VoIP Tech Chat

Patrick and Fred Chat… sometimes about VoIP

Microsoft Announces January Security Bulletin

3 comments

Microsoft announced today several critical warnings for Microsoft products, including Windows 2000, Windows 2003 Server, and Windows XP. Microsoft Security Advisories are a way for Microsoft to communicate security information to customers about issues that may not be classified as vulnerabilities and may not require a security bulletin. Each advisory will be accompanied with a unique Microsoft Knowledge Base Article number for reference to provide additional information about the changes.

The Microsoft Security Bulletin Summary follows:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Microsoft Security Bulletin Summary for January 2009
Issued: January 13, 2009
********************************************************************

This bulletin summary lists security bulletins released for
January 2009.

The full version of the Microsoft Security Bulletin Summary for
January 2009 can be found at

http://www.microsoft.com/technet/security/bulletin/ms09-jan.mspx.

With the release of the bulletins for January 2009, this bulletin
summary replaces the bulletin advance notification originally issued
on January 8, 2009. For more information about the bulletin advance
notification service, see

http://www.microsoft.com/technet/security/Bulletin/advance.mspx.

To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security
Notifications on

http://www.microsoft.com/technet/security/bulletin/notify.mspx.

Microsoft will host a webcast to address customer questions on
these bulletins on Wednesday, January 14, 2009,
at 11:00 AM Pacific Time (US & Canada). Register for the January
Security Bulletin Webcast at

http://www.microsoft.com/technet/security/bulletin/summary.mspx.

Microsoft also provides information to help customers prioritize
monthly security updates with any non-security, high-priority
updates that are being released on the same day as the monthly
security updates. Please see the section, Other Information.

Critical Security Bulletins
===========================

Microsoft Security Bulletin MS09-001

 - Affected Software:
   - Microsoft Windows 2000 Service Pack 4
   - Windows XP Service Pack 2 and
     Windows XP Service Pack 3
   - Windows XP Professional x64 Edition and
     Windows XP Professional x64 Edition Service Pack 2
   - Windows Server 2003 Service Pack 1 and
     Windows Server 2003 Service Pack 2
   - Windows Server 2003 x64 Edition and
     Windows Server 2003 x64 Edition Service Pack 2
   - Windows Server 2003 with SP1 for Itanium-based Systems and
     Windows Server 2003 with SP2 for Itanium-based Systems
   - Windows Vista and
     Windows Vista Service Pack 1
   - Windows Vista x64 Edition and
     Windows Vista x64 Edition Service Pack 1
   - Windows Server 2008 for 32-bit Systems
     (Windows Server 2008 Server Core installation affected)
   - Windows Server 2008 for x64-based Systems
     (Windows Server 2008 Server Core installation affected)
   - Windows Server 2008 for Itanium-based Systems

   - Impact: Remote Code Execution
   - Version Number: 1.0

Other Information
=================

Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows
Malicious Software Removal Tool on Windows Update, Microsoft Update,
Windows Server Update Services, and the Download Center.

Non-Security, High-Priority Updates on MU, WU, and WSUS:
========================================================
Please see:
* http://support.microsoft.com/kb/894199: Microsoft Knowledge Base
 Article 894199, Description of Software Update Services and
 Windows Server Update Services changes in content.
 Includes all Windows content.
* http://technet.microsoft.com/en-us/wsus/bb466214.aspx: New,
 Revised, and Released Updates for Microsoft Products Other Than
 Microsoft Windows

Microsoft Active Protections Program (MAPP)
===========================================
To improve security protections for customers, Microsoft provides
vulnerability information to major security software providers in
advance of each monthly security update release. Security software
providers can then use this vulnerability information to provide
updated protections to customers via their security software or
devices, such as antivirus, network-based intrusion detection
systems, or host-based intrusion prevention systems. To determine
whether active protections are available from security software
providers, please visit the active protections Web sites provided by
program partners, listed at

http://www.microsoft.com/security/msrc/mapp/partners.mspx.

Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing
a Microsoft security update, it is a hoax that may contain
malware or pointers to malicious Web sites. Microsoft does
not distribute security updates via e-mail.

The Microsoft Security Response Center (MSRC) uses PGP to digitally
sign all security notifications. However, PGP is not required for
reading security notifications, reading security bulletins, or
installing security updates. You can obtain the MSRC public PGP key
at

https://www.microsoft.com/technet/security/bulletin/pgp.mspx.

To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security
Notifications on

http://www.microsoft.com/technet/security/bulletin/notify.mspx.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.9.0 (Build 397)
Charset: utf-8

wsFVAwUBSWuY82A17vDdGxdTAQjPbhAAw+TSaXoVQzq63cfcM19mtmdzOCmFC9WK
50aN/S8oy2IPilmT850wvFNtZGgIKZPUYpRWmrYULZ+jKOWI1+qbvYQz+Sf+y7Ib
YpndUXJOgtwydk/4VSHKF7qDLCQ4IyOFsfUUq0xXaxf5Q0nwukOPvTJO2jNpN2Na
w19dv859lu8YO2MY9zKZhEZyu68i9rv18/HH7T3wrISj+HczhTpxz6LZUEF+Zps7
CHIYPqGuxzecTfYaEn7WlyraJ2NHin/Gk+9MpsLfMKCmmKsQ2/7J4SrDgDDpCyh0
Za7qqtTRm7Wg2TdqezxoJXpHUAfATFeA4Qiob92srJqjiSNjWNCXNequ2pe6K6B1
op1Bub4+RYaBNfr21SKahXHDt6C/heWnac2AfHXgl2Yjl7PGY5q8c/ckkyZEu9dj
l2Wo13HAZaI6lm0H2lMrqZxTAZqUeUNxEkV8GXux/xN3TXRgblndxQQGdlvVZ16o
i+XMoEgh+4oyWcVz4cbnFwR4Jt21ovv9KTuhu1j8D5vp4/reBDtRdw/KyrxbTJMh
droJmvmtRZv7j4F9DFFAxUN0xeIhnhfSG71qi6+uARuX2iJ1w1ge9vdTOkErNZHN
KEUNBVKuuP8VyaNEFagCXAYLFusvQp70aTeV0Fjit5tyAkmkg4ua6P9GwMykIQli
QrUieOEMeG0=
=DIwK
-----END PGP SIGNATURE-----

And there’s a revision, too:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Title: Microsoft Security Bulletin Major Revisions
Issued: January 13, 2009
********************************************************************

Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.

 * MS08-076 - Important
 * MS08-072 - Critical

Bulletin Information:
=====================

* MS08-076 - Important

- http://www.microsoft.com/technet/security/bulletin/ms08-076.mspx
- Reason for Revision: V3.0 (January 13, 2009): Added entry to the
   Frequently Asked Questions (FAQ) Related to This Security
   Update section explaining that Microsoft has re-released the
   update packages for Windows Media Format Runtime 9.5 on
   Windows XP Service Pack 2 (KB952069) and on Windows XP
   Service Pack 3 (KB952069). Customers running all other
   supported and affected versions of Windows Media components
   who have already applied the original security update
   packages do not need to take any further action. Also, listed
   Windows Media Player 6.4 and Windows Media Services 4.1 as
   affected on all editions of Microsoft Windows 2000 Service
   Pack 4; customers who were offered but have not applied this
   update, KB954600 for Windows Media Player 6.4, or KB952068
   for Windows Media Services 4.1, need to do so.
- Originally posted: December 9, 2008
- Updated: January 13, 2009
- Bulletin Severity Rating: Important
- Version: 3.0

* MS08-072 - Critical

- http://www.microsoft.com/technet/security/bulletin/ms08-072.mspx
- Reason for Revision: V2.0 (January 13, 2009): Added Microsoft
   Office Word Viewer to Affected Software table. Also, added an
   entry to the section, Frequently Asked Questions (FAQ)
   Related to This Security Update, explaining Microsoft Office
   Word Viewer. There were no changes to the security update
   binaries or detection. Customers with Microsoft Office Word
   Viewer who have successfully installed security update
   KB956366 do not need to reinstall.
- Originally posted: December 9, 2008
- Updated: January 13, 2009
- Bulletin Severity Rating: Critical
- Version: 2.0

Other Information
=================

Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing
a Microsoft security update, it is a hoax that may contain
malware or pointers to malicious Web sites. Microsoft does
not distribute security updates via e-mail.

The Microsoft Security Response Center (MSRC) uses PGP to digitally
sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or
install security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.

To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised,
subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.9.0 (Build 397)
Charset: utf-8

wsFVAwUBSWzi+mA17vDdGxdTAQj+JQ//Q4irc9uFZDbPuhHPJARBIB9/SfNMuXmx
A9nttjP2V1rrI86QkRsvjnfYd9FQlCS6htcP1dFk9wmoZPnSs6Uy7te7ZscGQus/
rdwpY2bDoftCfD617Y1PQD7+ye5r6rkE76FSVLwE30bDXADQKRcv57ENuwTJIC6D
2mXnjOfku3wxXDzDZ5jXWjLmIyafDblOclJWR5qqigHVnx+fhcPd7YGuDy4v1RL0
jeoMQHA017wLbjpNfdEv41qPGm605DCv9jOMlljss6Kyi8dWT+D6ohwwU4OiU0sH
rzoojLySum4XYd6gypKX0dba4ZIucj5tmtP2QOGIACxi8yeslZoqC0UBKfM/nz5v
UttdfQWwT4VF640w+Kd0GdRObj0KuRojKOQD/U6/usO4JiPUL8iPCrpm7iIW6c91
RIajeoPO5JYBSNJoxiobJMFoAxnMUXqArDLA0EqQ9oBSEICWLg4rn2tMZe1S1q1M
jYYckLMGHy7ZHvNGBWYdhxyDgnSUrPXKL6x/GPebdwP8jEzZfmUFX9czV7sjRPkh
zG0GAa+AM6VpEhoqbhbnGAT83I7h/PaIhADPW+VD7doxkAQoyjfDyEDlMa0c7V41
R9ZFtjeAnKcmBGFL1T1mIj+c+0T44l9hhju556qErLERtN5AlmgamfKLJfTj27rV
QzqwdRx4pZk=
=shsZ
-----END PGP SIGNATURE-----

Written by Fred

January 13th, 2009 at 5:09 pm

Posted in tech

Tagged with , , ,

3 Responses to 'Microsoft Announces January Security Bulletin'

Subscribe to comments with RSS or TrackBack to 'Microsoft Announces January Security Bulletin'.

  1. Microsoft Security Bulletin for Jan 2009 released http://bit.ly/TGU6

    Fred Posner

    13 Jan 09 at 10:12 pm

  2. Быстрая установка окон пвх, установка деревянных окон, технология установки окон, установка окон в деревянном доме, инструкция по установке окон, технология установки пластиковых окон, фирмы по установке окон, установка окон цена, договор на установку окон, установка решеток на окнах, установка решеток на окна, установка металлопластиковых окон, установка окон самостоятельно, установка мансардных окон, установка окон своими руками

    stanov

    12 Sep 09 at 3:49 am

  3. Our words exactly.

    Fred

    12 Sep 09 at 7:32 am

Leave a Reply