MS Sec Notification mailing list archives
Microsoft Security Bulletin Summary for September 2008
From: "Microsoft" <Microsoft () newsletters microsoft com>
Date: Tue, 9 Sep 2008 10:57:41 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ******************************************************************** Microsoft Security Bulletin Summary for September 2008 Issued: September 9, 2008 ******************************************************************** This bulletin summary lists security bulletins released for September 2008. The full version of the Microsoft Security Bulletin Summary for September 2008 can be found at http://www.microsoft.com/technet/security/bulletin/ms08-sep.mspx. With the release of the bulletins for September 2008, this bulletin summary replaces the bulletin advance notification originally issued on September 4, 2008. For more information about the bulletin advance notification service, see http://www.microsoft.com/technet/security/Bulletin/advance.mspx. To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx. Microsoft will host a webcast to address customer questions on these bulletins on Wednesday, September 10, 2008, at 11:00 AM Pacific Time (US & Canada). Register for the September Security Bulletin Webcast at http://www.microsoft.com/technet/security/bulletin/summary.mspx. Microsoft also provides information to help customers prioritize monthly security updates with any non-security, high-priority updates that are being released on the same day as the monthly security updates. Please see the section, Other Information. Critical Security Bulletins ============================ Microsoft Security Bulletin MS08-054 - Affected Software: - Windows Media Player 11 on Windows XP Service Pack 2 and Windows XP Service Pack 3 - Windows Media Player 11 on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Player 11 on Windows Vista and Windows Vista Service Pack 1 - Windows Media Player 11 on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 - Windows Media Player 11 on Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected) - Windows Media Player 11 on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected) - Impact: Remote Code Execution - Version Number: 1.0 Microsoft Security Bulletin MS08-052 - Affected Software: - Microsoft Internet Explorer 6 on Microsoft Windows 2000 Service Pack 4 - Microsoft .NET Framework 1.0 Service Pack 3 on Microsoft Windows 2000 Service Pack 4 - Microsoft .NET Framework 1.1 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 - Microsoft .NET Framework 2.0 on Microsoft Windows 2000 Service Pack 4 - Microsoft .NET Framework 2.0 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 - Windows XP Service Pack 2 and Windows XP Service Pack 3 - Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium based Systems - Windows Vista and Windows Vista Service Pack 1 - Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 - Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected) - Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected) - Windows Server 2008 for Itanium-based Systems - Microsoft Office XP Service Pack 3 - Microsoft Office 2003 Service Pack 2 - Microsoft Office 2003 Service Pack 3 - 2007 Microsoft Office System - 2007 Microsoft Office System Service Pack 1 - Microsoft Visio 2002 Service Pack 2 - Microsoft Office PowerPoint Viewer 2003 - Microsoft Works 8 - Microsoft Digital Image Suite 2006 - QFE update for SQL Server 2000 Reporting Services Service Pack 2 - GDR update for SQL Server 2005 Service Pack 2 - QFE update for SQL Server 2005 Service Pack 2 - GDR update for SQL Server 2005 x64 Edition Service Pack 2 - QFE update for SQL Server 2005 x64 Edition Service Pack 2 - GDR update for SQL Server 2005 for Itanium-based Systems Service Pack 2 - QFE update for SQL Server 2005 for Itanium-based Systems Service Pack 2 - Microsoft Visual Studio .NET 2002 Service Pack 1 - Microsoft Visual Studio .NET 2003 Service Pack 1 - Microsoft Visual Studio 2005 Service Pack 1 - Microsoft Visual Studio 2008 - Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package - Microsoft Report Viewer 2008 Redistributable Package - Microsoft Visual FoxPro 8.0 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4 - Microsoft Visual FoxPro 9.0 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4 - Microsoft Visual FoxPro 9.0 Service Pack 2 when installed on Microsoft Windows 2000 Service Pack 4 - Microsoft Platform SDK Redistributable: GDI+ - Microsoft Forefront Client Security 1.0 when installed on Microsoft Windows 2000 Service Pack 4 - Impact: Remote Code Execution - Version Number: 1.0 Microsoft Security Bulletin MS08-053 - Affected Software: - Windows Media Encoder 9 Series on Microsoft Windows 2000 Service Pack 4 - Windows Media Encoder 9 Series on Windows XP Service Pack 2 and Windows XP Service Pack 3 - Windows Media Encoder 9 Series on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Encoder 9 Series x64 Edition on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Media Encoder 9 Series on Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Windows Media Encoder 9 Series on Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Media Encoder 9 Series x64 Edition on Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Media Encoder 9 Series on Windows Vista and Windows Vista Service Pack 1 - Windows Media Encoder 9 Series on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 - Windows Media Encoder 9 Series x64 Edition on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 - Windows Media Encoder 9 Series on Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected) - Windows Media Encoder 9 Series on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected) - Windows Media Encoder 9 Series x64 Edition on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected) - Impact: Remote Code Execution - Version Number: 1.0 Microsoft Security Bulletin MS08-055 - Affected Software: - Microsoft Office XP Service Pack 3 - Microsoft Office 2003 Service Pack 2 - Microsoft Office 2003 Service Pack 3 - 2007 Microsoft Office System - 2007 Microsoft Office System Service Pack 1 - Microsoft Office OneNote 2007 - Microsoft Office OneNote 2007 Service Pack 1 - Impact: Remote Code Execution - Version Number: 1.0 Other Information ================= Microsoft Windows Malicious Software Removal Tool: ================================================== Microsoft has released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. Non-Security, High-Priority Updates on MU, WU, and WSUS: ======================================================== Please see: * http://support.microsoft.com/kb/894199: Microsoft Knowledge Base Article 894199, Description of Software Update Services and Windows Server Update Services changes in content for 2008. Includes all Windows content. * http://technet.microsoft.com/en-us/wsus/bb466214.aspx: New, Revised, and Released Updates for Microsoft Products Other Than Microsoft Windows Recognize and avoid fraudulent e-mail to Microsoft customers: ============================================================= If you receive an e-mail message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious Web sites. Microsoft does not distribute security updates via e-mail. The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, PGP is not required for reading security notifications, reading security bulletins, or installing security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx. To receive automatic notifications whenever Microsoft Security Bulletins are issued, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx. ******************************************************************** THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY. ******************************************************************** -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQIVAwUBSMagWFKuubOIpnsTAQIIxhAAqc+uTkNnmL+RskDh8DvKf0Esf5rEemrO YQ6v03hv1Gh5qgdCW/DaRNLGdCCkzSadk3pgghdjeKDsQrdnDHaT47OsoaIEjQzz HzGudXmhrJmeI3UvZYG7SctErIdIkDmS4shDq/sp+sHCEkJuKAbVrZniLg8//BkP /Qnaq5PbvyigmyfH1u2pJoNPX7H1wdvjSUBjY+IfrdqcjGDIHwinEltf3gOIl66h wqKy84goYKWSQcuq+yW8hOjSmOMBc1xB021TKlZZQ+0omhKIxDO5I0GVaV9KIkub 5cWdtq9IXi9HHpfCYHJfJ1+3n9rPShfZCmswz7mCLRIyz/+Bc3yCey8VmG9kuCi9 WH1e+4iKERhftpWxpXVZUWPXGQhUosp7HpAl1xj3tlTJixkvAKHzYsbk7P3XWhVx iJcxB3YQ92UWGTdfLWQCF7FuNq9OypeQGQxIq/912+8aaTkNEy6UhoibYfudtzr2 Z6u9AmgRrDeRYnPKMB+U5oxO4bmtDcJVXTVQEUHTVHgCFmMMBHnw49MiTaMpWXH4 AnEagvIOlCRnS7/CZZREv33vzmOWQo+fyJ4n2KHcxUtbS9j+7kM2OeAaVFg9AD/X QtTuwXgNnV9GdTJgf5Xvq/C/TTvySMllesU0meCPlpgoTMv1EiRUzeYpY6rdTLdC 1I0yBN+0O0k= =bGms -----END PGP SIGNATURE----- To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at the Microsoft.com web site <http://www.microsoft.com/misc/unsubscribe.htm>. You can manage all your Microsoft.com communication preferences at this site. Legal Information <http://www.microsoft.com/info/legalinfo/default.mspx>. This newsletter was sent by the Microsoft Corporation 1 Microsoft Way Redmond, Washington, USA 98052
Current thread:
- Microsoft Security Bulletin Summary for September 2008 Microsoft (Sep 09)