<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; Windows</title>
	<atom:link href="http://www.spamchronicles.com/tag/windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Microsoft Patch Tuesday for July 2007</title>
		<link>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 12:55:43 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-july-2007/</guid>
		<description><![CDATA[It&#8217;s the second Tuesday of July and that means patches from Microsoft. This month brings six patches, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" />It&#8217;s the second Tuesday of July and that means patches from <b>Microsoft</b>. This month brings <b>six patches</b>, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate.</p>
<p>Two of the patches affect <b>Microsoft Office</b> software:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the MS07-036 bulletin at Microsoft">MS07-036</a> is rated <b>critical</b> and affects all versions of <b>Microsoft Excel </b>from Excel 2000 on up. It also applies to the Office 2007 compatibility pack. It&#8217;s only rated critical for Excel 2000. Microsoft rates the other versions as &#8220;important&#8221;. The bulletin does not list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-037.mspx" title="Jump to the MS07-037 bulletin">MS07-037</a> is rated <b>important</b> and affects <b>Microsoft Office Publisher 2007</b> only. The bulletin does not list any known issues.</p>
<p>One patch affects Vista only:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-038.mspx" title="Jump to the MS07-038 bulletin">MS07-038</a> is rated <b>moderate</b> and affects <b>Windows Vista</b>, both 32-bit and 64-bit versions. This patches a vulnerability in the Windows Vista firewall that could allow an attacker to gather information about a host. There are no known issues listed in the bulletin.</p>
<p>One patch affects <b>.NET</b>:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx" title="Jump to the MS07-040 bulletin">MS07-040</a> is rated critical and affects .NET versions 1.x and 2.x, version 3.x is not affected. All operating systems are affected if they have a vulnerable version of .NET installed. There are no known issues listed in the bulletin.</p>
<p>The final desktop patch, <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-041.mspx" title="Jump to the MS07-041 bulletin">MS-07-041</a>, is rated important and affects Microsoft Internet Information Server (IIS) when running on Windows XP SP2. Earlier versions of Windows XP may be affected but Microsoft only supports service pack 2. IIS is not installed by default on Windows XP.</p>
<p>The server patch is is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx" title="Jump to the MS07-039 bulletin">MS07-039</a> and is a vulnerability in Active Directory that&#8217;s rated critical.</p>
<p>The patches are available through automatic update or can be downloaded individually from Microsoft.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for June 2007</title>
		<link>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/</link>
		<comments>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/#comments</comments>
		<pubDate>Wed, 13 Jun 2007 02:26:02 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-june-2007/</guid>
		<description><![CDATA[Microsoft released six security patches today. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches. The four critical desktop patches are: MS07-031 for Windows XP SP2, [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://www.spamchronicles.com/wp-content/uploads/2007/06/ms_security_alert.gif' alt='Microsoft Security Alert'><strong>Microsoft</strong> released <a href="http://www.microsoft.com/technet/security/bulletin/ms07-jun.mspx" title="Jump to the Microsoft announcement bulletin for June">six security patches today</a>. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches.</p>
<p>The four <strong>critical desktop patches</strong> are:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-031.mspx" title="Jump to the bulletin for MS07-031 at Microsoft">MS07-031</a> for Windows XP SP2, Windows XP x64 and Windows XP x64 SP2. It&#8217;s rated as &#8220;important&#8221; for Windows 2000 SP4. Earlier versions of Windows 2000 and XP may be affected but aren&#8217;t supported by Microsoft. On Windows XP this vulnerability can allow remote code execution. On other OS&#8217;s the vulnerability results in a denial of service attack (such as a system crash). The user must visit a malicious website to be exploited.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" title="Jump to the MS07-033 bulletin at Microsoft">MS07-033</a> is the cumulative patch for all versions of Internet Explorer and is critical on all desktop OS&#8217;s that run it. Since this is a cumulative update it carries forward any baggage of earlier issues (like changes in ActiveX control handling). As usual, the most serious vulnerability impact is remote code execution. Six new vulnerabilities are identified in the bulletin some of which allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx" title="Jump to the MS07-034 bulletin at Microsoft">MS07-034</a> is for Windows Mail on Vista (including Vista x64). It is rated &#8220;important&#8221; for Outlook Express 6 on all versions of Windows XP. There are five different vulnerabilities identified. On XP they may disclose information, on Vista they allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/ms07-035.mspx" title="Jump to the MS07-035 bulletin at Microsoft">MS07-035</a> is for all desktop OS&#8217;s except Vista. It&#8217;s not needed on Vista. This allows remote code execution.</p>
<p>The patches are released through Windows Update and are available for individual download.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/" rel="bookmark" class="crp_title">Yahoo Messenger Critical Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec: Hackers Can Bypass Firewall With Windows Update</title>
		<link>http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/</link>
		<comments>http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/#comments</comments>
		<pubDate>Wed, 16 May 2007 03:41:05 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/symantec-hackers-can-bypass-firewall-with-windows-update/</guid>
		<description><![CDATA[Symantec has been in the news recently for saying Microsoft&#8217;s Windows Update can be used to update malware. Specifically, for using BITS (Background Intelligent Transfer Service) to update itself. Some took the headline view when they posted about the story and gave the impression that Windows Update was vulnerable. It makes good headlines to say [...]]]></description>
			<content:encoded><![CDATA[<p>Symantec has been in the news recently for saying Microsoft&#8217;s <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/05/malware_update_with_windows_up.html" title="Jump to the Symantec blog entry on Windows Update and hackers">Windows Update can be used to update malware</a>. Specifically, for using BITS (Background Intelligent Transfer Service) to update itself.</p>
<p>Some took the headline view when they posted about the story and gave the impression that Windows Update was vulnerable. It makes good headlines to say Windows Update can be exploited. Plus Symantec has been complaining about Microsoft getting into the security software business.</p>
<p>Windows Update itself isn&#8217;t vulnerable. The trojan has to get on the PC in some other way, such as email. Then, once it&#8217;s on the PC it modifies BITS. Since BITS is on every Windows XP SP2 and Vista PC it&#8217;s a known target so it&#8217;s a good selection to attack. But any application which is allowed through the firewall could be exploited in the same way.</p>
<p>It&#8217;s not a reason to stop using Windows Update. The patches are needed to keep the exploits from getting on the PC in the first place. Once an piece of malware is on the PC it&#8217;s difficult to keep it from changing any system resources it has access to. Hopefully Microsoft will come up with a way to make Windows Update more secure despite this and they should do all they can since it&#8217;s part of the operating system. But keeping malware off the PC in the first place is the main problem. Once malware is on the PC is the biggest concern really that BITS can then be exploited so the malware can update itself?</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/29/google-getting-into-malware-detection/" rel="bookmark" class="crp_title">Google Getting Into Malware Detection</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/04/18/annoying-antivirus-software/" rel="bookmark" class="crp_title">Annoying Antivirus Software</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2007 Patch Tuesday</title>
		<link>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/</link>
		<comments>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/#comments</comments>
		<pubDate>Wed, 09 May 2007 01:34:18 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[ms-office-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/may-2007-patch-tuesday/</guid>
		<description><![CDATA[Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. Mac users also take notice since Office 2004 for the Mac is also vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. <strong>Mac</strong> users also take notice since <strong>Office 2004 for the Mac </strong>is also vulnerable and needs patching.</p>
<p><a title="Jump to the Microsoft Bulletin for MS07-023" href="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</a> is for Office, specifically Microsoft Excel. All versions from 2000-2007 are affected as-is the Excel viewers and compatibility packs. Office 2004 for Mac is also vulnerable and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-024" href="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">MS07-024</a> is also for Office, this time it&#8217;s for Word. The patch is NOT needed for the latest version, Word 2007. But it&#8217;s needed for all versions from 2000-2003 and Office 2004 for Mac. The Word viewer also needs updating, Microsoft Works 2004, 2005 and 2006 are also vulnerable and needs updating.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx">MS07-025</a> is another Office patch. and affects every version from 2000-2007 along with all the viewers and compatibility packs. Office 2004 for Mac is also affected and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-027" href="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</a> is the cumulative update for Internet Explorer. All supported versions of Internet Explorer on all supported operating systems are affected and needs to be updated.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-028" href="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx">MS07-028</a> is a patch for CAPCOM which is the &#8220;Cryptographic API Component Object Model&#8221;. CAPCOM is an Active X control that allows scriptors (VBS, ASP, etc&#8230;) he ability to encrypt data. It&#8217;s part of the Biztalk servers but may be installed by other software. My Windows XP SP2 machine needed the update, other systems may not need it.</p>
<p>You can get the updates through Windows Update. The links above will also bring you to the bulletins at the Microsoft site. I applied the updates to Windows XP SP2 and Vista without a problem. I don&#8217;t run any versions of Office at home so I can&#8217;t try those updates. There aren&#8217;t any compatibility warnings in the bulletins. </p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>News Report: Microsoft OneCare Flunks Virus Test</title>
		<link>http://www.spamchronicles.com/2007/04/18/news-report-microsoft-onecare-flunks-virus-test/</link>
		<comments>http://www.spamchronicles.com/2007/04/18/news-report-microsoft-onecare-flunks-virus-test/#comments</comments>
		<pubDate>Thu, 19 Apr 2007 03:40:32 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/anti-virus/news-report-microsoft-onecare-flunks-virus-test/</guid>
		<description><![CDATA[Beta News is reporting that Microsoft acknowledged that their Microsoft Onecare product flunked the Anti-virus tests given by the Virus Bulletin in February. From the article&#8230; &#8220;We are looking closely at the methodology and results of the test to ensure that Windows Live OneCare performs better in future tests,&#8221; the Microsoft spokesperson told us, &#8220;and, [...]]]></description>
			<content:encoded><![CDATA[<p>Beta News is <a href="http://www.betanews.com/article/Microsoft_Acknowledges_Vista_AntiVirus_Failed_VB100_Test/1170809025" title="Jump to the BetaNews article about Microsoft OneCare failing the tests">reporting</a> that Microsoft acknowledged that their Microsoft Onecare product flunked the Anti-virus tests given by the <a href="http://www.virusbtn.com/index" title="Jump to the Virus Bulletin website">Virus Bulletin</a> in February.</p>
<p>From the article&#8230;</p>
<blockquote><p>&#8220;We are looking closely at the methodology and results of the test to ensure that Windows Live OneCare performs better in future tests,&#8221; the Microsoft spokesperson told us, &#8220;and, most importantly, as part of our ongoing work to continually enhance Windows Live OneCare to ensure the highest level of protection and service that we can provide our customers.&#8221;  </p></blockquote>
<p>BetaNews also reported that McAfee&#8217;s VirusScan Enterprise 8.1 flunked the test.</p>
<p>The February testing was done on Windows Vista. Virus Bulletin is a respected virus test organization. The test agains in the wild viruses. Their test procedure is documented <a href="http://www.virusbtn.com/vb100/about/100procedure.xml" title="Jump to the Virus Bulletin page about their test procedure.">here</a>. As for software that past the test, Beta news reported they were&#8230;</p>
<blockquote><p>&#8230;both CA&#8217;s Home and eTrust (enterprise) products, Fortinet&#8217;s FortiClient, F-Secure Anti-Virus, Kaspersky Anti-Virus 6.0 (which was added to the ZoneAlarm suite last November), Sophos Anti-Virus 6.5, and Symantec AntiVirus 10.2</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/29/summary/" rel="bookmark" class="crp_title">Spam Counts and Summary</a></li><li><a href="http://www.spamchronicles.com/2007/04/23/viruses-spam-and-software-updates-2/" rel="bookmark" class="crp_title">Viruses, Spam and Software Updates</a></li><li><a href="http://www.spamchronicles.com/2007/04/11/grisoft-avg-releases-free-anti-rootkit/" rel="bookmark" class="crp_title">Grisoft AVG Releases Free Anti-Rootkit</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/" rel="bookmark" class="crp_title">Symantec: Hackers Can Bypass Firewall With Windows Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/04/18/news-report-microsoft-onecare-flunks-virus-test/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Patch for Animated Cursor Vulnerability</title>
		<link>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/</link>
		<comments>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/#comments</comments>
		<pubDate>Tue, 03 Apr 2007 20:00:04 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-releases-patch-for-animated-cursor-vulnerability/</guid>
		<description><![CDATA[Microsoft has released a patch for the animated cursor vulnerability. The bulletin is MS07-017. They also address six other vulnerabilities in the Graphics Rendering Engine (GDI), although none are rated critical. They make a note of an known issue with the Realtek HD Audio Control Panel (Rthdcpl.exe) on Windows XP SP2 which is documented here. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released a patch for the <a href="http://www.spamchronicles.com/windows/windows-pc-have-cursor-hole/" title="Jump to my original posting on the vulnerability">animated cursor vulnerability</a>. The bulletin is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx" title="Jump to the bulletin on the Microsoft website">MS07-017</a>.</p>
<p>They also address six other vulnerabilities in the Graphics Rendering Engine (GDI), although none are rated critical.</p>
<p>They make a note of an known issue with the <strong>Realtek HD Audio Control Panel</strong> (Rthdcpl.exe) on Windows XP SP2 which is documented <a href="http://support.microsoft.com/kb/935448/" title="Jump to the Microsoft document on this issue.">here</a>.</p>
<p>The Microsoft bulletin for &#8220;home users&#8221; is <a href="http://www.microsoft.com/athome/security/update/bulletins/200704oob.mspx" title="Jump to the Microsoft bulletin for home users">here</a>.</p>
<p>The Microsoft bulletin fot &#8220;technical users&#8221; is <a href="http://www.microsoft.com/technet/security/bulletin/ms07-017.mspx" title="Jump to the Microsoft bulltin for technical users.">here</a>.</p>
<p>As usual, the patch will be in Windows update.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows PC Have Cursor Hole</title>
		<link>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/</link>
		<comments>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/#comments</comments>
		<pubDate>Sun, 01 Apr 2007 01:58:32 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/windows/windows-pc-have-cursor-hole/</guid>
		<description><![CDATA[Microsoft released a security advisory about a flaw in animated cursors which would allow drive-by installs. Windows 2000 SP4 and all recent operating systems are affected, including Vista. IE 7 running on Vista would be protected by a drive-by install if is it running in protected mode. Also, Outlook 2007 uses Word to display messages [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released a <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx" title="Microsoft Security Advisory 935423">security advisory</a> about a flaw in animated cursors which would allow drive-by installs. Windows 2000 SP4 and all recent operating systems are affected, including Vista. IE 7 running on Vista would be protected by a drive-by install if is it running in <a href="http://www.microsoft.com/windows/products/windowsvista/features/details/IE7protectedmode.mspx" title="Info on protected mode from Microsoft's website">protected mode</a>. Also, Outlook 2007 uses Word to display messages in preview so it would not be vulnerable.</p>
<p>The only real protection from this vulnerability would be for Microsoft to release a patch. The next &#8220;patch Tuesday&#8221; is April 10th. [Updated 4/2: Microsoft has said they will release a patch on Tuesday 4/3]</p>
<p>There&#8217;s also a significant impact within e-mail. The microsoft security bulliten mentions e-mail as a method to exploit the vulnerabilty.</p>
<blockquote><p><strong>What might an attacker use this function to do?</strong><br />
An attacker could try to exploit the vulnerability by creating a specially crafted web page. An attacker could also create a specially-crafted email message and send it to an affected system. Upon viewing a web page, previewing or reading a specially crafted message, or opening a specially crafted email attachment the attacker could cause the affected system to execute code. While animated cursors typically are associated with the .ani file extension, a successful attack is not constrained by this file type.</p></blockquote>
<p><span id="more-20"></span></p>
<p>Even previewing the mail message in an preview pane could infect the machine. (See below for exceptions to this)</p>
<p>Microsofts recommendation for e-mail is: </p>
<blockquote><p>Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors. When a workaround reduces functionality, it is identified in the following section. </p>
<p>• Read e-mail messages in plain text format if you are using Outlook 2002 or a later version, or Windows Mail to help protect yourself from the HTML e-mail preview attack vector. Microsoft Outlook 2002 users who have applied Office XP Service Pack 1 or a later version can enable this setting and view e-mail messages that are not digitally signed or e-mail messages that are not encrypted in plain text only.</p>
<p>Caveat: Reading e-mail in plain text on Windows Vista Mail does not mitigate attempts to exploit the vulnerability when Forwarding and Replying to mail sent by an attacker.</p>
<p>Note: Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability. Impact of Workaround: E-mail messages that are viewed in plain text format will not contain pictures, specialized fonts, animations, or other rich content. Additionally:</p>
<p>• The changes are applied to the preview pane and to open messages.</p>
<p>• Pictures become attachments so that they are not lost.</p>
<p>• Because the message is still in Rich Text or HTML format in the store, the object model (custom code solutions) may behave unexpectedly.</p></blockquote>
<p>Microsoft makes the usual recommendations of not reading e-mail from a source you don&#8217;t know. But addresses can be spoofed or faked so any vulnerabity like this (where just viewing the message could infect the pc is a problem). Turnng off the preview pane will prevent accidents. There&#8217;s really isn&#8217;t any protection until Microsoft releases a patch.</p>
<p>Here&#8217;s a video of what happens when the vulnerability is used for a DoS attack on a PC (video via <a href="http://uneasysilence.com/archive/2007/03/10132/" title="Jump to the article with the video on UneasySilence">UneasySilence</a>):</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
