Comments Off

Microsoft Security Advisory (960906): Vulnerability in WordPad Text Converter Could Allow Remote Code Execution – Version: 2.0

Revision Note: V2.0 (April 14, 2009): Advisory updated to reflect publication of security bulletin. Summary: Microsoft is investigating new reports of a vulnerability in the WordPad Text Converter for Word 97 files on Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack [...]


Comments Off

Microsoft Security Advisory (968272): Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution – Version: 3.0

Revision Note: V3.0 (April 14, 2009) Advisory updated to reflect publication of security bulletin. Summary: Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. At this time, we are aware only of limited and targeted attacks [...]


Comments Off

Microsoft Security Advisory (969136): Vulnerability in Microsoft Office PowerPoint Could Allow Remote Code Execution – Version: 2.0

Revision Note: V2.0 (May 12, 2009): Advisory updated to reflect publication of security bulletin. Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-017 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-017. The vulnerability addressed [...]


Comments Off

Microsoft Security Advisory (971888): Update for DNS Devolution – Version: 1.0

Revision Note: Advisory published. Summary: Microsoft is announcing the availability of an update to DNS devolution that can help customers in keeping their systems protected. Customers whose domain name has three or more labels , such as “contoso.co.us”, or who do not have a DNS suffix list configured, or for whom the following mitigating factors [...]


Comments Off

Microsoft Security Advisory (945713): Vulnerability in Web Proxy Auto-Discovery (WPAD) Could Allow Information Disclosure – Version: 2.0

Revision Note: V2.0 (June 9, 2009): Advisory updated to reflect publication of security bulletin MS09-008 and Microsoft Security Advisory 971888. Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-008 to address the WPAD issue and have released configuration guidance and updates for DNS devolution in Microsoft Security [...]