
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security Bulletin
Revisions
Issued: June 24, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS07-042 - Critical
Bulletin Information:
=====================
* MS07-042 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
- Reason for Revision: V4.0 (June 24, 2008): Bulletin updated:
Added Windows XP Service Pack 3, Windows Vista Service Pack
1, Windows Vista x64 Edition Service Pack 1, Windows Server
2008 for 32-bit Systems, Windows Server 2008 for x64-based
Systems, and Windows Server 2008 for Itanium-based Systems as
affected software. This is a detection update only. There
were no changes to the binaries.
- Originally posted: August 14, 2007
- Updated: June 24, 2008
- Bulletin Severity Rating: Critical
- Version: 4.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBSGFOLVKuubOIpnsTAQLAhg/+LFjneZqKtfw1ZQF/4nWHEFmk58kCp/ha
Xzg4Sfb8QeAT//8Ed1bByC5MuAw7BfgIllvFOQ/8qHYgqeQRL32qTwlfSicJNlZL
PgCnA/V2fCn62gtSJUpTFFPF+bVcByInpeMeAtSWVPg8TBdt1N+xcgdVhMVKeJ/V
8Wmb5SnxTIK/PrnRJmDaWJWvKW7kwOtxzaejZJiJJdNeFZxKQdjT4gwe/q0/9Ew4
6+Msf/NVloI15A+DkKXGcpYKAP2g2Yi8cStHxW/VkUxMDgedKLpC6sep8yPU1aTR
sy6E/rjTZT1Vj0wZ2mXu3p0w82RluWdb9ss6plrPq+0SXQL6vX1WR6AIsWcEakFv
Praa5UHjj+uKPweOqIwANRqfLK8zT6bPDMJx0/E7DXE/aDzfZ17pTB2U5SDufwvq
zsq7cfn9fDQh0IFle7XVeIxm7NCofbB31ZK0VH2FFllW2Rhjv/PGxidmTTWFYUBB
XhFISjrXZyKmy9y9gT3cD1u9U7U7RdC4281Qi2EkXP1IOG7PJ2pjbEh6lrEeIBSX
FLlYlY8f1++Lr4pMvVSnNoY7zj6ynM5S71abT4L0ltO/nOR/QYAMQvILQ8FEv3xt
wYlQkT5C63IRLeZZA8P+gFy4tYtagbIXaWdZzYb/FcCVqkIhLUCL8ryFpKcVKxaB
L+HkjLd0wpE=
=tMmb
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Re-Releases
Issued: June 19, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS08-030 - Critical
Bulletin Information:
=====================
* MS08-030 - Critical
-
http://www.microsoft.com/technet/security/bulletin/ms08-030.mspx
- Reason for Revision: V2.0 (June 18, 2008): Added "Why was this
security update reoffered on June 18, 2008?" entry to the
Update FAQ to advise customers running Windows XP Service
Pack 2 and Windows XP Service Pack 3 that a revised version
of the security update is available.
- Originally posted: June 10, 2008
- Updated: June 19, 2008
- Bulletin Severity Rating: Critical
- Version: 2.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBSFqRNlKuubOIpnsTAQKz8A/+LVfgzi+xaz93Tw9udy/B7ROTztHNi+uc
K8CGT8xSvXDlAnJJkLXS4f2dBymuECb5fxWOXTUlkMVv+HkIkbMObY6gC0ggZrn8
3K0B30UsIn7zBntXbDBht+hifJOeqv2eGWCB5cLLd3asoNtUQxwPZp2O3mmOb22i
7KZ/TZadDweBfKr1k9XsU/VigwSWvi+neGc5WpiMNsMP7dEskmPz1rlwVFuBO32U
sISpzeVMcaoC8eyPYf/+ofncXERux8IM00IkNalOD32U+HCMiI8I7mDPRx0JDDUY
Nmqy474nFAcxtDZwv/uuXsyb7QdNvywD2taBZiewG/u4JFSE2HK2vS8P8Yk47rVK
difqy/gKhPLs4CT0Zr3XlQrZLLqXrFVbKNkkPsvjb66TgGwTtD303oZDeNNesB8F
3ZWdYBGdJ+kwz7v7gld+rsFkEd3om5DgRGj7vPeZLVpocHeTR39brWNcj/puUHLP
p5BQ+OmIzFcBgzuiEvsMwcEG2YjbYwhvkXpjCEltJPyUEuml3Exar8aK/8TYA7ZU
Xy25pUE2CK8Ukq1PB5oCbRA22YPaX6iH/D4CQQmWc/vlyjGJBPQeeL/zf8lStgQD
U8IGwwRDQD4eIGi8Ff9Q+PtgCfTfSmDRY6F/GUVQOPUkuQq4FbO59MG5LxrPeqTb
ESHQPEIAhBY=
=8BuF
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Major Revisions
Issued: June 18, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS06-078
Bulletin Information:
=====================
* MS06-078
- http://www.microsoft.com/technet/security/bulletin/ms06-078.mspx
- Reason for Revision: V6.0 (June 18, 2008): Bulletin updated to
remove Microsoft Windows XP Service Pack 3 from the Affected
Software list for Microsoft Windows Media Player 6.4 and to
add Microsoft Windows Media Player 6.4 when installed on
Microsoft Windows XP Service Pack 3 to the Non-Affected
Software list.
- Originally posted: December 12, 2006
- Updated: June 18, 2008
- Bulletin Severity Rating: Critical
- Version: 6.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBSFlbJlKuubOIpnsTAQKwmQ/9HFaTcZKMW5v5oVaQrhd04OO9Owf+8BkF
IIwHFU4DAq8FQUkOFjhJOCDixukbwBYXcMfSF1z6JaVFAXsCdJhgYfKOd43jT6Ii
I4szka3g0PV4/besZ64lXZdmgGylZtaVyKWUoDI4fMYolN2oS5fqok6rXHI64R5/
Ur/h1ykBToX65UFsFlH5YItEfNW8WSUfEP/TiY7+P+BfgkHhujRcWo0sCjgvy1kk
qJf0RJ9khwqVHUMEZXwSq3tkWqAc78yZvBsR1a9TB70UNuiaF9C3JDIAH5KXgs1o
7sA8a7xeS35JFjm1qsb9tg0NmPQDHUCE0VD3gaa6Rjr5YfglkpvrNHxd0VfmWGW1
uHDpMUIJaJ/5B6Uw2xT0eBrKJ0EBYbZg+DvMlsvGTB1WlyO+SBepUrJuV1Zwn88t
lSNWwMRR9jKqxmXOasOX6ldiVfu3zrVm3sObDvjjHkLhtUX1hAmS+9a8I6y88yY1
vJgVvGVZA9jRuSpm2HqQm8Lh+yVIcgj6NeD1oWi5jSAQat26RD+So58+McpJj1aL
5dq8rnVXxBPINuUylrPOSea3emQPxKidk5qC8gn176ILhmTUta3wvGGpcVTyTz8+
l2J/tpU2KrIGwkenJGWCrlRTV4Xxhk6yB1hbeF/yogE3xojzHJSoiLez8G5ZW+e8
Fc4zQRXHmr0=
=5A5/
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Revisions
Issued: April 22, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS08-024 - Critical
* MS07-040 - Critical
Bulletin Information:
=====================
* MS08-024 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms08-024.mspx
- Reason for Revision: V2.0 (April 22, 2008): Added Internet
Explorer 7 for Windows XP Service Pack 3 and Internet
Explorer 7 for Windows XP x64 Edition Service Pack 3 to
affected software.
- Originally posted: April 8, 2008
- Updated: April 22, 2008
- Bulletin Severity Rating: Critical
- Version: 2.0
* MS07-040 - Critical
-
http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx
- Reason for Revision: V3.0 (April 22, 2008): Bulletin updated:
Added .NET Framework 1.0 (KB928367), .NET Framework 1.1
(KB928366), and .NET Framework Version 2.0 (KB928365) as
affected components for Windows XP Service Pack 3 and Windows
XP Professional x64 Edition Service Pack 3. This is a
detection update only. There were no changes to the binaries.
- Originally posted: July 10, 2007
- Updated: April 22, 2008
- Bulletin Severity Rating: Critical
- Version: 3.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBSA5vrlKuubOIpnsTAQI8sg//cLjwsNfpkD2IoXAwYeGJnU2KFcpS2eod
b2bOwmruUTgAHX3xblWJxZQZYxMcQZOfOi4zSyaMSxZB9NelkyTyiY1DWXuJftMq
hbg95+nSXZk/7HID5X8kUlYzmI8NTGFTjS83R673rMFsnurnHF6DY22paAy6hUdv
Ffzo4tZ0uDqRfiMXeMGYajnUPy8sZaeOOMiypIoz5bnTReW0H7/HQLRY4cL4Oqp0
60OPDa0eVFhVa9TBQTyilm29eGX019eP1XQp1/4tbPd3i6e+z4UZgV7y7lF6Oejw
N5bvvQtKbvmG3TCkV8+2oYzp31GwdS8eeTowYKt0O5x7fqskNx9lbI51eBnbhuMf
0cQjHG6f9sOulAnTWzNXMbdvDt32wHli4vl5ia2nhFU6C/HHPaKRxYJNOIiLSmCf
erNwLuyL8fIPWaj8cbvGQ3I6xs5B4zzQ9pvff1mxMvtXzqEfdyOiSg8X5v/hGYH6
nX+YNkRpkpOGwg+cyq2M6bzXTq6UotPLz3uKIN30ffmm+2HZruWUtx/ZLD+5F3rO
Q3mE6ZL5M5KPk9Mon4manbfRXtgnZVHfOZpSJPQ4Xv+cXKrCSL+SKlGk/pVyA0Sr
9Iiq73uiWGAnBykGI2y8/kUp8nCt+q/1vj3HZRVmHN3eeCabhAy/m5Rk4/Q2YKFE
7t4Zdml95b8=
=sQHH
-----END PGP SIGNATURE-----
To cancel your subscription to this newsletter, reply to this
message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe
at the Microsoft.com web site <http://www.microsoft.com/misc/unsubscribe.htm>.
You can manage all your Microsoft.com communication preferences at this site.
Legal Information
<http://www.microsoft.com/info/legalinfo/default.mspx>.
This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052
Scanned By Sophos PureMessage
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Microsoft Security
Bulletin Summary for April 2008
Issued: April 8, 2008
********************************************************************
This bulletin summary lists security bulletins released for
April 2008.
The full version of the Microsoft Security Bulletin Summary
for April 2008 can be found at http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx.
With the release of the bulletins for April 2008, this
bulletin summary replaces the bulletin advance notification originally issued on
April 3, 2008. For more information about the bulletin advance notification
service, see http://www.microsoft.com/technet/security/Bulletin/advance.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
Microsoft will host a webcast to address customer questions on
these bulletins on Wednesday, April 9, 2008, at 11:00 AM Pacific Time (US &
Canada). Register for the April Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.
Microsoft also provides information to help customers
prioritize monthly security updates with any non-security, high-priority updates
that are being released on the same day as the monthly security updates. Please
see the section, Other Information.
Critical Security Bulletins
===========================
Microsoft Security Bulletin MS08-018
- Affected Software:
- Microsoft Project 2000 Service Release 1
- Microsoft Project 2002 Service Pack 1
- Microsoft Project 2003 Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-021
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and Windows XP
Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and Windows Server 2003
Service Pack 2
- Windows Server 2003 x64 Edition and Windows Server 2003 x64
Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista and Windows Vista Service Pack 1
- Windows Vista x64 Edition and Windows Vista x64 Edition
Service Pack 1
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for Itanium-based Systems
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-022
- Affected Software:
- VBScript 5.1 and JScript 5.1 on Microsoft Windows 2000 Service
Pack 4
- VBScript 5.6 and JScript 5.6 on Microsoft Windows 2000 Service
Pack 4
- VBScript 5.6 and JScript 5.6 on Windows XP Service Pack 2
- VBScript 5.6 and JScript 5.6 on Windows XP Professional x64
Edition and Windows XP Professional x64 Edition Service Pack 2
- VBScript 5.6 and JScript 5.6 on Windows Server 2003 Service
Pack 1 and Windows Server 2003 Service Pack 2
- VBScript 5.6 and JScript 5.6 on Windows Server 2003 x64
Edition and Windows Server 2003 x64 Edition Service Pack 2
- VBScript 5.6 and JScript 5.6 on Windows Server 2003 with SP1
for Itanium-based Systems and Windows Server 2003 with SP2 for
Itanium-based Systems
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-023
- Affected Software:
- Microsoft Internet Explorer 5.01 Service Pack 4
- Microsoft Internet Explorer 6 Service Pack 1
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and Windows XP
Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and Windows Server 2003
Service Pack 2
- Windows Server 2003 x64 Edition and Windows Server 2003 x64
Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista and Windows Vista Service Pack 1
- Windows Vista x64 Edition and Windows Vista x64 Edition
Service Pack 1
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for Itanium-based Systems
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-024
- Affected Software:
- Internet Explorer 5.01 Service Pack 4 on Microsoft Windows
2000 Service Pack 4
- Internet Explorer 6 Service Pack 1 when installed on Microsoft
Windows 2000 Service Pack 4
- Internet Explorer 6 for Windows XP Service Pack 2
- Internet Explorer 6 for Windows XP Professional x64 Edition
and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 6 for Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Internet Explorer 6 for Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 6 for Windows Server 2003 with SP1 for
Itanium-based Systems and Windows Server 2003 with SP2 for
Itanium-based Systems
- Internet Explorer 7 for Windows XP Service Pack 2
- Internet Explorer 7 for Windows XP Professional x64 Edition
and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Internet Explorer 7 for Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Server 2003 with SP1 for
Itanium-based Systems and Windows Server 2003 with SP2 for
Itanium-based Systems
- Internet Explorer 7 in Windows Vista and Windows Vista Service
Pack 1
- Internet Explorer 7 in Windows Vista x64 Edition and Windows
Vista x64 Edition Service Pack 1
- Internet Explorer 7 in Windows Server 2008 for 32-bit Systems
- Internet Explorer 7 in Windows Server 2008 for x64-based
Systems
- Internet Explorer 7 in Windows Server 2008 for Itanium-based
Systems
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================
Microsoft Security Bulletin MS08-020
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and Windows XP
Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and Windows Server 2003
Service Pack 2
- Windows Server 2003 x64 Edition and Windows Server 2003 x64
Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64 Edition
- Impact: Spoofing
- Version Number: 1.0
Microsoft Security Bulletin MS08-025
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 2
- Windows XP Professional x64 Edition and Windows XP
Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and Windows Server 2003
Service Pack 2
- Windows Server 2003 x64 Edition and Windows Server 2003 x64
Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista and Windows Vista Service Pack 1
- Windows Vista x64 Edition and Windows Vista x64 Edition
Service Pack 1
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for Itanium-based Systems
- Impact: Elevation of Privilege
- Version Number: 1.0
Microsoft Security Bulletin MS08-019
- Affected Software:
- Microsoft Visio 2002 Service Pack 2
- Microsoft Visio 2003 Service Pack 2
- Microsoft Visio 2003 Service Pack 3
- Microsoft Visio 2007
- Microsoft Visio 2007 Service Pack 1
- Impact: Remote Code Execution
- Version Number: 1.0
Other Information
=================
Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows Malicious
Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update
Services, and the Download Center.
Non-Security, High-Priority Updates on MU, WU, and WSUS:
========================================================
Please see:
* http://support.microsoft.com/kb/894199: Microsoft Knowledge Base
Article 894199, Description of Software Update Services and
Windows Server Update Services changes in content for 2008.
Includes all Windows content.
* http://technet.microsoft.com/en-us/wsus/bb466214.aspx: New,
Revised, and Released Updates for Microsoft Products Other Than
Microsoft Windows
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, PGP is not required for
reading security notifications, reading security bulletins, or installing
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS"
WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS
OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS
SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR/uWjVKuubOIpnsTAQKZRg/+Jhezih/d6FwKRKF8ABJgbCbJU0hjHecR
oLo0c+oDXdB7EfWbYxnAT0Er7oyqXeqHJQ/t7lkcPoKVYKgqlinJgRacxmqe5/RX
VLvYc24op1uEBSCBS4n/e1voqjs+j7s63gneSROS0PEzfWJMub2YVieEB/DGQlmP
lY1FVl4DApLnmwTywzyl23Jo13NdKbUzeRJXZ11MMNrZqKS5khuG+F7bcgmt4auW
AjWSbSt5wP3UutJcCiCFlmfiTxEtC3VTcuiz0FleD1JZ1uROsbyHPGqdmbepgxxw
XDHv2E4ejvvqrnBd2mpNy01OnkbEpgMbNIUfZZLApd10SqdQgUfaITd1bRBagTeS
kwq/WxruQc58rzc3rn26g0V3wlfMIfDDy9Np6imOR+SgPGD6c4g/xO9yjhTd86s/
MzUoQqXw+5nucL2YB4g7Zz6UGpB6RkCY9DWNRgNPivl3kzg8vgu7j885ApayJZUx
oaWpHCXTkxC9usjjWvdkvxsGUSMB5ucXTZuPSNiZXmf/Ug+MoNg8wH7kli8QSLuL
HtbG8CU3+R5g5izLarxa8RUJ7lbfG9atQp7pOZw742BIWW8npqH1HjiXPEbJiLCD
TQk7SGrBUevNk0+pcqHG2//q0gxPHxh3K0XOPGkyaPVoOF8y6EpRtyGaNL9FGSHZ
kOe7Qbo1vrs=
=TlW/
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Major Revisions
Issued: March 26, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS07-025
Bulletin Information:
=====================
* MS07-025
- http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx
- Reason for Revision: V2.0 (March 26, 2008): This Bulletin has
been revised to add Microsoft Office Compatibility Pack for
Word, Excel, and PowerPoint 2007 File Formats and Microsoft
Office Compatibility Pack for Word, Excel, and PowerPoint
2007 File Formats Service Pack 1 to the Affected Software list.
- Originally posted: May 8, 2007
- Updated: March 26, 2008
- Bulletin Severity Rating: Critical
- Version: 2.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR+rHz1KuubOIpnsTAQIOCg/+O/rU7HTsbpBdtinz6SPVMxXNIqFwS7sD
Fn6TNGC9euyH+AFxdBVTdos1TFN2KpAymi+A6luvRPnPdluPKZGjUe7URqiHAsvq
wedGuow1TwuYCUm2tSTOy64pjXr3JLf7JBX3adK979e33J+Cm41QvgWhstBcl8Tt
Xf4cfi9QvvqTs4UIXVwo+i6CR3PdI/mbonvdRE/glp8g6GjjatFvg4VGm+cVnH2Q
4dWakiVp7oJspu8IyyKMr6CAe8mWAwR4UDaQOOazlfjE1w5JxXsRZI65eTDZHJZW
li+Ywzfsl9Qh0DWW6tYuuJZvWm+DDMNzuIftoF/2gUemNfSMSPfPNq/P9bpf5ssu
gcJ5n53nYP0fMjfwqVkDwUuQqrLAuiPyMqdUzhL2N4NBcqtuKy2B/cL8yy1h2RRY
AszBlMMGqRPHM+q+F8bD517VvPGD92WTgdKR+tukw+9/DfK8BeLEfTJedV+RHpyX
COFyu6Jkbm135KfRUtUnN4DDXi83mrdlxL0YwID0etjvppjYYHygNwLOZNHVw4nS
lRF1uJMnNmZa9/0iecf+7utFkMucMJGRJk5nCp2dHSL7t5JHYHJu0U/HMaDRyLzf
TAWrLpoGECTIhd9ab2myBC4BTUZo/3mmYdYzLgSn9iWD1qRtOoHlrg0JGqQjlCSp
6I9d+xpVxz8=
=aEnn
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Revisions
Issued: March 25, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS07-040 - Critical
Bulletin Information:
=====================
* MS07-040 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms07-040.mspx
- Reason for Revision: Bulletin Updated: Added .NET Framework 1.0
(KB928367) and .NET Framework 1.1 (KB929729) as affected
components for Windows Vista Service Pack 1 and Windows
Server 2008.
- Originally posted: July 10, 2007
- Updated: March 25, 2008
- Bulletin Severity Rating: Critical
- Version: 2.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR+l7CFKuubOIpnsTAQIZShAAme4WwcT+4SW6prB20G5S5U9DHzQVhVQF
ftb7uNgyk+1PdTdiGLBA3hRVBExPg055SNzJhV+lNb7iqvvT+BwKJWzRZu43OTRP
Zv2rSd+RUZ/TYipjNQrm7kvUG88vkG+iw9P54Pcm5X6XMe4p7TgjeY+sn5lXKQLu
J5JESqPCVvgX3mTJkrgCYld/NptOl1lOLtEPr7H4oYZf0g9q57Cru2xMQCF1QJ82
KnyX5fVFj2t8tnLmXINTYjuaifZewk73Tw1ef+tkOZT2ywTNLs0se73CJ1mWS8US
GDJ2pIrlFdTEbdsP5w46ULCXHzELQZQlOzKtHb4bn8WR1+V60J05KomdL+wB3Xl7
4TUkdmFCYRL61ci4VWC6+USEQRgNAhB7vrJgrPB7Har8ETtB1yJuS7Aexi9XWKGK
hMjLpKWsiPdrOTTBXn7VzkMMby+y+2OSo61bGP3DdSmx+0NZoMQTZEQIWL199qpn
fxxb38+KuQn8Vn+MnRiBR5tgdXbUHeRWTZDdxUXgx162NG9obUuOvAIpo61amOdr
LhtpZA+WEBQZRcHJmI2InLzG7/nJex8t8urknYyHnHUFI9Ji+1GMm/Q0ruetomyl
/3EZncUj8DxM90VApRsLJmky5CW1PZDrBkbdzHmWo7Ht6v9gxTjX8jR06Lmlaad/
riApdjF/its=
=uShH
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Re-Releases
Issued: March 19, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS08-014 - Critical
Bulletin Information:
=====================
* MS08-014 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx
- Reason for Revision: V3.0 (March 19, 2008): Bulletin updated.
Added Excel Viewer 2003 Service Pack 3 and Compatibility Pack
Service Pack 1 to non-affected software. Added FAQ added
about re-release to fix known issues relating to Excel 2003
Service Pack 2 or Service Pack 3. Updated the file name of
the Excel 2003 update executable.
- Originally posted: March 11, 2008
- Updated: March 19, 2008
- Bulletin Severity Rating: Critical
- Version: 3.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR+FLtlKuubOIpnsTAQLlYw//ZIH0Edr+zID0LGAhlILCpfpnWoyKxowk
e+eTGr0PtFno6uWDr0KUi43sM6T1AxYe4dB7xH0AUoFW6gzbXS4REEggHt5xivet
Y05usOPXVwOfr1rHSMrWKMaQfMxsszNfpQtH3LxvQx6d7owNS/ZM9p/aeJMM4VdY
pL/ihxsIiZ5KYYVDOWA/tZDzwFziE5cJMC0TKgJ0I6wRhnfBv8sTTzl1oU5da9ne
pXqLLAWh++k+bzOeIX+rHH0Dl7F7UcWnU8F15ADWrvsFaZ6TgJExQcIT+NqBoIgo
sRGnRV+77OlCe31qOYOgGApTQUcoQDjmCqG+jfGKj8bFTL18RA5gPlzvRo955PJE
DFPft+ucu1V0llOnkDxNEhX7aYKMG1xVp90cOWBhIiFaauBIv+DcdZwnn6pPL4cO
n8W1x5a9yr6Ws5IvEs8xQ1Y0o8uWwnM2INvqI+3IfDXKP+v3iRNmsKYhSj8rPdXq
+09k1bPzBtNkECkwKhwo526BEqRNValcQ7QdUmpeJVElV+pYVSDLIgcC+n6ADqRY
WCu0M/BmWyWvQXDCPrJ/tvxET8Q/JaDJyrGBbW6wgniT3j8NZJ2r/GvFBOOriPOK
ZoXF42B+2u0pCj5PHTd93L8htFmxXE5/2ybjrEO9LmppiPt41+Qao6Pavq9+UpCk
Qs/+CFLux5w=
=uFdX
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft Security
Bulletin Re-Release
Issued: March 13, 2008
********************************************************************
Summary
=======
The following bulletin has undergone a major revision increment.
Please see the bulletin for more detail.
* MS08-014 - Critical
Bulletin Information:
=====================
* MS08-014 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx
- Reason for Revision: FAQ added about known issues relating to
users of Excel 2003 Service Pack 2 or Service Pack 3
- Originally posted: March 11, 2008
- Updated: March 13, 2008
- Bulletin Severity Rating: Critical
- Version: 2.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR9oojVKuubOIpnsTAQK4nxAAhN7WPOYj65Aho5Pde4j0V8E4IvKM/qOn
REbbpHI7514rYyqnUHr1oqZY4PiLh9oy80LyczH6Y0Vav1r2Wr3RYyc9HNzHAkVO
o6n29YAZZCo4NgKcBb1+eTRDp5hRSKlu1zmo6sgc3q44I4iGtZ6tgLGpQpYzAA61
4L6vBTmSq1rYPXqmwUcZ5GOHW9a4HDaBCclmnWeLCzOpYJ+f3pfvbIgg3LXeb4ml
tB1oAk8S3SS8LrgkGPKtnyQ3MJbqPi8tIKxPS+1ytOutjniXIxVDZsed6/D8IfOJ
obPb3S9dluujgulf3TeUiFEJLc115gqZlWNJrshdf7dJw08/V5ssKJsp72kB2o1+
YCZZNi4wTChajSikl2gsW8jtIl1fXL/+t1n9WSEFwNqBgPl1IWPjS/7dt2I5IE2h
b3Foeodck+z03vkTEZJJ32jUdp+eKiMfqhx7LtfbZqqoOgb41vx8PsG7oKWHvBNL
tiQbQh4xUDjFSlOHQAEf7SiB3f8mrWipl3pdCLLwiRD3sPK07bMVfARobu933DXV
gLIKAJ4JVXtS3LyDkf0z2nPTEwoP1JHCwHejPrWX4YCZpbUwGNu0mW8I/O61rPyF
sI7XXP7fNUpAhXL7cvzrgd3GHtC0ykkl9kgV3i/VS+2wX7Z3ablUHlzfSnM7KOM2
Ljw/xssprhg=
=C2oc
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Microsoft
Security Bulletin Summary for February 2008
Issued: February 12, 2008
********************************************************************
This bulletin summary lists security bulletins released for
February 2008.
The full version of the Microsoft Security Bulletin Summary
for February 2008 can be found at http://www.microsoft.com/technet/security/bulletin/ms08-feb.mspx.
With the release of the bulletins for February 2008, this
bulletin summary replaces the bulletin advance notification originally issued on
February 7, 2008. For more information about the bulletin advance notification
service, see http://www.microsoft.com/technet/security/Bulletin/advance.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
Microsoft will host a webcast to address customer questions on
these bulletins on Wednesday, February 13, 2008, at 11:00 AM Pacific Time (US &
Canada). Register for the February Security Bulletin Webcast at http://www.microsoft.com/technet/security/bulletin/summary.mspx.
Microsoft also provides information to help customers
prioritize monthly security updates with any non-security, high-priority updates
that are being released on the same day as the monthly security updates. Please
see the section, Other Information.
Critical Security Bulletins
===========================
Microsoft Security Bulletin MS08-007
- Affected Software:
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64 Edition
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-008
- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista
- Windows Vista x64 Edition
- Microsoft Office 2004 for Mac
- Microsoft Visual Basic 6.0 Service Pack 6
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-009
- Affected Software:
- Microsoft Word 2000 Service Pack 3
- Microsoft Word 2002 Service Pack 3
- Microsoft Word 2003 Service Pack 2
- Microsoft Office Word Viewer 2003
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-010
- Affected Software:
- Internet Explorer 5.01 Service Pack 4 on Microsoft Windows
2000 Service Pack 4
- Internet Explorer 6 Service Pack 1 when installed on Microsoft
Windows 2000 Service Pack 4
- Internet Explorer 6 for Windows XP Service Pack 2
- Internet Explorer 6 for Windows XP Professional x64 Edition
and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 6 for Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Internet Explorer 6 for Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 6 for Windows Server 2003 with SP1 for
Itanium-based Systems and Windows Server 2003 with SP2 for
Itanium-based Systems
- Internet Explorer 7 for Windows XP Service Pack 2
- Internet Explorer 7 for Windows XP Professional x64 Edition
and Windows XP Professional x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Internet Explorer 7 for Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Internet Explorer 7 for Windows Server 2003 with SP1 for
Itanium-based Systems and Windows Server 2003 with SP2 for
Itanium-based Systems
- Internet Explorer 7 in Windows Vista
- Internet Explorer 7 in Windows Vista x64 Edition
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-012
- Affected Software:
- Microsoft Office Publisher 2000
- Microsoft Office Publisher 2002
- Microsoft Office Publisher 2003 Service Pack 2
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-013
- Affected Software:
- Microsoft Office 2000 Service Pack 3
- Microsoft Office XP Service Pack 3
- Microsoft Office 2003 Service Pack 2
- Microsoft Office 2004 for Mac
- Impact: Remote Code Execution
- Version Number: 1.0
Important Security Bulletins
============================
Microsoft Security Bulletin MS08-003
- Affected Software:
- Active Directory on Microsoft Windows 2000 Server Service Pack
4
- ADAM when installed on Windows XP Professional Service Pack 2
- ADAM when installed on Windows XP Professional x64 Edition
Service Pack 2
- Active Directory on Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- ADAM when installed on Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Active Directory on Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- ADAM when installed on Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Active Directory on Windows Server 2003 with SP1 for Itanium-
based Systems and Windows Server 2003 with SP2 for Itanium-
based Systems
- Impact: Denial of Service
- Version Number: 1.0
Microsoft Security Bulletin MS08-004
- Affected Software:
- Windows Vista
- Windows Vista x64 Edition
- Impact: Denial of Service
- Version Number: 1.0
Microsoft Security Bulletin MS08-005
- Affected Software:
- Microsoft Internet Information Services 5.0 on Microsoft
Windows 2000 Service Pack 4
- Microsoft Internet Information Services 5.1 on Windows XP
Professional Service Pack 2
- Microsoft Internet Information Services 5.1 on Windows XP
Professional x64 Edition and Windows XP Professional x64
Edition Service Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 Service Pack 1 and Windows Server 2003 Service Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 x64 Edition and Windows Server 2003 x64 Edition Service
Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 with SP1 for Itanium-based Systems and Windows Server
2003 with SP2 for Itanium-based Systems
- Microsoft Internet Information Services 7.0 on Windows Vista
- Microsoft Internet Information Services 7.0 on Windows Vista
x64 Edition
- Impact: Elevation of Privilege
- Version Number: 1.0
Microsoft Security Bulletin MS08-006
- Affected Software:
- Microsoft Internet Information Services 5.1 on Windows XP
Professional Service Pack 2
- Microsoft Internet Information Services 6.0 on Windows XP
Professional x64 Edition and Windows XP Professional x64
Edition Service Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 Service Pack 1 and Windows Server 2003 Service Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 x64 Edition and Windows Server 2003 x64 Edition Service
Pack 2
- Microsoft Internet Information Services 6.0 on Windows Server
2003 with SP1 for Itanium-based Systems and Windows Server
2003 with SP2 for Itanium-based Systems
- Impact: Remote Code Execution
- Version Number: 1.0
Microsoft Security Bulletin MS08-011
- Affected Software:
- Microsoft Works 6 File Converter on Microsoft Office 2003
- Service Pack 2
- Microsoft Works 6 File Converter on Microsoft Office 2003
- Service Pack 3
- Microsoft Works 6 File Converter on Microsoft Works 8.0
- Microsoft Works 6 File Converter on Microsoft Works Suite 2005
- Impact: Remote Code Execution
- Version Number: 1.0
Other Information
=================
Microsoft Windows Malicious Software Removal Tool:
==================================================
Microsoft has released an updated version of the Microsoft Windows Malicious
Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update
Services, and the Download Center.
Non-Security, High-Priority Updates on MU, WU, and WSUS:
========================================================
For this month:
* Microsoft has released seven non-security,
high-priority updates on Microsoft Update (MU) and
Windows Server Update Services (WSUS).
* Microsoft has released two non-security,
high-priority update for Windows on Windows Update (WU) and
WSUS.
Note that this information pertains only to non-security,
high-priority updates on Microsoft Update, Windows Update, and Windows Server
Update Services released on the same day as the Security Bulletin Summary.
Information will not be provided about non-security updates released on other
days.
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, read security bulletins, or install security updates.
You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS"
WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS
OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS
SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR7Hao1KuubOIpnsTAQJdMg//V5qZACOi38xZm1xlOV8pg4N0KXQFnH/b
ZSY5PjhGxXLYzBHigKZsu1OCqoPOQCPZjC2zXo3f/u3EaxF07bx0d2xOYkMv8u2u
r8MO5KDRJmHGtAweKuKPgJP3IZa5bYhptqwFxPU1prhggjtgeWs+zoSqeE1iagFp
9jKrkCi/LY+at0xIWh0eiDu5Pd/Fi5WzORR4zpSjxuFKFw49AsM2LpGtHAsADNqR
clvFU2FYq7xVMNH85sTaroKEIiibPyS48RLj7M9JTy0m+JcBMtv5Ra3ujMKlsdan
AiGRJ1ajuVHq9LAbydriclt8RzhAOCujRRJ8VGpsR9taeGojLttfGKw2fdc6vuJl
GxtHJzbWwZszfSdDkAZuTu7ZsdL74RpIvs7lwVLQqRPuAg7anWXinhXYqdMwySnh
l+Nl4WjyeJiSAfp1fwuuftfEPrN2d+97a6juMQPPiWPcgrD5kMCLqaH4VNpTEqv7
ORhmScS9+e6zrEr7FYFAuo+jwKxlfMgISyS75CmwJ/am4Q7ALwbHk45zRLTnGVhm
qA4/GV9nv+JoTZWdT6EjF4VIDVKBErTOxlv/ih4Lc5kqUBNiHL52XMHLdH/QTEvQ
YJbUpKh/v3lhkb2Tl9qmhZWCsJ6ilk6yP0/g5zDjNNKS0Il2Qmraj/+Qpg/PRL0f
QKG+Fv9Wq0k=
=xtO1
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
********************************************************************
Title: Microsoft
Security Bulletin Re-Releases
Issued: January 9, 2008
********************************************************************
Summary
=======
The following bulletins have undergone a major revision increment.
Please see the appropriate bulletin for more details.
* MS07-042 - Critical
Bulletin Information:
=====================
* MS07-042 - Critical
- http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
- Reason for Revision: Bulletin updated: Added Microsoft Word
Viewer 2003 as an affected product. Also added an Update FAQ
clarifying the kill bit for Microsoft XML Parser 2.6 and its
applicability to this security update.
- Originally posted: August 14, 2007
- Updated: January 9, 2008
- Bulletin Severity Rating: Critical
- Version: 3.0
Other Information
=================
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft
security update, it is a hoax that may contain malware or pointers to malicious
Web sites. Microsoft does not distribute security updates via e-mail.
The Microsoft Security Response Center (MSRC) uses PGP to
digitally sign all security notifications. However, it is not required to read
security notifications, security bulletins, security advisories, or install
security updates. You can obtain the MSRC public PGP key at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.
To receive automatic notifications whenever Microsoft Security
Bulletins and Microsoft Security Advisories are issued or revised, subscribe to
Microsoft Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.
********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQIVAwUBR4VoGVKuubOIpnsTAQLSTg//dD37MCmThrIE6u9Hp7IV0Q98/40QNCOH
1xy/dbgPiaqYq1qV3PS8bMBl2jWJmM1+FtkEKq24Aumyo2xZ8h6kPdEQVzNbu0u5
Lha6ZHwiRFFpkTMSsjeyCN8oXWnjrV+CSlJRB6+O9pZPffmsgUFGVmnn4DhCK46D
aq0N1ws3v7C6jhYbg/8Y+t84hMRDP3c33gDAeQELU7z2oNkF4uQDL7a7StncYWYU
DFt5SU3dpZNVzK9SDF9meaiXwQTux0s4oOdOOIB+I0enlWkZahy/HEwAyb9avxYJ
c7+7NYYjoELSwWSI4gZpejA7djqmzlPGxWjSvQi8e6jOe+jHGuc3OI8gplvPF3zC
myd8i5WiG1IziQhae2Jz8gsdBP17IIQdPMKxK0EFI2nz3YrmBsN9pTVkBASxvXOV
F2aocgrYjFzLMVmAIjdmGGzLeUW3pXPY4gKJqWfn8LJEEzV7imvJLPdWo9OjZXhp
QzeJVM9087wMjSMJGP7w2SUEMYHn7Kq6MrMwm5zXavwSD1/YrGRW0Vk198mZ5JTZ
MB4QBHcbmaX373sr9couWfPH4Pv3IJZ8QXBxxLGfMz2p2HFCzMU0y/Capsxl0BE7
AmuVlU3Glc9zyYQaEQ25bkH98yWdqgLC6RqrlkvVMBfBjk1I944v5Q6vHcGt2ivL
OZKcmVBqI7U=
=oE5f
-----END PGP SIGNATURE-----