<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC security update RSS Feed</title>
 <link>http://www.maximumpc.com/tags/security_update</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Microsoft Releases Out-of-Band Security Patch for Internet Explorer</title>
 <link>http://www.maximumpc.com/article/news/microsoft_releases_outofband_security_patch_internet_explorer</link>
 <description>&lt;!--paging_filter--&gt;&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u96627/ie7_logo.jpg&quot; width=&quot;405&quot; height=&quot;165&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Last week’s cyber attacks, that targeted Google and several other large U.S. companies, has &lt;a href=&quot;http://news.cnet.com/8301-30684_3-10437240-265.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-20&quot;&gt;certainly gotten Microsoft’s attention&lt;/a&gt;. The attack was orchestrated, in part, through a zero-day flaw in Internet Explorer (IE). The flaw seems to be obscure, and restricted to IE 6 and IE 7, but that hasn’t stopped Microsoft from releasing an out-of-cycle patch for IE.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=222301040&quot;&gt;Microsoft has acknowledgde the flaw&lt;/a&gt;, and says the “vulnerability exists as an invalid pointer reference within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.”&lt;/p&gt;
&lt;p&gt;Microsoft, in &lt;a href=&quot;http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx&quot;&gt;an announcement posted today&lt;/a&gt;, says the confusion surrounding this particular attack has compelled Microsoft to act now. Microsoft’s primary advice: upgrade to IE 8, which is not affected by this flaw. If you don’t plan to upgrade, then updates for earlier versions will be made available, with specific timing of the updates to be announced tomorrow. In the meantime, Microsoft suggests using the workarounds and mitigations provided in &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/979352.mspx&quot;&gt;Security Advisory 979352&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Microsoft&lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/microsoft_releases_outofband_security_patch_internet_explorer#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/5877">cyber attack</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/security_update">security update</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6124">zero-day</category>
 <pubDate>Tue, 19 Jan 2010 16:57:40 -0600</pubDate>
 <dc:creator>Bart Salisbury</dc:creator>
 <guid isPermaLink="false">10362 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Recent Microsoft Patches Causing System Crashes</title>
 <link>http://www.maximumpc.com/article/news/recent_microsoft_patches_causing_system_crashes</link>
 <description>&lt;!--paging_filter--&gt;&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u96627/bscreen.jpg&quot; width=&quot;405&quot; height=&quot;253&quot; /&gt; &lt;/p&gt;
&lt;p&gt;Stop me if you’ve heard this one before: &lt;a href=&quot;http://www.pcworld.com/article/183335/&quot;&gt;a security patch issued by Microsoft on November 10 is causing some PCs to crash&lt;/a&gt;. Not a simple blue screen of death, mind you, but a black screen of death. Operating systems affected include Windows 7, Vista, and XP; probably so that no Windows user will be denied this blessed experience.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.pcworld.com/article/183335/&quot;&gt;Jeremy Kirk, of the IDG News Services&lt;/a&gt;, reports the problem to be linked to Microsoft’s monkeying about with the Access Control List (ACL). The ACL is a list of permissions for the logged-in user. It interacts with registry keys to create visible desktop features, like the sidebar.&lt;/p&gt;
&lt;p&gt;The patch changes some of those registry keys, which messes with certain installed applications. These applications are unaware of the registry changes, don’t run properly, and, in a fit of pique, bring the PC to a crashing halt. According to Mel Morris, the CEO of Prevx, a United Kingdom security firm: “If you’ve got this problem, it’s masively debilitating.” &lt;a href=&quot;http://www.prevx.com/blog/140/Black-Screen-woes-could-affect-millions-on-Windows--Vista-and-XP.html&quot;&gt;Prevx, at its web site, offers a fix for the problem&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Anakin101/Wikipedia Commons&lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/recent_microsoft_patches_causing_system_crashes#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/10591">access control list</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/10590">black screen of death</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/10593">Prevx</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/10592">registry key</category>
 <category domain="http://www.maximumpc.com/geek_tested/security_update">security update</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <pubDate>Mon, 30 Nov 2009 16:56:39 -0600</pubDate>
 <dc:creator>Bart Salisbury</dc:creator>
 <guid isPermaLink="false">9419 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Google Patches Chrome Security Vulnerabilities</title>
 <link>http://www.maximumpc.com/article/news/google_patches_chrome_security_vulnerabilities</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;Several security vulnerabilities were reported in Google’s Chrome web browser after its beta version was launched earlier this month with much ado. Google has quickly responded with &lt;a href=&quot;http://www.eweek.com/c/a/Security/Google-Patches-Security-Vulnerabilities-in-Chrome/&quot;&gt;a security update that fixes four vulnerabilities&lt;/a&gt;. The update addresses two buffer overflow vulnerabilities, both rated critical by Google, and two other minor bugs. However, the carpet-bombing threat, first brought to light by security researcher Aviv Raff, still looms. &lt;/p&gt;
&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u46168/chrome_0.jpg&quot; width=&quot;415&quot; height=&quot;281&quot; /&gt;&lt;/div&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/google_patches_chrome_security_vulnerabilities#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4904">google chrome</category>
 <category domain="http://www.maximumpc.com/geek_tested/open_source">open source</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch">patch</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/security_update">security update</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/geek_tested/threat">threat</category>
 <category domain="http://www.maximumpc.com/geek_tested/vulnerability">vulnerability</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2783">web browser</category>
 <pubDate>Wed, 10 Sep 2008 19:11:23 -0500</pubDate>
 <dc:creator>Pulkit Chandna</dc:creator>
 <guid isPermaLink="false">3478 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>MS07-069 Windows XP Woes Solved (and We Suggested It First!)</title>
 <link>http://www.maximumpc.com/article/ms07_069_windows_xp_woes_solved_and_we_suggested_it_first</link>
 <description>&lt;!--paging_filter--&gt;&lt;h4&gt;MS07-069&#039;s No Joy - But MS Has the Solution&lt;/h4&gt;
&lt;p&gt;Microsoft&#039;s MS07-069 cumulative security update for Internet Explorer hasn&#039;t been the most welcome update this holiday season. As our own Paul Lilly &lt;a href=&quot;/article/daily_news_brief_evga_responds_to_gripes_over_680is_broke_penryn_support&quot;&gt;reported&lt;/a&gt;, lots of Windows XP SP2 users have no longer been able to connect to the Internet with IE after this update (brought to you by the same Windows Update that gave you &lt;a href=&quot;/article/send_windows_desktop_search_packing_now&quot;&gt;Windows Desktop Search 3.01!&lt;/a&gt;). We suggested a workaround &lt;a href=&quot;/article/bedeviled_by_ie_browser_crashes_try_these_fixes&quot;&gt;yesterday&lt;/a&gt;, but there&#039;s now a definitive solution that requires just a little registry magic. &lt;/p&gt;
&lt;h4&gt;For Browsing Benefits, Dial KB946627&lt;/h4&gt;
&lt;p&gt;Microsoft Knowledge Base article &lt;a href=&quot;http://support.microsoft.com/kb/946627/&quot;&gt;946627&lt;/a&gt; provides the details, which involve creating a new registry key and DWORD value in Windows XP SP2&#039;s registry. Here&#039;s a hint: save yourself some typing (or mistyping) by copying and pasting the the subkey during the registry editing process. The best news: you&#039;re back in business immediately, with no reboot required. &lt;/p&gt;
&lt;h4&gt;Great Minds Think Alike!&lt;/h4&gt;
&lt;p&gt;As it turns out, Microsoft&#039;s solution in KB article 946627 is the &lt;b&gt;same &lt;/b&gt;registry fix detailed as part two of the solution in KB article 942367, which we suggested as a solution yesterday. So, if you already performed &lt;a href=&quot;http://support.microsoft.com/kb/942367&quot;&gt;the steps we suggested&lt;/a&gt;, relax - you&#039;ve already fixed the problem! &lt;/p&gt;
&lt;h4&gt;Put This In Our Stockings, Steve and Bill, Please!&lt;/h4&gt;
&lt;p&gt;Here&#039;s a wish for every Windows user this Christmastime: Microsoft, please, &lt;b&gt;please&lt;/b&gt;, &lt;b&gt;&lt;i&gt;please &lt;/i&gt;&lt;/b&gt;test these security updates more thoroughly before they go out. It&#039;s absurd to make users need to whip out Regedit to fix problems of this type. &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/ms07_069_windows_xp_woes_solved_and_we_suggested_it_first#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/ie6">IE6</category>
 <category domain="http://www.maximumpc.com/geek_tested/ie7">IE7</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/news">news</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security_update">security update</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows">windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <pubDate>Thu, 20 Dec 2007 11:12:33 -0600</pubDate>
 <dc:creator>Mark Soper</dc:creator>
 <guid isPermaLink="false">1718 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
