<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://myitforum.com/cs2/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results matching tags 'Microsoft Office' and 'Internet News'</title><link>http://myitforum.com/cs2/search/SearchResults.aspx?q=&amp;tag=Microsoft+Office%2CInternet+News&amp;orTags=0&amp;o=DateDescending</link><description>Search results matching tags 'Microsoft Office' and 'Internet News'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007.1 SP2 (Build: 31113.47)</generator><item><title>Microsoft Security Advisory Notification - Issued: April 14, 2009</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2009/04/15/microsoft-security-advisory-notification-issued-april-14-2009.aspx</link><pubDate>Wed, 15 Apr 2009 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:134582</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Title: Microsoft Security Advisory Notification&lt;/p&gt;  &lt;p&gt;Issued: April 14, 2009&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Security Advisories Updated or Released Today ==============================================&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (968272)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Microsoft Office Excel&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/968272.mspx"&gt;http://www.microsoft.com/technet/security/advisory/968272.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (960906)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in WordPad Text Converter&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/960906.mspx"&gt;http://www.microsoft.com/technet/security/advisory/960906.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (953818)&lt;/p&gt;  &lt;p&gt;- Title: Blended Threat from Combined Attack Using&lt;/p&gt;  &lt;p&gt;Apple&amp;#39;s Safari on the Windows Platform&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/953818.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953818.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Added references and links to MS09-014 and MS09-015, which address the issue in this advisory.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (951306)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Windows Could Allow&lt;/p&gt;  &lt;p&gt;Elevation of Privilege&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;http://www.microsoft.com/technet/security/advisory/951306.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;</description></item><item><title>Microsoft Security Advisory Notification - Issued: April 14, 2009</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2009/04/15/microsoft-security-advisory-notification-issued-april-14-2009.aspx</link><pubDate>Wed, 15 Apr 2009 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:134582</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Title: Microsoft Security Advisory Notification&lt;/p&gt;  &lt;p&gt;Issued: April 14, 2009&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Security Advisories Updated or Released Today ==============================================&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (968272)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Microsoft Office Excel&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/968272.mspx"&gt;http://www.microsoft.com/technet/security/advisory/968272.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (960906)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in WordPad Text Converter&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/960906.mspx"&gt;http://www.microsoft.com/technet/security/advisory/960906.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (953818)&lt;/p&gt;  &lt;p&gt;- Title: Blended Threat from Combined Attack Using&lt;/p&gt;  &lt;p&gt;Apple&amp;#39;s Safari on the Windows Platform&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/953818.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953818.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Added references and links to MS09-014 and MS09-015, which address the issue in this advisory.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (951306)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Windows Could Allow&lt;/p&gt;  &lt;p&gt;Elevation of Privilege&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;http://www.microsoft.com/technet/security/advisory/951306.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;</description></item><item><title>Microsoft Security Advisory Notification - Issued: April 14, 2009</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2009/04/15/microsoft-security-advisory-notification-issued-april-14-2009.aspx</link><pubDate>Wed, 15 Apr 2009 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:134582</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Title: Microsoft Security Advisory Notification&lt;/p&gt;  &lt;p&gt;Issued: April 14, 2009&lt;/p&gt;  &lt;p&gt;********************************************************************&lt;/p&gt;  &lt;p&gt;Security Advisories Updated or Released Today ==============================================&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (968272)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Microsoft Office Excel&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/968272.mspx"&gt;http://www.microsoft.com/technet/security/advisory/968272.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (960906)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in WordPad Text Converter&lt;/p&gt;  &lt;p&gt;Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/960906.mspx"&gt;http://www.microsoft.com/technet/security/advisory/960906.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (953818)&lt;/p&gt;  &lt;p&gt;- Title: Blended Threat from Combined Attack Using&lt;/p&gt;  &lt;p&gt;Apple&amp;#39;s Safari on the Windows Platform&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/953818.mspx"&gt;http://www.microsoft.com/technet/security/advisory/953818.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V2.0 (April 14, 2009): Added references and links to MS09-014 and MS09-015, which address the issue in this advisory.&lt;/p&gt;  &lt;p&gt;* Microsoft Security Advisory (951306)&lt;/p&gt;  &lt;p&gt;- Title: Vulnerability in Windows Could Allow&lt;/p&gt;  &lt;p&gt;Elevation of Privilege&lt;/p&gt;  &lt;p&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;http://www.microsoft.com/technet/security/advisory/951306.mspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Revision Note: V3.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin.&lt;/p&gt;</description></item><item><title>Microsoft Security Bulletin Summary for October 2008 - Exploitability Index</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2008/10/14/microsoft-security-bulletin-summary-for-october-2008-exploitability-index.aspx</link><pubDate>Tue, 14 Oct 2008 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:123172</guid><dc:creator>cmosby</dc:creator><description>&lt;table cellspacing="0" cellpadding="0"&gt;  &lt;tr&gt; &lt;td style="padding-right:6px;padding-left:0px;padding-bottom:0px;padding-top:6px;"&gt;&amp;nbsp;&lt;/td&gt; &lt;td class="secLabel"&gt; startA(&amp;#39;s&amp;#39;+sID) &lt;a style="text-decoration:none;"&gt; &lt;h3&gt;Exploitability Index&lt;/h3&gt; endA() &lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt; &lt;div id="s7l1-EJBAE"&gt; chkHide(&amp;#39;s&amp;#39;+sID);  &lt;div class="expandoIndent"&gt; &lt;p&gt;&lt;b&gt;How do I use this table?&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Use this table to learn about the likelihood of functioning exploit code to be released for each of the security updates that you may need to install. You should review each of the assessments below, in accordance with your specific configuration, in order to prioritize your deployment. For more information about what these ratings mean, and how they are determined, please see &lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;Microsoft Exploit Index&lt;/a&gt;.&lt;/p&gt; &lt;table class="dataTable" id="EVBAE" cellspacing="0" cellpadding="0"&gt;  &lt;tr class="stdHeader"&gt; &lt;td id="colEYBAE"&gt;Bulletin ID&lt;/td&gt; &lt;td id="colE3BAE"&gt;Bulletin Title&lt;/td&gt; &lt;td id="colEACAE"&gt;CVE ID&lt;/td&gt; &lt;td id="colEECAE"&gt;Exploitability Index Assessment&lt;/td&gt; &lt;td id="colEICAE" style="border-right:#cccccc 1px solid;"&gt;Key Notes&lt;/td&gt;&lt;/tr&gt;  &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128145"&gt;MS08-056&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128145"&gt;Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4020&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Functioning exploit code could be created. However, the severity impact is limited as the vulnerability allows spoofing in a dialog in specific Web application scenarios only. As a result, this may get little attention from attackers.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4019&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3471&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3477&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2947&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;(Public at bulletin release)&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3472&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3473&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3475&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3474&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3476&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125712"&gt;MS08-059&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125712"&gt;Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3466&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;While only specific types of enterprise customers would likely install Host Integration Server, functioning exploit code is likely to be created.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128125"&gt;MS08-060&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128125"&gt;Vulnerability in Active Directory Could Allow Remote Code Execution (957280)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4023&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Triggering the vulnerability to cause a denial of service condition is likely. However, creating functioning exploit code to leverage remote code execution is difficult due to not being able to control a needed write address.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2250&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2252&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Functioning exploit is most likely to be created for multiprocessor systems.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2251&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Triggering the vulnerability may be possible, but successful, functioning exploit code is very difficult to create.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=120829"&gt;MS08-062&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=120829"&gt;Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-1446&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Consistent exploit code has been discovered in limited, targeted attacks. While the Internet Printing Protocol (IPP) service is enabled by default, access to this service using IIS also requires authentication by default on all platforms.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=127994"&gt;MS08-063&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=127994"&gt;Vulnerability in SMB Could Allow Remote Code Execution (957095)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4038&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128103"&gt;MS08-064&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128103"&gt;Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4036&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128102"&gt;MS08-065&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128102"&gt;Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3479&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;While information disclosure might be possible, obtaining useful content from memory is not always possible. The memory corruption issue can be triggered, but remote code execution is difficult to gain.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125709"&gt;MS08-066&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125709"&gt;Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3464&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>Microsoft Security Bulletin Summary for October 2008 - Exploitability Index</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2008/10/14/microsoft-security-bulletin-summary-for-october-2008-exploitability-index.aspx</link><pubDate>Tue, 14 Oct 2008 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:123172</guid><dc:creator>cmosby</dc:creator><description>&lt;table cellspacing="0" cellpadding="0"&gt;  &lt;tr&gt; &lt;td style="padding-right:6px;padding-left:0px;padding-bottom:0px;padding-top:6px;"&gt;&amp;nbsp;&lt;/td&gt; &lt;td class="secLabel"&gt; startA(&amp;#39;s&amp;#39;+sID) &lt;a style="text-decoration:none;"&gt; &lt;h3&gt;Exploitability Index&lt;/h3&gt; endA() &lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt; &lt;div id="s7l1-EJBAE"&gt; chkHide(&amp;#39;s&amp;#39;+sID);  &lt;div class="expandoIndent"&gt; &lt;p&gt;&lt;b&gt;How do I use this table?&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Use this table to learn about the likelihood of functioning exploit code to be released for each of the security updates that you may need to install. You should review each of the assessments below, in accordance with your specific configuration, in order to prioritize your deployment. For more information about what these ratings mean, and how they are determined, please see &lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;Microsoft Exploit Index&lt;/a&gt;.&lt;/p&gt; &lt;table class="dataTable" id="EVBAE" cellspacing="0" cellpadding="0"&gt;  &lt;tr class="stdHeader"&gt; &lt;td id="colEYBAE"&gt;Bulletin ID&lt;/td&gt; &lt;td id="colE3BAE"&gt;Bulletin Title&lt;/td&gt; &lt;td id="colEACAE"&gt;CVE ID&lt;/td&gt; &lt;td id="colEECAE"&gt;Exploitability Index Assessment&lt;/td&gt; &lt;td id="colEICAE" style="border-right:#cccccc 1px solid;"&gt;Key Notes&lt;/td&gt;&lt;/tr&gt;  &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128145"&gt;MS08-056&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128145"&gt;Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4020&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Functioning exploit code could be created. However, the severity impact is limited as the vulnerability allows spoofing in a dialog in specific Web application scenarios only. As a result, this may get little attention from attackers.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4019&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3471&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;MS08-057&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124653"&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3477&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2947&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;(Public at bulletin release)&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3472&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3473&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3475&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3474&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128060"&gt;MS08-058&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=128060"&gt;Cumulative Security Update for Internet Explorer (956390)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3476&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125712"&gt;MS08-059&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125712"&gt;Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3466&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;While only specific types of enterprise customers would likely install Host Integration Server, functioning exploit code is likely to be created.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128125"&gt;MS08-060&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128125"&gt;Vulnerability in Active Directory Could Allow Remote Code Execution (957280)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4023&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Triggering the vulnerability to cause a denial of service condition is likely. However, creating functioning exploit code to leverage remote code execution is difficult due to not being able to control a needed write address.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2250&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2252&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Functioning exploit is most likely to be created for multiprocessor systems.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;MS08-061&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=121738"&gt;Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-2251&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Triggering the vulnerability may be possible, but successful, functioning exploit code is very difficult to create.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=120829"&gt;MS08-062&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=120829"&gt;Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-1446&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;Consistent exploit code has been discovered in limited, targeted attacks. While the Internet Printing Protocol (IPP) service is enabled by default, access to this service using IIS also requires authentication by default on all platforms.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=127994"&gt;MS08-063&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=127994"&gt;Vulnerability in SMB Could Allow Remote Code Execution (957095)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4038&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128103"&gt;MS08-064&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128103"&gt;Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-4036&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;2 - Inconsistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="record"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128102"&gt;MS08-065&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=128102"&gt;Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3479&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;3 - Functioning exploit code unlikely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;While information disclosure might be possible, obtaining useful content from memory is not always possible. The memory corruption issue can be triggered, but remote code execution is difficult to gain.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr class="evenRecord"&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125709"&gt;MS08-066&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=125709"&gt;Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;CVE-2008-3464&lt;/p&gt;&lt;/td&gt; &lt;td&gt; &lt;p class="lastInCell"&gt;&lt;a href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;1 - Consistent exploit code likely&lt;/a&gt;&lt;/p&gt;&lt;/td&gt; &lt;td style="border-right:#cccccc 1px solid;"&gt; &lt;p class="lastInCell"&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;</description></item><item><title>Update: Microsoft admits it knew about, didn't patch, bugs - ComputerWorld.com</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2008/03/26/update-microsoft-admits-it-knew-about-didn-t-patch-bugs-computerworld-com.aspx</link><pubDate>Wed, 26 Mar 2008 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:114251</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;h3&gt;&lt;/h3&gt; &lt;div class="article"&gt; &lt;h1&gt;Update: Microsoft admits it knew about, didn&amp;#39;t patch, bugs&lt;/h1&gt; &lt;div class="subhead"&gt;&lt;/div&gt; &lt;div class="storyby"&gt;Gregg Keizer&lt;/div&gt; &lt;div class="thinline"&gt;&lt;/div&gt; &lt;div style="float:right;width:1px;height:130px;"&gt;&lt;/div&gt; &lt;div style="clear:right;padding-right:0px;padding-left:10px;float:right;padding-bottom:10px;padding-top:15px;"&gt; 
document.write(&amp;#39;&amp;#39;);
    &lt;div class="padtop10"&gt;&lt;/div&gt; 

document.write(&amp;#39;&amp;#39;);
    if ((!document.images &amp;amp;&amp;amp; navigator.userAgent.indexOf(&amp;#39;Mozilla/2.&amp;#39;) &amp;gt;= 0)|| navigator.userAgent.indexOf(&amp;quot;WebTV&amp;quot;) &amp;gt;= 0) {document.write(&amp;#39;&lt;a href="http://ad.doubleclick.net/jump/idg.us.cpw.security/index;pos=ezblaster;keyw=printer;tile=8;sz=336x35;keyw=printer;ord=&amp;#39;%20+%20ord%20+%20&amp;#39;?" target="_blank"&gt;&lt;img src="http://ad.doubleclick.net/ad/idg.us.cpw.security/index;pos=ezblaster;keyw=printer;tile=8;sz=336x35;keyw=printer;ord=&amp;#39;%20+%20ord%20+%20&amp;#39;?" width="336" height="35" border="0" alt="" /&gt;&amp;#39;);}  &lt;/div&gt; &lt;p&gt;&lt;b&gt;March 25, 2008&lt;/b&gt; (Computerworld) Microsoft Corp.&amp;#39;s security team today acknowledged that it knew of bugs in its Jet Database Engine as far back as 2005 but did not patch the problems because it thought it had blocked the obvious attack vectors. &lt;/p&gt; &lt;p&gt;A researcher at Symantec Corp. said Microsoft should have fixed the flaws years ago. &lt;/p&gt; &lt;p&gt;In a post to the Microsoft Security Research Center (MSRC) blog &lt;a href="http://blogs.technet.com/msrc/archive/2008/03/24/update-msrc-blog-microsoft-security-advisory-950627.aspx" target="new"&gt;late Monday afternoon&lt;/a&gt;, Mike Reavey, the MSRC&amp;#39;s operations manager, admitted that outside researchers had notified Microsoft in 2005 and 2007 of separate bugs in Jet, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic. &lt;/p&gt; &lt;p&gt;In both cases, Microsoft told the researchers that it would not fix the flaw because it considered users safe. Outlook blocked the .mdb file format from being opened, Exchange servers stripped them from incoming messages and Internet Explorer issued warnings when users clicked on such files, said Reavey as he explained Microsoft&amp;#39;s decision. &lt;/p&gt; &lt;p&gt;But the company hadn&amp;#39;t thought of the attack strategy now being used by hackers. &amp;quot;Everything changed with the discovery of this new attack vector that allowed an attacker to load an .mdb file via opening a Microsoft Word document,&amp;quot; he said. &amp;quot;The previous guidance does not work against this new attack. So that&amp;#39;s why we alerted customers to these attacks and are re-investigating Jet parsing flaws -- this is a new attack vector discovered that we didn&amp;#39;t know about.&amp;quot; &lt;/p&gt; &lt;p&gt;Attackers are, in fact, doing an end run around Outlook, researchers at Symantec said last week. That finding prompted &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=18&amp;amp;articleId=9070840"&gt;Microsoft to issue a security advisory&lt;/a&gt; warning users running Word on Windows 2000, XP and Server 2003 SP1 to take defensive steps. &lt;/p&gt; &lt;p&gt;One researcher said today that Microsoft could have done more -- and done something earlier -- to prevent the sudden scramble for a fix. &lt;/p&gt; &lt;p&gt;&amp;quot;I can&amp;#39;t count the number of times we&amp;#39;ve seen this in the past with a Microsoft product,&amp;quot; said Oliver Friedrichs, a director with Symantec&amp;#39;s security response team. &amp;quot;Clearly, there should have been more concern from Microsoft in the first place. There have been two vulnerabilities, one in 2005 and another in 2007, and both were left unpatched. &lt;/p&gt; &lt;p&gt;&amp;quot;It does draw some concern,&amp;quot; Friedrichs said. &lt;/p&gt; &lt;p&gt;The MSRC is still working out how it wants to patch the vulnerability or whether it can put up more barriers to the now-known Word attack. It may block Word documents from automatically loading .mdb files, Reavey said, or it may replace the version of Jet in Windows 2000, XP and Server 2003 SP1 with a newer edition that doesn&amp;#39;t contain the bug. The new Jet Database Engine is part of Windows Vista and Windows Server 2003 SP2, and it is slated for inclusion in Windows XP SP3, making those operating systems immune to attacks. &lt;/p&gt; &lt;p&gt;Reavey did not provide any additional details on a patch timeline. Last Friday, an MSRC spokesman said a fix might come as a so-called &amp;quot;out-of-band&amp;quot; release -- in other words, before the next scheduled general security update, which is due April 8. &lt;/p&gt; &lt;p&gt;No matter what kind of patch it produces or when it pushes a fix to users, Microsoft can&amp;#39;t change the .mdb file format to make it less dangerous, according to Reavey. &amp;quot;Jet database files (file type .mdb) will remain on the unsafe file type list because they can run code by design,&amp;quot; he noted. &amp;quot;Even if we tried to, we could not secure this file format, it will always present attackers an opportunity to run code.&amp;quot; &lt;/p&gt; &lt;p&gt;Until a patch is released, Reavey repeated advice that both Microsoft and Symantec gave last week: disable Jet or block .mdb files at the gateway. &lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt; &lt;p&gt;Source: &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=windows&amp;amp;articleId=9071660&amp;amp;taxonomyId=125&amp;amp;intsrc=kc_top"&gt;Update: Microsoft admits it knew about, didn&amp;#39;t patch, bugs&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Update: Microsoft admits it knew about, didn't patch, bugs - ComputerWorld.com</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2008/03/26/update-microsoft-admits-it-knew-about-didn-t-patch-bugs-computerworld-com.aspx</link><pubDate>Wed, 26 Mar 2008 04:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:114251</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;h3&gt;&lt;/h3&gt; &lt;div class="article"&gt; &lt;h1&gt;Update: Microsoft admits it knew about, didn&amp;#39;t patch, bugs&lt;/h1&gt; &lt;div class="subhead"&gt;&lt;/div&gt; &lt;div class="storyby"&gt;Gregg Keizer&lt;/div&gt; &lt;div class="thinline"&gt;&lt;/div&gt; &lt;div style="float:right;width:1px;height:130px;"&gt;&lt;/div&gt; &lt;div style="clear:right;padding-right:0px;padding-left:10px;float:right;padding-bottom:10px;padding-top:15px;"&gt; 
document.write(&amp;#39;&amp;#39;);
    &lt;div class="padtop10"&gt;&lt;/div&gt; 

document.write(&amp;#39;&amp;#39;);
    if ((!document.images &amp;amp;&amp;amp; navigator.userAgent.indexOf(&amp;#39;Mozilla/2.&amp;#39;) &amp;gt;= 0)|| navigator.userAgent.indexOf(&amp;quot;WebTV&amp;quot;) &amp;gt;= 0) {document.write(&amp;#39;&lt;a href="http://ad.doubleclick.net/jump/idg.us.cpw.security/index;pos=ezblaster;keyw=printer;tile=8;sz=336x35;keyw=printer;ord=&amp;#39;%20+%20ord%20+%20&amp;#39;?" target="_blank"&gt;&lt;img src="http://ad.doubleclick.net/ad/idg.us.cpw.security/index;pos=ezblaster;keyw=printer;tile=8;sz=336x35;keyw=printer;ord=&amp;#39;%20+%20ord%20+%20&amp;#39;?" width="336" height="35" border="0" alt="" /&gt;&amp;#39;);}  &lt;/div&gt; &lt;p&gt;&lt;b&gt;March 25, 2008&lt;/b&gt; (Computerworld) Microsoft Corp.&amp;#39;s security team today acknowledged that it knew of bugs in its Jet Database Engine as far back as 2005 but did not patch the problems because it thought it had blocked the obvious attack vectors. &lt;/p&gt; &lt;p&gt;A researcher at Symantec Corp. said Microsoft should have fixed the flaws years ago. &lt;/p&gt; &lt;p&gt;In a post to the Microsoft Security Research Center (MSRC) blog &lt;a href="http://blogs.technet.com/msrc/archive/2008/03/24/update-msrc-blog-microsoft-security-advisory-950627.aspx" target="new"&gt;late Monday afternoon&lt;/a&gt;, Mike Reavey, the MSRC&amp;#39;s operations manager, admitted that outside researchers had notified Microsoft in 2005 and 2007 of separate bugs in Jet, a Windows component that provides data access to applications such as Microsoft Access and Visual Basic. &lt;/p&gt; &lt;p&gt;In both cases, Microsoft told the researchers that it would not fix the flaw because it considered users safe. Outlook blocked the .mdb file format from being opened, Exchange servers stripped them from incoming messages and Internet Explorer issued warnings when users clicked on such files, said Reavey as he explained Microsoft&amp;#39;s decision. &lt;/p&gt; &lt;p&gt;But the company hadn&amp;#39;t thought of the attack strategy now being used by hackers. &amp;quot;Everything changed with the discovery of this new attack vector that allowed an attacker to load an .mdb file via opening a Microsoft Word document,&amp;quot; he said. &amp;quot;The previous guidance does not work against this new attack. So that&amp;#39;s why we alerted customers to these attacks and are re-investigating Jet parsing flaws -- this is a new attack vector discovered that we didn&amp;#39;t know about.&amp;quot; &lt;/p&gt; &lt;p&gt;Attackers are, in fact, doing an end run around Outlook, researchers at Symantec said last week. That finding prompted &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=18&amp;amp;articleId=9070840"&gt;Microsoft to issue a security advisory&lt;/a&gt; warning users running Word on Windows 2000, XP and Server 2003 SP1 to take defensive steps. &lt;/p&gt; &lt;p&gt;One researcher said today that Microsoft could have done more -- and done something earlier -- to prevent the sudden scramble for a fix. &lt;/p&gt; &lt;p&gt;&amp;quot;I can&amp;#39;t count the number of times we&amp;#39;ve seen this in the past with a Microsoft product,&amp;quot; said Oliver Friedrichs, a director with Symantec&amp;#39;s security response team. &amp;quot;Clearly, there should have been more concern from Microsoft in the first place. There have been two vulnerabilities, one in 2005 and another in 2007, and both were left unpatched. &lt;/p&gt; &lt;p&gt;&amp;quot;It does draw some concern,&amp;quot; Friedrichs said. &lt;/p&gt; &lt;p&gt;The MSRC is still working out how it wants to patch the vulnerability or whether it can put up more barriers to the now-known Word attack. It may block Word documents from automatically loading .mdb files, Reavey said, or it may replace the version of Jet in Windows 2000, XP and Server 2003 SP1 with a newer edition that doesn&amp;#39;t contain the bug. The new Jet Database Engine is part of Windows Vista and Windows Server 2003 SP2, and it is slated for inclusion in Windows XP SP3, making those operating systems immune to attacks. &lt;/p&gt; &lt;p&gt;Reavey did not provide any additional details on a patch timeline. Last Friday, an MSRC spokesman said a fix might come as a so-called &amp;quot;out-of-band&amp;quot; release -- in other words, before the next scheduled general security update, which is due April 8. &lt;/p&gt; &lt;p&gt;No matter what kind of patch it produces or when it pushes a fix to users, Microsoft can&amp;#39;t change the .mdb file format to make it less dangerous, according to Reavey. &amp;quot;Jet database files (file type .mdb) will remain on the unsafe file type list because they can run code by design,&amp;quot; he noted. &amp;quot;Even if we tried to, we could not secure this file format, it will always present attackers an opportunity to run code.&amp;quot; &lt;/p&gt; &lt;p&gt;Until a patch is released, Reavey repeated advice that both Microsoft and Symantec gave last week: disable Jet or block .mdb files at the gateway. &lt;/p&gt;&lt;/div&gt;&lt;/blockquote&gt; &lt;p&gt;Source: &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=windows&amp;amp;articleId=9071660&amp;amp;taxonomyId=125&amp;amp;intsrc=kc_top"&gt;Update: Microsoft admits it knew about, didn&amp;#39;t patch, bugs&lt;/a&gt;&lt;/p&gt;</description></item><item><title>SANS Internet Storm Center - DST hype</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2007/03/10/sans-internet-storm-center-dst-hype.aspx</link><pubDate>Sat, 10 Mar 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:99805</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=2400"&gt;DST hype&lt;/a&gt; &lt;p&gt;Published: 2007-03-10,&lt;br&gt;Last Updated: 2007-03-10 18:38:01 UTC&lt;br&gt;by Swa Frantzen (Version: 2)  &lt;p&gt;With last minute -pun intended- patches for the DST change being released in the last few days, it's now too late to panic and go about breaking more than what you'll fix.&lt;br&gt;Let's look ahead at what's likely to be going to happen if you are in or are dealing with others in an affected area: &lt;ul&gt; &lt;li&gt;Machines that got patched, including patches for applications keeping their own independent timezone information will likely work without a hick-up.  &lt;li&gt;Home machines missing an update, or not being supported likely will end up on the wrong time, just as the rest of the house, car and phone. Users know how to update the time (well those that aren't owners of VCRs with a perpetual blinking 00:00 on it anyway). Even so, the impact of this will be mostly negligible.  &lt;li&gt;Businesses might have meetings, conf. calls etc where participants end up turning up on the wrong time. Simple reminders and rescheduling can fix this, nothing earth shattering will happen. And if you're working in large international businesses this mess happens more often at every DST change where the different continents don't sync the changes, where the southern hemisphere changes in the other direction etc.  &lt;li&gt;Time sensitive applications in businesses that are still using local time might go wrong. The typical applications there would be logs and access control  &lt;ul&gt; &lt;li&gt;Logs: If you're used to dealing with days that don't have the 2 to 3 hour hour, or -worse- days where 2:30 happens twice, you're well equipped to deal with a log that 's one hour off. Just record when it got straightened out and you'll be fine. If you do need to make changes, out best suggestion is to get rid of local time. UTC rules, it has much less changes (a leap second is about the worst that happens and that can be automated) and it is independent of location, politicians feeling the need to mess with time, and DST changes. &lt;li&gt;Access control: Time based access control can be a bit more tricky but you know if after all the media attention you still don't have a plan "B" you deserve the wrath of people being mad at you for having been waiting for an hour locked out of the building. Even then it's not going not to be all that huge of an issue &lt;/li&gt;&lt;/ul&gt; &lt;li&gt;Time critical systems. Well are you sure they are time critical if you run use local time? UTC rules here without a doubt! &lt;/li&gt;&lt;/ul&gt;That said, I'm sure many of you will enjoy fellow handler John Bambenek appearance on &lt;a href="http://www.comedycentral.com/motherload/index.jhtml?ml_video=83445"&gt;Comedy Central's Daily Show&lt;/a&gt;. Sorry about the ad in front, and it's time limited, so if you want to see it in a few months, it'll likely be a broken link. &lt;p align="center"&gt;&lt;font color="#ff0000"&gt;GEEKS USE UTC&lt;/font&gt; &lt;p&gt;Anyway I've posted a new poll where you can show us you crystal ball skillz. I'll replace it overnight with one where you can tell us how it went. Enjoy!&lt;br&gt;UPDATE&lt;br&gt;Jon wrote in with a story of&amp;nbsp; his supplier of punch-clocks that had needed firmware upgrades for the clocks due to the DST change and the pain he felt due to it: Not only was it hard to update the clocks, but worse the clocks started to skip an hour &lt;em&gt;every day&lt;/em&gt; since they got update. Clearly his vendor didn't get the reasons for proper testing, or more likely ended up in that spot what I was trying to warn about in the first paragraph: "&lt;em&gt;Now [it's] too late to panic and go about breaking more than what you'll fix&lt;/em&gt;". I feel Jon's pain and wish him a speedy recovery of his clocks and the data they collect.&lt;br&gt;--&lt;br&gt;Swa Frantzen -- NET2S&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Source: &lt;a href="http://isc.sans.org/diary.html?storyid=2400&amp;amp;rss"&gt;SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc&lt;/a&gt;&lt;/p&gt;</description></item><item><title>SANS Internet Storm Center - DST hype</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2007/03/10/sans-internet-storm-center-dst-hype.aspx</link><pubDate>Sat, 10 Mar 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:99805</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=2400"&gt;DST hype&lt;/a&gt; &lt;p&gt;Published: 2007-03-10,&lt;br&gt;Last Updated: 2007-03-10 18:38:01 UTC&lt;br&gt;by Swa Frantzen (Version: 2)  &lt;p&gt;With last minute -pun intended- patches for the DST change being released in the last few days, it's now too late to panic and go about breaking more than what you'll fix.&lt;br&gt;Let's look ahead at what's likely to be going to happen if you are in or are dealing with others in an affected area: &lt;ul&gt; &lt;li&gt;Machines that got patched, including patches for applications keeping their own independent timezone information will likely work without a hick-up.  &lt;li&gt;Home machines missing an update, or not being supported likely will end up on the wrong time, just as the rest of the house, car and phone. Users know how to update the time (well those that aren't owners of VCRs with a perpetual blinking 00:00 on it anyway). Even so, the impact of this will be mostly negligible.  &lt;li&gt;Businesses might have meetings, conf. calls etc where participants end up turning up on the wrong time. Simple reminders and rescheduling can fix this, nothing earth shattering will happen. And if you're working in large international businesses this mess happens more often at every DST change where the different continents don't sync the changes, where the southern hemisphere changes in the other direction etc.  &lt;li&gt;Time sensitive applications in businesses that are still using local time might go wrong. The typical applications there would be logs and access control  &lt;ul&gt; &lt;li&gt;Logs: If you're used to dealing with days that don't have the 2 to 3 hour hour, or -worse- days where 2:30 happens twice, you're well equipped to deal with a log that 's one hour off. Just record when it got straightened out and you'll be fine. If you do need to make changes, out best suggestion is to get rid of local time. UTC rules, it has much less changes (a leap second is about the worst that happens and that can be automated) and it is independent of location, politicians feeling the need to mess with time, and DST changes. &lt;li&gt;Access control: Time based access control can be a bit more tricky but you know if after all the media attention you still don't have a plan "B" you deserve the wrath of people being mad at you for having been waiting for an hour locked out of the building. Even then it's not going not to be all that huge of an issue &lt;/li&gt;&lt;/ul&gt; &lt;li&gt;Time critical systems. Well are you sure they are time critical if you run use local time? UTC rules here without a doubt! &lt;/li&gt;&lt;/ul&gt;That said, I'm sure many of you will enjoy fellow handler John Bambenek appearance on &lt;a href="http://www.comedycentral.com/motherload/index.jhtml?ml_video=83445"&gt;Comedy Central's Daily Show&lt;/a&gt;. Sorry about the ad in front, and it's time limited, so if you want to see it in a few months, it'll likely be a broken link. &lt;p align="center"&gt;&lt;font color="#ff0000"&gt;GEEKS USE UTC&lt;/font&gt; &lt;p&gt;Anyway I've posted a new poll where you can show us you crystal ball skillz. I'll replace it overnight with one where you can tell us how it went. Enjoy!&lt;br&gt;UPDATE&lt;br&gt;Jon wrote in with a story of&amp;nbsp; his supplier of punch-clocks that had needed firmware upgrades for the clocks due to the DST change and the pain he felt due to it: Not only was it hard to update the clocks, but worse the clocks started to skip an hour &lt;em&gt;every day&lt;/em&gt; since they got update. Clearly his vendor didn't get the reasons for proper testing, or more likely ended up in that spot what I was trying to warn about in the first paragraph: "&lt;em&gt;Now [it's] too late to panic and go about breaking more than what you'll fix&lt;/em&gt;". I feel Jon's pain and wish him a speedy recovery of his clocks and the data they collect.&lt;br&gt;--&lt;br&gt;Swa Frantzen -- NET2S&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Source: &lt;a href="http://isc.sans.org/diary.html?storyid=2400&amp;amp;rss"&gt;SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Google Apps Premier Edition Takes Aim at the Enterprise - eWeek</title><link>http://myitforum.com/cs2/blogs/cmosby/archive/2007/02/22/google-apps-premier-edition-takes-aim-at-the-enterprise-eweek.aspx</link><pubDate>Thu, 22 Feb 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">8e8f7986-475c-475d-bdc9-a1b3a63b955b:99325</guid><dc:creator>cmosby</dc:creator><description>&lt;p&gt;Hmmm isnt this interesting....&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;Google Apps Premier Edition Takes Aim at the Enterprise &lt;p&gt;By &lt;a href="http://www.eweek.com/author_bio/0,1908,a=2592,00.asp"&gt;John Pallatto&lt;/a&gt;&lt;br&gt;February 22, 2007 &lt;p&gt;After months of testing, Google is ready to see whether businesses large and small are ready to pay to use its online suite of basic business applications, including spreadsheets, e-mail, word processing, calendars and instant messaging.  &lt;p&gt;Google, which has steadily transformed itself from a search engine pioneer into a data access, Internet advertising and business application powerhouse, introduced on Feb. 22 its Google Apps Premier Edition at a cost of $50 per account per year.  &lt;p&gt;The Premier Edition adds Google Docs and Spreadsheets; Gmail for mobile devices on BlackBerry; and application-level controls to Google Calendar, Gmail, Google Talk and Start Page applications that the company introduced as a free service starting in August 2006. &lt;br&gt;&lt;br&gt;While the free applications were initially offered to serve small and midsize companies, the Premier Edition has collaboration and management features that will appeal to companies of all sizes, including large enterprises, said Dave Girouard, vice president and general manager of Google's enterprise group in Mountain View, Calif.  &lt;p&gt;Google Docs and Spreadsheets allow multiple employees to work on the same document simultaneously and the applications keep track of all revisions and edits. The application-level control features allow administrators to set limits on how documents are shared inside and outside an organization.  &lt;p&gt;&lt;u&gt;Click here&lt;/u&gt; to read about the launch of Google's private-label apps start pages. &lt;p&gt;Google is supporting the apps with a 99.9 percent update service-level agreement in which customers will receive credits for downtime. The company is also offering 10GB of storage per user, as well as application programming interfaces to enable data migration, user provisioning and single sign-on, along with mail gateways to allow businesses to customize their e-mail service.  &lt;p&gt;These features are helping to draw interest from large organizations that "have a desire for choice," Girouard said. Google is seeing a "higher level of interest from big company CIOs than we would have expected at the start," he said.  &lt;p&gt;Providing basic business applications, spreadsheets, word processing and e-mail as an online service "is a big opportunity in the market that nobody has taken advantage of yet," he said.  &lt;p&gt;But Girouard denied that the Premier Edition is designed specifically to take market share away from Microsoft Office. Google doesn't believe that enterprise customers will "buy any less Microsoft products" because they decide to use Google Apps. Instead they expect that companies will use Google apps as a supplement to their Microsoft Office applications and to give employees who wouldn't normally have a copy of Microsoft Office on their desktops a chance to use the Google productivity applications online, Girouard said.  &lt;p&gt;Surveys have shown that more than 40 percent of the work force isn't given access to e-mail by their employers, Girouard said. Google Apps could provide an inexpensive way for employers to provide e-mail access to workers in retail or in other industries where people are not normally linked to desktop workstations, he said.  &lt;p&gt;To read Peter Coffee's view on whether Google poses a serious challenge to Microsoft Office, &lt;u&gt;click here.&lt;/u&gt; &lt;p&gt;But analysts said that the Premier Edition poses a long-term challenge to Microsoft, which has garnered huge revenues and profits from selling its Office package for hundreds of dollars a copy plus annual maintenance fees.  &lt;p&gt;"This is the first time there is a compelling, low-cost, service-based alternative to Microsoft Office. And although Google isn't positioning this offering directly against Office, that's where it is headed," said Erica Driver, principal analyst with Forrester Research in Cambridge, Mass.  &lt;p&gt;&lt;b&gt;Next Page: Window of opportunity.&lt;/b&gt; &lt;p&gt;"Microsoft has a couple of years' opportunity to respond to this. But it is certainly an indicator of the direction in which Google is headed. And I fully expect [Google] to add more and more features and capabilities into this suite," Driver said.  &lt;p&gt;In the next few years, said Driver, Google will focus on delivering this service to workers who wouldn't normally have access to Microsoft Office.  &lt;p&gt;"But looking ahead a few years, I see this cutting into Microsoft's revenues and I also see it forcing Microsoft to consider alternative delivery mechanisms for its own products—most noticeably software as a service," she said.  &lt;p&gt;Microsoft is definitely going to have to find a way to respond to the challenge posed by Google Apps over the next five years, said Jim Murphy, research director with AMR Research in Boston.  &lt;p&gt;"It is the beginning of probably the most significant challenge we have seen to Microsoft on the desktop, enterprise or otherwise, in probably 10 years," when it was locked in competition with IBM over the Lotus desktop applications, Murphy said.  &lt;p&gt;What do corporate executives think about Google's chances of cutting into Microsoft's Office and Live business? &lt;u&gt;Find out here.&lt;/u&gt; &lt;p&gt;The introduction of Google Apps is "timely," he said, because enterprises will soon have to decide whether they will upgrade to the latest version of Microsoft Office.  &lt;p&gt;Companies of all sizes will likely experiment with Google Apps before they decide whether to carry out the next Office upgrade. "At least it's going to interest CIOs, and they are going to look at it," Murphy said.  &lt;p&gt;"In five years we'll see a more competitive environment" in the desktop applications market, Murphy said. Microsoft will at least have that much time to decide whether it can use its own experience with the Office Live applications to successfully shift into the software-as-a-service model, he said.  &lt;p&gt;One company that decided to make the shift is Prudential Real Estate Affiliates, a Chicago-area franchise that employees 450 sales agents and support staff. The agency has been using Gmail for nearly a year in place of an outsourced e-mail service that performed so poorly that it had to be replaced, said Camden Daily, the group's technology director.  &lt;p&gt;The agency had already worked with Google on the Google Earth and Maps projects, so it used its Google contacts to join the Gmail beta program. "We went ahead and switched, and basically everybody loved the interface ever since," he said.  &lt;p&gt;Daily said he rarely gets complaints from users saying they can't access the Gmail service or are having trouble learning how to use it.  &lt;p&gt;Using Gmail also saves Daily a lot of time and effort in software installation and maintenance. "We're a pretty big real estate company. But we only have a couple of people in our IT department," he said. Since all software updates and patches will be handled in Google's data center, "if a new a new update comes along, I'm not going to have to walk around and touch 50 machines to install it. I don't have to worry about patches, security problems," Daily said.  &lt;p&gt;There is also a lot of interest among the agency staff in using the Google Calendar, he said. But the agency has been holding off until it finds the right synchronization utility for staffers who want to access the calendar with their BlackBerrys and other smart devices.  &lt;p&gt;Check out eWEEK.com's Enterprise Applications Center for the latest news, reviews and analysis about productivity and business solutions. &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Source: &lt;a href="http://www.eweek.com/article2/0,1895,2097453,00.asp"&gt;Google Apps Premier Edition Takes Aim at the Enterprise&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>