<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Shavlik</title>
	
	<link>http://blog.shavlik.com</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Tue, 08 May 2012 20:42:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Shavlik" /><feedburner:info uri="shavlik" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><image><link>http://blog.shavlik.com/</link><url>http://blog.shavlik.com/wp-content/uploads/2011/01/logo_shavlik-e1294331663313.jpg</url><title>Visit the Shavlik Blog</title></image><feedburner:emailServiceId>Shavlik</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Shavlik" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2FShavlik" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><feedburner:browserFriendly>This is an XML content feed of Shavlik’s blogs. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item>
		<title>May 2012 Patch Tuesday Overview</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/mc6EdObThlY/</link>
		<comments>http://blog.shavlik.com/2012/05/08/may-2012-patch-tuesday-overview/#comments</comments>
		<pubDate>Tue, 08 May 2012 20:42:11 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Current Threats and Vulnerabilities]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Patrol]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[Zero-Day]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2660</guid>
		<description><![CDATA[<p>Marking the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may" target="_blank">May 2012 edition of Patch Tuesday</a>, Microsoft has released seven new security bulletins addressing 23 vulnerabilities.</p>
<p>The first bulletin administrators should address immediately is the mammoth security bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034" target="_blank">MS12-034</a>.  The sheer size of this security bulletin will undoubtedly affect the majority of your network when patching this month.</p>
<p>This bulletin covers:
72 Microsoft operating systems / service pack combinations
31 Microsoft .NET installation versions and types
9 Microsoft Office installation versions and types
6 Microsoft Silverlight installation versions and types</p>
<p>This is by far one of the largest security bulletins Microsoft has ever released.  This bulletin will address seven vulnerabilities with &#8230;]]></description>
			<content:encoded><![CDATA[<p>Marking the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may" target="_blank">May 2012 edition of Patch Tuesday</a>, Microsoft has released seven new security bulletins addressing 23 vulnerabilities.</p>
<p>The first bulletin administrators should address immediately is the mammoth security bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034" target="_blank">MS12-034</a>.  The sheer size of this security bulletin will undoubtedly affect the majority of your network when patching this month.</p>
<p>This bulletin covers:<br />
72 Microsoft operating systems / service pack combinations<br />
31 Microsoft .NET installation versions and types<br />
9 Microsoft Office installation versions and types<br />
6 Microsoft Silverlight installation versions and types</p>
<p>This is by far one of the largest security bulletins Microsoft has ever released.  This bulletin will address seven vulnerabilities with three of the vulnerabilities already publicly disclosed.  There are quite a few scenarios an attacker could exploit the vulnerabilities, but the most tempting attack scenario will involve a user visiting a malicious website.  With an unpatched system, the user will be subject to an attack that will result in Remote Code Execution.  <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035" target="_blank">MS12-035</a> is a second security bulletin that addresses vulnerabilities in the Microsoft .NET application.  Both MS12-034 and MS12-035 will need to be applied to applicable systems with .NET installed.  As most administrators are already aware of, patching Microsoft .NET can be extremely time-consuming.  Administrators should plan for a longer than usual patch cycle for their machines with .NET installed with two security bulletins affection the Microsoft .NET product.</p>
<p>Next up on the priority list for patching this month is <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-029" target="_blank">MS12-029</a>.  This security bulletin addresses one vulnerability in older versions of Microsoft Word (pre Microsoft Word 2010).  An attacker can gain Remote Code Execution if a user opens a malicious RTF type document with Microsoft Word.  RTF documents are very common documents that are typically allowed through email systems as attachments.</p>
<p>Microsoft also released a new security advisory for their ActiveX Kill Bits with <a href="http://technet.microsoft.com/en-us/security/advisory/2695962" target="_blank">Microsoft Security Advisory (2695962)</a>.  In the past, Microsoft released ActiveX Kill Bit updates in a security bulletin format.  With the change to a security advisory format, it is important to not forget about these patches during your normal patch Tuesday cycle.</p>
<p>On the non-Microsoft front, Adobe has joined patch Tuesday with a security bulletin release of their own.  The 4 new Adobe Security bulletins affect a variety of products:<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb12-10.html" target="_blank">APSB12-10</a> &#8211; Adobe Illustrator:  5 vulnerabilities fixed, can lead to Remote Code Execution<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb12-11.html" target="_blank">APSB12-11</a> &#8211; Adobe Photoshop:  2 vulnerabilities fixed, can lead to Remote Code Execution<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb12-12.html" target="_blank">APSB12-12</a> &#8211; Adobe Flash Professional:  1 vulnerability fixed, can lead to Remote Code Execution<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb12-13.html" target="_blank">APSB12-13</a> &#8211; Adobe Shockwave Player:  5 vulnerabilities fixed, can lead to Remote Code Execution</p>
<p>Last Friday, Adobe released an update for their Adobe Flash Player with <a href="http://www.adobe.com/support/security/bulletins/apsb12-09.html" target="_blank">APSB12-09</a>.  This security bulletin addresses a zero-day vulnerability that is currently being exploited in the wild.  Adobe Flash is a widely used program and often targeted by attackers, so this bulletin should be deployed as soon as possible with your Microsoft security bulletins.</p>
<p>In all, this typically light patching month will feature quite a few security bulletins to address on networks (7 Microsoft security bulletins, 1 Microsoft security advisory, 5 Adobe bulletins).</p>
<p>I will be going over the May Patch Tuesday in detail in addition to any other non-Microsoft releases since the last Patch Tuesday in our Monthly Patch Tuesday webinar. This webinar is scheduled for next Wednesday, May 9th at 11:00am CST. You can register for this webinar <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=664452644" target="_blank">here</a>.</p>
<p>- Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=mc6EdObThlY:lZ00tY5sGy4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=mc6EdObThlY:lZ00tY5sGy4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=mc6EdObThlY:lZ00tY5sGy4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=mc6EdObThlY:lZ00tY5sGy4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=mc6EdObThlY:lZ00tY5sGy4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=mc6EdObThlY:lZ00tY5sGy4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/mc6EdObThlY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/05/08/may-2012-patch-tuesday-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/05/08/may-2012-patch-tuesday-overview/</feedburner:origLink></item>
		<item>
		<title>May 2012 Patch Tuesday Advanced Notification</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/Dum_FhN2rGw/</link>
		<comments>http://blog.shavlik.com/2012/05/03/may-2012-patch-tuesday-advanced-notification/#comments</comments>
		<pubDate>Thu, 03 May 2012 21:18:22 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Patrol]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2657</guid>
		<description><![CDATA[<p>Microsoft has released their Advanced Notification for the May 2012 edition of Patch Tuesday.  Microsoft is planning to release seven bulletins addressing 23 vulnerabilities.  In addition, they will be releasing a Security Advisory to update ActiveX killbits.  Last year, Microsoft moved the ActiveX killbit updates from a Security Bulletin to a Security Advisory.  So, you should be aware that there will be eight bulletins that need your attention next Tuesday.</p>
<p>Security Bulletin Breakdown:</p>

4 bulletins are rated as Critical
3 bulletins are rated as Important
5 bulletins addressing vulnerabilities that could lead to Remote Code Execution
2 bulletins addressing vulnerabilities that could lead to Elevation &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released their Advanced Notification for the May 2012 edition of Patch Tuesday.  Microsoft is planning to release seven bulletins addressing 23 vulnerabilities.  In addition, they will be releasing a Security Advisory to update ActiveX killbits.  Last year, Microsoft moved the ActiveX killbit updates from a Security Bulletin to a Security Advisory.  So, you should be aware that there will be eight bulletins that need your attention next Tuesday.</p>
<p>Security Bulletin Breakdown:</p>
<ul>
<li>4 bulletins are rated as Critical</li>
<li>3 bulletins are rated as Important</li>
<li>5 bulletins addressing vulnerabilities that could lead to Remote Code Execution</li>
<li>2 bulletins addressing vulnerabilities that could lead to Elevation of Privilege</li>
</ul>
<p>Affected Products:</p>
<ul>
<li>All supported Microsoft Operating Systems</li>
<li>All supported Microsoft Office products (2003, 2007, 2010)</li>
<li>Microsoft Office Compatibility Pack</li>
<li>Microsoft Visio Viewer 2010</li>
<li>Microsoft Excel Viewer</li>
<li>Microsoft Silverlight 4, 5</li>
</ul>
<p>I will be going over the May Patch Tuesday in detail in addition to any other non-Microsoft releases since the last Patch Tuesday in our Monthly Patch Tuesday webinar.  This webinar is scheduled for next Wednesday, May 9th at 11:00am CST.  You can register for this webinar <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=664452644" target="_blank">here</a>.</p>
<p> - Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=Dum_FhN2rGw:jt_rEdspdgE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Dum_FhN2rGw:jt_rEdspdgE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=Dum_FhN2rGw:jt_rEdspdgE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Dum_FhN2rGw:jt_rEdspdgE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=Dum_FhN2rGw:jt_rEdspdgE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Dum_FhN2rGw:jt_rEdspdgE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/Dum_FhN2rGw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/05/03/may-2012-patch-tuesday-advanced-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/05/03/may-2012-patch-tuesday-advanced-notification/</feedburner:origLink></item>
		<item>
		<title>NetChk Protect End-of-Life for versions 7.5, 7.6, and 7.8</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/NIE5Wahr8Gc/</link>
		<comments>http://blog.shavlik.com/2012/05/02/netchk-protect-end-of-life-for-versions-7-5-7-6-and-7-8/#comments</comments>
		<pubDate>Wed, 02 May 2012 17:02:43 +0000</pubDate>
		<dc:creator>Chris Goettl</dc:creator>
				<category><![CDATA[Product Blog]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2653</guid>
		<description><![CDATA[<p>VMware customers using the Shavlik branded versions of Protect please note that we are announcing the end-of-life for versions 7.5, 7.6, and 7.8.  You will see the following message when contacting support.</p>
<p>&#8220;In November of 2012, Shavlik, a VMware Company, will End-of-Life (EOL) the following NetChk Protect versions by disabling the ability to update the XML data. As of November 1, 2012, the ability to update XML data on Protect 7.5, 7.6 and 7.8 versions of the product will be disabled. Please refer to VMware’s Life Cycle Policies page under VMware vCenter Protect Essentials/Essentials Plus for further information at <a href="https://www.vmware.com/support/policies/lifecycle/" target="_blank">https://www.vmware.com/support/policies/lifecycle/</a> &#38;<a &#8230;]]></description>
			<content:encoded><![CDATA[<p>VMware customers using the Shavlik branded versions of Protect please note that we are announcing the end-of-life for versions 7.5, 7.6, and 7.8.  You will see the following message when contacting support.</p>
<p>&#8220;In November of 2012, Shavlik, a VMware Company, will End-of-Life (EOL) the following NetChk Protect versions by disabling the ability to update the XML data. As of November 1, 2012, the ability to update XML data on Protect 7.5, 7.6 and 7.8 versions of the product will be disabled. Please refer to VMware’s Life Cycle Policies page under VMware vCenter Protect Essentials/Essentials Plus for further information at <a href="https://www.vmware.com/support/policies/lifecycle/" target="_blank">https://www.vmware.com/support/policies/lifecycle/</a> &amp;<a href="https://www.vmware.com/files/pdf/support/Shavlik-Legacy-EOL-Information.pdf" target="_blank">https://www.vmware.com/files/pdf/support/Shavlik-Legacy-EOL-Information.pdf</a>.</p>
<p>To upgrade to the latest version of vCenter (NetChk) Protect Essentials, please visit:  <a href="http://www.shavlik.com/downloads.aspx" target="_blank">http://www.shavlik.com/downloads.aspx</a>.&#8221;</p>
<p>The vCenter Protect support team will also be directly contacting customers who are last known to be on these versions.  As always we will do everything we can to ensure Protect customers have been notified of the versions that will no longer be supported.</p>
<p>Regards,</p>
<p>Chris Goettl<br />
Product Owner<br />
SMB Management Solutions<br />
VMware</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=NIE5Wahr8Gc:7AyHxZgr3Wk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=NIE5Wahr8Gc:7AyHxZgr3Wk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=NIE5Wahr8Gc:7AyHxZgr3Wk:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=NIE5Wahr8Gc:7AyHxZgr3Wk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=NIE5Wahr8Gc:7AyHxZgr3Wk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=NIE5Wahr8Gc:7AyHxZgr3Wk:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/NIE5Wahr8Gc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/05/02/netchk-protect-end-of-life-for-versions-7-5-7-6-and-7-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/05/02/netchk-protect-end-of-life-for-versions-7-5-7-6-and-7-8/</feedburner:origLink></item>
		<item>
		<title>Visit MVware @ Microsoft Management Summit (April 16th-20th) in Las Vegas</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/cii70BN9_W0/</link>
		<comments>http://blog.shavlik.com/2012/04/16/visit-mvware-microsoft-management-summit-april-16th-20th-in-las-vegas/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 20:38:52 +0000</pubDate>
		<dc:creator>Mike Bleakmore</dc:creator>
				<category><![CDATA[Corporate Blog]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[MMS 2012]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[VMWare]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2647</guid>
		<description><![CDATA[<p>Keeping up to date with patches historically meant operating systems and applications from Microsoft.  In today’s threat landscape, however, third-party applications have become the leading cause of most vulnerabilities on the network.  Many companies around the world rely on Microsoft System Configuration Manager (SCCM) for patch management.  That simply is not enough to bolster network security, however, because Microsoft applications are not the only ones at risk.</p>
<p>Microsoft Management Summit 2012 begins today in Las Vegas and if you are attending the show, we invite you to stop by VMware booth #621.  We’ll be demonstrating the latest releases of our VMware &#8230;]]></description>
			<content:encoded><![CDATA[<p>Keeping up to date with patches historically meant operating systems and applications from Microsoft.  In today’s threat landscape, however, third-party applications have become the leading cause of most vulnerabilities on the network.  Many companies around the world rely on Microsoft System Configuration Manager (SCCM) for patch management.  That simply is not enough to bolster network security, however, because Microsoft applications are not the only ones at risk.</p>
<p>Microsoft Management Summit 2012 begins today in Las Vegas and if you are attending the show, we invite you to stop by VMware booth #621.  We’ll be demonstrating the latest releases of our VMware vCenter Protect Update Catalog and VMware vCenter Protect Essentials at the booth.  These solutions simplify and automate patch management for Microsoft and third-party applications.</p>
<p><strong>About VMware’s solutions for patch management</strong></p>
<p>VMware vCenter Protect Update Catalog extends SCCM beyond Microsoft products to solve critical third-party patch management needs.  vCenter Protect Update Catalog plugs into SCCM as a simple data service that requires no additional agents, console or management to learn.  Just import the third-party patch catalog for Adobe, Google, Java Firefox, iTunes, etc. into SCCM and you’ll be patching vulnerabilities on your servers and workstations in minutes.  <a href="http://www.vmware.com/products/datacenter-virtualization/vcenter-protect-update-catalog/overview.html">Click here to learn more about vCenter Protect Update Catalog.</a></p>
<p>VMware vCenter Protect Essentials reduces the cost and complexity of IT management with an integrated approach to IT security and compliance.  vCenter Protect Essentials provides centralized Windows patch management and asset inventory management for both virtual and physical machines.  This includes centralized management for Windows operating systems and the most widely used Windows-hosted applications running on both virtual and physical servers and workstations.  <a href="http://www.vmware.com/products/datacenter-virtualization/vcenter-protect/overview.html">Click here to learn more about vCenter Protect Essentials.</a></p>
<p>Hope to see you in Las Vegas this week, and don’t forget to enter your name to win an Xbox 360 with Kinect at booth #621.</p>
<p>- Mike Bleakmore</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=cii70BN9_W0:iE8rNNTzq80:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=cii70BN9_W0:iE8rNNTzq80:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=cii70BN9_W0:iE8rNNTzq80:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=cii70BN9_W0:iE8rNNTzq80:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=cii70BN9_W0:iE8rNNTzq80:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=cii70BN9_W0:iE8rNNTzq80:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/cii70BN9_W0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/04/16/visit-mvware-microsoft-management-summit-april-16th-20th-in-las-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/04/16/visit-mvware-microsoft-management-summit-april-16th-20th-in-las-vegas/</feedburner:origLink></item>
		<item>
		<title>April 2012 Patch Tuesday Overview</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/EuccHruzMrk/</link>
		<comments>http://blog.shavlik.com/2012/04/10/april-2012-patch-tuesday-overview/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 19:05:29 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Current Threats and Vulnerabilities]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Patrol]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Zero-Day]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2639</guid>
		<description><![CDATA[<p>Microsoft has released six bulletins addressing 11 vulnerabilities in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr" target="_blank">April 2012 version of Patch Tuesday</a>.</p>
<p>Marking the fourth Patch Tuesday of the year, Microsoft and non-Microsoft vendors are making this quite an interesting month with critical security bulletins and new products to consider in your monthly Patch Tuesday.</p>
<p>There are many products that are affected by the new security bulletins. This means you will be seeing quite a few patches missing on a single machine.  For example, <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-027" target="_blank">MS12-027</a> affects 29 different products and service pack levels.  For those administrators responsible for reporting their patch compliance, this can &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released six bulletins addressing 11 vulnerabilities in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr" target="_blank">April 2012 version of Patch Tuesday</a>.</p>
<p>Marking the fourth Patch Tuesday of the year, Microsoft and non-Microsoft vendors are making this quite an interesting month with critical security bulletins and new products to consider in your monthly Patch Tuesday.</p>
<p>There are many products that are affected by the new security bulletins. This means you will be seeing quite a few patches missing on a single machine.  For example, <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-027" target="_blank">MS12-027</a> affects 29 different products and service pack levels.  For those administrators responsible for reporting their patch compliance, this can be quite a headache.</p>
<p>As scheduled, Microsoft has released their bi-monthly update for Internet Explorer.  With any browser (Microsoft or non-Microsoft), patching is always on the top of the priority list as Internet browsers are one of the most targeted pieces of software for exploitation.  With Internet Explorer 10 (bundled with Windows 8), Microsoft is turning on automatic updates in the background.  We will have to wait and see if Microsoft increases their patch releases for their browser like Google Chrome and Mozilla Firefox.  Since the last time Microsoft has patched Internet Explorer (February 2012 Patch Tuesday), Google released new updates to their browser seven times.  Five of these releases were security releases. </p>
<p>Speaking of browsing threats, <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-027" target="_blank">MS12-027</a> is a bulletin that can be attacked via browsing.  MS12-027 fixes one vulnerability that Microsoft has received limited attacks against.  Browsing to a malicious website with Internet Explorer will result in remote code execution.  An attacker could also try sending a RTF file with embedded malicious ActiveX controls.  If the user opens the file on an unpatched system, the attacker can gain full access to the system.  As Microsoft has already seen active exploits against this vulnerability and it contains a web browsing scenario, it will be critical to push this patch out to your desktop systems as soon as possible. </p>
<p>On a different front for this security bulletin, software developers will need to pay particular attention to the information inside of this bulletin.  Any developer that has released an ActiveX control should review the information for this security bulletin.  These developers may need to release updates to their own software to ensure they are not using a vulnerable file in their ActiveX control.</p>
<p>With this Patch Tuesday we are also seeing the first security bulletin affecting the Windows 8 Consumer Preview.  Anyone using this operating system will want to apply <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-024" target="_blank">MS12-024</a>.  It is good to see that Microsoft is not forgetting about their widely available (and used) preview operating system.</p>
<p>There are a few non-Microsoft vendors joining the Patch Tuesday security bulletin party with their own releases.  Adobe is releasing updates for their Acrobat and Reader product lines during their own quarterly security bulletin update (<a href="http://www.adobe.com/support/security/bulletins/apsb12-08.html" target="_blank">APSB12-08</a>).  This security update addresses four vulnerabilities.</p>
<p>Google has released an update for their Chrome browser with version 18.0.1025.152.  This latest version of the Google Chrome browser is a non-security update.</p>
<p>I will be talking about the April Patch Tuesday as well as any other non-Microsoft patches that have been recently released tomorrow, April 11<sup>th</sup> at 11:00am CT in part of our monthly Patch Tuesday webinar.  <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=661844476">Click here</a> to register for the webinar.</p>
<p>- Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=EuccHruzMrk:Ri2onz5292A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=EuccHruzMrk:Ri2onz5292A:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=EuccHruzMrk:Ri2onz5292A:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=EuccHruzMrk:Ri2onz5292A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=EuccHruzMrk:Ri2onz5292A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=EuccHruzMrk:Ri2onz5292A:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/EuccHruzMrk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/04/10/april-2012-patch-tuesday-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/04/10/april-2012-patch-tuesday-overview/</feedburner:origLink></item>
		<item>
		<title>April 2012 Patch Tuesday Advanced Notification</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/rGwbcpGK0Ao/</link>
		<comments>http://blog.shavlik.com/2012/04/05/april-2012-patch-tuesday-advanced-notification/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 19:14:58 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Current Threats and Vulnerabilities]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Patrol]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2633</guid>
		<description><![CDATA[<p>Microsoft has released their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr" target="_blank">Advance Notification</a> for the upcoming April Patch Tuesday.  With the six bulletins announced, Microsoft is planning to address 11 vulnerabilities.  This marks Microsoft&#8217;s heavy patch month and we are seeing this with the sheer number of affected products this month.  We are also looking at a heavy server patching month to go along with all workstations being affected.</p>
<p> Security Bulletin Breakdown:</p>

4 bulletins are rated as Critical
2 bulletins are rated as Important
5 bulletins addressing vulnerabilities that could lead to Remote Code Execution
1 bulletin addressing a vulnerability that could lead to Elevation of Privilege

<p> Affected Products:</p>

All supported Microsoft &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr" target="_blank">Advance Notification</a> for the upcoming April Patch Tuesday.  With the six bulletins announced, Microsoft is planning to address 11 vulnerabilities.  This marks Microsoft&#8217;s heavy patch month and we are seeing this with the sheer number of affected products this month.  We are also looking at a heavy server patching month to go along with all workstations being affected.</p>
<p> Security Bulletin Breakdown:</p>
<ul>
<li>4 bulletins are rated as Critical</li>
<li>2 bulletins are rated as Important</li>
<li>5 bulletins addressing vulnerabilities that could lead to Remote Code Execution</li>
<li>1 bulletin addressing a vulnerability that could lead to Elevation of Privilege</li>
</ul>
<p> Affected Products:</p>
<ul>
<li>All supported Microsoft operating systems</li>
<li>All supported Internet Explorer browsers</li>
<li>Microsoft Office 2003, 2007, 2010</li>
<li>Microsoft Office 2003 Web Components</li>
<li>Microsoft SQL Server 2000, 2005, 2008, 2008 R2</li>
<li>Microsoft BizTalk Server 2002</li>
<li>Microsoft Commerce Server 2002, 2008, 2009, 2009 R2</li>
<li>Microsoft Visual FoxPro 8, 9</li>
<li>Microsoft Visual Basic 6.0 Runtime</li>
<li>Microsoft Forefront Unified Access Gateway</li>
</ul>
<p> I will be going over the April Patch Tuesday in detail in addition to any other non-Microsoft releases since the last Patch Tuesday in our Monthly Patch Tuesday webinar.  This webinar is scheduled for next Wednesday, April 11th at 11:00am CST.  You can register for this webinar <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=661844476">here</a>.</p>
<p> - Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=rGwbcpGK0Ao:jtqn7tROcLE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=rGwbcpGK0Ao:jtqn7tROcLE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=rGwbcpGK0Ao:jtqn7tROcLE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=rGwbcpGK0Ao:jtqn7tROcLE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=rGwbcpGK0Ao:jtqn7tROcLE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=rGwbcpGK0Ao:jtqn7tROcLE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/rGwbcpGK0Ao" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/04/05/april-2012-patch-tuesday-advanced-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/04/05/april-2012-patch-tuesday-advanced-notification/</feedburner:origLink></item>
		<item>
		<title>March 2012 Patch Tuesday Overview</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/3XT3-UbVQ94/</link>
		<comments>http://blog.shavlik.com/2012/03/13/march-2012-patch-tuesday-overview/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 19:41:59 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2627</guid>
		<description><![CDATA[<p>Microsoft has released six bulletins for the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar" target="_blank">March 2012 Patch Tuesday</a>.  With this release, Microsoft is addressing seven vulnerabilities.</p>
<p>The primary bulletin administrators should look to address first is <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020" target="_blank">MS12-020</a>.  This bulletin addresses two privately reported vulnerabilities to Microsoft affecting the Remote Desktop Protocol on all supported versions of the Microsoft operating system.</p>
<p>If an attacker sends a specially crafted packet to a machine with RDP enabled, the attack could result in Remote Code Execution on the target machine.  Although Microsoft is stating that most machines do not have RDP enabled by default, I know of many organizations &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released six bulletins for the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar" target="_blank">March 2012 Patch Tuesday</a>.  With this release, Microsoft is addressing seven vulnerabilities.</p>
<p>The primary bulletin administrators should look to address first is <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020" target="_blank">MS12-020</a>.  This bulletin addresses two privately reported vulnerabilities to Microsoft affecting the Remote Desktop Protocol on all supported versions of the Microsoft operating system.</p>
<p>If an attacker sends a specially crafted packet to a machine with RDP enabled, the attack could result in Remote Code Execution on the target machine.  Although Microsoft is stating that most machines do not have RDP enabled by default, I know of many organizations that use RDP to troubleshoot machines.  This Windows component comes even more into play with machines that are not physically located next to users such as virtualized machines.  Using RDP is a common technique used to connect to virtualized machines.</p>
<p>There are a couple of varying factors with this vulnerability that could help or increase the risk of attack on a network.  First, older operating systems (Windows XP, 2003) can potentially have an unauthenticated attack vector on this vulnerability.  With these systems, an attacker can simply send specially crafted RDP network packets to the target system and gain full system level access.  Newer versions of the Microsoft operating system (Windows Vista, 2008, 7, 2008 R2) have a security feature that can be turned on to prevent unauthenticated access.  This technology, Network Level Authentication, will force an attacker to provide valid credentials to gain access to the system.</p>
<p>This bulletin simply scares me when it comes to protecting an environment from future attacks.  This vulnerability has the real potential to become victim to a worm outbreak if this vulnerability is not patched.  Although this vulnerability may be difficult to exploit, I can assure you attackers will be working hard to create a valid attack against the vulnerability.  With that said, administrators should patch this bulletin immediately.</p>
<p>A lot of organizations have patch maintenance windows that only allow patching at certain times.  If an administrator has a maintenance window later this month but wants to help mitigate the risk of this vulnerability, Microsoft has supplied a FixIt tool to enable NLA on newer operating systems.  In addition, they have provided a FixIt tool to enable support for NLA on Windows XP SP3.  Windows XP does not have this technology as it is an older operating system.</p>
<p>On the non-Microsoft front, Adobe has released an update for their ColdFusion program with security bulletin APSB12-06.  This security bulletin is rated as important and addresses one vulnerability.  Mozilla is hinting at releasing security updates for Thunderbird and SeaMonkey later today.  So far, they have released new versions of Firefox with 10.0.3 and 3.6.28.  Both of the Firefox updates are security updates.</p>
<p>As with any Patch Tuesday, keep your eyes and ears open for any other vendors potentially sneaking in a security update.</p>
<p>There have been some non-Microsoft security updates released since the February Patch Tuesday including:</p>
<p>Adobe Flash<br />
Apple iTunes<br />
Google Chrome<br />
Mozilla Firefox<br />
Mozilla Thunderbird<br />
Mozilla SeaMonkey<br />
Oracle Java</p>
<p>With the RDP bulletin released today along with all of the other non-Microsoft security bulletins released today and during this month, administrators will have their own March Madness to deal with patching their networks.</p>
<p>I will be talking about the March Patch Tuesday as well as any other non-Microsoft patches that have been recently released next Wednesday, March 14th at 11:00am CST in part of our monthly Patch Tuesday webinar. <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=667118480" target="_blank">Click here</a> to register for the webinar.</p>
<p>- Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=3XT3-UbVQ94:YYUfs0MBzHU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=3XT3-UbVQ94:YYUfs0MBzHU:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=3XT3-UbVQ94:YYUfs0MBzHU:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=3XT3-UbVQ94:YYUfs0MBzHU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=3XT3-UbVQ94:YYUfs0MBzHU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=3XT3-UbVQ94:YYUfs0MBzHU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/3XT3-UbVQ94" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/03/13/march-2012-patch-tuesday-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/03/13/march-2012-patch-tuesday-overview/</feedburner:origLink></item>
		<item>
		<title>March 2012 Patch Tuesday Advanced Notification</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/Gs9EMHhJCs0/</link>
		<comments>http://blog.shavlik.com/2012/03/08/march-2012-patch-tuesday-advanced-notification/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 23:19:34 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2622</guid>
		<description><![CDATA[<p>Microsoft has released their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar" target="_blank">advanced notification</a> for the March 2012 edition of Patch Tuesday.  Microsoft is planning to release six bulletins addressing seven vulnerabilities.</p>
<p> Security Bulletin Breakdown:</p>

1 bulletin is rated as Critical
4 bulletins are rated as Important
1 bulletin is rated as Moderate
2 vulnerabilities could lead to Remote Code Execution
2 vulnerabilities could lead to Elevation of Privilege
2 vulnerabilities could lead to Denial of Service

<p> Affected Products:</p>

All supported Microsoft Operating Systems
Microsoft Visual Studio 2008, 2010
Microsoft Expression Design 1, 2, 3, 4

<p> </p>
<p>I will be talking about the March Patch Tuesday as well as any other non-Microsoft patches that have been recently released next &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-mar" target="_blank">advanced notification</a> for the March 2012 edition of Patch Tuesday.  Microsoft is planning to release six bulletins addressing seven vulnerabilities.</p>
<p> Security Bulletin Breakdown:</p>
<ul>
<li>1 bulletin is rated as Critical</li>
<li>4 bulletins are rated as Important</li>
<li>1 bulletin is rated as Moderate</li>
<li>2 vulnerabilities could lead to Remote Code Execution</li>
<li>2 vulnerabilities could lead to Elevation of Privilege</li>
<li>2 vulnerabilities could lead to Denial of Service</li>
</ul>
<p> Affected Products:</p>
<ul>
<li>All supported Microsoft Operating Systems</li>
<li>Microsoft Visual Studio 2008, 2010</li>
<li>Microsoft Expression Design 1, 2, 3, 4</li>
</ul>
<p> </p>
<p>I will be talking about the March Patch Tuesday as well as any other non-Microsoft patches that have been recently released next Wednesday, March 14th at 11:00am CST in part of our monthly Patch Tuesday webinar.  <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=667118480" target="_blank">Click here</a> to register for the webinar.</p>
<p> - Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=Gs9EMHhJCs0:rPiI7AOHFqM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Gs9EMHhJCs0:rPiI7AOHFqM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=Gs9EMHhJCs0:rPiI7AOHFqM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Gs9EMHhJCs0:rPiI7AOHFqM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=Gs9EMHhJCs0:rPiI7AOHFqM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=Gs9EMHhJCs0:rPiI7AOHFqM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/Gs9EMHhJCs0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/03/08/march-2012-patch-tuesday-advanced-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/03/08/march-2012-patch-tuesday-advanced-notification/</feedburner:origLink></item>
		<item>
		<title>February 2012 Patch Tuesday Overview</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/DDv2EUSvJdg/</link>
		<comments>http://blog.shavlik.com/2012/02/14/february-2012-patch-tuesday-overview/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 22:39:13 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch Patrol]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2614</guid>
		<description><![CDATA[<p>Microsoft has released nine new security bulletins for the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb" target="_blank">February 2012 edition of Patch Tuesday</a>.  This Patch Tuesday is typically marked as a &#8216;heavy&#8217; release month and includes nine new security bulletins addressing 21 vulnerabilities.</p>
<p>There are two bulletins that administrators should look to patch immediately.  Both of these bulletins address vulnerabilties that have the potential for drive-by attack scenarios from websites.</p>
<p>First up is Microsoft security bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-010" target="_blank">MS12-010</a>.  This bulletin affects all supported Microsoft Internet Explorer browsers and addresses four vulnerabilities in the browser.  As is the case with most, if not all Internet Browsers, it is &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released nine new security bulletins for the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb" target="_blank">February 2012 edition of Patch Tuesday</a>.  This Patch Tuesday is typically marked as a &#8216;heavy&#8217; release month and includes nine new security bulletins addressing 21 vulnerabilities.</p>
<p>There are two bulletins that administrators should look to patch immediately.  Both of these bulletins address vulnerabilties that have the potential for drive-by attack scenarios from websites.</p>
<p>First up is Microsoft security bulletin <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-010" target="_blank">MS12-010</a>.  This bulletin affects all supported Microsoft Internet Explorer browsers and addresses four vulnerabilities in the browser.  As is the case with most, if not all Internet Browsers, it is extremely important to patch as soon as possible as browsers are one of the most attacked pieces of software.  The vulnerabilities addressed in this patch could allow an attacker to exploit the browser through malicious websites.</p>
<p>Similarly, <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-013" target="_blank">MS12-013</a> also has a possible drive-by attack vector.  This bulletin addresses one vulnerability in the C Run-Time Library.  If an attacker can entice a user to open a malicious media file, the attacker can gain full access to a system.  In this new media and social media age, media file attack vectors are just as important as browser attack vectors when it comes to patching security vulnerabilities.</p>
<p>Our old friend, the DLL preload vulnerability, is making a return after a one-month hiatus.  Two bulletins this month fix the DLL preload vulnerability in Microsoft applications.</p>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-012" target="_blank">MS12-012</a> &#8211; Color Control Panel<br />
<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-014" target="_blank">MS12-014</a> &#8211; Indeo Codec</p>
<p>Since releasing the Security Advisory for this issue in November 2010, Microsoft has patched different programs affected by this vulnerability 22 times.  It is safe to say we will continue to see the DLL preload vulnerability being addressed by Microsoft in the coming months.</p>
<p>On the non-Microsoft front, there is already one vendor joining Patch Tuesday.  Adobe released two new security bulletins today affecting two Adobe products.  Security bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb12-02.html" target="_blank">APSB12-02</a> affects Adobe Shockwave and fixes nine vulnerabilities.  Adobe Security bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb12-04.html" target="_blank">APSB12-04</a> affects Adobe RoboHelp for Word and fixes one vulnerability.</p>
<p>This has been quite a busy month with multiple non-Microsoft vendors releasing security updates for their software.  After a very quiet December and January, it appears the non-Microsoft vendors are getting back to a normal cadence for releasing security updates for their software application.  The following vendors have released security updates since January 2012 Patch Tuesday:</p>
<p>Opera<br />
Google Chrome (twice)<br />
Yahoo Messenger<br />
Mozilla Firefox (twice)<br />
Mozilla Thunderbird (twice)<br />
Mozilla SeaMonkey (twice)<br />
Real Player<br />
Skype</p>
<p>For those administrators who wait for a monthly maintenance window for their patching needs, this month is going to be quite a large month combining all of the Microsoft and non-Microsoft security bulletins released since the last Patch Tuesday.</p>
<p>I will be talking about these patches along with the latest non-Microsoft patches that have been recently released tomorrow, February 15th at 11:00am CT as part of our monthly Patch Tuesday webinar.  Click <a href="https://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=664550674" target="_blank">here</a> to register for the webinar.</p>
<p>- Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=DDv2EUSvJdg:YBduPgw0TgM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=DDv2EUSvJdg:YBduPgw0TgM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=DDv2EUSvJdg:YBduPgw0TgM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=DDv2EUSvJdg:YBduPgw0TgM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=DDv2EUSvJdg:YBduPgw0TgM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=DDv2EUSvJdg:YBduPgw0TgM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/DDv2EUSvJdg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/02/14/february-2012-patch-tuesday-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/02/14/february-2012-patch-tuesday-overview/</feedburner:origLink></item>
		<item>
		<title>February 2012 Patch Tuesday Advanced Notification</title>
		<link>http://feedproxy.google.com/~r/Shavlik/~3/j-Pl3gdDbWg/</link>
		<comments>http://blog.shavlik.com/2012/02/09/february-2012-patch-tuesday-advanced-notification/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 23:55:42 +0000</pubDate>
		<dc:creator>Jason Miller</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.shavlik.com/?p=2607</guid>
		<description><![CDATA[<p>Microsoft has announced their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb" target="_blank">February 2012 Advanced Notification</a> for the upcoming Patch Tuesday.  Microsoft is planning to release nine security bulletins fixing 21 vulnerabilities.</p>
<p>Security Bulletin Breakdown:</p>

4 bulletins are rated as Critical
5 bulletins are rated as Important
7 vulnerabilities could lead to Remote Code Execution
2 vulnerabilities could lead to Elevation of Privilege

<p>Affected Products:</p>

All supported Microsoft Operating systems
All supported Internet Explorer browsers
Visio Viewer 2010
SharePoint Server 2010
SharePoint Foundation 2010
Silverlight 4

<p>There has been no word of other vendors planning to release new security bulletins, but we are constantly monitoring to find any other vendors planning on joining Microsoft&#8217;s Patch Tuesday.</p>
<p>I will be talking &#8230;]]></description>
			<content:encoded><![CDATA[<p>Microsoft has announced their <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-feb" target="_blank">February 2012 Advanced Notification</a> for the upcoming Patch Tuesday.  Microsoft is planning to release nine security bulletins fixing 21 vulnerabilities.</p>
<p>Security Bulletin Breakdown:</p>
<ul>
<li>4 bulletins are rated as Critical</li>
<li>5 bulletins are rated as Important</li>
<li>7 vulnerabilities could lead to Remote Code Execution</li>
<li>2 vulnerabilities could lead to Elevation of Privilege</li>
</ul>
<p>Affected Products:</p>
<ul>
<li>All supported Microsoft Operating systems</li>
<li>All supported Internet Explorer browsers</li>
<li>Visio Viewer 2010</li>
<li>SharePoint Server 2010</li>
<li>SharePoint Foundation 2010</li>
<li>Silverlight 4</li>
</ul>
<p>There has been no word of other vendors planning to release new security bulletins, but we are constantly monitoring to find any other vendors planning on joining Microsoft&#8217;s Patch Tuesday.</p>
<p>I will be talking about these patches along with the latest non-Microsoft patches that have been recently released next Wednesday, February 15th at 11:00am CST in part of our monthly Patch Tuesday webinar.  Click <a title="February Patch Tuesday Webinar" href="ttps://vmwareevents.webex.com/vmwareevents/onstage/g.php?t=a&amp;d=664550674" target="_blank">here</a> to register for the webinar.</p>
<p>- Jason Miller</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Shavlik?a=j-Pl3gdDbWg:D-77CENF7aA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=j-Pl3gdDbWg:D-77CENF7aA:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=j-Pl3gdDbWg:D-77CENF7aA:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=j-Pl3gdDbWg:D-77CENF7aA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Shavlik?i=j-Pl3gdDbWg:D-77CENF7aA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Shavlik?a=j-Pl3gdDbWg:D-77CENF7aA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Shavlik?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Shavlik/~4/j-Pl3gdDbWg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.shavlik.com/2012/02/09/february-2012-patch-tuesday-advanced-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.shavlik.com/2012/02/09/february-2012-patch-tuesday-advanced-notification/</feedburner:origLink></item>
	</channel>
</rss>

