[MS Security Bulletin] Advance Notification for April 2009 - Issued: April 9, 2009

Next week Microsoft plans to release the following Security bulletins:

  • 5 x Critical - Windows (3); IE (1);  Excel (1)
  • 2 x Important - Windows (1); ISA (1)
  • 1 x Moderate - Windows (1)

Further details:

This is an advance notification of security bulletins that Microsoft is intending to release on April 14, 2009. The full version of the Microsoft Security Bulletin Advance Notification for April 2009 can be found at
http://www.microsoft.com/technet/security/bulletin/ms09-apr.mspx.


This bulletin advance notification will be replaced with the April bulletin summary on April 14, 2009. For more information about the bulletin advance notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.

To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

Microsoft will host a webcast to address customer questions on these bulletins on Wednesday, April 15, 2009, at 11:00 AM Pacific Time (US & Canada). Register for the April Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.


Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information. This advance notification provides the software subject as the bulletin identifier, because the official Microsoft Security Bulletin numbers are not issued until release. The bulletin summary that replaces this advance notification will have the proper Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the
bulletin identifier. The security bulletins for this month are as follows, in order of severity:


Critical Security Bulletins

Windows 1 Bulletin
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Microsoft Office Word 2000 Service Pack 3
    - Microsoft Office Word 2002 Service Pack 3
    - Microsoft Office Converter Pack
    - Impact: Remote Code Execution
    - Version Number: 1.0

Windows 2 Bulletin
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Windows Vista and
      Windows Vista Service Pack 1
    - Windows Vista x64 Edition and
      Windows Vista x64 Edition Service Pack 1
    - Windows Server 2008 for 32-bit Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems
    - Impact: Remote Code Execution
    - Version Number: 1.0

Windows 3 Bulletin
  - Affected Software:
    - DirectX 8.1 on Microsoft Windows 2000 Service Pack 4
    - DirectX 9.0 on Microsoft Windows 2000 Service Pack 4
    - DirectX 9.0 on Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - DirectX 9.0 on Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - DirectX 9.0 on Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - DirectX 9.0 on Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - DirectX 9.0 on
      Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    Note: The update for DirectX 9.0 also applies to DirectX 9.0a,
    DirectX 9.0b, and DirectX 9.0c
    - Impact: Remote Code Execution
    - Version Number: 1.0

IE Bulletin
  - Affected Software:
    - Internet Explorer 5.01 Service Pack 4 when installed on
      Microsoft Windows 2000 Service Pack 4
    - Internet Explorer 6 Service Pack 1 when installed on
      Microsoft Windows 2000 Service Pack 4
    - Internet Explorer 6 for
      Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Internet Explorer 6 for
      Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Internet Explorer 6 for
      Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Internet Explorer 6 for
      Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Internet Explorer 6 for
      Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Internet Explorer 7 for
      Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Internet Explorer 7 for
      Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Internet Explorer 7 for
      Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Internet Explorer 7 for
      Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Internet Explorer 7 for
      Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Internet Explorer 7 in
      Windows Vista and
      Windows Vista Service Pack 1
    - Internet Explorer 7 in
      Windows Vista x64 Edition and
      Windows Vista x64 Edition Service Pack 1
    - Internet Explorer 7 in
      Windows Server 2008 for 32-bit Systems
      (Windows Server 2008 Server Core installation not affected)
    - Internet Explorer 7 in
      Windows Server 2008 for x64-based Systems
      (Windows Server 2008 Server Core installation not affected)
    - Internet Explorer 7 in
      Windows Server 2008 for Itanium-based Systems
    - Impact: Remote Code Execution
    - Version Number: 1.0

Excel Bulletin
  - Affected Software:
    - Microsoft Office Excel 2000 Service Pack 3
    - Microsoft Office Excel 2002 Service Pack 3
    - Microsoft Office Excel 2003 Service Pack 3
    - Microsoft Office Excel 2007 Service Pack 1
    - Microsoft Office 2004 for Mac
    - Microsoft Office 2008 for Mac
    - Microsoft Office Excel Viewer 2003 Service Pack 3
    - Microsoft Office Excel Viewer
    - Microsoft Office Compatibility Pack for Word, Excel, and
      PowerPoint 2007 File Formats Service Pack 1
    Note: For Microsoft Office Excel 2007 Service Pack 1, customers also need to install the security update for Microsoft Office Compatibility Pack
              for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 to be protected from the vulnerabilities described in this bulletin
    - Impact: Remote Code Execution
    - Version Number: 1.0

Important Security Bulletins

Windows 4 Bulletin
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Windows Vista and
      Windows Vista Service Pack 1
    - Windows Vista x64 Edition and
      Windows Vista x64 Edition Service Pack 1
    - Windows Server 2008 for 32-bit Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems
    - Impact: Elevation of Privilege
    - Version Number: 1.0

ISA Bulletin
  - Affected Software:
    - Microsoft Forefront Threat Management Gateway,
      Medium Business Edition
      (Delivered both as a standalone product and as a component of
      Windows Essential Business Server 2008)
    - Microsoft Internet Security and Acceleration Server 2004
      Standard Edition Service Pack 3
      (Delivered as a standalone product. Also delivered as a
      component of Windows Small Business Server Enterprise Edition
      Service Pack 1 and
      Windows Small Business Server 2003 R2 Enterprise Edition)
    - Microsoft Internet Security and Acceleration Server 2004
      Enterprise Edition Service Pack 3
    - Microsoft Internet Security and Acceleration Server 2006
    - Microsoft Internet Security and Acceleration Server 2006
      Supportability Update
    - Microsoft Internet Security and Acceleration Server 2006
      Service Pack 1
    - Impact: Denial of Service
    - Version Number: 1.0

Moderate Security Bulletins
Windows 5 Bulletin
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Windows XP Professional x64 Edition and
      Windows XP Professional x64 Edition Service Pack 2
    - Windows Server 2003 Service Pack 1 and
      Windows Server 2003 Service Pack 2
    - Windows Server 2003 x64 Edition and
      Windows Server 2003 x64 Edition Service Pack 2
    - Windows Server 2003 with SP1 for Itanium-based Systems and
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Windows Vista and
      Windows Vista Service Pack 1
    - Windows Vista x64 Edition and
      Windows Vista x64 Edition Service Pack 1
    - Windows Server 2008 for 32-bit Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems
    - Impact: Elevation of Privilege
    - Version Number: 1.0

Read the complete post at http://wmug.co.uk/blogs/cliffs_blog/archive/2009/04/09/ms-security-bulletin-advance-notification-for-april-2009-issued-april-9-2009.aspx