![CDATA[MS09-024]]></category>
		<category><![CDATA[MS09-025]]></category>
		<category><![CDATA[MS09-026]]></category>
		<category><![CDATA[MS09-027]]></category>
		<category><![CDATA[Patch Tuesday]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=340</guid>
		<description><![CDATA[OK, so yesterday&#8217;s Patch Tuesday does the deed for June. It&#8217;s a monster: 10 security bulletins, 31 vulnerabilities addressed, and involving most versions of Windows itself, IE, and various MS Office and related elements (Works, Word, and Excel). Even the Windows Print Spooler and OS Kernel get in on the act! Of the 10 bulletins [...]]]></description>
				<content:encoded><![CDATA[<p>OK, so yesterday&#8217;s Patch Tuesday does the deed for June. It&#8217;s a monster: 10 security bulletins, 31 vulnerabilities addressed, and involving most versions of Windows itself, IE, and various MS Office and related elements (Works, Word, and Excel). Even the Windows Print Spooler and OS Kernel get in on the act!</p>
<p>Of the 10 bulletins issues, half (5) are critical, and fill some gaping widely-known holes in MS security. Chief among these: the dual WebDAV gothas for IIS publicized in May (explained in this <a href="http://blogs.zdnet.com/security/?p=3424" target="_blank">Ryan Naraine blog</a> from 5/19) and the infamous Pwn2Own vulnerability discovered in March at the CanSecWest conference in Vancouver.</p>
<table border="1" cellspacing="4" cellpadding="4">
<thead>
<tr>
<th>Bulletin ID</th>
<th>Rating</th>
<th>Target</th>
<th>Remarks</th>
</tr>
</thead>
<tbody>
<tr>
<td>MS09-018</td>
<td>Critical</td>
<td>Active Directory, Server 2000/203</td>
<td>2 remote code execution items</td>
</tr>
<tr>
<td>MS09-019</td>
<td>Critical</td>
<td>IE version 5-8</td>
<td>8 vulnerabilities, including remote code execution items</td>
</tr>
<tr>
<td>MS09-020</td>
<td>Important</td>
<td>IIS</td>
<td>2 vulnerabiliites allowing elevation of privilege</td>
</tr>
<tr>
<td>MS09-021</td>
<td>Critical</td>
<td>MS Excel</td>
<td>7 vulnerabilities including remote code execution</td>
</tr>
<tr>
<td>MS09-022</td>
<td>Critical</td>
<td>Windows Print Spooler</td>
<td>3 vulnerabilities, including remote code execution (Windows</td>
</tr>
<tr>
<td>MS09-023</td>
<td>Moderate</td>
<td>Windows Search</td>
<td>Single vulnerability could allow info disclosure</td>
</tr>
<tr>
<td>MS09-024</td>
<td>Critical</td>
<td>Microsoft Works converter</td>
<td>Could allow remote code execution</td>
</tr>
<tr>
<td>MS09-025</td>
<td>Important</td>
<td>Windows kernel</td>
<td>4 vulnerabilities that could allow elevation of privilege</td>
</tr>
<tr>
<td>MS09-026</td>
<td>Important</td>
<td>RPC</td>
<td>Could allow execution of arbitrary code or takeover</td>
</tr>
<tr>
<td>MS09-027</td>
<td>Critical</td>
<td>MS Word</td>
<p>I downloaded mine for Vista yesterday and they appear to have installed and taken without a hitch. You&#8217;ll probably want to start testing these right away, if you don&#8217;t plan to deploy them as-is.</p>
<td>2 vulnerabiltiies could allow remote code execution</td>
</tr>
</tbody>
</table>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-june09-a-real-whopper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
