Showing posts with label Updates. Show all posts
Showing posts with label Updates. Show all posts

Tuesday, July 14, 2009

Windows Security Updates for July 2009

Patch Tuesday is here. From the Microsoft Security Bulletin, there are six security updates. There are two for the Windows operating system, one for the Microsoft Office system, one for the Windows Internet Explorer browser, one for Microsoft ISA Server, and one for Microsoft Virtual PC.


Most important I believe is the fix for the Internet Explorer Video Active X exploit. Microsoft Security Bulletin MS09-032 patches this one by setting killbits in IE to stop the exploit before it can do anything.

Here are the specific updates:

MS09-032 - addresses a vulnerability in Microsoft Internet Explorer (KB 973346) - This one is mentioned above with the Video Active X issue.

MS09-028 - addresses a vulnerability in Microsoft Windows (KB 971633) - This addresses vulnerbilities in DirectShow that could allow specially crafted Quicktime files to gain the same rights as the current user. Not good if you are logged in as an admin user, like most people are.

MS09-029 - addresses a vulnerability in Microsoft Windows (KB 961371) - Embedded OpenType Font Engine which could allow your computer to be taken over.

MS09-030 - addresses a vulnerability in Microsoft Office (KB 969516)
MS09-031 - addresses a vulnerability in Microsoft ISA Server (KB 970953)
MS09-033 - addresses a vulnerability in Microsoft Virtual PC (KB 969856)

You can see all the gory and boring details on the July 2009 Security Bulletin. Of course, the easy way to get patched against these threats is to go to Windows Update.

Monday, July 06, 2009

Internet Explorer Video Active X Exploit

Been awhile since Windows had a zero day exploit that would allow the bad guys to take over your computer just by visiting a web site. Got one now. All you need to do is to visit a web site that has been set up to use this vulnerability with Internet Explorer and boom, they got you. Apparently, a flaw in Microsoft directShow( MSVIDCTL.DLL ) lets them do it. It does need to be IE 6 or 7 with Windows XP or Windows 2003. Yay! Vista and presumably Windows 7 aren't affected.


One way to avoid this is to not use IE. Firefox, Opera, Safari and other browsers aren't affected. The bad guys could try to open IE or trick you into opening it, so it's best to the video Active X advisory page and use the fix it button to turn off the part of IE that allows the exploit.

F-secure detects it as Exploit:W32/Agent.LBV. They have a write up and plug for their free beta of ISTP or ExploitShield that also protect you. Also has video link showing them trying to get infected with it and failing.

McAfee detects it as Exploit-MSDirectShow.b and has their write up here that says this has been around since last December and only has become widely know recently.

The Registry key that the Microsoft advisory page modifies is this. Best to not mess around in the registry. Might be more, but I'm not going to list them all.

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]
"Compatibility Flags"=dword:00000400

More tech details at Microsoft Security Advisory 972890.

Wednesday, July 01, 2009

iPhoto update 8.0.4 available

I don't use iPhoto too much, but it has it uses. There's a nice 103 MB update for it that fixes the issue from the iPhoto 8.03 update that caused iPhoto to crash. You could work around it by holding the Option key and then choosing your library, but what fun was that. I didn't have that problem, but this should help those that did.

Tuesday, June 30, 2009

Firefox 3.5 final available

Probably not a secret to most, but the latest version of Firefox is out. A big update, since the version went from 3.0 to 3.5. Most of the changes are underneath, so they aren't readily apparent. I've run it for a few hours and haven't had any issues. Tried doing just about everything you can with a browser and it all went well.

Speed is one thing that Firefox 3.5 is touted as having over the older version. It seems like everyone is touting their new, even faster browser. I do notice that Firefox doesn't compare itself to other browsers like Safari and IE but the earlier 3.0 and 2 versions. Safari is still faster for me going loading new pages, but clicking back to ones in your history, it's still Firefox.

One thing you'll see that is new is the private browsing feature. Safari has had it for quite awhile. Google Chrome launched with it and spread awareness, even getting the nickname "porn mode". Nothing groundbreaking, but handy to have. You can always just clear your private data manually.

Firefox 3.5 does have one thing that no other browser has. It supports some video types natively, without the need for a plug-in or 3rd party add-on. However, it's only the open source Ogg file types. Most things people watch online aren't using this. you can see a demo of a video that also showcases the new features. If web developers make more use of Ogg files, then this could be good. My guess is that it won't mean much until more file types are supported. Wikipedia might be an exception.

Missing is a top sites feature, like Safari and Opera have. You can get it with add-ons for Firefox, but this is becoming a standard feature of these days. I didn't think it was a big deal when Opera had it and then when Safari 4 added it. Once i started using it, it was like tabbed browsing. How did I get by without it before?

Other features include geolocation, the ability to drag tabs to be their own window, and adding a window as a new tab in a different browser window.

Of course there is security. there's a whole list of features listed at the Mozilla Firefox security page. Private browsing and Forget This Site are the new ones listed. Many of the others, like antimalware and antiphising are listed as improved. I haven't tested those two filters, but they are likely to be weak as they have been in all browsers.

You can download Firefox 3.5 at www.getfirefox.com now. The internal updater for Firefox 3.0 doesn't offer it, as of yet.

Tuesday, June 23, 2009

Airport and Time Capsule Update 7.4.2

Well, here we go. First update and it's an Apple router one.


Apple released firmware update 7.4.2 for their Airport Base Station and Time Capsule today. Nothing particular for security mentioned, but there are several fixes which are listed as:

  • Fixes some problems with extending and maintaining connectivity with extended networks
  • Fixes an issue with clients that enable 802.11 "Power Save"
  • Fixes connectivity issues with some third-party devices
  • Fixes an issue when the base station is configured for PPPoE
  • Fixes some Back To My Mac issues with connectivity and support for third-party routers
You don't have to use an Airport router for a Mac to get online and a Windows computer can use an Airport router. I got a Time Capsule for a good cheap price recently and i like it. It's an 802.11n router, has an internal hard drive for sharing files and has a USB port that you can connect more hard drives and printers to so all my Macs and PC's can easily share files and print.

The wireless range is pretty good. I can turn down the transmit power to 25% and still connect through two outside walls and on the other side of the yard from where the router is.

Thursday, May 29, 2008

Service Pack 3 Available On CD

For those who are not on a good Internet connection or one where you are limited in bandwidth, you can get Service Pack 3 on CD now. You can also download a disk image or stand alone installer, which you can use to take home or save for a re-install. Having SP 3 available will help if you do need to re-install, so you won' have to go online and expose yourself to the evils of the Internet. You can check it out on Microsoft TechNet.

Wednesday, May 28, 2008

Mac OS 10.5.3 for leopard, Security Update for Tiger

A few hours ago, Apple made the 10.5.3 update available on Software Update. There's lots of changes and fixes in this one. If you have 10.4 Tiger, you do get a nice set of security updates so you don't feel left out.  


The 10.5.3 update details can be found at Apple. The kbase article mentions inprovements or fixes for: Address Book, Automator, Airport, iCal, iChat, Mail, Parental Controls, Spaces, Time Machine and voice Over. I also noticed changes to Back to My Mac and Finder. 

For BTMM, there is now a red, green and yellow indicator for the service. I think it is just checking connectivity to the BTMM servers and successful login. I'm behind a crapy Linksys router that doesn't like to keep UPnP on, but I get a green light. So I can see the other mac, but connections still fail, as should since Universal Plug n Play isn't on. 

Finder now has a more accurate display of uploads to network drives, like iDisk. It used to sit on the closing file and would stay there until the file was finished uploading. That could be another 20 minutes or longer. Now it displays a rough estimate of the time remaining in the upload. 

If you have Tiger or haven't updated to 10.5.3, then you still want to use check updates for Security Update 2008-003. Updates include AFP Server, Apache, AppKit, CFNetwork, CoreFoundation, CoreGraphics, CoreTypes, Common Unix Printing System (CUPS), Flash Player Plug-in, iCal, LoginWindow, Mail, Wiki Server and  more. 

I installed 10.5.3 and had no problems. It was faster than the 10.5.2 update. So far, I'v only seen the usual people who seem to have trouble with every update complain. I see no reason to hold off of this set of updates.

Saturday, May 24, 2008

Spyware Doctor False Positive Flags Part of XP Service Pack 3

Apparantly, Spyware Doctor may be detecting Rundll32.exe as having Trojan-Spy.Pophot.WX. The latest update, 5.09900, should fix this. In any event, you should run Spyware Doctor's Smart Update t be safe.

Friday, May 23, 2008

Spybot Search & Destroy May 21st

2008-05-21

Keylogger
+ KGBKeylogger ++ KGBKeylogger.REFOG ++ SmartPCKeylogger

Malware
++ AntiSpyCheck ++ BugDoctor + ConOpt.BHO (3) ++ DeusCleaner ++ DoctorCleaner ++ EliteProtector + ErrorDoctor + FakeAlert.cc ++ LiveAntispy ++ MalwareDestructor + MyNetProtector ++ PCSleek.FreeErrorCleaner + Smitfraud-C. ++ Spyburner ++ SpyKill + Trojan-Guarder + Vario.AntiVirus + Win32.BHO.je + Win32.Renos + WinSpyKiller + Worldsecurityonline.FakeAlert

PUPS
++ SpyPry

Security
+ Microsoft.Windows.AppFirewallBypass

Trojan
+ Smitfraud-C.MSVPS + Virtumonde.ddc ++ Win32.Agent.abd ++ Win32.Agent.ark ++ Win32.Agent.byc + Win32.AutoRun ++ Win32.Delf.bj ++ Win32.Friendown + Win32.PcClient.agu + Win32.Small.ih

Total: 609774 fingerprints in 159642 rules for 3951 products.

http://spybot.info/en/updatehistory/index.html

Spyware Doctor 5.09900

Spyware Doctor has been updated with new spyware definitions.

Latest Database Version: 5.09900
Intelli-Signatures: 520,229

Spyware Doctor protects your computer in 3 ways. First, it has the On guard monitor which watches places spyware will change your computer settings. By alerting you, Spyware Doctor gives you the option to not allow unwanted programs on your computer. Second, Spyware Doctor has a feature called Immunize that completely blocks known spyware from even installing. Third, spyware Doctor has a large detection database that removes spyware that has gotten onto your computer. I have used Spyware Doctor in tests against SpyAxe and SpyFalcon. It completely removed the those two. A restart of the computer and resetting my wallpaper was the hardest part.

A free scan is available from the Spyware Doctor Homepage:
http://www.pctools.com/spyware-doctor/

New Intelli-Signatures:

5.09900 - Trojan.Delf.CDI


5.09890 - Trojan-PWS.QQTen, Trojan.PHP.Agent, RogueAntiSpyware.MalWarrior


5.09880 - Trojan-Downloader.WMA.Wimad, Trojan-Downloader.Small.FQO, Trojan-Downloader.Firu, Adware.Agent.BYY, Trojan-Downloader.Banload.MCC, Trojan.Agent.LRY, PSWTool.SAMInside, Trojan-Dropper.Agent.NHA

Extended Intelli-Signatures:

5.09900 - Trojan.Mebroot, Trojan.DNS_Changer, PWSTool.QQPass, Exploit.MSWord, Exploit.MSPpt, Exploit.MSExcel, Backdoor.PCclient, Backdoor.Hupigon.GEN, Backdoor.Graybird.GEN, Adware.NewWeb, Adware.ILookup_Begin2Search, Trojan.QQHook.A, Trojan.Riler, Trojan-PWS.Lineage


5.09890 - Worm.Mytob, Trojan-Spy.Zbot, Trojan-Spy.VB, Trojan-Spy.Qeds, Trojan-Spy.Lyndra, Trojan-Spy.Agent, Trojan-PWS.QQRob, Trojan-PWS.QQRob.U, Trojan-PWS.QQPass.UP, Trojan-PWS.QQPass.GE, Trojan-PWS.OnlineGames, Trojan-PWS.OnLineGames.GEN, Trojan.Zquest, Trojan.Startpage, Trojan.Downloader, Trojan.Agent.LPV, Trojan.Agent.EMB, Trojan.AdRotator, Spyware.SahAgent, Spyware.Known_Bad_Sites, Rootkit.Agent, Exploit.MSPpt, Exploit.JS.Agent, Backdoor.Hupigon, Backdoor.Hupigon.GEN, Backdoor.Graybird.GEN, Backdoor.Bifrose, Backdoor.Bifrose.ACI, Backdoor.Agent, Application.Perfect_Keylogger, Adware.Zeno_Search_Assistant, Adware.TTC, Adware.PodcastbarMini, Adware.OneStepSearch, Adware.MokeAd, Adware.Deskbar, Adware.Cinmus, Adware.Agent.BN, Adware.Adsponsor


5.09880 - Trojan.Virtumonde, Adware.Mokead, Trojan.DNS_Changer, Trojan-PWS.OnLineGames.GEN, Adware.Loadscc, Trojan.Agent.BOW, Trojan-Downloader.Zlob.GEN, Backdoor.Hupigon.GEN, Trojan-Spy.VB, Trojan-Spy.Banker.ALR, Trojan-Downloader.Agent.NVP, Backdoor.Hupigon , Application.HP-Compaq, Trojan-PWS.OnlineGames.HZJ, Worm.Mytob, Trojan-Spy.Pophot.WX, Trojan-Dropper.Agent.BPF

General Information:
Updates are posted 5 times per week on average.
Updates are installed by running Spyware Doctors' Smart Update feature.

Wednesday, April 23, 2008

Nod32 Update 3046 (20080422)

NOD32 Antivirus detection database has been updated to version 3046 (20080422)

NOD32 Antivirus is in my opinion the best anti virus program available. It is light on resources, easy to maintain, and has one of the best detection and removal capabilities among anti virus programs.

Since its first submission for testing in May 1998, NOD32 was the only tested product that has never missed a single In the Wild virus. NOD32 has been selected as the "Antivirus program of 2001" by Australian PC User magazine, "Best Buy, Best Performance, Best Value" by the independent UK Consumer's Association
From Eset's NOD32 product information page.



Threats added in this update include the following:

3046 (20080422)
Win32/Adware.Vapsup (3), Win32/Adware.Vapsup.AB (2), Win32/Adware.Vapsup.AI, Win32/Adware.Vapsup.W, Win32/Adware.Virtumonde, Win32/Adware.Virtumonde.FP, Win32/Agent.NTQ, Win32/Agent.NTS, Win32/AutoRun.LQ (3), Win32/AutoRun.LR (2), Win32/AutoRun.LS (2), Win32/IRCBot.AEY, Win32/Mypis.AH (2), Win32/Pacex.Gen (6), Win32/Privaz.V (8), Win32/PSW.LdPinch.SUI, Win32/PSW.OnLineGames.NFF, Win32/PSW.OnLineGames.NHY, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMX, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.NNU, Win32/PSW.OnLineGames.NOH (2), Win32/PSW.OnLineGames.NOI (2), Win32/PSW.OnLineGames.ODJ, Win32/PSW.OnLineGames.XTT (2), Win32/PSW.QQRob.NAQ, Win32/Qhost, Win32/Rootkit.Vanti.NBM (2), Win32/Socks.EQ (2), Win32/Spy.Agent.NES (3), Win32/Spy.Agent.NGA, Win32/Spy.Delf.NHF (3), Win32/Spy.Delf.NHV, Win32/Spy.Delf.NIG (3), Win32/Spy.Delf.NIK (5), Win32/Spy.Delf.NIL (5), Win32/Spy.KeyLogger.AEV, Win32/TrojanDownloader.Dadobra.IA, Win32/TrojanDownloader.Zlob.BTY, Win32/TrojanDownloader.Zlob.BUZ (2), Win32/TrojanDownloader.Zlob.BVD, Win32/TrojanDownloader.Zlob.BVE (16), Win32/TrojanDropper.Agent.NJR, Win32/Ysmarsys.H (3), Win32/Ysmarsys.I, Win32/Ysmarsys.J, Win32/Ysmarsys.K

Earlier
Update 3045 (20080422)

IRC/SdBot, PDF/Exploit.Pidief.M, VBS/Agent.AI (3), Win32/Adware.BHO.APH (2), Win32/Adware.Cinmus, Win32/Adware.Vapsup (5), Win32/Adware.Vapsup.AB, Win32/Adware.Vapsup.AI (2), Win32/Adware.Vapsup.W, Win32/Adware.Virtumonde.FP, Win32/Agent.KKP, Win32/Agent.KLQ, Win32/Agent.NHE, Win32/Agent.NKJ (6), Win32/Agent.NTV, Win32/BHO.NDR (2), Win32/DNSChanger, Win32/Hupigon (4), Win32/Inject.BCJ, Win32/Obfuscated.NBH (2), Win32/Pacex.Gen (5), Win32/PSW.Agent.NHN (46), Win32/PSW.LdPinch.NEL, Win32/PSW.OnLineGames.NFF, Win32/PSW.OnLineGames.NFL (2), Win32/PSW.OnLineGames.NHY, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NNU (5), Win32/PSW.OnLineGames.NOF, Win32/PSW.OnLineGames.NOH (3), Win32/PSW.OnLineGames.WEA, Win32/PSW.OnLineGames.XTT (3), Win32/Rootkit.Vanti.NBM, Win32/Small.NDV, Win32/Spy.Agent.NFZ, Win32/Spy.Banker.LPX (2), Win32/Spy.Banker.LRB, Win32/Spy.Banker.OTP (2), Win32/TrojanDownloader.Agent.NXT, Win32/TrojanDownloader.Agent.NXU, Win32/TrojanDownloader.Agent.NXV, Win32/TrojanDownloader.Banload.LFX (2), Win32/TrojanDownloader.Delf.FBX (2), Win32/TrojanDownloader.FakeAlert.CD (2), Win32/TrojanDownloader.Zlob.BUZ (2), Win32/TrojanDownloader.Zlob.BVC (3), Win32/TrojanDownloader.Zlob.BVD (17), Win32/TrojanDropper.Agent.NJV (2), Win32/Ysmarsys.G (2)

Spyware Doctor 5.09660

Spyware Doctor has been updated with new spyware definitions.


Latest Database Version: 5.09660

Intelli-Signatures: 641,913



Spyware Doctor protects your computer in 3 ways. First, it has the On guard monitor which watches places spyware will change your computer settings. By alerting you, Spyware Doctor gives you the option to not allow unwanted programs on your computer. Second, Spyware Doctor has a feature called Immunize that completely blocks known spyware from even installing. Third, spyware Doctor has a large detection database that removes spyware that has gotten onto your computer.

A free scan is available from the Spyware Doctor Homepage:

http://www.pctools.com/spyware-doctor/



New Intelli-Signatures:

5.09660 - Adware.BHO.AJ, RogueAntiSpyware.AntiSpywareMaster, Trojan.BurningHardDisk.HOAX, Trojan.Chaincodr, Trojan-Downloader.Agent.HNP, Trojan-PWS.OnlineGames.CVQ, Trojan-PWS.OnlineGames.NFE, Trojan-PWS.QQPass.ARG, Trojan-PWS.Tibia.DB, Trojan-Spy.Agent.AZB, Trojan-Spy.Agent.BBO, Trojan-Spy.Bancos.U, Trojan-Spy.Yazoka

5.09650 - Backdoor.Hupigon, Backdoor.VB.BDZ

5.09640 - HackTool.QQShou, IM-Worm.Kelvir, Trojan.Startpage.U, Trojan-Spy.Lorex

Extended Intelli-Signatures:

5.09660 - Adware.Adbars, Adware.BHO.GEN, Adware.Borlander, Adware.Cinmus, Adware.WebDir, Application.Ardamax_Keylogger, Backdoor.Bifrose.ACI, Backdoor.Cakl, Backdoor.Hupigon, Backdoor.PCclient, Backdoor.Sdbot.AAD, HackTool.Hupigon, PSWTool.Brutus, Trojan.Startpage, Trojan-Downloader.Banload, Trojan-Downloader.Small.GEN, Trojan-PWS.Lineage.ACJ, Trojan-PWS.Lineage, Trojan-PWS.Magania, Trojan-PWS.OnlineGames, Trojan-PWS.QQPass, Trojan-PWS.Tibia, Trojan-Spy.Banker.CHC

5.09650 - Adware.Comet_Cursor, Adware.NewdotNet, Adware.NewWeb, Adware.OneStepSearch, Adware.Sogou, Adware.Starware, Adware.WhenU_SaveNow, Backdoor.Beastdoor, Backdoor.CIADoor, Backdoor.G_Door, Backdoor.Hupigon.GEN, Backdoor.Nuclear, RogueAntiSpyware.Ultimate_Defender, Trojan.Dumaru, Trojan.SC_Keylogger, Trojan.Vipgsm, Trojan-PWS.Magania, Trojan-PWS.OnlineGames, Trojan-PWS.Tibia, Trojan-Spy.Banbra.H, Trojan-Spy.Banker.GEN

5.09640 - Adware.EliteBar, Adware.Webbuying, Backdoor.IRC.Flood, Backdoor.Poison, Backdoor.SkRat, PSWTool.Brutus, Rootkit.Agent, Trojan.FakeAlert, Trojan.Laoshen, Trojan.Popuper, Trojan-Downloader.Agent.AKQ, Trojan-Downloader.Small.BUY, Trojan-Downloader.Small.GEN, Trojan-PWS.LdPinch, Trojan-PWS.OnlineGames, Trojan-PWS.QQShou, Worm.Spybot


General Information:

Updates are posted 5 times per week on average.

Updates are installed by running Spyware Doctors' Smart Update feature.

Tuesday, April 22, 2008

Firefox 2.0.0.14 Update

Firefox v2.0.0.14 released
From an admin account, start Firefox, then >Help >Check for Updates
-or-

Download
- http://www.mozilla.com/firefox/

What's new:
- http://www.mozilla.com/en-US/firefox.../releasenotes/
April 16, 2008

- http://www.mozilla.org/projects/secu...irefox2.0.0.14

- http://secunia.com/advisories/29787/

Release Date: 2008-04-17
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch...
Solution: Update to version 2.0.0.14.

Tuesday, February 12, 2008

Leopard Graphics Update for 10.5.2

After you update to Mac OS 10.5.2 Leopard, there's an update for your video graphics. Not much detail provided on the download page, but performance is reported to greatly increase for World of Warcraft. After you update to 10.5.2, run software update again to get this update.

Monday, February 11, 2008

Mac OS 10.5.2 and Security Update 2008-001

Apple released the next big update for Leopard today, 10.5.2. There's also a security update for users running 10.4 Tiger, Security Update 2008-001. Security updates for Leopard are included in 10.5.2 while tiger will have the 2008-001 as an update.


Mac OS 10.5.2 includes updates for Airport, Back to My Mac, iCal, iChat, Mail, Printing, Safari, Time Machine, and much more. The security update includes fixes for Safari, Mail, Parental Controls, Samba, Terminal and X11.

Here are links to more information about the Leopard 10.5.2 update and Security Update 2008-001. To get these updates, click the Apple in the top left of the screen and select Software Update.

Saturday, January 05, 2008

Microsoft Advance Security Bulletin For January 2008

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don’t forget to prepare for the updates as I’ve outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 8th January 2008 Microsoft is planning to release:

Security Updates

One Critical Bulletin.

  • One Microsoft Security Bulletin affecting Microsoft Windows with a Maximum Severity rating of Critical. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

One Important Bulletin.

  • One Microsoft Security Bulletin affecting Windows with a Maximum Severity rating of Important. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Centre.

Non-security High Priority updates on MU, WU,WSUS and SUS

  • Microsoft will release two NON-SECURITY High-Priority Updates for Windows on Windows Update (WU)
  • Microsoft will release five NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).

Microsoft Security Bulletin Advance Notification

Obtaining Other Security Updates

Updates for other security issues are available from the following locations:

  • Security updates are available from Microsoft Download Center. You can find them most easily by doing a keyword search for “security update”.
  • Updates for consumer platforms are available from Microsoft Update.
  • You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft Knowledge Base Article 913086.

Microsoft will host a webcast to address customer questions on these bulletins on January 9, 2008, at 11:00 AM Pacific Time (US & Canada). Register now for the January Security Bulletin Webcast. After this date, this webcast is available on-demand. For more information, see Microsoft Security Bulletin Summaries and Webcasts.

Thursday, January 03, 2008

Ad-Aware SE No Longer Supported

If you are using Lavasoft’s Ad-Aware SE then you must uninstall it and replace it with Ad-Aware 2007 Free.  Lavasoft will no longer provide definition updates for Ad-Aware SE.. and an anti-malware program that doesn’t get regular updates is as much use to you as a chocolate teapot.

Please note; Ad-Aware 2007 Free is only compatible with Windows 2000, XP, 2003 Server and Vista(32-bit).  If you are running earlier versions of Windows (Windows 98 or ME) then you will not be able to use it.

Monday, December 10, 2007

Microsoft Security Bulletin Advance Notification for December 2007

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

The following updates are planned for release on Tuesday December 11th.

Critical (3)

Microsoft Security Bulletin 2
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, DirectX, DirectShow...

Microsoft Security Bulletin 6
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, Windows Media Format Runtime...

Microsoft Security Bulletin 7
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, Internet Explorer...

Important (4)

Microsoft Security Bulletin 1
Maximum Severity Rating: Important
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows...

Microsoft Security Bulletin 3
Maximum Severity Rating: Important
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows...

Microsoft Security Bulletin 4
Maximum Severity Rating: Important
Impact of Vulnerability: Elevation of Privilege...
Affected Software: Windows...

Microsoft Security Bulletin 5
Maximum Severity Rating: Important
Impact of Vulnerability: Local Elevation of Privilege...
Affected Software: Windows...
---

Microsoft Windows Malicious Software Removal Tool
Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

Non-Security, High-Priority Updates on MU, WU, and WSUS
For this month:
• Microsoft is planning to release -six- non-security, high-priority updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
• Microsoft is planning to release -one- non-security, high-priority update for Windows on Windows Update (WU).
Note that this information pertains only to non-security, high-priority updates on Microsoft Update, Windows Update, and Windows Server Update Services released on the same day as the security bulletin summary. Information is not provided about non-security updates released on other days..."

Thursday, November 08, 2007

Microsoft Security Bulletin Advance Notification for November 2007

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 13 November 2007 Microsoft is planning to release:

Security Updates

One Critical Bulletin.

  • One Microsoft Security Bulletin affecting Microsoft Windows with a Maximum Severity rating of Critical. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

One Important Bulletin.

  • One Microsoft Security Bulletin affecting Windows with a Maximum Severity rating of Important. This update may require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Centre.

Non-security High Priority updates on MU, WU,WSUS and SUS

  • Microsoft will release zero NON-SECURITY High-Priority Updates for Windows on Windows Update (WU)
  • Microsoft will release three NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).

Microsoft Security Bulletin Advance Notification

Obtaining Other Security Updates

Updates for other security issues are available from the following locations:

  • Security updates are available from Microsoft Download Center. You can find them most easily by doing a keyword search for "security update".
  • Updates for consumer platforms are available from Microsoft Update.
  • You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft Knowledge Base Article 913086

Saturday, November 03, 2007

Firefox Update to v2.0.0.9

I've had a bad cold which finally got the better of me yesterday, so I didn't get to tell you about the latest update to Firefox.  If you use Firefox and it hasn't already prompted you to download and intsall the update then you can do it manually by opening Firefox and going to Help > Check For Updates.

This is a stability update that corrects several issues that were found in the previous version of Firefox.