[MS Security Bulletin] Summary for November 2009 - Issued: November 10, 2009

This bulletin summary lists security bulletins released for November 2009.


The full version of the Microsoft Security Bulletin Summary for November 2009 can be found at http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx.


With the release of the bulletins for November 2009, this bulletin summary replaces the bulletin advance notification originally issued on November 5, 2009. For more information about the bulletin
advance notification service, see http://www.microsoft.com/technet/security/Bulletin/advance.mspx.


To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.


Microsoft will host a webcast to address customer questions on these bulletins on Wednesday, November 11, 2009, at 11:00 AM Pacific Time (US & Canada). Register for the Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.


Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.


Critical Security Bulletins
Microsoft Security Bulletin MS09-063
  - Affected Software:
    - Windows Vista,
      Windows Vista Service Pack 1, and
      Windows Vista Service Pack 2
    - Windows Vista x64 Edition,
      Windows Vista x64 Edition Service Pack 1, and
      Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems and
      Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems and
      Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems and
      Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Impact: Remote Code Execution
    - Version Number: 1.0


Microsoft Security Bulletin MS09-064
  - Affected Software:
    - Microsoft Windows 2000 Server Service Pack 4
    - Impact: Remote Code Execution
    - Version Number: 1.0

Microsoft Security Bulletin MS09-065
  - Affected Software:
    - Microsoft Windows 2000 Service Pack 4
    - Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Windows XP Professional x64 Edition Service Pack 2
    - Windows Server 2003 Service Pack 2
    - Windows Server 2003 x64 Edition Service Pack 2
    - Windows Server 2003 with SP2 for Itanium-based Systems
    - Windows Vista,
      Windows Vista Service Pack 1, and
      Windows Vista Service Pack 2
    - Windows Vista x64 Edition,
      Windows Vista x64 Edition Service Pack 1, and
      Windows Vista x64 Edition Service Pack 2
    - Windows Server 2008 for 32-bit Systems and
      Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for x64-based Systems and
      Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Windows Server 2008 for Itanium-based Systems and
      Windows Server 2008 for Itanium-based Systems Service Pack 2
    - Impact: Remote Code Execution
    - Version Number: 1.0

Important Security Bulletins
Microsoft Security Bulletin MS09-066
  - Affected Software:
    - Active Directory on
      Microsoft Windows 2000 Service Pack 4
    - Active Directory Application Mode (ADAM) on
      Windows XP Service Pack 2 and
      Windows XP Service Pack 3
    - Active Directory Application Mode (ADAM) on
      Windows XP Professional x64 Edition Service Pack 2
    - Active Directory on
      Windows Server 2003 Service Pack 2
    - Active Directory Application Mode (ADAM) on
      Windows Server 2003 Service Pack 2
    - Active Directory on
      Windows Server 2003 x64 Edition Service Pack 2
    - Active Directory Application Mode (ADAM) on
      Windows Server 2003 x64 Edition Service Pack 2
    - Active Directory on
      Windows Server 2003 with SP2 for Itanium-based Systems
    - Active Directory and
      Active Directory Lightweight Directory Service (AD LDS) on
      Windows Server 2008 for 32-bit Systems and
      Windows Server 2008 for 32-bit Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Active Directory and
      Active Directory Lightweight Directory Service (AD LDS) on
      Windows Server 2008 for x64-based Systems and
      Windows Server 2008 for x64-based Systems Service Pack 2
      (Windows Server 2008 Server Core installation affected)
    - Impact: Denial of Service
    - Version Number: 1.0

Microsoft Security Bulletin MS09-067
  - Affected Software:
    - Microsoft Office Excel 2002 Service Pack 3
    - Microsoft Office Excel 2003 Service Pack 3
    - Microsoft Office Excel 2007 Service Pack 1 and
      Microsoft Office Excel 2007 Service Pack 2
    - Microsoft Office 2004 for Mac
    - Microsoft Office 2008 for Mac
    - Open XML File Format converter for Mac
    - Microsoft Office Excel Viewer 2003 Service Pack 3
    - Microsoft Office Excel Viewer Service Pack 1 and
      Microsoft Office Excel Viewer Service Pack 2
    - Microsoft Office Compatibility Pack for Word, Excel, and
      PowerPoint 2007 File Formats Service Pack 1 and
      Microsoft Office Compatibility Pack for Word, Excel, and
      PowerPoint 2007 File Formats Service Pack 2
    - Impact: Remote Code Execution
    - Version Number: 1.0

Microsoft Security Bulletin MS09-068
  - Affected Software:
    - Microsoft Office Word 2002 Service Pack 3
    - Microsoft Office Word 2003 Service Pack 3
    - Microsoft Office 2004 for Mac
    - Microsoft Office 2008 for Mac
    - Open XML File Format converter for Mac
    - Microsoft Office Word Viewer 2003 Service Pack 3
    - Microsoft Office Word Viewer
    - Impact: Remote Code Execution
    - Version Number: 1.0

Read the complete post at http://wmug.co.uk/blogs/cliffs_blog/archive/2009/11/10/ms-security-bulletin-summary-for-november-2009-issued-november-10-2009.aspx

Published Tuesday, November 10, 2009 3:37 AM by Cliff Hobbs - FAQShop.com and Microsoft MVP ConfigMgr/ SMS