Thursday, May 07, 2009

Microsoft Advance Notice: Security Bulletin for May 2009

On May 12, 2009, Microsoft is planning to release one new security bulletin, identified as critical. Below is a summary.
Bulletin ID: PowerPoint
Maximum Severity Rating: Critical
Vulnerability Impact: Remote Code Execution
Restart Requirement: May require restart
Affected Software: Microsoft Office
According to the MSRC Blog post by Jerry Bryant, Microsoft is also planning to release at least one high priority, non-security update and additional detections to the Microsoft Windows Malicious Software Removal Tool.

References:


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, May 04, 2009

Windows Security Updates Are For Everyone

Here we go again with sensationalism. Are bloggers so desperate for readers that they need to twist a simple explanation about security updates into headline-grabbing misinformation?

Microsoft has not made changes in policy. Windows security updates are and have been available for everyone, including non-genuine systems. As Paul Cooke recently explained in the Windows Security Blog:
"Not only do all security updates go to all users' systems, but non-genuine Windows systems are able to install service packs, update rollups, and important reliability and application compatibility updates. In addition, the users of non-genuine Windows systems can also upgrade a lot of the other software on their computer. For example Internet Explorer 8 has numerous security-oriented features and improvements, and it is available to all users."
For some reason, articles are being published playing this up as if it were something new for Windows 7 and that Microsoft is ignoring piracy. Providing security updates to all Windows users is not something new for Windows 7 nor does it imply that Microsoft has gone soft on piracy.

Rather than jumping the gun, perhaps reading the rest of the article and noting that Paul also stated that worms such as Blaster (2003) and Sasser (2004) followed publicly available Microsoft security updates. The same is true with Conficker with MS08-067 having been available since October, 2008.

Security updates for non-genuine Windows systems can be obtained as follows:
Windows Vista: use the Windows Update control panel
Windows XP: use Automatic Updates
Note:
Optional updates, available through the Windows Update and Microsoft Update websites, are not available to non-genuine Windows systems.


Reference:
Who Gets Windows Security Updates? - Windows Security Blog - The Windows Blog



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, May 03, 2009

Adobe Reader Vulnerability

The Adobe Product Response Team reported:
"A Security Advisory has been posted in regards to the Adobe Reader vulnerability last mentioned in the Adobe PSIRT blog on April 28 (“Update to Adobe Reader Issue”, CVE-2009-1492). We are in the process of fixing the issue, and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009. Adobe plans to make available Windows updates for Adobe Reader versions 9.X, 8.X, and 7.X and Acrobat versions 9.X, 8.X, and 7.X, Macintosh updates for Adobe Reader versions 9.X and 8.X and Acrobat versions 9.X and 8.X, as well as Adobe Reader for Unix versions 9.X and 8.X."
There are a couple of options available, one of which is the work-around provided by Adobe:
1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the ‘Enable Acrobat JavaScript’ option
5. Click OK
The recommended option, however, is to use an alternate reader. There are a number of open source readers available from http://pdfreaders.org/.

Sidebar:
I discontinued using Foxit PDF Reader some time ago as it now includes the Ask Toolbar and eBay desktop shortcut. It has been reported that there is reduced functionality when those add-ons are not included in the installation of Foxit.

Reference: Adobe Product Security Incident Response Team (PSIRT)




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...