 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Windows Enterprise Desktop &#187; Rundown on Patch Tuesday for April 2011</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/tag/rundown-on-patch-tuesday-for-april-2011/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 21:03:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Patch Tuesday: April 2011 Is a Doozy!</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-april-2011-is-a-doozy/</link>
		<comments>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-april-2011-is-a-doozy/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 13:53:39 +0000</pubDate>
		<dc:creator>Ed Tittel</dc:creator>
				<category><![CDATA[17 Security Updates Plus can leave up to 24 update files for some Windows machines for April 2011 Patch Tuesday]]></category>
		<category><![CDATA[April 2011 Patch Tuesday synopsis]]></category>
		<category><![CDATA[Rundown on Patch Tuesday for April 2011]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=1490</guid>
		<description><![CDATA[With up to 24 files recommended for some Windows PCs from this month's Patch Tuesday update cycle (April 2011), admins will have some work to do to get this stuff parceled out. Patches for recent zero-day IE and PWN2OWN exploits add some urgency to this regularly scheduled excercise.]]></description>
				<content:encoded><![CDATA[<p>Here&#8217;s what I found waiting for me on my production Windows 7 Professional (x86) machine this morning, in the wake of the latest Patch Tuesday:</p>
<div id="attachment_1491" class="wp-caption aligncenter" style="width: 551px"><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/79/files/2011/04/1104-patch-tuesday.jpg"><img class="size-medium wp-image-1491" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/79/files/2011/04/1104-patch-tuesday.jpg" alt="Up to 24 files to download and install!" width="541" height="607" /></a><p class="wp-caption-text">A personal record for Patch Tuesday: Up to 24 files to download and install!</p></div>
<p>Notice that only two items are unchecked by default: KB2511250 relates to an issue printing SVG graphics or CSS3 style sheets in IE9, and the Malicious Software Removal Tool is a usual Patch Tuesday feature. The former is something many users are not likely to need, while Microsoft is being smart about leaving the latter unchecked because it takes some time to run to completion and has occasionally caused problems when batched in with Patch Tuesday stuff in the past.</p>
<p>All this said, here&#8217;s a quick abstract of the <a href="http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx" target="_blank">Security Bulletin Summary for April 2011</a>:</p>
<table class="MsoNormalTable" width="86%" border="0" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><strong><span>Bulletin ID</span></strong></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><strong><span>Bulletin Title</span></strong></p>
</td>
<td width="16%" valign="top">
<p class="MsoNormal"><strong><span>Rating and Impact</span></strong></p>
</td>
<td width="11%" valign="top">
<p class="MsoNormal"><strong><span>Restart Required</span></strong></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><strong><span>Affected Software</span></strong></p>
</td>
</tr>
</thead>
<tbody>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkID=214126"><span>MS11-018</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Cumulative Security Update for IE   (2497640)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows,<br />
IE</span></td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212314"><span>MS11-019</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerabilities in SMB Client   Could Allow Remote Code Execution (2511455)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212236"><span>MS11-020</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in SMB Server   Could Allow Remote Code Execution (2508429)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkID=214005"><span>MS11-027</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Cumulative Security Update of   ActiveX Kill Bits (2508272)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=207931"><span>MS11-028</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in .NET Framework   Could Allow Remote Code Execution (2484015)</span><span> to bypass Code Access Security (CAS) restrictions.</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkID=208524"><span>MS11-029</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in GDI+ Could   Allow Remote Code Execution (2489979)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows,<br />
MS Office</span></td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212595"><span>MS11-030</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in DNS Resolution   Could Allow Remote Code Execution (2509553)</span><span> </span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212243"><span>MS11-031</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in JScript and   VBScript Scripting Engines Could Allow Remote Code Execution (2514666)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212224"><span>MS11-032</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in the OpenType   Compact Font Format (CFF) Driver Could Allow Remote Code Execution (2507618)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Critical</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=210121"><span>MS11-021</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerabilities in MS Excel   Could Allow Remote Code Execution (2489279)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Office</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkID=210727"><span>MS11-022</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerabilities in MS PowerPoint   Could Allow Remote Code Execution (2489283)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Office,<br />
MS Server Software</span></td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=210206"><span>MS11-023</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerabilities in MS Office   Could Allow Remote Code Execution (2489293)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Office</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212226"><span>MS11-024</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in Windows Fax   Cover Page Editor Could Allow Remote Code Execution (2527308)</span><span> </span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=209720"><span>MS11-025</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in MS Foundation   Class (MFC) Library Could Allow Remote Code Execution (2500212)</span><span> </span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Developer Tools and Software</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=212523"><span>MS11-026</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in MHTML Could   Allow Information Disclosure (2503658)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
Information Disclosure</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=208110"><span>MS11-033</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerability in WordPad Text   Converters Could Allow Remote Code Execution (2485663)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
RCE</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Maybe</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
<tr>
<td width="10%" valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=211826"><span>MS11-034</span></a></span></p>
</td>
<td width="43%" valign="top">
<p class="MsoNormal"><span>Vulnerabilities in Windows   Kernel-Mode Drivers Could Allow Elevation of Privilege (2506223)</span></p>
</td>
<td valign="top">
<p class="MsoNormal"><span><a href="http://go.microsoft.com/fwlink/?LinkId=21140"><span>Important</span></a><br />
Elevation of Privilege</span></td>
<td width="11%" valign="top">
<p class="MsoNormal"><span>Yes</span></p>
</td>
<td width="19%" valign="top">
<p class="MsoNormal"><span>MS Windows</span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal">Note: RCE is my abbreviation for Remote Code Execution, by far the most likely type of vulnerability you&#8217;ll encounter in this  month&#8217;s batch of updates. Lots of important IE vulnerabilities are addressed here, including some recently reported zero-day and the latest PWN2OWN exploits as well. Roll up your sleeves, admins: you&#8217;ve got some work to do!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/patch-tuesday-april-2011-is-a-doozy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
