Tuesday, November 12, 2013

Om Mani Padme Hum

Om Mani Padme Hum

- wong chee tat :)

Microsoft Security Bulletin Advance Notification for November 2013


Microsoft Security Bulletin Advance Notification for November 2013

Published:
Version: 1.0
This is an advance notification of security bulletins that Microsoft is intending to release on November 12, 2013.
This bulletin advance notification will be replaced with the November bulletin summary on November 12, 2013. For more information about the bulletin advance notification service, see Microsoft Security Bulletin Advance Notification.
To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications.
Microsoft will host a webcast to address customer questions on the security bulletins on November 13, 2013, at 11:00 AM Pacific Time (US & Canada). Register now for the November Security Bulletin Webcast.
Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information.

Bulletin Information

Executive Summaries

Affected Software

Detection and Deployment Tools and Guidance

Other Information

Microsoft Windows Malicious Software Removal Tool

Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

Non-Security Updates on MU, WU, and WSUS

For information about non-security releases on Windows Update and Microsoft Update, please see:

Microsoft Active Protections Program (MAPP)

To improve security protections for customers, Microsoft provides vulnerability information to major security software providers in advance of each monthly security update release. Security software providers can then use this vulnerability information to provide updated protections to customers via their security software or devices, such as antivirus, network-based intrusion detection systems, or host-based intrusion prevention systems. To determine whether active protections are available from security software providers, please visit the active protections websites provided by program partners, listed in Microsoft Active Protections Program (MAPP) Partners.

Security Strategies and Community

Update Management Strategies
Security Guidance for Update Management provides additional information about Microsoft’s best-practice recommendations for applying security updates.
Obtaining Other Security Updates
Updates for other security issues are available from the following locations:
  • Security updates are available from Microsoft Download Center. You can find them most easily by doing a keyword search for "security update".
  • Updates for consumer platforms are available from Microsoft Update.
  • You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft Knowledge Base Article 913086.
IT Pro Security Community
Learn to improve security and optimize your IT infrastructure, and participate with other IT Pros on security topics in IT Pro Security Community.

Support

Disclaimer

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.


- wong chee tat :)

Clarification on Security Advisory 2896666 and the ANS for the November 2013 Security Bulletin Release

Clarification on Security Advisory 2896666 and the ANS for the November 2013 Security Bulletin Release
Dustin C. Childs
7 Nov 2013 10:00 AM

Today, we’re providing advance notification for the release of eight bulletins, three Critical and five Important, for November 2013. The Critical updates address vulnerabilities in Internet Explorer and Microsoft Windows, and the Important updates address issues in Windows and Office.

While this release won’t include an update for the issue first described in Security Advisory 2896666, we’d like to tell you a bit more about it. We’re working to develop a security update and we’ll release it when ready. In the meantime, the advisory includes a Fix it which prevents the attacks from succeeding and we recommend customers apply it to help protect their systems. We also want to provide clarification on the products that the advisory notes are affected. We’ve seen some confusion due to the shared nature of the GDI+ component, which is where the issue resides. There are three ways you can have the GDI+ component installed on your system: Office, Windows, and Lync.

For Office:

Office 2003 and Office 2007 are affected regardless of the installed operating system. Currently, we are only aware of targeted attacks against Office 2007 users.
Office 2010 is affected only if installed on Windows XP or Windows Server 2003. Office 2010 is not affected when installed on Windows Vista or newer systems.
Office 2013 is not affected, regardless of OS platform.

For Windows:

Supported versions of Windows Vista and Windows Server 2008 ship with the affected component but are not known to be under active attack.
Other versions of Windows are not directly impacted. Customers who use these systems are only impacted if they have an affected version of Office or Lync.

For Lync clients:

All supported versions of Lync client are affected but are not known to be under active attack.

Again, we’re only aware of targeted attacks against Office 2007. In those attacks, Windows XP was the operating system seen in use.

As always, we’ve scheduled the security bulletin release for the second Tuesday of the month, November 12, 2013, at approximately 10:00 a.m. PST. Revisit this blog at that time for analysis of the risk and impact, as well as deployment guidance, together with a brief video overview of this month’s updates. Until then, please review the ANS summary page for more information that will help customers prepare for security bulletin testing and deployment.

Don’t forget, you can also follow the MSRC team’s recent activity on Twitter at @MSFTSecResponse.

Thank you,

Dustin Childs
Group Manager, Response Communications
Microsoft Trustworthy Computing






- wong chee tat :)