<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rssdatehelper="urn:rssdatehelper" version="2.0"><channel><title>Latest Security Advisories</title><link>http://technet.microsoft.com/security/advisory</link><dc:date>Tue, 14 Feb 2012 08:00:00 GMT</dc:date><generator>umbraco</generator><description /><language>en-US</language><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/microsoft/IzLi" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="microsoft/izli" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><title>Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution - Version: 14.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2269637</link><dc:date>2012-02-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2269637</guid><content:encoded><![CDATA[
            Revision Note: V14.0 (February 14, 2012): Added the following Microsoft Security Bulletins to the Updates relating to Insecure Library Loading section: MS12-012, "Vulnerability in Color Control Panel Could Allow Remote Code Execution;" and MS12-014, "Vulnerability in Indeo Codec Could Allow Remote Code Execution."<br />
          Summary: Microsoft is aware that research has been published detailing a remote attack vector for a class of vulnerabilities that affects how applications load external libraries.]]></content:encoded></item><item><title>Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Version: 3.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2641690</link><dc:date>2012-01-19T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2641690</guid><content:encoded><![CDATA[
            Revision Note: V3.0 (January 19, 2012): Revised to announce the release of an update for Windows Mobile 6.x, Windows Phone 7, and Windows Phone 7.5 devices.<br />
          Summary: Microsoft is aware that DigiCert Sdn. Bhd, a Malaysian subordinate certification authority (CA) under Entrust and GTE CyberTrust, has issued 22 certificates with weak 512 bit keys. These weak encryption keys, when broken, could allow an attacker to use the certificates fraudulently to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer. While this is not a vulnerability in a Microsoft product, this issue affects all supported releases of Microsoft Windows.]]></content:encoded></item><item><title>Microsoft Security Advisory (2588513): Vulnerability in SSL/TLS Could Allow Information Disclosure - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2588513</link><dc:date>2012-01-10T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2588513</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (January 10, 2012): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS12-006 to address this issue. For more information about this issue, including download links for an available security update, please review MS12-006. The vulnerability addressed is the SSL/TLS Information Disclosure Vulnerability - CVE-2011-3389.]]></content:encoded></item><item><title>Microsoft Security Advisory (2659883): Vulnerability in ASP.NET Could Allow Denial of Service - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2659883</link><dc:date>2011-12-29T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2659883</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (December 29, 2011): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS11-100 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-100. The vulnerability addressed is the Collisions in HashTable May Cause DoS Vulnerability - CVE-2011-3414.]]></content:encoded></item><item><title>Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2639658</link><dc:date>2011-12-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2639658</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (December 13, 2011): Advisory updated to reflect publication of security bulletins.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS11-087 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-087. The vulnerability addressed is the TrueType Font Parsing Vulnerability - CVE-2011-3402.]]></content:encoded></item><item><title>Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2607712</link><dc:date>2011-09-19T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2607712</guid><content:encoded><![CDATA[
            Revision Note: V5.0 (September 19, 2011): Revised to announce the rerelease of the KB2616676 update. See the Update FAQ in this advisory for more information.<br />
          Summary: Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root Certification Authorities Store. A fraudulent certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer. While this is not a vulnerability in a Microsoft product, this issue affects all supported releases of Microsoft Windows.]]></content:encoded></item><item><title>Microsoft Security Advisory (2562937): Update Rollup for ActiveX Kill Bits - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2562937</link><dc:date>2011-08-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2562937</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (August 9, 2011): Advisory published.<br />
          Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.]]></content:encoded></item><item><title>Microsoft Security Advisory (2524375): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2524375</link><dc:date>2011-07-06T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2524375</guid><content:encoded><![CDATA[
            Revision Note: V5.0 (July 6, 2011): Announced the release of an update for Zune HD devices and moved Zune devices to the Non-Affected Devices table.<br />
          Summary: Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store, on all supported releases of Microsoft Windows, Windows Mobile 6.x, Windows Phone 7, Microsoft Kin, and Zune HD devices. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.]]></content:encoded></item><item><title>Microsoft Security Advisory (2501584): Release of Microsoft Office File Validation for Microsoft Office - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2501584</link><dc:date>2011-06-30T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2501584</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (June 30, 2011): Announced that the Office File Validation Add-in described in Microsoft Knowledge Base Article 2501584 is available through the Microsoft Update service.<br />
          Summary: Microsoft is announcing the availability of the Office File Validation feature for supported editions of Microsoft Office 2003 and Microsoft Office 2007. The feature, previously only available for supported editions of Microsoft Office 2010, is designed to make it easier for customers to protect themselves from Office files that may contain malformed data, such as unsolicited Office files received from unknown or known sources, by scanning and validating files before they are opened.]]></content:encoded></item><item><title>Microsoft Security Advisory (2506014): Update for the Windows Operating System Loader - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2506014</link><dc:date>2011-04-12T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2506014</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (April 12, 2011): Advisory published.<br />
          Summary: Microsoft is announcing the availability of an update to winload.exe to address an issue in driver signing enforcement. While this is not an issue that would require a security update, this update addresses a method by which unsigned drivers could be loaded by winload.exe. This technique is often utilized by malware to stay resident on a system after the initial infection. ]]></content:encoded></item><item><title>Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2501696</link><dc:date>2011-04-12T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2501696</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (April 12, 2011): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into public reports of this vulnerability. We have issued MS11-026 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-026. The vulnerability addressed is the MHTML Mime-Formatted Request Vulnerability - CVE-2011-0096.]]></content:encoded></item><item><title>Microsoft Security Advisory (973811): Extended Protection for Authentication - Version: 1.12</title><link>http://technet.microsoft.com/en-us/security/advisory/973811</link><dc:date>2011-04-12T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/973811</guid><content:encoded><![CDATA[
            Revision Note: V1.12 (April 12, 2011): Updated the FAQ with information about a non-security update enabling Microsoft Outlook to opt in to Extended Protection for Authentication.<br />
          Summary: Microsoft is announcing the availability of a new feature, Extended Protection for Authentication, on the Windows platform. This feature enhances the protection and handling of credentials when authenticating network connections using Integrated Windows Authentication (IWA).]]></content:encoded></item><item><title>Microsoft Security Advisory (2491888): Vulnerability in Microsoft Malware Protection Engine Could Allow Elevation of Privilege - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/advisory/2491888</link><dc:date>2011-03-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2491888</guid><content:encoded><![CDATA[
            Revision Note: V1.1 (March 8, 2011): Revised advisory FAQ to announce updated version of the MSRT and added Forefront Security for Exchange Server to the list of non-affected software.<br />
          Summary: Microsoft is releasing this security advisory to help ensure customers are aware that an update to the Microsoft Malware Protection Engine also addresses a security vulnerability reported to Microsoft. The update addresses a privately reported vulnerability that could allow elevation of privilege if the Microsoft Malware Protection Engine scans a system after an attacker with valid logon credentials has created a specially crafted registry key. An attacker who successfully exploited the vulnerability could gain the same user rights as the LocalSystem account. The vulnerability could not be exploited by anonymous users.]]></content:encoded></item><item><title>Microsoft Security Advisory (967940): Update for Windows Autorun - Version: 2.1</title><link>http://technet.microsoft.com/en-us/security/advisory/967940</link><dc:date>2011-02-22T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/967940</guid><content:encoded><![CDATA[
            Revision Note: V2.1 (February 22, 2011): Summary revised to notify users of a change in the deployment logic for updates described in this advisory. This change is intended to minimize the user interaction required to install the updates on systems configured for automatic updating.<br />
          Summary: Microsoft is announcing the availability of updates to the Autorun feature that help to restrict AutoPlay functionality to only CD and DVD media on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. Restricting AutoPlay functionality to only CD and DVD media can help protect customers from attack vectors that involve the execution of arbitrary code by Autorun when inserting a USB flash drive, network shares, or other non-CD and non-DVD media containing a file system with an Autorun.inf file.]]></content:encoded></item><item><title>Microsoft Security Advisory (2490606): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2490606</link><dc:date>2011-02-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2490606</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (February 8, 2011): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into public reports of this vulnerability. We have issued MS11-006 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-006. The vulnerability addressed is the Windows Shell Graphics Processing Overrun Vulnerability - CVE-2010-3970.]]></content:encoded></item><item><title>Microsoft Security Advisory (2488013): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2488013</link><dc:date>2011-02-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2488013</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (February 8, 2011): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into public reports of this vulnerability. We have issued MS11-003 to address this issue. For more information about this issue, including download links for an available security update, please review MS11-003. The vulnerability addressed is the CSS Memory Corruption Vulnerability - CVE-2010-3971.]]></content:encoded></item><item><title>Microsoft Security Advisory (2458511): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2458511</link><dc:date>2010-12-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2458511</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (December 14, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-090 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-090. The vulnerability addressed is the Uninitialized Memory Corruption Vulnerability - CVE-2010-3962.]]></content:encoded></item><item><title>Microsoft Security Advisory (2416728): Vulnerability in ASP.NET Could Allow Information Disclosure - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2416728</link><dc:date>2010-09-28T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2416728</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (September 28, 2010): Advisory updated to reflect publication of security bulletin<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-070 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-070. The vulnerability addressed is the ASP.NET Padding Oracle Vulnerability - CVE-2010-3332.]]></content:encoded></item><item><title>Microsoft Security Advisory (2401593): Vulnerability in Outlook Web Access Could Allow Elevation of Privilege - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2401593</link><dc:date>2010-09-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2401593</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (September 14, 2010): Advisory published.<br />
          Summary: Microsoft has completed the investigation of a publicly disclosed vulnerability in Outlook Web Access (OWA) that may affect Microsoft Exchange customers. An attacker who successfully exploited this vulnerability could hijack an authenticated OWA session. The attacker could then perform actions on behalf of the authenticated user without the user's knowledge, within the security context of the active OWA session.]]></content:encoded></item><item><title>Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation Bypass - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2264072</link><dc:date>2010-08-10T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2264072</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (August 10, 2010): Advisory published.<br />
          Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that can help to protect against this issue. This advisory also offers a non-security update for one of the potential attack scenarios through Windows Telephony Application Programming Interfaces (TAPI). ]]></content:encoded></item><item><title>Microsoft Security Advisory (977377): Vulnerability in TLS/SSL Could Allow Spoofing - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/977377</link><dc:date>2010-08-10T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/977377</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (August 10, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-049 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-049. The vulnerability addressed is the TLS/SSL Renegotiation Vulnerability - CVE-2009-3555. For additional information on this advisory, see Microsoft Knowledge Base Article 977377.]]></content:encoded></item><item><title>Microsoft Security Advisory (2286198): Vulnerability in Windows Shell Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2286198</link><dc:date>2010-08-02T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2286198</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (August 2, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability.]]></content:encoded></item><item><title>Microsoft Security Advisory (2219475): Vulnerability in Windows Help and Support Center Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2219475</link><dc:date>2010-07-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2219475</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (July 13, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-042 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-042. The vulnerability addressed is the Help Center URL Validation Vulnerability - CVE-2010-1885.]]></content:encoded></item><item><title>Microsoft Security Advisory (2028859): Vulnerability in Canonical Display Driver Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2028859</link><dc:date>2010-07-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2028859</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (July 13, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-043 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-043. The vulnerability addressed is the Canonical Display Driver Integer Overflow Vulnerability - CVE-2009-3678.]]></content:encoded></item><item><title>Microsoft Security Advisory (980088): Vulnerability in Internet Explorer Could Allow Information Disclosure</title><link>http://technet.microsoft.com/en-us/security/advisory/980088</link><dc:date>2010-06-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/980088</guid><content:encoded><![CDATA[
            Revision Note: V1.2 (June 9, 2010): Added information about MS10-035 and clarified a FAQ entry about the caching vector.<br />
          Summary: Microsoft is investigating new public reports of a vulnerability in Internet Explorer. This advisory contains information about which versions of Internet Explorer are vulnerable as well as workarounds and mitigations for this issue.]]></content:encoded></item><item><title>Microsoft Security Advisory (983438): Vulnerability in Microsoft SharePoint Could Allow Elevation of Privilege - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/983438</link><dc:date>2010-06-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/983438</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (June 8, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-039 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-039. The vulnerability addressed is the Help.aspx XSS Vulnerability - CVE-2010-0817.]]></content:encoded></item><item><title>Microsoft Security Advisory (981169): Vulnerability in VBScript Could Allow Remote Code Execution</title><link>http://technet.microsoft.com/en-us/security/advisory/981169</link><dc:date>2010-04-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/981169</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (April 13, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-022 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-022. The vulnerability addressed is the VBScript Help Keypress Vulnerability - CVE-2010-0483.]]></content:encoded></item><item><title>Microsoft Security Advisory (977544): Vulnerability in SMB Could Allow Denial of Service - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/977544</link><dc:date>2010-04-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/977544</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (April 13, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-020 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-020. The vulnerability addressed is the SMB Client Incomplete Response Vulnerability - CVE-2009-3676.]]></content:encoded></item><item><title>Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/981374</link><dc:date>2010-03-30T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/981374</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (March 30, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-018 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-018. The vulnerability addressed is the Uninitialized Memory Corruption Vulnerability - CVE-2010-0806.]]></content:encoded></item><item><title>Microsoft Security Advisory (979682): Vulnerability in Windows Kernel Could Allow Elevation of Privilege - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/979682</link><dc:date>2010-02-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/979682</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (February 9, 2010): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-015 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-015. The vulnerability addressed is the Windows Kernel Exception Handler Vulnerability - CVE-2010-0232.]]></content:encoded></item><item><title>Microsoft Security Advisory (979352): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/979352</link><dc:date>2010-01-21T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/979352</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (January 21, 2010): Advisory updated to reflect publication of security bulletin<br />
          Summary: Microsoft has completed the investigation the public reports of this vulnerability. We have issued MS10-002 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-002. The vulnerability addressed is the HTML Object Memory Corruption Vulnerability - CVE-2010-0249.]]></content:encoded></item><item><title>Microsoft Security Advisory (979267): Vulnerabilities in Adobe Flash Player 6 Provided in Windows XP Could Allow Remote Code Execution </title><link>http://technet.microsoft.com/en-us/security/advisory/979267</link><dc:date>2010-01-12T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/979267</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (January 12, 2010): Advisory published.<br />
          Summary: Security Advisory]]></content:encoded></item><item><title>Microsoft Security Advisory (974926): Credential Relaying Attacks on Integrated Windows Authentication - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/974926</link><dc:date>2009-12-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/974926</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (December 8, 2009): Advisory published.<br />
          Summary: This advisory addresses the potential for attacks that affect the handling of credentials using Integrated Windows Authentication (IWA), and the mechanisms Microsoft has made available for customers to help protect against these attacks.]]></content:encoded></item><item><title>Microsoft Security Advisory (954157): Security Enhancements for the Indeo Codec - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/954157</link><dc:date>2009-12-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/954157</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (December 8, 2009): Advisory published.<br />
          Summary: Microsoft is announcing the availability of an update that provides security mitigations to the Indeo codec on supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003. ]]></content:encoded></item><item><title>Microsoft Security Advisory (977981): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/977981</link><dc:date>2009-12-08T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/977981</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (December 8, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed investigating public reports of this vulnerability. We have issued Microsoft Security Bulletin MS09-072 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-072. The vulnerability addressed is the HTML Object Memory Corruption Vulnerability - CVE-2009-3672.]]></content:encoded></item><item><title>Microsoft Security Advisory (975497): Vulnerabilities in SMB Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/975497</link><dc:date>2009-10-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/975497</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (October 13, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Security Advisory]]></content:encoded></item><item><title>Microsoft Security Advisory (975191): Vulnerabilities in the FTP Service in Internet Information Services - Version: 3.0</title><link>http://technet.microsoft.com/en-us/security/advisory/975191</link><dc:date>2009-10-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/975191</guid><content:encoded><![CDATA[
            Revision Note: V3.0 (October 13, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this issue. We have released MS09-053 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-053. The vulnerabilities addressed are the IIS FTP Service DoS Vulnerability (CVE-2009-2521) and the IIS FTP Service RCE and DoS Vulnerability (CVE-2009-3023).]]></content:encoded></item><item><title>Microsoft Security Advisory (973882): Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution - Version: 4.0</title><link>http://technet.microsoft.com/en-us/security/advisory/973882</link><dc:date>2009-10-13T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/973882</guid><content:encoded><![CDATA[
            Revision Note: V4.0 (October 13, 2009): Advisory revised to add an entry in the Updates related to ATL section to communicate the release of Microsoft Security Bulletin MS09-060, "Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution."<br />
          Summary: Security Advisory]]></content:encoded></item><item><title>Microsoft Security Advisory (973472): Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/973472</link><dc:date>2009-08-11T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/973472</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (August 11, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation of a privately reported vulnerability in Microsoft Office Web Components. We have issued MS09-043 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-043. The vulnerability addressed is the Office Web Components HTML Script Vulnerability - CVE-2009-1136.]]></content:encoded></item><item><title>Microsoft Security Advisory (972890): Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/972890</link><dc:date>2009-07-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/972890</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (July 14, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-032 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-032. The vulnerability addressed is the Microsoft Video ActiveX Control Vulnerability - CVE-2008-0015.]]></content:encoded></item><item><title>Microsoft Security Advisory (971778): Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/971778</link><dc:date>2009-07-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/971778</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (July 14, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-028 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-028. The vulnerability addressed is the DirectX NULL Byte Overwrite Vulnerability - CVE-2009-1537.]]></content:encoded></item><item><title>Microsoft Security Advisory (969898): Update Rollup for ActiveX Kill Bits - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/advisory/969898</link><dc:date>2009-06-17T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/969898</guid><content:encoded><![CDATA[
            Revision Note: V1.1 (June 17, 2009): Added an entry to Frequently Asked Questions to communicate that for the purpose of automatic updating, this update does not replace the Cumulative Security Update of ActiveX Kill Bits (950760) that is described in Microsoft Security Bulletin MS08-032.<br />
          Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.]]></content:encoded></item><item><title>Microsoft Security Advisory (960715): Update Rollup for ActiveX Kill Bits - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/advisory/960715</link><dc:date>2009-06-17T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/960715</guid><content:encoded><![CDATA[
            Revision Note: V1.2 (June 17, 2009): Added an entry to Frequently Asked Questions to communicate that for the purpose of automatic updating, this update does not replace the Cumulative Security Update of ActiveX Kill Bits (950760) that is described in Microsoft Security Bulletin MS08-032.<br />
          Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.]]></content:encoded></item><item><title>Microsoft Security Advisory (956391): Update Rollup for ActiveX Kill Bits - Version: 1.3</title><link>http://technet.microsoft.com/en-us/security/advisory/956391</link><dc:date>2009-06-17T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/956391</guid><content:encoded><![CDATA[
            Revision Note: V1.3 (June 17, 2009): Added an entry to Frequently Asked Questions to communicate that for the purpose of automatic updating, this update does not replace the Cumulative Security Update of ActiveX Kill Bits (950760) that is described in Microsoft Security Bulletin MS08-032.<br />
          Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.]]></content:encoded></item><item><title>Microsoft Security Advisory (971888): Update for DNS Devolution - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/971888</link><dc:date>2009-06-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/971888</guid><content:encoded><![CDATA[
            Revision Note: Advisory published.<br />
          Summary: Microsoft is announcing the availability of an update to DNS devolution that can help customers in keeping their systems protected. Customers whose domain name has three or more labels , such as "contoso.co.us", or who do not have a DNS suffix list configured, or for whom the following mitigating factors do not apply may inadvertently be allowing client systems to treat systems outside of the organizational boundary as though they were internal to the organization's boundary.]]></content:encoded></item><item><title>Microsoft Security Advisory (971492): Vulnerability in Internet Information Services Could Allow Elevation of Privilege - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/971492</link><dc:date>2009-06-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/971492</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (June 9, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-020 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-020. The vulnerability addressed is the IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability - CVE-2009-1535.]]></content:encoded></item><item><title>Microsoft Security Advisory (945713): Vulnerability in Web Proxy Auto-Discovery (WPAD) Could Allow Information Disclosure - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/945713</link><dc:date>2009-06-09T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/945713</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (June 9, 2009): Advisory updated to reflect publication of security bulletin MS09-008 and Microsoft Security Advisory 971888.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-008 to address the WPAD issue and have released configuration guidance and updates for DNS devolution in Microsoft Security Advisory 971888. For more information about this issue, including download links for an available security update, please review MS09-008 and Microsoft Security Advisory 971888. The vulnerabilities addressed are the WPAD server registration vulnerabilities in WINS and DNS - CVE-2009-0094 and CVE-2009-0093.]]></content:encoded></item><item><title>Microsoft Security Advisory (969136): Vulnerability in Microsoft Office PowerPoint Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/969136</link><dc:date>2009-05-12T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/969136</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (May 12, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-017 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-017. The vulnerability addressed is the Memory Corruption Vulnerability - CVE-2009-0556.]]></content:encoded></item><item><title>Microsoft Security Advisory (968272): Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution - Version: 3.0</title><link>http://technet.microsoft.com/en-us/security/advisory/968272</link><dc:date>2009-04-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/968272</guid><content:encoded><![CDATA[
            Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability.]]></content:encoded></item><item><title>Microsoft Security Advisory (960906): Vulnerability in WordPad Text Converter Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/960906</link><dc:date>2009-04-14T00:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/960906</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft is investigating new reports of a vulnerability in the WordPad Text Converter for Word 97 files on Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2. Windows XP Service Pack 3, Windows Vista, and Windows Server 2008 are not affected as these operating systems do not contain the vulnerable code.]]></content:encoded></item></channel></rss>

