Very small patch cycle for me this month, keep in mind that I'm only covering the Security Updates in these monthly blog reports.
There was a re-release of MS08-037 (KB951749).
Also, if you held off from deploying the MS09-056 patches that broke OCS you may want to include them this month after making sure you've deployed OCSASNFIX.EXE (refer here for more info)
|
Bulletin ID
|
Bulletin Title
|
Max Severity Rating
|
Vulnerability Impact
|
Restart Requirement
|
Affected Software*
|
|
MS09-069
|
Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)
|
Important
|
Denial of Service
|
Requires restart
|
Microsoft Windows 2000, Windows XP, and Windows Server 2003
|
|
MS09-070
|
Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)
|
Important
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows Server 2003 and Windows Server 2008
|
|
MS09-071
|
Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
|
Critical
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008
|
|
MS09-072
|
Cumulative Security Update for Internet Explorer (976325)
|
Critical
|
Remote Code Execution
|
Requires restart
|
Internet Explorer on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
|
|
MS09-073
|
Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
|
Important
|
Remote Code Execution
|
Requires restart
|
Microsoft Windows 2000, Windows XP, Windows Server 2003, Office XP, Office 2003, Works 8.5, and Office Converter Pack
|
|
MS09-074
|
Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)
|
Critical
|
Remote Code Execution
|
May require restart
|
Microsoft Project 2000, Project 2002, and Project 2003
|
Our X86 package weighed in at 158MB, and the X64 package came in at 229MB.
Read the complete post at http://wmug.co.uk/blogs/r0b/archive/2009/12/09/december-2009-microsoft-security-bulletins.aspx