<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC vulnerabilities RSS Feed</title>
 <link>http://www.maximumpc.com/tags/vulnerabilities</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Microsoft Discusses OS Vulnerabilities, Dangerous Software</title>
 <link>http://www.maximumpc.com/article/news/microsoft_discusses_os_vulnerabilities_dangerous_software</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;During the Black Hat conference in Las Vegas this week, Microsoft &lt;a href=&quot;http://www.dailytech.com/Microsoft+Talks+Security+at+Black+Hat+Conference/article15796.htm&quot;&gt;plans to provide a progress report&lt;/a&gt; on the security initiatives that it launched last summer, as well as release new security tools to better equip IT professionals and security researchers.&lt;/p&gt;
&lt;p&gt;&amp;quot;There&#039;s a race between attackers and defenders and if we want to win, we have to share information, &lt;a href=&quot;http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml;jsessionid=RV44GBZZ0GZS0QSNDLOSKHSCJUNN2JVN?articleID=218600627&quot;&gt;said Mike Reavey&lt;/a&gt;, director of the Microsoft Security Response Center.&lt;/p&gt;
&lt;p&gt;One way the software maker plans to do this is by releasing the Microsoft Office Visualization Tool, a utility which provides a graphical overview of the Office binary file format. According to Microsoft, the software will make it easier for programmers to understand how attacks target Office files, noting that most malware attacks application vulnerabilities and not the OS itself.&lt;/p&gt;
&lt;p&gt;&amp;quot;In order to build protections, you have to understand how a specific file format is meant to be used, so then you can understand how it&#039;s being misused,&amp;quot; Reavey added.&lt;/p&gt;
&lt;p&gt;During the conference, Microsoft also plans to release Project Quant, an online information resource designed to provide organizations with a framework for evaluating the cost of patch management processes. In addition, the company also plans to release the Microsoft Security Update Guide, a publication that explains the entire Microsoft update process, and a publish a report titled, &amp;quot;Building a Safer, More Trusted Internet Through Information Sharing.&amp;quot; &lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Microsoft_0.png&quot; width=&quot;405&quot; height=&quot;262&quot; /&gt; &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/microsoft_discusses_os_vulnerabilities_dangerous_software#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/7070">Black Hat</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <pubDate>Tue, 28 Jul 2009 15:00:50 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">7208 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>China Testing Green Dam for Mac OSX and Still Pushing Ahead Despite Security Warnings</title>
 <link>http://www.maximumpc.com/article/news/china_testing_green_dam_mac_osx_and_still_pushing_ahead_despite_security_warnings</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;&lt;img src=&quot;/files/u21826/header-Great-Firewall-China.jpg&quot; alt=&quot;Green Dam&quot; title=&quot;Green Dam&quot; width=&quot;410&quot; height=&quot;300&quot; /&gt; &lt;/p&gt;
&lt;p&gt;Despite &lt;a href=&quot;/article/news/cybersitter_code_found_china_censorship_software&quot;&gt;recently announced delays&lt;/a&gt; in China’s requirement to &lt;a href=&quot;/article/news/china_demands_all_new_pcs_include_censorship_software&quot;&gt;include&lt;/a&gt; Green Dam anti-pornography software on new PCs, the initiative is far from dead. PC makers who unanimously decried the hasty July 1st deadline managed to buy themselves an extension, but are still being told they to comply with the new requirements. The Chinese Ministry of Industry and Information Technology re-affirmed its commitment to Green Dam Youth Escort on Thursday, and claims that it sees the software as being an important tool for protecting young people from pornography and violence on the internet. To further reinforce its commitment to total penetration, software publisher Jinhui has been told to write a Mac OSX version of the software, and it is currently in beta testing.  &lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;Critics of the Green Dam filtering software continue to question the motivation behind the initiative, and have accused the Ministry of using the software to &lt;a href=&quot;/article/news/china%E2%80%99s_war_against_pornography_targets_google&quot;&gt;further political repression&lt;/a&gt;. This may be a valid concern when you consider that the Ministry in charge of Green Dam’s implantation is also responsible for suppressing illegal political activity. The situation for the Chinese gets even worse when you consider that several industry tests have shown multiple security vulnerabilities in the filtering software, and it even appears to have a high occurrence of &lt;a href=&quot;http://www.sci-tech-today.com/story.xhtml?story_id=67532&amp;amp;full_skip=1&quot;&gt;false positives&lt;/a&gt; in the filtering algorithm. The vulnerabilities are considered so serious in fact, that Sony is including a disclaimer with all new PCs.&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;Will Linux be the only safe haven for the Chinese?  &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/china_testing_green_dam_mac_osx_and_still_pushing_ahead_despite_security_warnings#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/censorship">censorship</category>
 <category domain="http://www.maximumpc.com/geek_tested/china">china</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8313">CyberSitter</category>
 <category domain="http://www.maximumpc.com/geek_tested/google">Google</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8246">Green Dam Youth Escort</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8312">Solid Oak</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4748">suggest</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8245">web browsing</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8314">web filtering</category>
 <pubDate>Sat, 04 Jul 2009 16:25:26 -0500</pubDate>
 <dc:creator>Justin Kerr</dc:creator>
 <guid isPermaLink="false">6864 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>China’s War Against Pornography Targets Google</title>
 <link>http://www.maximumpc.com/article/news/china%E2%80%99s_war_against_pornography_targets_google</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;&lt;img src=&quot;/files/u46173/googlechina.jpg&quot; alt=&quot;China Censorship&quot; title=&quot;China Censorship&quot; width=&quot;415&quot; height=&quot;262&quot; /&gt; &lt;/p&gt;
&lt;p&gt;The Chinese Health Ministry has been waging a &lt;a href=&quot;/article/news/chinas_new_censorship_software_potential_largescale_disaster&quot;&gt;very public war&lt;/a&gt; against pornography lately, and although they appeared to be &lt;a href=&quot;/article/news/cybersitter_code_found_china_censorship_software&quot;&gt;softening their approach&lt;/a&gt;, new developments on Thursday have left Google scrambling. &lt;span&gt; &lt;/span&gt;In what some people are calling “&lt;a href=&quot;http://news.cnet.com/Beijing-adding-more-curbs-to-Net-access/2100-1028_3-6249819.html?tag=newsEditorsPicksArea.0&quot;&gt;a rigged demo&lt;/a&gt;”, a CCTV state-owned television monopoly broadcast an interview demonstrating the dangers of the Google Suggested Search feature which attempts to auto complete simple search terms with popular related queries. At one point during the interview, when the host typed the word “son” into Google, a suggested search was returned stating, “abnormal relationship between son and mother”.    &lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;Google has formally commented on the matter, and has explained that the suggested search feature is based on popularity. In their defense, Google claims that nobody had entered this phrase for several months, but the term suddenly became popular in Beijing in the days leading up to the show. Though this is hardly conclusive evidence of a conspiracy, it certainly falls into the category of “suspicious” if true.&lt;span&gt;  &lt;/span&gt;Regardless, Google claims to be working on a new system that would help it remove all traces of pornography from its Chinese database, but describes it as “a major engineering effort”. &amp;quot;Google has been working to remove pornography from our search results in China, in accordance with our operating license there,&amp;quot; the company said.&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;Google already filters a significant amount of political content from its search results, and critics fear that further censorship will only complicate the efforts of rights activists. It is also worth noting that the government agency charged with cracking down on pornography, is also responsible for suppressing illegal political activity. &lt;span&gt; &lt;/span&gt;American officials have been critical of knee jerk restrictions on companies trying to comply with Chinas increasing demand for pornography censorship, and I’m sure we will hear more on this issue in the coming months.&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;What do you think of the ongoing developments in China?&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;em&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt; Image Credit: floriswiegerinck.nl&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/china%E2%80%99s_war_against_pornography_targets_google#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/censorship">censorship</category>
 <category domain="http://www.maximumpc.com/geek_tested/china">china</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8313">CyberSitter</category>
 <category domain="http://www.maximumpc.com/geek_tested/google">Google</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8246">Green Dam Youth Escort</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8312">Solid Oak</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4748">suggest</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8245">web browsing</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8314">web filtering</category>
 <pubDate>Sun, 28 Jun 2009 14:10:58 -0500</pubDate>
 <dc:creator>Justin Kerr</dc:creator>
 <guid isPermaLink="false">6781 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>CyberSitter Code Found in China Censorship Software</title>
 <link>http://www.maximumpc.com/article/news/cybersitter_code_found_china_censorship_software</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header-Great-Firewall-China.jpg&quot; alt=&quot;China&#039;s Green Dam Youth Escort web filtering software appears to contain pilfered code&quot; width=&quot;410&quot; height=&quot;300&quot; /&gt;&lt;/div&gt;
&lt;p&gt;What do &lt;a href=&quot;http://www.solidoak.com/&quot;&gt;Solid Oak Software&#039;s&lt;/a&gt; CyberSitter  and China&#039;s &lt;a href=&quot;://www.maximumpc.com/article/news/chinas_new_censorship_software_potential_largescale_disaster&quot;&gt;Green Dam Youth Escort&lt;/a&gt; Internet filtering programs have in common? According to the &lt;strong&gt;BBC&lt;/strong&gt;, the &lt;a href=&quot;/article/news/chinas_new_censorship_software_potential_largescale_disaster&quot;&gt;answer &lt;/a&gt;is CyberSitter code. The BBC reports that both Solid Oak&#039;s Brian Milburn and a report from the University of Michigan conclude that the developer of Green Dam Youth Escort, Computer System Engineering Inc, have incorporated code from CyberSitter into Green Dam - without a license.&lt;/p&gt;
&lt;p&gt;According to the &lt;strong&gt;China Daily&lt;/strong&gt;, Solid Oak is sending &amp;quot;cease and desist&amp;quot; letters to HP and Dell to stop shipping computers bundled with Green Dam, and &lt;a href=&quot;http://www.chinadaily.com.cn/bizchina/2009-06/18/content_8296017.htm&quot;&gt;may seek legal action&lt;/a&gt; against the developers. The legal-technical drama is being played out against the background of China&#039;s requirement that all new systems sold as of July 1 include Green Dam, as we&lt;a href=&quot;/article/news/china_demands_all_new_pcs_include_censorship_software&quot;&gt; reported&lt;/a&gt; last week. &lt;/p&gt;
&lt;p&gt;Green Dam now appears to be taking steps to clean up its act. Version 3.174 of Green Dam has been modified from earlier versions, according to an &lt;a href=&quot;http://www.cse.umich.edu/~jhalderm/pub/gd/&quot;&gt;updated report&lt;/a&gt; from the University of Michigan dated today (June 18th). The new version does not use blacklist files from CyberSitter and makes other changes to help improve security, although the researchers conclude the software is still vulnerable to attacks. Stay tuned to MaximumPC.com for more in the continuing saga of Green Dam.&lt;/p&gt;
&lt;h6&gt;Image adapted from &lt;a href=&quot;http://upload.wikimedia.org/wikipedia/commons/e/e9/Great_wall_of_china-mutianyu_4.JPG&quot;&gt;Wikimedia Commons image&lt;/a&gt;. &lt;/h6&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/cybersitter_code_found_china_censorship_software#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/censorship">censorship</category>
 <category domain="http://www.maximumpc.com/geek_tested/china">china</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8313">CyberSitter</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8246">Green Dam Youth Escort</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8312">Solid Oak</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8245">web browsing</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8314">web filtering</category>
 <pubDate>Thu, 18 Jun 2009 16:51:23 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6652 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>China&#039;s New Censorship Software a Potential &quot;Large-Scale Disaster&quot;</title>
 <link>http://www.maximumpc.com/article/news/chinas_new_censorship_software_potential_largescale_disaster</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header-china-censorship.png&quot; alt=&quot;China&#039;s new Green Dam Youth Escort web filtering software is a potential security risk&quot; width=&quot;410&quot; height=&quot;275&quot; /&gt;&lt;/div&gt;
&lt;p&gt;The Chinese government is requiring all PC makers selling into the China market to bundle Green Dam Youth Escort web filtering software as of July 1, as we &lt;a href=&quot;/article/news/china_demands_all_new_pcs_include_censorship_software&quot;&gt;reported&lt;/a&gt; earlier this week. This software, already widely used in China&#039;s schools and elsewhere, has plenty of flaws, BBC News &lt;a href=&quot;http://news.bbc.co.uk/2/hi/technology/8094026.stm&quot;&gt;reports&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Unencrypted connections between client PCs and the company&#039;s servers, which could lead to information theft or the PCs being turned into botnet nodes for malware attacks&lt;/li&gt;
&lt;li&gt;Filtering only Internet Explorer browsers, not Firefox&lt;/li&gt;
&lt;li&gt;Support only for Microsoft Windows&lt;/li&gt;
&lt;li&gt;Inaccurate web site blocking&lt;/li&gt;
&lt;li&gt;Potential privacy risks for users because the software logs all web pages the user attemps to access&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Right now, it &lt;a href=&quot;http://www.npr.org/templates/story/story.php?storyId=105285844&quot;&gt;seems&lt;/a&gt; as if Green Dam Youth Escort is incapable of meeting its specified goals of &amp;quot;healthy development of the internet&amp;quot; and &amp;quot;effectively manag[ing] harmful material for the public and prevent it from being spread,&amp;quot; while providing a terrific opportunity for malware providers. Have you encountered similar problems with web filtering software? Hit Comment to sound off. &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/chinas_new_censorship_software_potential_largescale_disaster#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/censorship">censorship</category>
 <category domain="http://www.maximumpc.com/geek_tested/china">china</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8246">Green Dam Youth Escort</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8245">web browsing</category>
 <pubDate>Fri, 12 Jun 2009 14:21:23 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6594 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>A Patch Tuesday &quot;Two-Fer&quot; Secures Both Microsoft and Adobe Programs</title>
 <link>http://www.maximumpc.com/article/news/junes_patch_tuesday_secures_both_microsoft_and_adobe_programs</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_MS-Adobe-PatchTuesday.png&quot; alt=&quot;June 2009&#039;s Patch Tuesday also saw Adobe security updates&quot; width=&quot;410&quot; height=&quot;177&quot; /&gt;&lt;/div&gt;
&lt;p&gt;June 9th saw a rare &#039;double-header&#039; in security updates: Microsoft&#039;s monthly Patch Tuesday was joined by Adobe&#039;s quarterly security updates for Acrobat and Adobe Reader. How big was this month&#039;s 10-update Patch Tuesday? According to a Microsoft spokesperson &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10260659-83.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-20&quot;&gt;quoted by &lt;strong&gt;Cnet&lt;/strong&gt;&lt;/a&gt;, the 31 vulnerabilities covered by updates are &amp;quot;the most since Microsoft started releasing updates on a regular schedule of the second Tuesday of every month in October 2003.&amp;quot; &lt;/p&gt;
&lt;p&gt;Here&#039;s what Microsoft patched this week:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Critical remote code execution vulnerabilities in Active Directory on Windows 2000 Server, Windows Server 2003, and ADAM on Windows Server 2003 and Windows XP Professional (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-018.mspx&quot;&gt;MS09-018&lt;/a&gt;) &lt;/p&gt;
&lt;p&gt;Critical to Moderate remote code execution vulnerabilities in Windows Print Spooler in Windows 2000 SP4, Windows XP SP2/SP3 and x64, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-022.mspx&quot;&gt;MS09-022&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Moderate remote code execution vulnerabilities in IE5.01, IE6, IE 6SP1, IE7, and IE8. Note that IE8 in Windows 7 RC is not included (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx&quot;&gt;MS09-019&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Important remote code execution vulnerabilities in Microsoft Office Word 2000, 2002 (XP), 2003, and 2007 for Windows; 2004 and 2008 for Mac, Open XML converter for Mac; Microsoft Office Word Viewers and Compatibility Packs for 2007 file formats SP1 and SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx&quot;&gt;MS09-027&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to Important remote code execution vulnerabilities in Microsoft Office Excel 2000, 2002 (XP), 2003, and 2007 for Windows; 2004 and 2008 for Mac, Open XML converter for Mac; Microsoft Office Excel Viewers and Compatibility Packs for 2007 file formats SP1 and SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-027.mspx&quot;&gt;MS09-021&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Critical to important remote code execution vulnerabilities for Microsoft Works 8.5, 9 and Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2007 SP1 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-024.mspx&quot;&gt;MS09-024&lt;/a&gt;). &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in the RPC function in Windows 2000 SP4, Windows XP SP2/SP3 and x64, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-026.mspx&quot;&gt;MS09-026&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in Windows Kernel in Windows 2000 SP4, Windows XP SP2/SP3, Windows Server 2003 SP2 and x64 SP2, Windows Vista RTM/SP1/SP2 and x64 and Windows Server 2008 RTM/SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-025.mspx&quot;&gt;MS09-025&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Important elevation of privilege vulnerabilities in IIS 5.0, 5.1, and 6.0 when running on Windows 2000 SP4, Windows XP SP2/SP3 and x64 SP2, and Windows Server 2003 SP2 and x64 SP2 (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-020.mspx&quot;&gt;MS09-020&lt;/a&gt;).  &lt;/p&gt;
&lt;p&gt;Moderate information disclosure vulnerabilities in Windows Search 4.0 when running on Windows XP SP2, SP3, x64 SP2; Windows Server 2003 SP2 and x64 SP2 only (&lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-023.mspx&quot;&gt;MS09-023&lt;/a&gt;).  &lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;For details about the exploitability rating for each vulnerability (1-3, 1 being the most severe), &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-jun.mspx&quot;&gt;see&lt;/a&gt; the security bulletin summary. To find out about Windows Media Center and other updates, and where to get the Adobe updates, join us on page 2.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Microsoft also rolled out these updates in June:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The June 2009 version of the Windows Malicious Software Removal Tool (&lt;a href=&quot;http://support.microsoft.com/?kbid=890830&quot;&gt;KB890830&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;The June 2009 update for the Windows Mail Junk email filter (&lt;a href=&quot;http://support.microsoft.com/kb/905866&quot;&gt;KB905866&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Cumulative updates for Windows Media Center for Windows Vista (&lt;a href=&quot;http://support.microsoft.com/kb/967632&quot;&gt;KB967632&lt;/a&gt;) and Windows Media Center TV Pack for Windows Vista (&lt;a href=&quot;http://support.microsoft.com/kb/966315&quot;&gt;KB966315&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;An update to the ActiveX kill bits security pack (&lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/969898.mspx&quot;&gt;KB969898&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adobe was also busy sticking its fingers in the security dike this month, rolling out critical security update &lt;a href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-07.html&quot;&gt;APSB09-07&lt;/a&gt; with updates for Adobe Reader and Acrobat 9.x, 8.x, and 7.x. Vulnerabilities patched by the updates include stack overflow, integer overflow, memory corruption and heap overflow, all of which could be used to trigger arbitrary code execution. &lt;/p&gt;
&lt;p&gt;Stay safe out there!&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/junes_patch_tuesday_secures_both_microsoft_and_adobe_programs#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe">Adobe</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe_acrobat">Adobe Acrobat</category>
 <category domain="http://www.maximumpc.com/geek_tested/adobe_reader">Adobe Reader</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_office">Microsoft Office</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_windows">Microsoft Windows</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8236">Microsoft Windows Server</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8235">Microsoft Works</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <pubDate>Thu, 11 Jun 2009 19:11:41 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6586 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>February&#039;s Patch Tuesday Has Something for Everyone</title>
 <link>http://www.maximumpc.com/article/news/februarys_patch_tuesday_has_something_everyone</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_PT0209_edited-1.png&quot; alt=&quot;Patch Tuesday for February 2009 affects both Windows desktop and Server versions&quot; width=&quot;410&quot; height=&quot;256&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Whether you&#039;re using Windows and IE, managing Microsoft Exchange or SQL Server at work, or using Microsoft Office, this month&#039;s Patch Tuesday &lt;a href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx&quot;&gt;has a security update for you&lt;/a&gt;. All four security bulletins address Remote Code Execution vulnerabilities in recent and current service packs for each product listed:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IE 7:&lt;/strong&gt; Windows XP, Windows Vista, Windows Server 2003&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Office:&lt;/strong&gt; Visio 2002, 2003, 2007&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SQL:&lt;/strong&gt; SQL Server 2000 Desktop Engine on Windows 2000 and Windows Server 2003; Windows Internal Database (WYukon) on Windows Server 2003 and Windows Server 2008; SQL Server 2000 and SQL Server 2005 &lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exchange Server:&lt;/strong&gt; Exchange 2000 Server, Exchange Server 2003, Exchange Server 2007&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;But Wait, There&#039;s More!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Other updates to be released tomorrow include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cumulative Update for Windows Vista Media Center (KB960544)&lt;/li&gt;
&lt;li&gt;Cumulative Update for Windows Vista Media Center TVPack (KB958653)&lt;/li&gt;
&lt;li&gt;Upgrade Rollup for ActiveX Killbits for Windows (KB960715)&lt;/li&gt;
&lt;li&gt;February 2009 updates for Windows Mail Junk Email Filter (KB905866) and Windows Malicious Software Removal Tool (KB890830)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For details, &lt;a href=&quot;http://support.microsoft.com&quot;&gt;look up the KB article numbers&lt;/a&gt; starting Tuesday.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/februarys_patch_tuesday_has_something_everyone#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6909">Exchange</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6908">February 2009</category>
 <category domain="http://www.maximumpc.com/geek_tested/ie">IE</category>
 <category domain="http://www.maximumpc.com/geek_tested/internet_explorer">Internet Explorer</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft_office">Microsoft Office</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch_tuesday">Patch Tuesday</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6910">SQL</category>
 <category domain="http://www.maximumpc.com/geek_tested/updates">updates</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6911">Visio</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6912">vulnerabilities</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6690">Windows updates</category>
 <pubDate>Mon, 09 Feb 2009 10:48:26 -0600</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">5225 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
