<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC Patch Tuesday RSS Feed</title>
 <link>http://www.maximumpc.com/tags/patch_tuesday</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Microsoft Readying Biggest-Ever Patch Tuesday for Next Week</title>
 <link>http://www.maximumpc.com/article/news/microsoft_reading_biggestever_patch_tuesday_next_week</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;It&#039;s a good thing most of use have long since moved on from dial-up, because come Tuesday, Microsoft said it will send out its largest-ever number of security updates to fix and plug holes in every version of Windows, including the first update for Windows 7 RTM. Internet Explorer, Office, SQL Server, Forefront Security client, and some developer tools will also be in the mix.&lt;/p&gt;
&lt;p&gt;&amp;quot;Thirteen is not a lucky number,&amp;quot; &lt;a href=&quot;http://www.computerworld.com/s/article/9139155/Microsoft_plans_monster_Patch_Tuesday_next_week&quot;&gt;said Andrew Storms&lt;/a&gt;, director of security operations at nCircle Network Security, in response to the monster update scheduled for October 13. &amp;quot;They&#039;ve been a busy bunch at Microsoft, that&#039;s for sure.&amp;quot;&lt;/p&gt;
&lt;p&gt;Microsoft will ship 13 updates in all next week, eight of them considered critical. That&#039;s enough to break the record of 12 updates shipped in February 2007 and October 2008. &lt;/p&gt;
&lt;p&gt;Five of the updates will affect Windows 7, even though the OS has yet to formally launch. However, enterprises with volume licenses, party hosts, and others have been able to obtain and run the finalized the OS for awhile now.&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Windows_Patch.png&quot; width=&quot;405&quot; height=&quot;221&quot; /&gt; &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/microsoft_reading_biggestever_patch_tuesday_next_week#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <pubDate>Fri, 09 Oct 2009 08:35:14 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">8307 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>A Patch Tuesday &quot;Two-Fer&quot; Secures Both Microsoft and Adobe Programs</title>
 <link>http://www.maximumpc.com/article/news/junes_patch_tuesday_secures_both_microsoft_and_adobe_programs</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_MS-Adobe-PatchTuesday.png&quot; alt=&quot;June 2009&#039;s Patch Tuesday also saw Adobe security updates&quot; width=&quot;410&quot; height=&quot;177&quot; /&gt;&lt;/div&gt;
&lt;p&gt;June 9th saw a rare &#039;double-header&#039; in security updates: Microsoft&#039;s monthly Patch Tuesday was joined by Adobe&#039;s quarterly security updates for Acrobat and Adobe Reader. How big was this month&#039;s 10-update Patch Tuesday? According to a Microsoft spokesperson &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10260659-83.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-20&quot;&gt;quoted by &lt;strong&gt;Cnet&lt;/strong&gt;&lt;/a&gt;, the 31 vulnerabilities covered by updates are &amp;quot;the most since Microsoft started releasing updates on a regular schedule of the second Tuesday of every month in October 2003.&amp;quot; &lt;/p&gt;
&lt;p&gt;Here&#039;s what Microsoft patched this week:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Critical remote code execution vulnerabilities in Active Directory on Windows 2000 Server, Windows Server 2003, and ADAM on Windows Server 2003 and Windows XP Professional (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx&quot;&gt;MS09-018&lt;/a&gt;) &lt;/p&gt;
&lt;p&gt;Critical to Moderate remote code execution vulnerabilities in Windows Print Spooler in Windows 2000 SP4, Windows XP SP2/SP3 and x64, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-022.mspx&quot;&gt;MS09-022&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Moderate remote code execution vulnerabilities in IE5.01, IE6, IE 6SP1, IE7, and IE8. Note that IE8 in Windows 7 RC is not included (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx&quot;&gt;MS09-019&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Important remote code execution vulnerabilities in Microsoft Office Word 2000, 2002 (XP), 2003, and 2007 for Windows; 2004 and 2008 for Mac, Open XML converter for Mac; Microsoft Office Word Viewers and Compatibility Packs for 2007 file formats SP1 and SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx&quot;&gt;MS09-027&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Important remote code execution vulnerabilities in Microsoft Office Excel 2000, 2002 (XP), 2003, and 2007 for Windows; 2004 and 2008 for Mac, Open XML converter for Mac; Microsoft Office Excel Viewers and Compatibility Packs for 2007 file formats SP1 and SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx&quot;&gt;MS09-021&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to important remote code execution vulnerabilities for Microsoft Works 8.5, 9 and Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2007 SP1 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-024.mspx&quot;&gt;MS09-024&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in the RPC function in Windows 2000 SP4, Windows XP SP2/SP3 and x64, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-026.mspx&quot;&gt;MS09-026&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in Windows Kernel in Windows 2000 SP4, Windows XP SP2/SP3, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-025.mspx&quot;&gt;MS09-025&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in IIS 5.0, 5.1, and 6.0 when running on Windows 2000 SP4, Windows XP SP2/SP3 and x64 SP2, and Windows Server 2003 SP2 and x64 SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-020.mspx&quot;&gt;MS09-020&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Moderate information disclosure vulnerabilities in Windows Search 4.0 when running on Windows XP SP2, SP3, x64 SP2; Windows Server 2003 SP2 and x64 SP2 only (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-023.mspx&quot;&gt;MS09-023&lt;/a&gt;).  &lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;For details about the exploitability rating for each vulnerability (1-3, 1 being the most severe), &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx&quot;&gt;see&lt;/a&gt; the security bulletin summary. To find out about Windows Media Center and other updates, and where to get the Adobe updates, join us on page 2.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Microsoft also rolled out these updates in June:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The June 2009 version of the Windows Malicious Software Removal Tool (&lt;a href=&quot;http://support.microsoft.com/?kbid=890830&quot;&gt;KB890830&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;The June 2009 update for the Windows Mail Junk email filter (&lt;a href=&quot;http://support.microsoft.com/kb/905866&quot;&gt;KB905866&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Cumulative updates for Windows Media Center for Windows Vista (&lt;a href=&quot;http://support.microsoft.com/kb/967632&quot;&gt;KB967632&lt;/a&gt;) and Windows Media Center TV Pack for Windows Vista (&lt;a href=&quot;http://support.microsoft.com/kb/966315&quot;&gt;KB966315&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;An update to the ActiveX kill bits security pack (&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/969898.mspx&quot;&gt;KB969898&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adobe was also busy sticking its fingers in the security dike this month, rolling out critical security update &lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-07.html&quot;&gt;APSB09-07&lt;/a&gt; with updates for Adobe Reader and Acrobat 9.x, 8.x, and 7.x. Vulnerabilities patched by the updates include stack overflow, integer overflow, memory corruption and heap overflow, all of which could be used to trigger arbitrary code execution. &lt;/p&gt;
&lt;p&gt;Stay safe out there!&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/junes_patch_tuesday_secures_both_microsoft_and_adobe_programs#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe">Adobe</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe_acrobat">Adobe Acrobat</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe_reader">Adobe Reader</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_office">Microsoft Office</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_windows">Microsoft Windows</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8236">Microsoft Windows Server</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8235">Microsoft Works</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <pubDate>Thu, 11 Jun 2009 19:11:41 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6586 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>March 2009&#039;s Patch Tuesday&#039;s a Light, But Important One for Windows Users</title>
 <link>http://www.maximumpc.com/article/news/march_2009s_patch_tuesdays_a_light_but_important_one_windows_users</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/March09_PT.png&quot; alt=&quot;March 2009 Patch Tuesday&#039;s a Windows-only proposition&quot; width=&quot;410&quot; height=&quot;256&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Today, Microsoft released a trio of security bulletins covering all currently-supported Windows versions. Users of Windows 2000 SP4 through Windows Vista SP1 (as well as Windows Server 2003 and 2008) need to install the update for the critical Windows kernel vulnerability &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS09-006.mspx&quot;&gt;noted&lt;/a&gt; in Security Bulletin MS-09-006. The other two bulletins (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS09-007.mspx&quot;&gt;MS09-007&lt;/a&gt; and &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/MS09-008.mspx&quot;&gt;MS09-008&lt;/a&gt;) solve important vulnerabilities in SChannel (007) and DNS/WINS Server (008); these bulletins apply to Windows 2000 SP4 through Windows XP and Server 2003 only.&lt;/p&gt;
&lt;p&gt;Other updates to look for &lt;a href=&quot;http://support.microsoft.com/?kbid=894199&amp;amp;SD=tech&quot;&gt;include&lt;/a&gt; the usual updates to the Malicious Software Removal Tool and the Windows Mail junk email filter. If you&#039;re on Automatic Updates, follow instructions to reboot if needed after installation. If you prefer to be in charge, don&#039;t forget to download and install these as soon as possible.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/march_2009s_patch_tuesdays_a_light_but_important_one_windows_users#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/update">update</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_2000">Windows 2000</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4469">Windows Server 2003</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3375">Windows Server 2008</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_vista">Windows Vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <pubDate>Tue, 10 Mar 2009 19:08:39 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">5577 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>February&#039;s Patch Tuesday Has Something for Everyone</title>
 <link>http://www.maximumpc.com/article/news/februarys_patch_tuesday_has_something_everyone</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_PT0209_edited-1.png&quot; alt=&quot;Patch Tuesday for February 2009 affects both Windows desktop and Server versions&quot; width=&quot;410&quot; height=&quot;256&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Whether you&#039;re using Windows and IE, managing Microsoft Exchange or SQL Server at work, or using Microsoft Office, this month&#039;s Patch Tuesday &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx&quot;&gt;has a security update for you&lt;/a&gt;. All four security bulletins address Remote Code Execution vulnerabilities in recent and current service packs for each product listed:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IE 7:&lt;/strong&gt; Windows XP, Windows Vista, Windows Server 2003&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Office:&lt;/strong&gt; Visio 2002, 2003, 2007&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SQL:&lt;/strong&gt; SQL Server 2000 Desktop Engine on Windows 2000 and Windows Server 2003; Windows Internal Database (WYukon) on Windows Server 2003 and Windows Server 2008; SQL Server 2000 and SQL Server 2005 &lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exchange Server:&lt;/strong&gt; Exchange 2000 Server, Exchange Server 2003, Exchange Server 2007&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;But Wait, There&#039;s More!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Other updates to be released tomorrow include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cumulative Update for Windows Vista Media Center (KB960544)&lt;/li&gt;
&lt;li&gt;Cumulative Update for Windows Vista Media Center TVPack (KB958653)&lt;/li&gt;
&lt;li&gt;Upgrade Rollup for ActiveX Killbits for Windows (KB960715)&lt;/li&gt;
&lt;li&gt;February 2009 updates for Windows Mail Junk Email Filter (KB905866) and Windows Malicious Software Removal Tool (KB890830)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For details, &lt;a href=&quot;http://support.microsoft.com&quot;&gt;look up the KB article numbers&lt;/a&gt; starting Tuesday.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/februarys_patch_tuesday_has_something_everyone#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6909">Exchange</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6908">February 2009</category>
 <category domain="http://www.maximumpc.com/geek_tested/ie">IE</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_office">Microsoft Office</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6910">SQL</category>
 <category domain="http://www.maximumpc.com/geek_tested/updates">updates</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6911">Visio</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6690">Windows updates</category>
 <pubDate>Mon, 09 Feb 2009 10:48:26 -0600</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">5225 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Patch Tuesday Followed Immediately By New Exploit Wednesday</title>
 <link>http://www.maximumpc.com/article/news/patch_tuesday_followed_immediately_by_new_exploit_wednesday</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u58308/IE7_logo.jpg&quot; width=&quot;415&quot; height=&quot;152&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Not even a moment after Microsoft fixed 28 vulnerabilities in their software this past Patch Tuesday, a brand new exploit &lt;a href=&quot;http://www.tgdaily.com/content/view/40538/112/&quot;&gt;popped up&lt;/a&gt; in Internet Explorer 7.&lt;/p&gt;
&lt;p&gt; The new exploit allows attackers the ability to execute arbitrary code whenever someone visits a malicious website. Currently only users running Windows XP and Server 2003 are being targeted, so you Vista users haven’t a thing to worry about. Microsoft said they’re currently working on a patch to fix the issue, but they were unable to set a date.&lt;/p&gt;
&lt;p&gt; “Internet Explorer remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be across any site on the Internet,” said eEye&#039;s director of Research and Preview Services, Andre Protas. “An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials.”&lt;/p&gt;
&lt;p&gt; Until this issue is taken care of, those of you that are using IE7 can go and snag eEye’s Blink Software for protection from this threat. Or, you could go snag one of the other browsers, such as &lt;a href=&quot;http://www.mozilla.com/en-US/firefox/&quot;&gt;Mozilla’s Firefox&lt;/a&gt; or &lt;a href=&quot;http://www.google.com/chrome&quot;&gt;Google’s Chrome&lt;/a&gt;. I hear they’re not too shabby!&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Microsoft &lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/patch_tuesday_followed_immediately_by_new_exploit_wednesday#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <pubDate>Thu, 11 Dec 2008 14:10:00 -0600</pubDate>
 <dc:creator>Andy Salisbury</dc:creator>
 <guid isPermaLink="false">4530 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Eight Security Bulletins Released for Patch Tuesday</title>
 <link>http://www.maximumpc.com/article/news/eight_security_bulletins_released_patch_tuesday</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u58308/Microsoft_Logo.jpg&quot; width=&quot;415&quot; height=&quot;100&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Microsoft’s last Patch Tuesday of 2008 is &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx&quot;&gt;on its way&lt;/a&gt;, and it’s bringing a heavy amount of updates that you’ll want to be ready for.&lt;/p&gt;
&lt;p&gt; Yesterday Microsoft announced a whopping eight security bulletins that will be going public on December 9th. The announcement was meant to allow IT departments some prep time before the post-Monday patch fiasco. Six of the bulletins have been listed as “critical” with two posted up as “important.”&lt;/p&gt;
&lt;p&gt; Of the patches, two of them are meant directly for Windows itself. The others are for the separate applications of Microsoft’s Office suite.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Microsoft &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/eight_security_bulletins_released_patch_tuesday#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6003">Critical</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/5215">office</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/vista">vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <pubDate>Fri, 05 Dec 2008 16:09:25 -0600</pubDate>
 <dc:creator>Andy Salisbury</dc:creator>
 <guid isPermaLink="false">4477 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>A Quiet Patch Tuesday for November 2008</title>
 <link>http://www.maximumpc.com/article/news/a_quiet_patch_tuesday_november_2008</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_PT1108.png&quot; alt=&quot;November 2008 Patch Tuesday includes only two updates&quot; width=&quot;410&quot; height=&quot;256&quot; /&gt;&lt;/div&gt;
&lt;p&gt;This month&#039;s Patch Tuesday, unlike October&#039;s, is a quiet one, with just two security bulletins:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx&quot;&gt;MS08-069&lt;/a&gt; solves a remote code execution vulnerability in Microsoft&#039;s XML Core Service that is rated as Critical for version 3.0 and Important for later versions. All 32-bit and 64-bit desktop versions of Windows from Windows 2000 SP4 through Windows Vista SP1 are affected, as well as Microsoft Office 2003 and 2007. The Exploitability Index is 1 (Consistent Exploit Code Likely - the most serious ranking) or 2 (Inconsistent Exploit Code Likely), depending upon the version of XML Core Services installed. Windows Server 2003 and some installations of Windows Server 2008 are also affected.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx&quot;&gt;MS08-068&lt;/a&gt; patches a remote code execution vulnerability in the SMB protocol. MS08-068 is rated as Important for Windows 2000 SP4 and Windows XP, and Moderate for Windows Vista. Windows Server 2003 and all Windows Server 2008 installations are also affected. Despite Microsoft&#039;s rating this vulnerability as only Important rather than Critical, MS08-068&#039;s Exploitability Index is 1 because exploit code targeting Windows XP is already public.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That&#039;s it for Patch Tuesday security bulletins, both of which will be arriving soon via Windows Update (or can be downloaded manually if you prefer). What else has Microsoft served up? &lt;/p&gt;
&lt;p&gt;The only non-security content this time is the usual monthly update for the Malicious Software Removal Tool (&lt;a href=&quot;http://support.microsoft.com/kb/890830&quot;&gt;KB890830&lt;/a&gt;; &lt;strike&gt;not yet updated as this article was posted &lt;/strike&gt;&lt;strong&gt;now updated&lt;/strong&gt;) and the usual monthly update for the Windows Mail junk mail filter (KB905866), available in &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyId=AA029FDE-F341-44FC-8B85-0C6F3D3C2D69&amp;amp;displaylang=en&quot;&gt;32-bit&lt;/a&gt; and &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyId=749E10CD-F40C-4F94-8E38-D4221DED7652&quot;&gt;64-bit&lt;/a&gt; versions.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/a_quiet_patch_tuesday_november_2008#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/security_bulletin">security bulletin</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/geek_tested/updates">updates</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_2000">Windows 2000</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4469">Windows Server 2003</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3375">Windows Server 2008</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_vista">Windows Vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <pubDate>Tue, 11 Nov 2008 13:17:52 -0600</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">4225 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Microsoft Patches Critical Vulnerability for XP, Vista, Windows 7, and Others</title>
 <link>http://www.maximumpc.com/article/news/microsoft_patches_critical_vulnerability_xp_vista_windows_7_and_others</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header-security1008.png&quot; alt=&quot;Microsoft patches Server service vulnerability, doesn&#039;t wait for November Patch Tuesday&quot; width=&quot;410&quot; height=&quot;256&quot; /&gt;&lt;/div&gt;
&lt;p&gt; 
&lt;p&gt;Redmond usually releases security patches once a month, on Patch Tuesday, but Microsoft&#039;s security experts are worried enough about a newly reported vulnerability in the Server service to &lt;a href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&quot;&gt;post&lt;/a&gt; an &amp;quot;out-of-band&amp;quot; security update, &lt;strong&gt;MS08-067&lt;/strong&gt;, yesterday for all versions of Windows from Windows 2000 SP4 through Windows Server 2008 and Windows 7 pre-beta. Microsoft hasn&#039;t issued a security update between Patch Tuesday releases since April 2007, so this is a &lt;strong&gt;significant security issue&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Although all supported versions of Windows are vulnerable, Windows 2000 SP4, Windows XP, and Windows Server 2003 versions are especially vulnerable to this flaw, which can permit remote code execution via a specially crafted RFC request. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx&quot;&gt;According to&lt;/a&gt; the Security Bulletin summary for October, the vulnerability described in MS08-067 receives the highest Exploitability Index Assessment: &lt;strong&gt;1 - Consistent exploit code likely&lt;/strong&gt;. From the notes for MS08-067: &lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Consistent exploit code has been discovered in limited, targeted attacks, affecting Windows XP and Windows Server 2003. While this service is enabled by default on all affected platforms, exploitation is most likely on Microsoft Windows 2000, Windows XP, and Windows Server 2003.... &lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;If you&#039;re running Windows Update, install the update labeled &lt;a href=&quot;http://support.microsoft.com/kb/958644&quot;&gt;KB958644&lt;/a&gt;. If you need to download and install the update manually, &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx&quot;&gt;open&lt;/a&gt;  the Windows Operating System and Components section of the October security bulletin  and click the link for your operating system. The Windows 7 pre-beta updates for &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyID=e877d9c1-3e7c-4551-a899-c3fcc5175bb6&amp;amp;DisplayLang=en&quot;&gt;32-bit&lt;/a&gt; and &lt;a href=&quot;http://www.microsoft.com/downloads/details.aspx?FamilyID=0fa96b25-90e3-46ab-bcd5-051f4b2b881b&amp;amp;DisplayLang=en&quot;&gt;64-bit&lt;/a&gt; versions are not listed in the October security bulletin, but can be obtained by clicking the links provided here.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/microsoft_patches_critical_vulnerability_xp_vista_windows_7_and_others#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/5501">MS08-067</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_systems">Operating Systems</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/vulnerability">vulnerability</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_2000">Windows 2000</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3243">windows 7</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4469">Windows Server 2003</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3375">Windows Server 2008</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_vista">Windows Vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <pubDate>Fri, 24 Oct 2008 10:53:38 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">4012 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
