<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; ie-security-patch</title>
	<atom:link href="http://www.spamchronicles.com/tag/ie-security-patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Microsoft Patch Tuesday for July 2007</title>
		<link>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 12:55:43 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-july-2007/</guid>
		<description><![CDATA[It&#8217;s the second Tuesday of July and that means patches from Microsoft. This month brings six patches, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" />It&#8217;s the second Tuesday of July and that means patches from <b>Microsoft</b>. This month brings <b>six patches</b>, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate.</p>
<p>Two of the patches affect <b>Microsoft Office</b> software:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the MS07-036 bulletin at Microsoft">MS07-036</a> is rated <b>critical</b> and affects all versions of <b>Microsoft Excel </b>from Excel 2000 on up. It also applies to the Office 2007 compatibility pack. It&#8217;s only rated critical for Excel 2000. Microsoft rates the other versions as &#8220;important&#8221;. The bulletin does not list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-037.mspx" title="Jump to the MS07-037 bulletin">MS07-037</a> is rated <b>important</b> and affects <b>Microsoft Office Publisher 2007</b> only. The bulletin does not list any known issues.</p>
<p>One patch affects Vista only:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-038.mspx" title="Jump to the MS07-038 bulletin">MS07-038</a> is rated <b>moderate</b> and affects <b>Windows Vista</b>, both 32-bit and 64-bit versions. This patches a vulnerability in the Windows Vista firewall that could allow an attacker to gather information about a host. There are no known issues listed in the bulletin.</p>
<p>One patch affects <b>.NET</b>:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx" title="Jump to the MS07-040 bulletin">MS07-040</a> is rated critical and affects .NET versions 1.x and 2.x, version 3.x is not affected. All operating systems are affected if they have a vulnerable version of .NET installed. There are no known issues listed in the bulletin.</p>
<p>The final desktop patch, <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-041.mspx" title="Jump to the MS07-041 bulletin">MS-07-041</a>, is rated important and affects Microsoft Internet Information Server (IIS) when running on Windows XP SP2. Earlier versions of Windows XP may be affected but Microsoft only supports service pack 2. IIS is not installed by default on Windows XP.</p>
<p>The server patch is is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx" title="Jump to the MS07-039 bulletin">MS07-039</a> and is a vulnerability in Active Directory that&#8217;s rated critical.</p>
<p>The patches are available through automatic update or can be downloaded individually from Microsoft.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for June 2007</title>
		<link>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/</link>
		<comments>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/#comments</comments>
		<pubDate>Wed, 13 Jun 2007 02:26:02 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-june-2007/</guid>
		<description><![CDATA[Microsoft released six security patches today. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches. The four critical desktop patches are: MS07-031 for Windows XP SP2, [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://www.spamchronicles.com/wp-content/uploads/2007/06/ms_security_alert.gif' alt='Microsoft Security Alert'><strong>Microsoft</strong> released <a href="http://www.microsoft.com/technet/security/bulletin/ms07-jun.mspx" title="Jump to the Microsoft announcement bulletin for June">six security patches today</a>. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches.</p>
<p>The four <strong>critical desktop patches</strong> are:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-031.mspx" title="Jump to the bulletin for MS07-031 at Microsoft">MS07-031</a> for Windows XP SP2, Windows XP x64 and Windows XP x64 SP2. It&#8217;s rated as &#8220;important&#8221; for Windows 2000 SP4. Earlier versions of Windows 2000 and XP may be affected but aren&#8217;t supported by Microsoft. On Windows XP this vulnerability can allow remote code execution. On other OS&#8217;s the vulnerability results in a denial of service attack (such as a system crash). The user must visit a malicious website to be exploited.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" title="Jump to the MS07-033 bulletin at Microsoft">MS07-033</a> is the cumulative patch for all versions of Internet Explorer and is critical on all desktop OS&#8217;s that run it. Since this is a cumulative update it carries forward any baggage of earlier issues (like changes in ActiveX control handling). As usual, the most serious vulnerability impact is remote code execution. Six new vulnerabilities are identified in the bulletin some of which allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx" title="Jump to the MS07-034 bulletin at Microsoft">MS07-034</a> is for Windows Mail on Vista (including Vista x64). It is rated &#8220;important&#8221; for Outlook Express 6 on all versions of Windows XP. There are five different vulnerabilities identified. On XP they may disclose information, on Vista they allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/ms07-035.mspx" title="Jump to the MS07-035 bulletin at Microsoft">MS07-035</a> is for all desktop OS&#8217;s except Vista. It&#8217;s not needed on Vista. This allows remote code execution.</p>
<p>The patches are released through Windows Update and are available for individual download.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/" rel="bookmark" class="crp_title">Yahoo Messenger Critical Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2007 Patch Tuesday</title>
		<link>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/</link>
		<comments>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/#comments</comments>
		<pubDate>Wed, 09 May 2007 01:34:18 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[ms-office-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/may-2007-patch-tuesday/</guid>
		<description><![CDATA[Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. Mac users also take notice since Office 2004 for the Mac is also vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. <strong>Mac</strong> users also take notice since <strong>Office 2004 for the Mac </strong>is also vulnerable and needs patching.</p>
<p><a title="Jump to the Microsoft Bulletin for MS07-023" href="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</a> is for Office, specifically Microsoft Excel. All versions from 2000-2007 are affected as-is the Excel viewers and compatibility packs. Office 2004 for Mac is also vulnerable and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-024" href="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">MS07-024</a> is also for Office, this time it&#8217;s for Word. The patch is NOT needed for the latest version, Word 2007. But it&#8217;s needed for all versions from 2000-2003 and Office 2004 for Mac. The Word viewer also needs updating, Microsoft Works 2004, 2005 and 2006 are also vulnerable and needs updating.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx">MS07-025</a> is another Office patch. and affects every version from 2000-2007 along with all the viewers and compatibility packs. Office 2004 for Mac is also affected and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-027" href="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</a> is the cumulative update for Internet Explorer. All supported versions of Internet Explorer on all supported operating systems are affected and needs to be updated.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-028" href="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx">MS07-028</a> is a patch for CAPCOM which is the &#8220;Cryptographic API Component Object Model&#8221;. CAPCOM is an Active X control that allows scriptors (VBS, ASP, etc&#8230;) he ability to encrypt data. It&#8217;s part of the Biztalk servers but may be installed by other software. My Windows XP SP2 machine needed the update, other systems may not need it.</p>
<p>You can get the updates through Windows Update. The links above will also bring you to the bulletins at the Microsoft site. I applied the updates to Windows XP SP2 and Vista without a problem. I don&#8217;t run any versions of Office at home so I can&#8217;t try those updates. There aren&#8217;t any compatibility warnings in the bulletins. </p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
