<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UKFast Blog &#187; Micro-Clouseau</title>
	<atom:link href="http://blog.ukfast.co.uk/author/micro-clouseau/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ukfast.co.uk</link>
	<description>News and views from the UK&#039;s best hosting provider</description>
	<lastBuildDate>Fri, 10 Feb 2012 13:14:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>January 2012 Microsoft Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2012/01/11/january-2012-microsoft-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2012/01/11/january-2012-microsoft-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 17:31:50 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=9436</guid>
		<description><![CDATA[As mentioned in January’s advance notification post this month’s security bulletin releases are now confirmed to contain 7 bulletins addressing 8 vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and the services this may affect: Bulletin ID Bulletin Title and Executive Summary Maximum Severity Rating and Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="January 2012 Security Bulletin Release Advance Notification" href="../2012/01/04/January-2012-security-bulletin-release-advance-notification/"><strong>January’s advance notification</strong></a> post this month’s security bulletin releases are now confirmed to contain<strong> 7 bulletins addressing 8 vulnerabilities</strong>.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and the services this may affect:</p>
<table class="default_table" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top"><strong>Bulletin ID</strong></td>
<td valign="top"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="bottom"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="bottom"><strong>Restart Requirement</strong></td>
<td valign="bottom"><strong>Affected Software</strong></td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=227487">MS12-004</a></td>
<td valign="bottom"><strong>Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391)</strong>This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="bottom">Requires restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkID=235999">MS12-001</a></td>
<td valign="bottom"><strong>Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615)</strong>This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Security Feature Bypass</td>
<td valign="bottom">Requires restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=229637">MS12-002</a></td>
<td valign="bottom"><strong>Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381)</strong>This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="bottom">May require restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=235400">MS12-003</a></td>
<td valign="bottom"><strong>Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524)</strong>This security update resolves one privately reported vulnerability in Microsoft Windows. This security update is rated Important for all supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. All supported editions of Windows 7 and Windows Server 2008 R2 are not affected by this vulnerability.</p>
<p>The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="bottom">Requires restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=230777">MS12-005</a></td>
<td valign="bottom"><strong>Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)</strong>This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="bottom">May require restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkID=232510">MS12-006</a></td>
<td valign="bottom"><strong>Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)</strong>This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Information Disclosure</td>
<td valign="bottom">Requires restart</td>
<td valign="bottom">Microsoft Windows</td>
</tr>
<tr>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=227561">MS12-007</a></td>
<td valign="bottom"><strong>Vulnerability in</strong><strong> </strong><strong>AntiXSS</strong><strong> </strong><strong>Library Could Allow Information Disclosure (2607664)</strong>This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker&#8217;s user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability.</td>
<td valign="bottom"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Information Disclosure</td>
<td valign="bottom">May require restart</td>
<td valign="bottom">Microsoft Developer Tools and Software</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>In summary, we are likely to see updates requiring reboots of servers this month. As usual, as a UKFast customer, you will benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html"><strong>updates being applied automatically</strong></a> unless you have opted out of this service.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2012/01/11/january-2012-microsoft-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2012 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2012/01/04/january-2012-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2012/01/04/january-2012-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 16:26:59 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=9428</guid>
		<description><![CDATA[Advanced notification blog Microsoft is starting off 2012 with 7 bulletins addressing 8 vulnerabilities. Bulletin breakdown: 1 bulletin is rated as critical 6 bulletins are rated as important 1 vulnerability could lead to a security feature bypass 2 vulnerabilities could lead to information disclosure 1 vulnerability could lead to elevation of privileges These updates will [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Advanced notification blog</strong></p>
<p>Microsoft is starting off 2012 with <strong>7 bulletins </strong>addressing<strong> 8 vulnerabilities.</strong></p>
<p>Bulletin breakdown:</p>
<ul>
<li>1 bulletin is rated as critical</li>
<li>6 bulletins are rated as important</li>
<li>1 vulnerability could lead to a security feature bypass</li>
<li>2 vulnerabilities could lead to information disclosure</li>
<li>1 vulnerability could lead to elevation of privileges</li>
</ul>
<p>These updates will be applied to all Microsoft Operating Systems, Microsoft Developer tools and software.<br />
The following table summarises the security bulletins for this month in order of severity.</p>
<table class="default_table" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="25%"><strong>Bulletin ID</strong></td>
<td valign="top" width="25%">
<p align="center"><strong>Maximum Severity Rating and Vulnerability Impact</strong></p>
</td>
<td valign="top" width="25%">
<p align="center"><strong>Restart Requirement</strong></p>
</td>
<td valign="top" width="25%">
<p align="center"><strong>Affected Software</strong></p>
</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 1</td>
<td valign="top" width="25%">
<p align="center"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank"><strong>Critical</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Requires restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 2</td>
<td valign="top" width="25%">
<p align="center"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Requires restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 3</td>
<td valign="top" width="25%">
<p align="center"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">May require restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 4</td>
<td valign="top" width="25%">
<p align="center"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Requires restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Information Disclosure</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 5</td>
<td valign="top" width="25%">
<p align="center"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">May Require restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 6</td>
<td valign="top" width="25%">
<p align="center"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Requires restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Windows</p>
</td>
</tr>
<tr>
<td valign="top" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="25%">Bulletin 7</td>
<td valign="top" width="25%">
<p align="center"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx"><strong>Important</strong></a></p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">May require restart</p>
</td>
<td rowspan="2" valign="top" width="25%">
<p align="center">Microsoft Developer Tools and Software</p>
</td>
</tr>
<tr>
<td style="text-align: left;">Information Disclosure</td>
</tr>
</tbody>
</table>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 10<sup>th</sup> of January 2012</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2012/01/04/january-2012-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Microsoft Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/12/15/december-2011-microsoft-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/12/15/december-2011-microsoft-security-bulletin-release/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 10:20:47 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=9328</guid>
		<description><![CDATA[As mentioned in December&#8217;s advance notification post this month&#8217;s security bulletin releases are now confirmed to contain 14 bulletins addressing 20 vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided: Bulletin ID Bulletin Title and Executive Summary Maximum Severity Rating and Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="December 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/12/12/december-2011-security-bulletin-release-advance-notification/">December&#8217;s advance notification</a> post this month&#8217;s security bulletin releases are now confirmed to contain <strong>14 bulletins addressing 20 vulnerabilities</strong>.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table cellspacing="0" cellpadding="0" width="100%" class="default_table">
<tbody>
<tr>
<td valign="top" width="20%"><strong>Bulletin ID</strong></td>
<td valign="top" width="20%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="20%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="20%"><strong>Restart Requirement</strong></td>
<td valign="top" width="20%"><strong>Affected Software</strong></td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-087.mspx" target="_blank">MS11-087</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2639417)</strong><br />
This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted document or visits a malicious Web page that embeds TrueType font files.</td>
<td style="text-align: left;" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-090.mspx" target="_blank">MS11-090</a></td>
<td style="text-align: left;" valign="top"><strong>Cumulative Security Update of ActiveX Kill Bits (2618451)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft software. The vulnerability could allow remote code execution if a user views a specially crafted Web page that uses a specific binary behavior in Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes kill bits for four third-party ActiveX controls.</td>
<td style="text-align: left;" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Critical</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-092.mspx" target="_blank">MS11-092</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Windows Media Could Allow Remote Code Execution (2648048)</strong><br />
This security update resolves a privately reported vulnerability in Windows Media Player and Windows Media Center. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Digital Video Recording (.dvr-ms) file. In all cases, a user cannot be forced to open the file; for an attack to be successful, a user must be convinced to do so.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-088.mspx" target="_blank">MS11-088</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Microsoft Office IME (Chinese) Could Allow Elevation of Privilege (2652016)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user performed specific actions on a system where an affected version of the Microsoft Pinyin (MSPY) Input Method Editor (IME) for Simplified Chinese is installed. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights. Only implementations of Microsoft Pinyin IME 2010 are affected by this vulnerability. Other versions of Simplified Chinese IME and other implementations of IME are not affected.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-089.mspx" target="_blank">MS11-089</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Microsoft Office Could Allow Remote Code Execution (2590602)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-091.mspx" target="_blank">MS11-091</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2607702)</strong><br />
This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft Office. The most severe vulnerabilities could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-093.mspx" target="_blank">MS11-093</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in OLE Could Allow Remote Code Execution (2624667)</strong><br />
This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.The vulnerability could allow remote code execution if a user opens a file that contains a specially crafted OLE object. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-094.mspx" target="_blank">MS11-094</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2639142)</strong><br />
This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of the vulnerabilities could take complete control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-095.mspx" target="_blank">MS11-095</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Active Directory Could Allow Remote Code Execution (2640045)</strong><br />
This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow remote code execution if an attacker logs on to an Active Directory domain and runs a specially crafted application. To exploit this vulnerability, an attacker would first need to acquire credentials to log on to an Active Directory domain.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-096.mspx" target="_blank">MS11-096</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-3403.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-097.mspx" target="_blank">MS11-097</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2620712)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-098.mspx" target="_blank">MS11-098</a></td>
<td style="text-align: left;" valign="top"><strong>Vulnerability in Windows Kernel Could Allow Elevation of Privilege (2633171)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-099.mspx" target="_blank">MS11-099</a></td>
<td style="text-align: left;" valign="top"><strong>Cumulative Security Update for Internet Explorer (2618444)</strong><br />
This security update resolves three privately reported vulnerabilities in Internet Explorer. The most severe vulnerability could allow remote code execution if a user opens a legitimate HyperText Markup Language (HTML) file that is located in the same directory as a specially crafted dynamic link library (DLL) file.</td>
<td style="text-align: left;" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows, Internet Explorer</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (As usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
<p>&nbsp;</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/12/15/december-2011-microsoft-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/12/12/december-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/12/12/december-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 09:45:33 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=9308</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for December 2011, sees the release of 14 bulletins addressing 20 vulnerabilities. Bulletin Breakdown: 3 bulletins are rated Critical, 11 are Important 10 vulnerabilities can lead to Remote Code Execution 3 vulnerability can lead to Elevation of Privilege 1 vulnerability can lead to Information Disclosure &#160; The following table summarises the security [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; for December 2011, </strong>sees the release of<strong> 14 bulletins addressing 20 vulnerabilities.</strong></p>
<p>Bulletin Breakdown:</p>
<ul>
<li>3 bulletins are rated Critical, 11 are Important</li>
<li>10 vulnerabilities can lead to Remote Code Execution</li>
<li>3 vulnerability can lead to Elevation of Privilege</li>
<li>1 vulnerability can lead to Information Disclosure</li>
</ul>
<p>&nbsp;<br />
The following table summarises the security bulletins for this month in order of severity.</p>
<table class="default_table" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="middle" width="25%"><strong>Bulletin ID</strong></td>
<td valign="middle" width="25%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="middle" width="25%"><strong>Restart Requirement</strong></td>
<td valign="middle" width="25%"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 1</td>
<td valign="middle" width="25%"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Critical</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 2</td>
<td valign="middle" width="25%"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Critical</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 3</td>
<td valign="top" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 4</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Information Disclosure</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 5</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May Require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Office</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 6</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Office</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 7</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 8</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Office</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 9</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 10</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Office</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 11</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 12</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows</td>
</tr>
<tr>
<td valign="middle" width="25%">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 13</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">Requires restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Windows, Internet Explorer</td>
</tr>
<tr>
<td valign="middle" width="25%">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="middle" width="25%">Bulletin 14</td>
<td valign="middle" width="25%"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="middle" width="25%">May require restart</td>
<td rowspan="2" valign="middle" width="25%">Microsoft Office</td>
</tr>
<tr>
<td valign="middle" width="25%">Elevation of Privilege</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 13<sup>th</sup> of December.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/12/12/december-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>November 2011 Microsoft Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/11/09/november-2011-microsoft-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/11/09/november-2011-microsoft-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 12:19:18 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8882</guid>
		<description><![CDATA[As mentioned in Novembers advance notification post this month&#8217;s security bulletin releases are now confirmed to contain 4 bulletins addressing 4 vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided: Bulletin ID Bulletin Title and Executive Summary Maximum Severity Rating and Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="November 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/11/07/november-2011-security-bulletin-release-advance-notification/">Novembers advance notification</a> post this month&#8217;s security bulletin releases are now confirmed to contain <strong>4 bulletins addressing 4 vulnerabilities</strong>.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table class="default_table" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="15%"><strong>Bulletin ID</strong></td>
<td valign="top" width="41%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="18%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="18%"><strong>Restart Requirement</strong></td>
<td valign="top" width="18%"><strong>Affected Software</strong></td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-083.mspx" target="_blank">MS11-083</a></td>
<td valign="top"><strong>Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to a closed port on a target system.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-085.mspx" target="_blank">MS11-085</a></td>
<td valign="top"><strong>Vulnerability in Windows Mail and Windows Meeting Space Could Allow Remote Code Execution (2620704) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .eml or .wcinv file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Mail or Windows Meeting Space could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .eml or .wcinv file) from this location that is then loaded by a vulnerable application.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-086.mspx" target="_blank">MS11-086</a></td>
<td valign="top"><strong>Vulnerability in Active Directory Could Allow Elevation of Privilege (2630837)</strong><br />
This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS). The vulnerability could allow elevation of privilege if Active Directory is configured to use LDAP over SSL (LDAPS) and an attacker acquires a revoked certificate that is associated with a valid domain account and then uses that revoked certificate to authenticate to the Active Directory domain. By default, Active Directory is not configured to use LDAP over SSL.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-084.mspx" target="_blank">MS11-084</a></td>
<td valign="top"><strong>Vulnerability in Windows Kernel-Mode Drivers Could Allow Denial of Service (2617657) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user opens a specially crafted TrueType font file as an e-mail attachment or navigates to a network share or WebDAV location containing a specially crafted TrueType font file. For an attack to be successful, a user must visit the untrusted remote file system location or WebDAV share containing the specially crafted TrueType font file, or open the file as an e-mail attachment. In all cases, however, an attacker would have no way to force users to perform these actions. Instead, an attacker would have to persuade users to do so, typically by getting them to click a link in an e-mail message or Instant Messenger message.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Moderate</a><br />
Denial of Service</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
</tbody>
</table>
<p>While this is the lightest patch Tuesday of the year, MS11-083 affects all Windows based devices and is patching what looks to be the worst vulnerability of the year.</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (As usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
<p>&nbsp;</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/11/09/november-2011-microsoft-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/11/07/november-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/11/07/november-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Mon, 07 Nov 2011 14:25:27 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8875</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for November 2011, sees the release of 4 bulletins addressing 4 vulnerabilities. Bulletin Breakdown: 1 bulletin is rated Critical, 2 are Important and 1 Moderate 2 vulnerabilities can lead to Remote Code Execution 1 vulnerability can lead to Elevation of Privilege 1 vulnerability can lead to Denial of Service &#160; The following [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; for November 2011, </strong>sees the release of<strong> 4 bulletins addressing 4 vulnerabilities.</strong></p>
<p>Bulletin Breakdown:</p>
<ul>
<li>1 bulletin is rated Critical, 2 are Important and 1 Moderate</li>
<li>2 vulnerabilities can lead to Remote Code Execution</li>
<li>1 vulnerability can lead to Elevation of Privilege</li>
<li>1 vulnerability can lead to Denial of Service</li>
</ul>
<p>&nbsp;</p>
<p>The following table summarises the security bulletins for this month in order of severity.</p>
<table class="default_table" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="25%"><strong>Bulletin ID</strong></td>
<td valign="top" width="25%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="25%"><strong>Restart Requirement</strong></td>
<td valign="top" width="25%"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 1</td>
<td valign="top" width="92"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Critical</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 2</td>
<td valign="top" width="92"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 3</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 4</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Moderate</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Denial of service</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 8<sup>th</sup> of November.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/11/07/november-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>October 2011 Microsoft Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/10/13/october-2011-microsoft-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/10/13/october-2011-microsoft-security-bulletin-release/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 08:22:49 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8758</guid>
		<description><![CDATA[As mentioned in Octobers Advance notification post this month&#8217;s security bulletin releases are now confirmed to contain 8 bulletins addressing 23 vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided: Bulletin ID Bulletin Title and Executive Summary Maximum Severity [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="October 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/10/07/october-2011-security-bulletin-release-advance-notification/">Octobers Advance notification</a> post this month&#8217;s security bulletin releases are now confirmed to contain <strong>8 bulletins addressing 23 vulnerabilities</strong>.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table width="86%" border="1" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td valign="top" width="9%"><strong>Bulletin ID</strong></td>
<td valign="top" width="43%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="16%"><strong>Restart Requirement</strong></td>
<td valign="top" width="14%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top"><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-078" target="_blank">MS11-078</a></td>
<td valign="top"><strong>Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2604930)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Critical</a></p>
<p>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft .NET Framework, Microsoft Silverlight</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-081.mspx" target="_blank">MS11-081</a></td>
<td valign="top"><strong>Cumulative Security Update for Internet Explorer (2586448) </strong><br />
This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Critical</a></p>
<p>Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows, Internet Explorer</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-075.mspx" target="_blank">MS11-075</a></td>
<td valign="top"><strong>Vulnerability in Microsoft Active Accessibility Could Allow Remote Code Execution (2623699)</strong><br />
This security update resolves a privately reported vulnerability in the Microsoft Active Accessibility component. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, the Microsoft Active Accessibility component could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by a vulnerable application.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-076.mspx" target="_blank">MS11-076</a></td>
<td valign="top"><strong>Vulnerability in Windows Media Center Could Allow Remote Code Execution (2604926) </strong><br />
This security update resolves a publicly disclosed vulnerability in Windows Media Center. The vulnerability could allow remote code execution if an attacker convinces a user to open a legitimate file that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Media Center could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-077.mspx" target="_blank">MS11-077</a></td>
<td valign="top"><strong>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053)</strong><br />
This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment. For a remote attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open the specially crafted font file, or open the file as an e-mail attachment.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-079.mspx" target="_blank">MS11-079</a></td>
<td valign="top"><strong>Vulnerabilities in Microsoft Forefront Unified Access Gateway Could Cause Remote Code Execution (2544641) </strong><br />
This security update resolves five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL. However, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to persuade users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Forefront United Access Gateway</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-080.mspx" target="_blank">MS11-080</a></td>
<td valign="top"><strong>Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2592799) </strong><br />
This security update resolves a privately reported vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user&#8217;s system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Elevation of Privilege</td>
<td valign="top">Requires Restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-082.mspx" target="_blank">MS11-082</a></td>
<td valign="top"><strong>VVulnerabilities in Host Integration Server Could Allow Denial of Service (2607670) </strong><br />
This security update resolves two publicly disclosed vulnerabilities in Host Integration Server. The vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed. In this case, the Host Integration Server ports should be blocked from the Internet.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></p>
<p>Denial of Service</td>
<td valign="top">May Require Restart</td>
<td valign="top">Microsoft Host Integration Server</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (As usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
<p>MC.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/10/13/october-2011-microsoft-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/10/07/october-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/10/07/october-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 14:03:37 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8749</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for October 2011, sees the release of 8 bulletins addressing 23 vulnerabilities. Bulletin Breakdown: 2 bulletins are rated Critical, 6 are Important 6 vulnerabilities can lead to Remote Code Execution 1 vulnerability can lead to Elevation of Privilege 1 vulnerability can lead to Denial of Service The following table summarises the security [...]]]></description>
			<content:encoded><![CDATA[<p>This &#8216;<strong>Patch Tuesday&#8217; for October 2011, </strong>sees the release of<strong> 8 bulletins addressing 23 vulnerabilities.</strong></p>
<p><strong></strong><br />
Bulletin Breakdown:</p>
<ul>
<li>2 bulletins are rated Critical, 6 are Important</li>
<li>6 vulnerabilities can lead to Remote Code Execution</li>
<li>1 vulnerability can lead to Elevation of Privilege</li>
<li>1 vulnerability can lead to Denial of Service</li>
</ul>
<p>The following table summarises the security bulletins for this month in order of severity.</p>
<table width="533" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="81"><strong>Bulletin ID</strong></td>
<td valign="top" width="92"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="85"><strong>Restart Requirement</strong></td>
<td valign="top" width="80"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 1</td>
<td valign="top" width="92"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Critical</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft .NET Framework,<br />
Microsoft Silverlight</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 2</td>
<td valign="top" width="92"><a href="http://technet.microsoft.com/en-us/security/bulletin/rating" target="_blank">Critical</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows,<br />
Internet Explorer</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 3</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 4</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 5</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 6</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Forefront Unified Access Gateway</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 7</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 8</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Host Integration Server</td>
</tr>
<tr>
<td valign="top" width="92">Denial of Service</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 11<sup>th</sup> of October.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/10/07/october-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2011 Microsoft Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/09/14/september-2011-microsoft-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/09/14/september-2011-microsoft-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 13:20:06 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8627</guid>
		<description><![CDATA[As mentioned in September&#8217;s Advance notification post this month&#8217;s security bulletin releases are now confirmed to contain 5 bulletins addressing 15 vulnerabilities, all of which have an important rating. Microsoft has recommended for all security updates to be installed asap. The following table shows affected software by bulletin and the likelihood of an Operating System [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="September 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/09/09/8607/">September&#8217;s Advance notification</a> post this month&#8217;s security bulletin releases are now confirmed to contain <strong>5 bulletins addressing 15 vulnerabilities</strong>, all of which have an important rating. Microsoft has recommended for all security updates to be installed asap.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table width="86%" border="1" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td valign="top" width="9%"><strong>Bulletin ID</strong></td>
<td valign="top" width="43%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="16%"><strong>Restart Requirement</strong></td>
<td valign="top" width="14%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top"><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-070" target="_blank">MS11-070</a></td>
<td valign="top"><strong><strong>Vulnerability in WINS Could Allow Elevation of Privilege (2571621)</strong> </strong>This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow elevation of privilege if a user received a specially crafted WINS replication packet on an affected system running the WINS service. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Important<br />
</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-071.mspx" target="_blank">MS11-071</a></td>
<td valign="top"><strong><strong>Vulnerability in Windows Components Could Allow Remote Code Execution (2570947)</strong> </strong>This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate rich text format file (.rtf), text file (.txt), or Word document (.doc) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx" target="_blank">Important</a>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-072.mspx" target="_blank">MS11-072</a></td>
<td valign="top"><strong><strong>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)</strong> </strong>This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1986 and CVE-2011-1987.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office,<br />
Microsoft Server Software</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-073.mspx" target="_blank">MS11-073</a></td>
<td valign="top"><strong><strong>Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634)</strong>  </strong>This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file or if a user opens a legitimate Office file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited either of the vulnerabilities could gain the same user rights as the logged on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a>Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-074.mspx" target="_blank">MS11-074</a></td>
<td valign="top"><strong><strong>Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858)</strong> </strong>This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft SharePoint and Windows SharePoint Services. The most severe vulnerabilities could allow elevation of privilege if a user clicked on a specially crafted URL or visited a specially crafted Web site. For the most severe vulnerabilities, Internet Explorer 8 and Internet Explorer 9 users browsing to a SharePoint site in the Internet Zone are at a reduced risk because, by default, the XSS Filter in Internet Explorer 8 and Internet Explorer 9 helps to block the attacks in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9, however, is not enabled by default in the Intranet Zone.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a>Elevation of Privilege</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office,<br />
Microsoft Server Software</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (As usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
<p>MC.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/09/14/september-2011-microsoft-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/09/09/8607/</link>
		<comments>http://blog.ukfast.co.uk/2011/09/09/8607/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 08:44:33 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8607</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for September 2011, sees the release of 5 bulletins addressing 15 vulnerabilities: Bulletin Breakdown: All 5 bulletins are rated Important 3 vulnerabilities can lead to Remote Code Execution 2 vulnerabilities can lead to Elevation of Privilege The following table summarises the security bulletins for this month in order of severity. Bulletin ID [...]]]></description>
			<content:encoded><![CDATA[<p>This &#8216;<strong>Patch Tuesday&#8217; for September 2011, </strong>sees the release of<strong> 5 bulletins addressing 15 vulnerabilities:</strong><br />
Bulletin Breakdown:</p>
<ul>
<li>All 5 bulletins are rated Important</li>
<li>3 vulnerabilities can lead to Remote Code Execution</li>
<li>2 vulnerabilities can lead to Elevation of Privilege</li>
</ul>
<p>The following table summarises the security bulletins for this month in order of severity.</p>
<table width="533" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="81"><strong>Bulletin ID</strong></td>
<td valign="top" width="92"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="85"><strong>Restart Requirement</strong></td>
<td valign="top" width="80"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 1</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">Requires restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 2</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 3</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Office, Microsoft Server Software</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 4</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Office</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 5</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="80">Microsoft Office, Microsoft Server Software</td>
</tr>
<tr>
<td valign="top" width="92">Elevation of Privilege</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 13<sup>th</sup> of September.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/09/09/8607/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Looks to Crack Cloud Security</title>
		<link>http://blog.ukfast.co.uk/2011/08/11/microsoft-look-to-crack-cloud-security/</link>
		<comments>http://blog.ukfast.co.uk/2011/08/11/microsoft-look-to-crack-cloud-security/#comments</comments>
		<pubDate>Thu, 11 Aug 2011 16:16:28 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8481</guid>
		<description><![CDATA[Microsoft is looking to crack one of the key problems in cloud hosting; keeping data secure. Even though the technology offers many advantages, data security is one issue that is putting some companies off switching to the cloud. The team at Microsoft, however, has developed a technique that enables organisations to perform analysis on encrypted data without having [...]]]></description>
			<content:encoded><![CDATA[<h2><span class="Apple-style-span" style="font-size: 13px; font-weight: normal;">Microsoft is looking to crack one of the key problems in <a href="http://www.ukfast.co.uk/cloud-hosting.html">cloud hosting</a>; keeping data secure.</span></h2>
<p>Even though the technology offers many advantages, data security is one issue that is putting some companies off switching to the cloud.</p>
<p>The team at Microsoft, however, has developed a technique that enables organisations to perform analysis on encrypted data without having to decrypt – a move that will greatly improve the security of any data held in the cloud.</p>
<p>The technique, called homomorphic encryption, also ensures that the data emerges from the analysis fully decrypted.</p>
<p>In a paper written by Microsoft researchers Kristin Lauter,Vinod Vaikutanathan and Michael Naehrig, the research team point out that although there’s a need for encryption to meet the security concerns of customers it was hard to “ignore the elephant in the room, namely efficiency.” The researchers go on to point out that “all known fully homomorphic encryption schemes have a long way to go before they can be used in practice.”</p>
<p>The Microsoft team claims that it has solved some of the efficiency issues by using what they call a “somewhat” form of homomorphic encryption, which does not have the full capabilities of the technology but offers enough to be practical.</p>
<p>The researchers also state that they have demonstrated how the technology can be used in practical situations, for example, medical records &#8211; a clear example of where the Microsoft technology would have real practical use.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/08/11/microsoft-look-to-crack-cloud-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/08/10/august-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/08/10/august-2011-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 10 Aug 2011 13:53:22 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8476</guid>
		<description><![CDATA[As mentioned in August&#8217;s  Advance notification post this month&#8217;s security bulletin releases are now confirmed to contain 13 bulletins addressing 22 vulnerabilities, two of which have a critical rating. Microsoft has recommended for all security updates to be installed asap. The following table shows affected software by bulletin and the likelihood of an Operating System [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="August 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/08/05/august-2011-security-bulletin-release-advance-notification/">August&#8217;s  Advance notification</a> post this month&#8217;s security bulletin releases are now confirmed to contain <strong>13 bulletins addressing 22 vulnerabilities</strong>, two of which have a critical rating. Microsoft has recommended for all security updates to be installed asap.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table width="86%" border="1" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td valign="top" width="9%"><strong>Bulletin ID</strong></td>
<td valign="top" width="43%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="16%"><strong>Restart Requirement</strong></td>
<td valign="top" width="14%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx">MS11-057</a></td>
<td valign="top"><strong>Cumulative Security Update for Internet Explorer (2559049)</strong><br />
This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows, Internet Explorer</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-058.mspx">MS11-058</a></td>
<td valign="top"><strong>Vulnerabilities in DNS Server Could Allow Remote Code Execution (2562485) </strong><br />
This security update resolves two privately reported vulnerabilities in Windows DNS server. The more severe of these vulnerabilities could allow remote code execution if an attacker registers a domain, creates an NAPTR DNS resource record, and then sends a specially crafted NAPTR query to the target DNS server. Servers that do not have the DNS role enabled are not at risk.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-059.mspx">MS11-059</a></td>
<td valign="top"><strong>Vulnerability in Data Access Components Could Allow Remote Code Execution (2560656)</strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate Excel file (such as a .xlsx file) that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-060.mspx">MS11-060</a></td>
<td valign="top"><strong>Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978) </strong><br />
This security update resolves two privately reported vulnerabilities in Microsoft Visio. The vulnerabilities could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-061.mspx">MS11-061</a></td>
<td valign="top"><strong>Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege (2546250)</strong><br />
This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 prevents this attack for its users when browsing to a Remote Desktop Web Access server in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9 is not enabled by default in the Intranet Zone.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-062.mspx">MS11-062</a></td>
<td valign="top"><strong>Vulnerability in Remote Access Service NDISTAPI Driver Could Allow Elevation of Privilege (2566454)</strong><br />
This security update resolves a privately reported vulnerability in all supported editions of Windows XP and Windows Server 2003. This security update is rated Important for all supported editions of Windows XP and Windows Server 2003. Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are not affected by the vulnerability.<br />
The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to exploit the vulnerability and take complete control over the affected system. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-063.mspx">MS11-063</a></td>
<td valign="top"><strong>Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2567680) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-064.mspx">MS11-064</a></td>
<td valign="top"><strong>Vulnerabilities in TCP/IP Stack Could Allow Denial of Service (2563894) </strong><br />
This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow denial of service if an attacker sends a sequence of specially crafted Internet Control Message Protocol (ICMP) messages to a target system or sends a specially crafted URL request to a server that is serving Web content and has the URL-based Quality of Service (QoS) feature enabled.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Denial of Service</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-065.mspx">MS11-065</a></td>
<td valign="top"><strong>Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (2570222) </strong><br />
This security update resolves a privately reported vulnerability in the Remote Desktop Protocol. The vulnerability could allow denial of service if an affected system received a sequence of specially crafted RDP packets. Microsoft has also received reports of limited, targeted attacks attempting to exploit this vulnerability. By default, the Remote Desktop Protocol (RDP) is not enabled on any Windows operating system.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Denial of Service</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-066.mspx">MS11-066</a></td>
<td valign="top"><strong>Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943) </strong><br />
This security update resolves a privately reported vulnerability in ASP.NET Chart controls. The vulnerability could allow information disclosure if an attacker sent a specially crafted GET request to an affected server hosting the Chart controls. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker&#8217;s user rights directly, but it could be used to retrieve information that could be used to further compromise the affected system. Only web applications using Microsoft Chart Control are affected by this issue. Default installations of the .NET Framework are not affected.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Information Disclosure</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft .NET Framework, Microsoft Developer Tools</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-067.mspx">MS11-067</a></td>
<td valign="top"><strong>Vulnerability in Microsoft Report Viewer Could Allow Information Disclosure (2578230) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft Report Viewer. The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Information Disclosure</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Developer Tools</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-068.mspx">MS11-068</a></td>
<td valign="top"><strong>Vulnerability in Windows Kernel Could Allow Denial of Service (2556532) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if a user visits a network share (or visits a Web site that points to a network share) containing a specially crafted file. In all cases, however, an attacker would have no way to force a user to visit such a network share or Web site. Instead, an attacker would have to convince a user to do so, typically by getting the user to click a link in an e-mail message or Instant Messenger message.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Moderate</a><br />
Denial of Service</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-069.mspx">MS11-069</a></td>
<td valign="top"><strong>Vulnerability in .NET Framework Could Allow Information Disclosure (2567951) </strong><br />
This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow information disclosure if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker&#8217;s Web site. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Moderate</a><br />
Information Disclosure</td>
<td valign="top">May Require restart</td>
<td valign="top">Microsoft .NET Framework</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (As usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)<br />
MC.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/08/10/august-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/07/13/july-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/07/13/july-2011-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 12:41:27 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8351</guid>
		<description><![CDATA[As mentioned in July&#8217;s Advance notification post this month&#8217;s security bulletin releases, are now confirmed to contain 4 bulletins addressing 22 vulnerabilities, one of which has a critical rating, Microsoft has recommended for all security updates to be installed asap. The remaining three all have been rated as important bulletins. This month sees a light [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="July 2011 Security Bulletin Release Advance Notification" href="../2011/07/06/july-2011-security-bulletin-release-advance-notification/">July&#8217;s Advance notification </a> post this month&#8217;s security bulletin releases, are now confirmed to contain <strong>4 bulletins addressing 22 vulnerabilities</strong>, one of which has a critical rating, Microsoft has recommended for all security updates to be installed asap. The remaining three all have been rated as important bulletins.</p>
<p>This month sees a light bulletin release from Microsoft covering a small range of affected products including</p>
<ul>
<li>All supported Microsoft operating systems</li>
<li>Microsoft Visio 2003</li>
</ul>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table width="86%" border="1" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td valign="top" width="9%"><strong>Bulletin ID</strong></td>
<td valign="top" width="43%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="16%"><strong>Restart Requirement</strong></td>
<td valign="top" width="14%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=217102">MS11-053</a></td>
<td valign="top"><strong>Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220)</strong>This security update resolves a privately reported vulnerability in the Windows Bluetooth Stack. The vulnerability could allow remote code execution if an attacker sent a series of specially crafted Bluetooth packets to an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability only affects systems with Bluetooth capability.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=220172">MS11-054</a></td>
<td valign="top"><strong>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)</strong>This security update resolves 15 privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=217465">MS11-056</a></td>
<td valign="top"><strong>Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938) </strong>This security update resolves five privately reported vulnerabilities in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS). The vulnerabilities could allow elevation of privilege if an attacker logs on to a user&#8217;s system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=220276">MS11-055</a></td>
<td valign="top"><strong>Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847) </strong>This security update resolves a publicly disclosed vulnerability in Microsoft Visio. The vulnerability could allow remote code execution if a user opens a legitimate Visio file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>MS11-053 &#8211; Critical</p>
<p>This new security bulletin addresses one vulnerability in the Bluetooth stack for Windows Vista and Windows 7 and does not apply to Server editions (2003 or 2008). An attacker in the same vicinity of a vulnerable machine with Bluetooth enabled could result in an attacker sending malicious Bluetooth packets.  This could result in remote code execution.</p>
<p>If you have mobile users working outside of your office environment using Windows Vista or Windows 7, you will want to look at patching these machines as soon as possible.</p>
<p>Something of note with regards to this security update. Microsoft has reported and are releasing a non-security patch this month to coincide with this security bulletin. From testing occasionally on Windows 7 systems the update fails to install the windows drivers if you are using windows update. Microsoft are fixing issues with the User-mode Plug-and-Play (UMPnP) manager stack and as a result Microsoft will be offering a child-update within MS11-053. If the security update noticed the non-security update is not installed on the system, the non-security update will be deployed to the system first. This will prompt a reboot of the system, after the reboot the security update will then be offered and installed. This scenario will result in a longer patch deployment and as previously mentioned only effects desktop based operating systems and not Server editions.</p>
<p>&nbsp;</p>
<p>MS11-055 &#8211; Important</p>
<p>The DLL preloading issue that Microsoft has been addressing over the past year appears to be back again and this important security update resolves 15 privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.</p>
<p>&nbsp;</p>
<p>This update applies to all supported desktops and server editions including Windows XP SP3, Windows Vista, Windows 7 and Server 2003 and Server 2008</p>
<p>&nbsp;</p>
<p>MS11-054 &#8211; Important</p>
<p>This security update addresses 15 vulnerabilities in the Windows Kernel-Mode Drivers.  Which at first glance, the number of vulnerabilities addressed in this single bulletin naturally raises concerns.  All of the vulnerabilities addressed in this bulletin are however related and  an attacker must first have access to a system before they can actually exploit the vulnerability.</p>
<p>&nbsp;</p>
<p>This update applies to all supported desktops and server editions including Windows XP SP3, Windows Vista, Windows 7 and Server 2003 and Server 2008</p>
<p>&nbsp;</p>
<p>MS11-056 &#8211; Important</p>
<p>This security update addresses 5 vulnerabilities in the Windows Client/Server Run-time Subsystem on all supported Microsoft operating systems.  Like MS11-054, all of the vulnerabilities are related and again This bulletin also requires for an attacker to first have access to a system before they can exploit the vulnerability.</p>
<p>Please click the following link to view <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/7418.201107_2D00_deployment.png">Microsoft’s deployment priority guidance</a> which assists in deployment planning. You can also follow this link to view the <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/7367.201107_2D00_severity_2D00_xi.png">risk and impact graph</a> to visually see an aggregate view of this month’s severity and exploitability index.).</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)<br />
MC.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/07/13/july-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/07/06/july-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/07/06/july-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 12:36:44 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8341</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for July 2011, sees the release of 4 bulletins addressing 22 vulnerabilities: Bulletin Breakdown: 1 bulletin is rated Critical 3 bulletins are rated Important 2 vulnerabilities can lead to Remote Code Execution 2 vulnerabilities can lead to Elevation of Privilege The following table summarizes the security bulletins for this month in order [...]]]></description>
			<content:encoded><![CDATA[<p>This &#8216;<strong>Patch Tuesday&#8217; for July 2011, </strong>sees the release of<strong> 4 bulletins addressing 22 vulnerabilities:</strong><br />
Bulletin Breakdown:</p>
<ul>
<li>1 bulletin is rated Critical</li>
<li>3 bulletins are rated Important</li>
<li>2 vulnerabilities can lead to Remote Code Execution</li>
<li>2 vulnerabilities can lead to Elevation of Privilege</li>
</ul>
<p>The following table summarizes the security bulletins for this month in order of severity.</p>
<table width="86%" border="1" cellspacing="0" cellpadding="0">
<thead>
<tr>
<td valign="top" width="9%"><strong>Bulletin ID</strong></td>
<td valign="top" width="43%"><strong>Bulletin Title and Executive Summary</strong></td>
<td valign="top" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="16%"><strong>Restart Requirement</strong></td>
<td valign="top" width="14%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=217102">MS11-053</a></td>
<td valign="top"><strong>Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (2566220)</strong>This security update resolves a privately reported vulnerability in the Windows Bluetooth Stack. The vulnerability could allow remote code execution if an attacker sent a series of specially crafted Bluetooth packets to an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability only affects systems with Bluetooth capability.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=220172">MS11-054</a></td>
<td valign="top"><strong>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2555917)</strong>This security update resolves 15 privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logged on locally and ran a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=217465">MS11-056</a></td>
<td valign="top"><strong>Vulnerabilities in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2507938) </strong>This security update resolves five privately reported vulnerabilities in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS). The vulnerabilities could allow elevation of privilege if an attacker logs on to a user&#8217;s system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td valign="top">Requires restart</td>
<td valign="top">Microsoft Windows</td>
</tr>
<tr>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=220276">MS11-055</a></td>
<td valign="top"><strong>Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847) </strong>This security update resolves a publicly disclosed vulnerability in Microsoft Visio. The vulnerability could allow remote code execution if a user opens a legitimate Visio file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td valign="top">May require restart</td>
<td valign="top">Microsoft Office</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>This month sees a relatively light patch Tuesday in comparison to recent months from Microsoft</p>
<p>&nbsp;</p>
<p>The full list of software affected by these updates is:</p>
<p>&nbsp;</p>
<ul>
<li>All supported Microsoft operating systems</li>
<li>Microsoft Visio 2003</li>
</ul>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing from the 13<sup>th</sup> of July.</p>
<p>The ‘<a href="http://www.microsoft.com/technet/security/bulletin/ms11-jul.mspx">Microsoft Security Bulletin Notification for July 2011</a>‘ page should be referenced for detailed information on how these updates are to affect your servers or solutions when released on 15th June (as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/server-maintenance.html">updates being applied automatically </a>unless you have opted out of this service.)<br />
MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/07/06/july-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/06/15/june-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/06/15/june-2011-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 14:11:09 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8235</guid>
		<description><![CDATA[As mentioned in June’s Advance notification post this month’s security bulletin releases, are now confirmed to be 16 security bulletins, addressing 34 vulnerabilities, nine of which have a critical rating with four of these critical bulletins listed as Top Priorities. The remaining seven all have been rated as important bulletins. This month again sees a [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a title="June 2011 Security Bulletin Release Advance Notification" href="http://blog.ukfast.co.uk/2011/06/10/june-2011-security-bulletin-release-advance-notification/">June’s Advance notification</a> post this month’s security bulletin releases, are now confirmed to be <strong>16 security bulletins</strong>,<strong> addressing 34 vulnerabilities</strong>, nine of which have a critical rating with four of these critical bulletins listed as Top Priorities. The remaining seven all have been rated as important bulletins.</p>
<p>This month again sees a very large bulletin release from Microsoft covering a large range of affected products including</p>
<p>Windows (XP, Vista, Windows 7, Server 2003 and Server 2008 (including R2))<br />
Office<br />
Internet Explorer (6, 7, 8 and 9)<br />
.NET<br />
SQL (2005 and 2008)<br />
Visual Studios<br />
ISA Server<br />
and Silverlight.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table border="1" cellspacing="0" cellpadding="0" width="600" height="110">
<tbody>
<tr>
<td width="75" valign="top"><strong>Bulletin ID</strong></td>
<td width="200" valign="top"><strong>Bulletin Title and Executive Summary</strong></td>
<td width="92" valign="top"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td width="85" valign="top"><strong>Restart Requirement</strong></td>
<td width="64" valign="top"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-038.mspx" target="_blank">MS11-038</a></td>
<td width="200" valign="top"><strong>Vulnerability in OLE Automation Could Allow Remote Code Execution (2476490) </strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code execution if a user visits a Web site containing a specially crafted Windows Metafile (WMF) image. In all cases, however, an attacker would have no way to force users to visit such a Web site. Instead, an attacker would have to convince users to visit a malicious Web site, typically by getting them to click a link in an e-mail message or Instant Messenger request.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-039.mspx" target="_blank">MS11-039</a></td>
<td width="200" valign="top"><strong>Vulnerability in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2514842)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows, Microsoft .NET Framework, Microsoft Silverlight</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-040.mspx" target="_blank">MS11-040</a></td>
<td width="200" valign="top"><strong>Vulnerability in Threat Management Gateway Firewall Client Could Allow Remote Code Execution (2520426)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Forefront Threat Management Gateway</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in the Microsoft Forefront Threat Management Gateway (TMG) 2010 Client, formerly named the Microsoft Forefront Threat Management Gateway Firewall Client. The vulnerability could allow remote code execution if an attacker leveraged a client computer to make specific requests on a system where the TMG firewall client is used.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-041.mspx" target="_blank">MS11-041</a></td>
<td width="200" valign="top"><strong>Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2525694)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user visits a network share (or visits a web site that points to a network share) containing a specially crafted OpenType font (OTF). In all cases, however, an attacker would have no way to force a user to visit such a web site or network share. Instead, an attacker would have to convince a user to visit the web site or network share, typically by getting them to click a link in an e-mail message or Instant Messenger message.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-042.mspx" target="_blank">MS11-042</a></td>
<td width="200" valign="top"><strong>Vulnerabilities in Distributed File System Could Allow Remote Code Execution (2535512)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves two privately reported vulnerabilities in the Microsoft Distributed File System (DFS). The more severe of these vulnerabilities could allow remote code execution when an attacker sends a specially crafted DFS response to a client-initiated DFS request. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-043.mspx" target="_blank">MS11-043</a></td>
<td width="200" valign="top"><strong>Vulnerability in SMB Client Could Allow Remote Code Execution (2536276)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sent a specially crafted SMB response to a client-initiated SMB request. To exploit the vulnerability, an attacker must convince the user to initiate an SMB connection to a specially crafted SMB server.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-044.mspx" target="_blank">MS11-044</a></td>
<td width="200" valign="top"><strong>Vulnerability in .NET Framework Could Allow Remote Code Execution (2538814)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows, Microsoft .NET Framework</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a publicly disclosed vulnerability in Microsoft .NET Framework. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs). Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-050.mspx" target="_blank">MS11-050</a></td>
<td width="200" valign="top"><strong>Cumulative Security Update for Internet Explorer (2530548)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows, Internet Explorer</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves eleven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-052.mspx" target="_blank">MS11-052</a></td>
<td width="200" valign="top"><strong>Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2544521)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows, Internet Explorer</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in the Microsoft implementation of Vector Markup Language (VML). This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows clients; and Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows servers. Internet Explorer 9 is not affected by the vulnerability.<br />
The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-037.mspx" target="_blank">MS11-037</a></td>
<td width="200" valign="top"><strong>Vulnerability in MHTML Could Allow Information Disclosure (2544893)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a publicly disclosed vulnerability in the MHTML protocol handler in Microsoft Windows. The vulnerability could allow information disclosure if a user opens a specially crafted URL from an attacker&#8217;s Web site. An attacker would have to convince the user to visit the Web site, typically by getting them to follow a link in an e-mail message or Instant Messenger message.</td>
<td width="92" valign="top">Information Disclosure</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-045.mspx" target="_blank">MS11-045</a></td>
<td width="200" valign="top"><strong>Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Office</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves eight privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1272, CVE-2011-1273, and CVE-2011-1279. Microsoft Excel 2010 is only affected by CVE-2011-1273 described in this bulletin. The automated Microsoft Fix it solution, &#8220;Disable Edit in Protected View for Excel 2010,&#8221; available in Microsoft Knowledge Base Article 2501584, blocks the attack vectors for exploiting CVE-2011-1273.</td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-046.mspx" target="_blank">MS11-046</a></td>
<td width="200" valign="top"><strong>Vulnerability in Ancillary Function Driver Could Allow Elevation of Privilege (2503665)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a publicly disclosed vulnerability in the Microsoft Windows Ancillary Function Driver (AFD). The vulnerability could allow elevation of privilege if an attacker logs on to a user&#8217;s system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.</td>
<td width="92" valign="top">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-047.mspx" target="_blank">MS11-047</a></td>
<td width="200" valign="top"><strong>Vulnerability in Hyper-V Could Allow Denial of Service (2525835)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Windows Server 2008 Hyper-V and Windows Server 2008 R2 Hyper-V. The vulnerability could allow denial of service if a specially crafted packet is sent to the VMBus by an authenticated user in one of the guest virtual machines hosted by the Hyper-V server. An attacker must have valid logon credentials and be able to send specially crafted content from a guest virtual machine to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.</td>
<td width="92" valign="top">Denial of Service</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-048.mspx" target="_blank">MS11-048</a></td>
<td width="200" valign="top"><strong>Vulnerability in SMB Server Could Allow Denial of Service (2536275)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker created a specially crafted SMB packet and sent the packet to an affected system. Firewall best practices and standard default firewall configurations can help protect networks from attacks originating outside the enterprise perimeter that would attempt to exploit this vulnerability.</td>
<td width="92" valign="top">Denial of Service</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-049.mspx" target="_blank">MS11-049</a></td>
<td width="200" valign="top"><strong>Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">Requires Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Office,<br />
Microsoft SQL Server,<br />
Microsoft Visual Studio</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Microsoft XML Editor. The vulnerability could allow information disclosure if a user opened a specially crafted Web Service Discovery (.disco) file with one of the affected software listed in this bulletin. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system.</td>
<td width="92" valign="top">Information Disclosure</td>
</tr>
<tr>
<td rowspan="2" width="75" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-051.mspx" target="_blank">MS11-051</a></td>
<td width="200" valign="top"><strong>Vulnerability in Active Directory Certificate Services Web Enrolment Could Allow Elevation of Privilege (2518295)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="top">May Require Restart</td>
<td rowspan="2" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="200" valign="top">This security update resolves a privately reported vulnerability in Active Directory Certificate Services Web Enrolment. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the site in the context of the target user. An attacker who successfully exploited this vulnerability would need to send a specially crafted link and convince a user to click the link. In all cases, however, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes the user to the vulnerable Web site.</td>
<td width="92" valign="top">Elevation of Privilege</td>
</tr>
</tbody>
</table>
<p>This month as mentioned Microsoft has highlighted 4 of the critical updates in particular as a top priority these are:</p>
<ul>
<li>MS11-042 (DFS). This bulletin resolves two privately reported issues affecting all versions of Windows with the critical rating applying to Windows XP and Server 2003 systems that utilize DFS (Distributed File Servers) for later editions of windows (vista, windows7 and Server 2008) the severity is listed as Important.</li>
<li>MS11-043 (SMB Client). This bulletin resolves one privately reported issue affecting all versions of SMB Client on All versions of Windows.</li>
<li>MS11-050 (Internet Explorer). This security bulletin resolves 11 privately reported issues in Internet Explorer (Internet Explorer 9 is only affected by 4 of these issues).</li>
<li>MS11-052 (Windows). This bulletin resolves one privately reported issue in Windows and is also Critical – This update does not affect users who use Internet Explorer 9.</li>
</ul>
<p>Please click the following link to view <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/2654.deployment_2D00_201106.png">Microsoft’s deployment priority guidance</a> which assists in deployment planning. You can also follow this link to view the <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/7220.severity_2D00_xi_2D00_201106.png">risk and impact graph</a> to visually see an aggregate view of this month’s severity and exploitability index.).</p>
<p>So in summary, we are likely to see updates requiring reboots of servers this month. (as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)<br />
MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/06/15/june-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/06/10/june-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/06/10/june-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 13:48:45 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8229</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for June 2011, sees the release of 16 bulletins addressing 34 vulnerabilities: Bulletin Breakdown: 9 bulletins are rated Critical 7 bulletins are rated Important 10 vulnerabilities can lead to Remote Code Execution 2 vulnerabilities can lead to Information Disclosure 2 vulnerabilities can lead to Denial of Service 2 vulnerabilities can lead to [...]]]></description>
			<content:encoded><![CDATA[<p>This &#8216;<strong>Patch Tuesday&#8217; for June 2011,</strong> sees the release of <strong>16 bulletins addressing 34 vulnerabilities:</strong><br />
Bulletin Breakdown:</p>
<ul>
<li>9 bulletins are rated Critical</li>
<li>7 bulletins are rated Important</li>
<li>10 vulnerabilities can lead to Remote Code Execution</li>
<li>2 vulnerabilities can lead to Information Disclosure</li>
<li>2 vulnerabilities can lead to Denial of Service</li>
<li>2 vulnerabilities can lead to Elevation of Privilege</li>
</ul>
<p>The following table summarizes the security bulletins for this month in order of severity.</p>
<table border="1" cellspacing="0" cellpadding="0" width="533" height="110">
<tbody>
<tr>
<td width="81" valign="middle"><strong>Bulletin ID</strong></td>
<td width="92" valign="middle"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td width="85" valign="middle"><strong>Restart Requirement</strong></td>
<td width="64" valign="middle"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 1</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires Restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="3" width="81" valign="middle">Bulletin 2</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="3" width="85" valign="middle">May require restart</td>
<td width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td rowspan="2" width="92" valign="middle">Remote Code Execution</td>
<td width="64" valign="middle">Microsoft .NET Framework,</td>
</tr>
<tr>
<td width="64" valign="middle">Microsoft Silverlight</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 3</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td width="64" valign="middle">Microsoft Forefront Threat</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
<td width="64" valign="middle">Management Gateway</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 4</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 5</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 6</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 7</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">May require restart</td>
<td width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
<td width="64" valign="middle">Microsoft .NET Framework</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 8</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
<td width="64" valign="middle">Internet Explorer</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 9</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" width="85" valign="middle">May require restart</td>
<td width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
<td width="64" valign="middle">Internet Explorer</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 10</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">May require restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Information Disclosure</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 11</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">May require restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Office</td>
</tr>
<tr>
<td width="92" valign="middle">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 12</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Elevation of Privilege</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 13</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Denial of Service</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 14</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">Requires restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Denial of Service</td>
</tr>
<tr>
<td rowspan="3" width="81" valign="middle">Bulletin 15</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="3" width="85" valign="middle">May require restart</td>
<td width="64" valign="middle">Microsoft Office</td>
</tr>
<tr>
<td rowspan="2" width="92" valign="middle">Information Disclosure</td>
<td width="64" valign="middle">Microsoft SQL Server,</td>
</tr>
<tr>
<td width="64" valign="middle">Microsoft Visual Studio</td>
</tr>
<tr>
<td rowspan="2" width="81" valign="middle">Bulletin 16</td>
<td width="92" valign="middle"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" width="85" valign="middle">May require restart</td>
<td rowspan="2" width="64" valign="middle">Microsoft Windows</td>
</tr>
<tr>
<td width="92" valign="middle">Elevation of Privilege</td>
</tr>
</tbody>
</table>
<p>This is another heavy security patch Tuesday from Microsoft. With vulnerability patches being applied across a large range of Microsoft products including, noticeably Server 2003, 2008 R2 and Sql 2005, 2008, 2008 R2.<br />
The full list of software affected by these updates is:</p>
<ul>
<li>All supported Microsoft Operating systems (XP, 2003, Vista, 2008, 7, 2008 R2)</li>
<li>All supported versions of Internet Explorer (7, 8, 9)</li>
<li>All supported versions of Microsoft Office Excel (XP, 2003, 2007, 2010)</li>
<li>Microsoft InfoPath 2007, 2010</li>
<li>Microsoft Excel Viewer</li>
<li>Microsoft Office Compatibility Pack 2007</li>
<li>SQL Server 2005, 2008, 2008 R2</li>
<li>Microsoft Silverlight</li>
<li>Microsoft Visual Studio 2005, 2008, 2010</li>
<li>Microsoft Forefront Threat Management Gateway 2010 Client</li>
</ul>
<p>&nbsp;</p>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing in the next couple of days.<br />
The &#8216;<a href="http://www.microsoft.com/technet/security/bulletin/ms11-jun.mspx">Microsoft Security Bulletin Advance Notification for June 2011</a>&#8216; page should be referenced for detailed information on how these updates are to affect your servers or solutions when released on 15th June (as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/server-maintenance.html">updates being applied automatically </a>unless you have opted out of this service.)<br />
MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/06/10/june-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/05/11/may-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/05/11/may-2011-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 11 May 2011 11:21:03 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8136</guid>
		<description><![CDATA[As mentioned in May&#8217;s Advance notification post this month&#8217;s security bulletin releases, are now confirmed to be 2 security bulletins, addressing 3 vulnerabilities, one of which has a critical rating and the other is rated as important. This month sees a significant drop in the number of updates released after the record breaking volume last [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in <a href="http://www.ukfastblog.co.uk/2011/05/011/may-security-bulletin-release-advance-notification/">May&#8217;s Advance notification</a> post this month&#8217;s security bulletin releases, are now confirmed to be<strong> 2 security bulletins, addressing 3 vulnerabilities</strong>, one of which has a critical rating and the other is rated as important.</p>
<p>This month sees a significant drop in the number of updates released after the record breaking volume last month.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided:</p>
<table border="1" cellspacing="0" cellpadding="0" width="600" height="110">
<tbody>
<tr>
<td width="81" valign="top"><strong>Bulletin ID</strong></td>
<td width="150" valign="top"><strong>Bulletin Title and Executive Summary</strong></td>
<td width="92" valign="top"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td width="85" valign="top"><strong>Restart Requirement</strong></td>
<td width="64" valign="top"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-035.mspx" target="_blank">MS11-035</a></td>
<td width="150" valign="top"><strong>Vulnerability in WINS Could Allow Remote Code Execution (2524426)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="150" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="150" valign="top">This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system. Only customers who manually installed this component are affected by this issue.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/MS11-036.mspx" target="_blank">MS11-036</a></td>
<td width="150" valign="top"><strong>Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814)</strong></td>
<td width="92" valign="top"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Office</td>
</tr>
<tr>
<td width="150" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="150" valign="top">This security update resolves two privately reported vulnerabilities in Microsoft PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1269 and CVE-2011-1270.</td>
<td width="92" valign="top"></td>
</tr>
</tbody>
</table>
<p>This month, we have a sole Critical bulletin <a href="http://www.microsoft.com/technet/security/bulletin/MS11-035.mspx" target="_blank">MS11-035</a>. This security bulletin affects all Server customers (Microsoft Server 2003 and Server 2008) who have installed and use “WINS Service”. Please note the Wins service is not installed on any UKFast servers as a default.</p>
<p>The second bulletin <a href="http://www.microsoft.com/technet/security/bulletin/MS11-036.mspx" target="_blank">MS11-036</a> affects older versions of the Microsoft PowerPoint product. The exploit requires for a user to open a malicious PowerPoint document which could then lead to remote code execution. For users who have installed and are using the Office suite (Office 2003 &amp; Office 2007) on their server(s) it is worth highlighting that Microsoft released the “<a href="http://www.microsoft.com/technet/security/advisory/2501584.mspx" target="_blank">Office File Validation</a>”, something available by default with Office 2010, mitigates risk of the addressed vulnerability MS11-036. The Office File validation has been made available to Office 2003 and Office 2007 users towards the middle of last month and the download can be obtained from the following Microsoft URL: <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6a4e39a4-4c3f-4cc7-98ec-1cb2d5cb5881&amp;displaylang=en" target="_blank">Office 2003 &amp; 2007 File Validation</a></p>
<p><a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6a4e39a4-4c3f-4cc7-98ec-1cb2d5cb5881&amp;displaylang=en" target="_blank"></a><br />
Please click the following link to view <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/3731.DP.png" target="_blank">Microsoft’s deployment priority guidance</a> which assists in deployment planning. You can also follow this link to view the <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-45-71/2275.Severity-XI.png" target="_blank">risk and impact graph</a> to visually see an aggregate view of this month’s severity and exploitability index.<br />
We expect both updates will only affect a small number of systems, those who have specifically installed WINS and/or the Office suite on their server(s). So in summary, we are <strong>Unlikely to see</strong> updates requiring <strong>reboots of servers this month</strong>.<br />
MC.<br />
(as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/05/11/may-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/05/06/may-2011-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/05/06/may-2011-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 06 May 2011 13:45:26 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8131</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for May 2011, sees the release of 2 bulletins addressing 3 vulnerabilities: Bulletin Breakdown: 2 security Bulletins 1 security Bulletin has a critical rating 1 security Bulletin has an important rating Both Bulletins address vulnerabilities that could lead to Remote Code Execution. At present we know 1 Bulletin affects Windows Server Operating [...]]]></description>
			<content:encoded><![CDATA[<p>This &#8216;<strong>Patch Tuesday&#8217; for May 2011,</strong> sees the release of<strong> </strong><strong>2</strong> <strong>bulletins addressing 3 vulnerabilities:</strong></p>
<p>Bulletin Breakdown:</p>
<ul>
<li>2 security Bulletins</li>
<li>1 security Bulletin has a critical rating</li>
<li>1 security Bulletin has an important rating</li>
</ul>
<p>Both Bulletins address vulnerabilities that could lead to Remote Code Execution. At present we know 1 Bulletin affects Windows Server Operating systems (Server 2003, 2008 &amp; 2008 R2). The other Bulletin affects the Microsoft Office Product family (PowerPoint Xp, 2003, 2007 &amp; Office Compatibility Pack)</p>
<p>The following table summarizes the security bulletins for this month in order of severity.</p>
<p>For details on affected software, see the next section, <strong>Affected Software</strong>.<em></em><em><br />
</em></p>
<table width="533" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="81"><strong>Bulletin ID</strong></td>
<td valign="top" width="92"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td valign="top" width="85"><strong>Restart Requirement</strong></td>
<td valign="top" width="64"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 1</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Critical</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="64">Microsoft Windows</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
<tr>
<td rowspan="2" valign="top" width="81">Bulletin 2</td>
<td valign="top" width="92"><a href="http://www.microsoft.com/technet/security/bulletin/rating.mspx">Important</a></td>
<td rowspan="2" valign="top" width="85">May require restart</td>
<td rowspan="2" valign="top" width="64">Microsoft Office</td>
</tr>
<tr>
<td valign="top" width="92">Remote Code Execution</td>
</tr>
</tbody>
</table>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing in the next couple of days.</p>
<p>The ‘Microsoft Security Bulletin Advance Notification for May 2011′ page should be referenced for detailed information on how these updates are to affect your servers or solutions when released on 8th February (as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/05/06/may-2011-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Changes to Microsoft&#8217;s Exploitability Index</title>
		<link>http://blog.ukfast.co.uk/2011/05/06/changes-to-microsofts-exploitability-index/</link>
		<comments>http://blog.ukfast.co.uk/2011/05/06/changes-to-microsofts-exploitability-index/#comments</comments>
		<pubDate>Fri, 06 May 2011 11:30:38 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://blog.ukfast.co.uk/?p=8121</guid>
		<description><![CDATA[Microsoft has released some information on improvements to their exploitability index and advance notification services. The exploitability index was created by Microsoft back in 2008 to assist Microsoft users in prioritising bulletin deployment. Since the original release Microsoft has received feedback from users requesting further information by platform. As a result, Microsoft has released improvements [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released some information on improvements to their exploitability index and advance notification services.</p>
<p>The exploitability index was created by Microsoft back in 2008 to assist Microsoft users in prioritising bulletin deployment. Since the original release Microsoft has received feedback from users requesting further information by platform.</p>
<p>As a result, Microsoft has released improvements to their exploitability index as of Thursday the 5<sup>th</sup> of May. For those not familiar with it, the exploitability index is a release from Microsoft to advise users what is likely to occur within the first 30 days after releasing security updates. Changes include a new column which represents Microsoft’s assessment of their most current products. For example, Windows 7 has been broken out from Windows Xp and Vista.</p>
<p>&nbsp;</p>
<p>Their full release says:</p>
<p>Today we are announcing changes to Microsoft’s <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">Exploitability Index.</a></p>
<p>Since October 2008, we have used the Exploitability Index to provide customers with valuable exploitability analysis for our security bulletins, and starting Tuesday this information will become even more comprehensive for those who use Microsoft’s latest platforms.</p>
<p>The Exploitability Index assesses the likelihood of functional exploit code being developed for a particular vulnerability. By providing the index information month over month, we’re helping customers prioritize the security updates that matter to them. The Exploitability Index will continue to provide an aggregate exploitability rating across all affected products, and the improvements made to Exploitability Index will now offer additional information to help customers prioritize bulletins, specifically for the most recent platforms, e.g. Windows 7 Service Pack 1 and Office 2010.</p>
<p>For example, the Exploitability Index for CVE-2011-0097, a security issue addressed by <a href="http://www.microsoft.com/technet/security/bulletin/ms11-021.mspx">MS11-021</a> in the <a href="http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx">April 2011 release</a>, originally rated a “1 – Consistent Exploit Code Likely”. However, under the previous system, the Exploitability Index did not specifically illustrate that customers using Excel 2010 were at less risk; with Excel 2010, CVE-2010-0097 would rate a “2 – Inconsistent Exploit Code Likely”. In fact, our research has shown that 37 percent of the vulnerabilities addressed since July 2010 have had similar results; the latest platform was either entirely unaffected, or significantly more difficult to exploit.</p>
<p>Maarten Van Horenbeeck, senior security program manager, goes into more depth around the background of Exploitability Index and the value of these improvements in the MSRC blog post: <a href="http://blogs.technet.com/b/msrc/archive/2011/05/05/exploitability-index-improvements-amp-advance-notification-service-for-may-2011-bulletin-release.aspx">“Exploitability Index Improvements Now Offer Additional Guidance</a>”</p>
<p>Additionally, we&#8217;re providing <a href="http://www.microsoft.com/technet/security/bulletin/ms11-may.mspx">advanced notification</a> on the release of a Critical security bulletin addressing a vulnerability in Windows, and an Important bulletin addressing two vulnerabilities in Microsoft Office. As usual, the bulletin release is scheduled for the second Tuesday of the month, May 10, at approximately 10 a.m. PDT.</p>
<p>For all the latest information, you can also follow the MSRC team on Twitter at <a href="http://www.twitter.com/msftsecresponse">@MSFTSecResponse</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/05/06/changes-to-microsofts-exploitability-index/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/04/13/april-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/04/13/april-2011-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 11:11:55 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[April 2011]]></category>
		<category><![CDATA[Important]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[reboots]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=8035</guid>
		<description><![CDATA[As mentioned in the April Advance notification post this month’s security bulletin releases, are now confirmed to be 17 security bulletins, addressing 64 unique vulnerabilities, nine of which are critical and eight rated Important. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2011/04/08/april-security-bulletin-release-advance-notification/">April  Advance notification post</a> this month’s security bulletin releases,  are now confirmed to be<strong> 17 security bulletins, addressing 64  unique vulnerabilities</strong>, nine of which are critical and eight  rated Important.</p>
<p>The following table shows affected software by  bulletin and the likelihood of an Operating System restart being  required and hence impacting on services provided.</p>
<table border="1" cellspacing="0" cellpadding="0" width="533">
<tbody>
<tr>
<td width="81" valign="top"><strong>Bulletin ID</strong></td>
<td width="211" valign="top"><strong>Bulletin Title and Executive Summary</strong></td>
<td width="92" valign="top"><strong>Maximum Severity Rating and   Vulnerability Impact</strong></td>
<td width="85" valign="top"><strong>Restart Requirement</strong></td>
<td width="64" valign="top"><strong>Affected Software</strong></td>
</tr>
<tr>
<td rowspan="4" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkID=214126">MS11-018</a></span></td>
<td width="211" valign="top"><strong>Cumulative Security Update for   Internet Explorer (2497640)</strong> <strong> </strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="4" width="85" valign="top">Requires restart</td>
<td width="64" valign="top">Microsoft Windows,</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
<td width="64" valign="top">Internet Explorer</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves four   privately reported vulnerabilities and one publicly disclosed vulnerability   in Internet Explorer. This security update is rated Critical for Internet   Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows clients;   and Moderate for Internet Explorer 6, Internet Explorer 7, and Internet   Explorer 8 on Windows servers. Internet Explorer 9 is not affected by the   vulnerabilities.</td>
<td width="92" valign="top"></td>
<td width="64" valign="top"></td>
</tr>
<tr>
<td width="211" valign="top">The most severe vulnerabilities could   allow remote code execution if a user views a specially crafted Web page   using Internet Explorer. An attacker who successfully exploited any of these   vulnerabilities could gain the same user rights as the local user. Users   whose accounts are configured to have fewer user rights on the system could   be less impacted than users who operate with administrative user rights.</td>
<td width="92" valign="top"></td>
<td width="64" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212314">MS11-019</a></span></td>
<td width="211" valign="top"><strong>Vulnerabilities in SMB Client Could   Allow Remote Code Execution (2511455)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves one   publicly disclosed vulnerability and one privately reported vulnerability in   Microsoft Windows. The vulnerabilities could allow remote code execution if   an attacker sent a specially crafted SMB response to a client-initiated SMB   request. To exploit these vulnerabilities, an attacker must convince the user   to initiate an SMB connection to a specially crafted SMB server.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212236">MS11-020</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in SMB Server Could   Allow Remote Code Execution (2508429)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in Microsoft Windows. The vulnerability   could allow remote code execution if an attacker created a specially crafted   SMB packet and sent the packet to an affected system. Firewall best practices   and standard default firewall configurations can help protect networks from   attacks originating outside the enterprise perimeter that would attempt to   exploit these vulnerabilities.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkID=214005">MS11-027</a></span></td>
<td width="211" valign="top"><strong>Cumulative Security Update of ActiveX   Kill Bits (2508272)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves two   privately reported vulnerabilities and one publicly disclosed vulnerability   in Microsoft software. The vulnerabilities could allow remote code execution   if a user views a specially crafted Web page that instantiates a specific   ActiveX control with Internet Explorer. Users whose accounts are configured   to have fewer user rights on the system could be less impacted than users who   operate with administrative user rights. This update also includes kill bits   for three third-party ActiveX controls.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=207931">MS11-028</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in .NET Framework Could   Allow Remote Code Execution (2484015)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   publicly disclosed vulnerability in Microsoft .NET Framework. The   vulnerability could allow remote code execution on a client system if a user   views a specially crafted Web page using a Web browser that can run XAML   Browser Applications (XBAPs). Users whose accounts are configured to have   fewer user rights on the system could be less impacted than users who operate   with administrative user rights. The vulnerability could also allow remote   code execution on a server system running IIS, if that server allows   processing ASP.NET pages and an attacker succeeds in uploading a specially   crafted ASP.NET page to that server and then executes the page, as could be   the case in a Web hosting scenario. This vulnerability could also be used by   Windows .NET applications to bypass Code Access Security (CAS) restrictions.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkID=208524">MS11-029</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in GDI+ Could Allow   Remote Code Execution (2489979)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td width="64" valign="top">Microsoft Windows,</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
<td width="64" valign="top">Microsoft Office</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in Microsoft Windows GDI+. The vulnerability   could allow remote code execution if a user viewed a specially crafted image   file using affected software or browsed a Web site that contains specially   crafted content. Users whose accounts are configured to have fewer user   rights on the system could be less impacted than users who operate with   administrative user rights.</td>
<td width="92" valign="top"></td>
<td width="64" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212595">MS11-030</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in DNS Resolution Could   Allow Remote Code Execution (2509553)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in Windows DNS resolution. The vulnerability   could allow remote code execution if an attacker gained access to the network   and then created a custom program to send specially crafted LLMNR broadcast   queries to the target systems. Firewall best practices and standard default   firewall configurations can help protect networks from attacks that originate   outside the enterprise perimeter. Best practices recommend that systems that   are connected to the Internet have a minimal number of ports exposed. In this   case, the LLMNR ports should be blocked from the Internet.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212243">MS11-031</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in JScript and VBScript   Scripting Engines Could Allow Remote Code Execution (2514666)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in the JScript and VBScript scripting   engines. The vulnerability could allow remote code execution if a user   visited a specially crafted Web site. An attacker would have no way to force   users to visit the Web site. Instead, an attacker would have to convince   users to visit the Web site, typically by getting them to click a link in an   e-mail message or Instant Messenger message that takes users to the   attacker&#8217;s Web site.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212224">MS11-032</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in the OpenType Compact   Font Format (CFF) Driver Could Allow Remote Code Execution (2507618)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in the OpenType Compact Font Format (CFF)   driver. The vulnerability could allow remote code execution if a user views   content rendered in a specially crafted CFF font. In all cases, an attacker   would have no way to force users to view the specially crafted content.   Instead, an attacker would have to convince users to visit a Web site,   typically by getting them to click a link in an e-mail message or Instant   Messenger message that takes users to the attacker&#8217;s Web site.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=210121">MS11-021</a></span></td>
<td width="211" valign="top"><strong>Vulnerabilities in Microsoft Excel   Could Allow Remote Code Execution (2489279)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Office</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves nine   privately reported vulnerabilities in Microsoft Office. The vulnerabilities   could allow remote code execution if a user opens a specially crafted Excel   file. An attacker who successfully exploited any of these vulnerabilities   could gain the same user rights as the logged-on user. Users whose accounts   are configured to have fewer user rights on the system could be less impacted   than users who operate with administrative user rights.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkID=210727">MS11-022</a></span></td>
<td width="211" valign="top"><strong>Vulnerabilities in Microsoft   PowerPoint Could Allow Remote Code Execution (2489283)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td width="64" valign="top">Microsoft Office,</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
<td width="64" valign="top">Microsoft Server Software</td>
</tr>
<tr>
<td width="211" valign="bottom">This security update resolves three   privately reported vulnerabilities in Microsoft PowerPoint. The   vulnerabilities could allow remote code execution if a user opens a specially   crafted PowerPoint file. An attacker who successfully exploited any of these   vulnerabilities could gain the same user rights as the local user. Users   whose accounts are configured to have fewer user rights on the system could   be less impacted than users who operate with administrative user rights. The   automated Microsoft Fix it solution for PowerPoint 2010,   &#8220;Disable Edit in Protected View for PowerPoint 2010,&#8221; available   inMicrosoft Knowledge Base Article 2501584, blocks the attack vectors for   exploiting the vulnerabilities described in CVE-2011-0655 and CVE-2011-0656.</td>
<td width="92" valign="top"></td>
<td width="64" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=210206">MS11-023</a></span></td>
<td width="211" valign="top"><strong>Vulnerabilities in Microsoft Office   Could Allow Remote Code Execution (2489293)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Office</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves one   publicly disclosed vulnerability and one privately reported vulnerability in   Microsoft Office. The vulnerabilities could allow remote code execution if a   user opens a specially crafted Office file or if a user opens a legitimate   Office file that is located in the same network directory as a specially   crafted library file. An attacker who successfully exploited either of these   vulnerabilities could gain the same user rights as the logged on user. Users   whose accounts are configured to have fewer user rights on the system could   be less impacted than users who operate with administrative user rights.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212226">MS11-024</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in Windows Fax Cover   Page Editor Could Allow Remote Code Execution (2527308)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves one   publicly disclosed vulnerability in Microsoft Windows. The vulnerability   could allow remote code execution if a user opened a specially crafted fax   cover page file (.cov) using the Windows Fax Cover Page Editor. An attacker   who successfully exploited this vulnerability could gain the same user rights   as the logged-on user. Users whose accounts are configured to have fewer user   rights on the system could be less impacted than users who operate with   administrative user rights.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=209720">MS11-025</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in Microsoft Foundation   Class (MFC) Library Could Allow Remote Code Execution (2500212)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">May require restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Developer Tools and   Software</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   publicly disclosed vulnerability in certain applications built using the   Microsoft Foundation Class (MFC) Library. The vulnerability could allow   remote code execution if a user opens a legitimate file associated with such   an affected application, and the file is located in the same network folder   as a specially crafted library file. For an attack to be successful, a user   must visit an untrusted remote file system location or WebDAV share and open   a document from this location that is then loaded by the affected   application.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=212523">MS11-026</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in MHTML Could Allow   Information Disclosure (2503658)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Information Disclosure</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   publicly disclosed vulnerability in the MHTML protocol handler in Microsoft   Windows. The vulnerability could allow information disclosure if a user   visited a specially crafted Web site. In a Web-based attack scenario, a Web site   could contain a specially crafted link that is used to exploit this   vulnerability. An attacker would have to convince users to visit the Web site   and open the specially crafted link.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="4" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=208110">MS11-033</a></span></td>
<td width="211" valign="top"><strong>Vulnerability in WordPad Text   Converters Could Allow Remote Code Execution (2485663)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="4" width="85" valign="top">May require restart</td>
<td rowspan="4" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Remote Code Execution</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves a   privately reported vulnerability in Microsoft Windows. This security update   is rated Important for all supported editions of Windows XP and Windows   Server 2003. All supported editions of Windows Vista, Windows Server 2008, Windows   7, and Windows Server 2008 R2 are not affected by the vulnerability.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td width="211" valign="top">The vulnerability could allow remote   code execution if a user opened a specially crafted file using WordPad. An   attacker who successfully exploited this vulnerability could gain the same   user rights as the local user. Users whose accounts are configured to have   fewer user rights on the system could be less impacted than users who operate   with administrative user rights.</td>
<td width="92" valign="top"></td>
</tr>
<tr>
<td rowspan="3" width="81" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=211826">MS11-034</a></span></td>
<td width="211" valign="top"><strong>Vulnerabilities in Windows   Kernel-Mode Drivers Could Allow Elevation of Privilege (2506223)</strong> <strong></strong></td>
<td width="92" valign="top"><span style="text-decoration: underline;"><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a></span></td>
<td rowspan="3" width="85" valign="top">Requires restart</td>
<td rowspan="3" width="64" valign="top">Microsoft Windows</td>
</tr>
<tr>
<td width="211" valign="top"></td>
<td width="92" valign="top">Elevation of Privilege</td>
</tr>
<tr>
<td width="211" valign="top">This security update resolves thirty   privately reported vulnerabilities in Microsoft Windows. The vulnerabilities   could allow elevation of privilege if an attacker logged on locally and ran a   specially crafted application. An attacker must have valid logon credentials   and be able to log on locally to exploit these vulnerabilities. The   vulnerabilities could not be exploited remotely or by anonymous users.</td>
<td width="92" valign="top"></td>
</tr>
</tbody>
</table>
<p>This month,  Microsoft’s Peter Voss has highlighted three top priority bulletins, all  with a Critical rating: MS11-020<strong> </strong>(SMB Server),  MS11-019 (SMB Client) and MS11-018 (Internet Explorer).</p>
<p><strong>MS11-018  (Internet Explorer).</strong> As you can see from the table above, This  security bulletin resolves four privately reported vulnerabilities and  one publicly disclosed vulnerability in Internet Explorer. This bulletin  is rated Critical for IE 6, IE 7 and IE 8 on Windows clients; and  Moderate for IE6, IE7, and IE8 on Windows servers. Please note clients  who have already upgraded their solutions to use Internet Explorer 9  will not be affected by the vulnerabilities. Microsoft is aware of  limited attacks leveraging vulnerabilities addressed by this bulletin,  including the vulnerability used at the CanSecWest 2011 Conference in  Vancouver, British Columbia (March 9-11) and is something Microsoft  Security Response tweeted about <a href="http://twitter.com/msftsecresponse/status/57499974124044289">recently</a>.</p>
<p><strong>MS11-019 (SMB Client)</strong>. This bulletin resolves one  publicly disclosed vulnerability and one privately reported  vulnerability in Microsoft Windows. The vulnerabilities could allow  remote code executions if an attacker sent a specially crafted SMB  response to a client-initiated SMB request. Microsoft publicly disclosed  this vulnerability to full disclosure on February 15th. Microsoft  performed a full investigation into the issue and found that remote-code  execution was extremely unlikely. As a result Microsoft had no evidence  of any active attacks and therefore opted not to disrupt Microsoft  users with an out-of-band security update.</p>
<p><strong>MS11-020 (SMB  Server)</strong>. This bulletin resolves an internally discovered  vulnerability in Microsoft Windows. The vulnerability could allow remote  code execution if an attacker created a specially crafted SMB packet  and sent the packet to an affected system.</p>
<p>Click the following  link to view <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/0245.Bulletin-Deployment-Priority.png">Microsoft’s  deployment priority guidance</a> which assists in deployment planning.  You can also follow this link to view <a href="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-71/8510.Severity-and-Exploitability-Index.png">the  risk and impact graph</a> to visually see an aggregate view of this  month&#8217;s severity and exploitability index.</p>
<p>In summary,  we are <strong>likely to see</strong> updates requiring <strong>reboots</strong> of servers <strong>this month</strong>.</p>
<p>MC.</p>
<p><em>(as  usual, as a UKFast customer, you benefit from these updates being  applied automatically unless you have opted out of this service.)</em></p>
<p>&nbsp;</p>
<h2><strong><em>Update 14/4/11 </em></strong></h2>
<p>We have received word from Microsoft that the following bulletins have undergone a minor revision increment.</p>
<p>Please see the appropriate bulletin for more details.</p>
<p>* MS11-019 &#8211; Critical</p>
<p>* MS11-017 &#8211; Important</p>
<p>&nbsp;</p>
<p>Bulletin Information:</p>
<p>* <strong>MS11-019 &#8211; Critical</strong></p>
<p>- <a href="http://www.microsoft.com/technet/security/bulletin/ms11-019.mspx">http://www.microsoft.com/technet/security/bulletin/ms11-019.mspx</a></p>
<p>- Reason for Revision: V1.1 (April 13, 2011): Clarified the</p>
<p>vulnerability description in the Executive Summary.</p>
<p>- Originally posted: April 12, 2011</p>
<p>- Updated: April 13, 2011</p>
<p>- Bulletin Severity Rating: Critical</p>
<p>- Version: 1.1</p>
<p>&nbsp;</p>
<p>*<strong> MS11-017 &#8211; Important</strong></p>
<p>- <a href="http://www.microsoft.com/technet/security/bulletin/ms11-017.mspx">http://www.microsoft.com/technet/security/bulletin/ms11-017.mspx</a></p>
<p>- Reason for Revision: V1.3 (April 13, 2011): Corrected the</p>
<p>bulletin replacement information for Remote Desktop</p>
<p>Connection 6.0 Client on supported editions of Windows Server</p>
<p>2003 and Remote Desktop Connection 6.1 Client on supported</p>
<p>editions of Windows Vista. This is a bulletin change only.</p>
<p>There were no changes to the detection or security update files.</p>
<p>- Originally posted: March 8, 2011</p>
<p>- Updated: April 13, 2011</p>
<p>- Bulletin Severity Rating: Important</p>
<p>- Version: 1.3</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/04/13/april-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2011 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/04/08/april-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2011/04/08/april-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 08 Apr 2011 11:10:55 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[advance notification]]></category>
		<category><![CDATA[April 2011]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security bulletin release]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=8017</guid>
		<description><![CDATA[This ‘Patch Tuesday’ for April 2011, sees the release of 17 bulletins addressing 64 vulnerabilities: &#160; The number of updates released this month will tie the record for the most security bulletins released by Microsoft within a single release.  It was December of last year that Microsoft also released 17 security bulletins.  On the vulnerability front, [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>‘Patch Tuesday’ for April 2011,</strong> sees the release of<strong> </strong><strong>17</strong> <strong>bulletins addressing 64 vulnerabilities:</strong></p>
<p>&nbsp;</p>
<p>The number of updates released this month will tie the record for the <a href="http://www.ukfast.co.uk/microsoft-news/record-64-bug-fixes-in-patch-tuesday.html" target="_blank">most security bulletins</a> released by Microsoft within a single release.  It was December of last year that Microsoft also released 17 security bulletins.  On the vulnerability front, yes, we have another Microsoft record.  With Microsoft fixing 64 vulnerabilities, they will surpass the previous Microsoft record of 49 vulnerabilities fixed in October of last year.</p>
<p>&nbsp;</p>
<p>Bulletin Breakdown:</p>
<ul>
<li>9 bulletins are rated as Critical</li>
<li>8 bulletins are rated as Important</li>
<li>16 bulletins address vulnerabilities that could lead to Remote Code Execution</li>
<li>1 bulletin addresses a vulnerability that could lead to Elevation of Privilege</li>
</ul>
<p>The following table summarizes the security bulletins for this month in order of severity.<a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification1.png"></a></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification1.png"><br />
</a><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification3.png"><img class="aligncenter size-full wp-image-8024" title="April Advance notification" src="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification3.png" alt="" width="601" height="678" /></a></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification.png"></a><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/04/April-Advance-notification2.png"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/04/08/april-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/03/28/march-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/03/28/march-2011-security-bulletin-release/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 13:56:08 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Important]]></category>
		<category><![CDATA[march 2011]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[reboots]]></category>
		<category><![CDATA[restart]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[UKFast]]></category>
		<category><![CDATA[UKFast customer]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=8005</guid>
		<description><![CDATA[This month Microsoft has released three new security bulletins, addressing four vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence the impact on services provided. &#160; &#160; In summary, we are unlikely to see updates requiring reboots of servers this month. MC. (as [...]]]></description>
			<content:encoded><![CDATA[<p>This month Microsoft has released three new security bulletins, addressing four vulnerabilities.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence the impact on services provided.</p>
<p>&nbsp;</p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/03/March-Microsoft-bulletin.png"><img class="aligncenter size-full wp-image-8006" title="March Microsoft bulletin" src="http://www.ukfastblog.co.uk/wp-content/uploads/2011/03/March-Microsoft-bulletin.png" alt="" width="634" height="650" /></a></p>
<p>&nbsp;</p>
<p>In summary, we are<strong> un</strong><strong>likely to see</strong> updates requiring<strong> </strong><strong>reboots</strong> of servers<strong> </strong><strong>this month</strong>.</p>
<p>MC.<br />
<em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/03/28/march-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/02/10/february-2011-security-bulletin-release-2/</link>
		<comments>http://blog.ukfast.co.uk/2011/02/10/february-2011-security-bulletin-release-2/#comments</comments>
		<pubDate>Thu, 10 Feb 2011 09:27:07 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[UKFast]]></category>
		<category><![CDATA[february 2011]]></category>
		<category><![CDATA[Important]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[reboots]]></category>
		<category><![CDATA[restart]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[UKFast customer]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7922</guid>
		<description><![CDATA[This month Microsoft has released twelve new security bulletins, addressing twenty-two vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided. In summary, we are likely to see updates requiring reboots of servers this month. MC. (as usual, as a [...]]]></description>
			<content:encoded><![CDATA[<p>This month Microsoft has released twelve new security bulletins, addressing twenty-two vulnerabilities.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided.</p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/02/kelvyntable1.jpeg"><img class="aligncenter size-full wp-image-7923" title="Windows Update" src="http://www.ukfastblog.co.uk/wp-content/uploads/2011/02/kelvyntable1.jpeg" alt="" width="624" height="2205" /></a></p>
<p>In summary, we are<strong> likely to see</strong> updates requiring<strong> reboots</strong> of servers<strong> this month</strong>.</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/server-maintenance.html">updates being applied automatically</a> unless you have opted out of this service.)</em></p>
<p><em><br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/02/10/february-2011-security-bulletin-release-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2011/02/07/february-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/02/07/february-2011-security-bulletin-release/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 10:16:40 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[february 2011]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[micro clouseau]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security bulletin release]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[UKFast]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7916</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; for February 2011, sees the release of 12 bulletins addressing 22 vulnerabilities: 3 bulletins are rated Critical 9 bulletins are rated Important 5 bulletins address Remote Code Execution vulnerabilities 5 bulletins address Elevation of Privilege vulnerabilities 1 bulletin addresses a Denial of Service vulnerability 1 bulletin addresses an Information Disclosure vulnerability These [...]]]></description>
			<content:encoded><![CDATA[<p>This<a title="February 2011 Security Bulletin Release" href="http://blog.ukfast.co.uk/2011/02/10/february-2011-security-bulletin-release-2/"> </a><strong><a title="February 2011 Security Bulletin Release" href="http://blog.ukfast.co.uk/2011/02/10/february-2011-security-bulletin-release-2/">&#8216;Patch Tuesday&#8217; for February 2011</a>,</strong> sees the release of<strong> 12</strong> <strong>bulletins addressing 22 vulnerabilities:</strong></p>
<ul>
<li>3 bulletins are rated Critical</li>
<li>9 bulletins are rated Important</li>
<li>5 bulletins address Remote Code Execution vulnerabilities</li>
<li>5 bulletins address Elevation of Privilege vulnerabilities</li>
<li>1 bulletin addresses a Denial of Service vulnerability</li>
<li>1 bulletin addresses an Information Disclosure vulnerability</li>
</ul>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/02/Windows-Table.jpeg"><img class="aligncenter size-full wp-image-7917" title="Windows Updates" src="http://www.ukfastblog.co.uk/wp-content/uploads/2011/02/Windows-Table.jpeg" alt="" width="636" height="528" /></a></p>
<p>These updates will affect the following Software:</p>
<ul>
<li>All supported versions of Internet Explorer</li>
<li>All supported versions of the Microsoft Windows operating system</li>
<li>Microsoft Visual Studio</li>
<li>Microsoft IIS</li>
<li>Microsoft Visio XP, 2003 and 2007</li>
</ul>
<p>We will issue further information on the impact of this month’s updates once they have been released for testing in the next couple of days.</p>
<p>The ‘Microsoft Security Bulletin Advance Notification for February 2011′ page should be referenced for detailed information on how these updates are to affect your servers or solutions when <strong>released on 8th February</strong> <em>(as usual, as a UKFast customer, you benefit from these u<a href="http://www.ukfast.co.uk/server-maintenance.html">pdates being applied automatically</a> unless you have opted out of this service.)</em></p>
<p>MC.</p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/02/Windows-Table.jpeg"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/02/07/february-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2011 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2011/01/13/january-2011-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2011/01/13/january-2011-security-bulletin-release/#comments</comments>
		<pubDate>Thu, 13 Jan 2011 12:22:09 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[January]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7869</guid>
		<description><![CDATA[This month Microsoft has released two new security bulletins, addressing three vulnerabilities. The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided.]]></description>
			<content:encoded><![CDATA[<p>This month <a href="http://www.microsoft.com/technet/security/bulletin/ms11-jan.mspx" target="_blank">Microsoft has released</a> two new security bulletins, addressing three vulnerabilities.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided.</p>
<div id="attachment_7873" class="wp-caption aligncenter" style="width: 635px"><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2011/01/Mic2.jpeg"><img class="size-full wp-image-7873" title="Microsoft Update" src="http://www.ukfastblog.co.uk/wp-content/uploads/2011/01/Mic2.jpeg" alt="Microsoft Update" width="625" height="634" /></a><p class="wp-caption-text">Microsoft Update</p></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2011/01/13/january-2011-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/11/10/november-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/11/10/november-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 12:27:57 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[bulletins]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7647</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are now confirmed to be 3 security bulletins, addressing 11 vulnerabilities.]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/11/05/november-2010-security-bulletin-release-advance-notification/" target="_blank">previous post</a> on this months security bulletin releases, there are now confirmed to be<strong> 3 security bulletins, addressing 11 vulnerabilities</strong>.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms10-nov.mspx" target="_blank">This month</a> follows a month where Microsoft released their largest number of bulletins to date and as is typical following such, bulletins released today are minimal.</p>
<p>So much so that for Windows Server Operating systems, unless you have specific applications installed you&#8217;ll find yourself unaffected.</p>
<p>The following table shows affected software by bulletin and the likelihood of an Operating System restart being required and hence impacting on services provided.</p>
<table id="ERC" border="1" cellspacing="0" cellpadding="0" width="86%">
<thead>
<tr valign="top">
<td id="colEUC" width="10%"><strong>Bulletin ID</strong></td>
<td id="colEYC" width="39%"><strong>Bulletin Title and Executive Summary</strong></td>
<td id="colE3C" width="16%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td id="colEAD" width="16%"><strong>Restart Requirement</strong></td>
<td id="colEED" width="17%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr valign="top">
<td><a href="http://go.microsoft.com/fwlink/?LinkId=203241">MS10-087</a></td>
<td>Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td><a href="http://go.microsoft.com/fwlink/?LinkId=198186">MS10-088</a></td>
<td>Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2293386)</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td><a href="http://go.microsoft.com/fwlink/?LinkId=199536">MS10-089</a></td>
<td>Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074)</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td>May require restart</td>
<td>Microsoft Forefront United Access Gateway</td>
</tr>
</tbody>
</table>
<p>In summary, we are <strong>will not </strong><strong>see</strong> updates requiring <strong>reboots</strong> of servers <strong>this month</strong> <strong><em>unless</em></strong> you have <strong>applicable</strong> <strong>software</strong> installed <strong>or missed updates</strong> from previous months.</p>
<p>Finally, the previously released <a href="http://www.microsoft.com/technet/security/advisory/2458511.mspx" target="_blank">Security Advisory</a> for Internet Explorer which should certainly concern those using the product or developing sites to be viewed by it, has had no update since our last posting on 5th of November.</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/11/10/november-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Hyper-V Cloud Launch</title>
		<link>http://blog.ukfast.co.uk/2010/11/08/microsoft-hyper-v-cloud-launch/</link>
		<comments>http://blog.ukfast.co.uk/2010/11/08/microsoft-hyper-v-cloud-launch/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 17:35:03 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[DDC]]></category>
		<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[private cloud]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7624</guid>
		<description><![CDATA[The Buzz is all about Microsoft Hyper-V Cloud - as they announce it at their main customer event for 2010 - at TechEd Europe 2010 in Berlin today.]]></description>
			<content:encoded><![CDATA[<p>The Buzz is all about <a href="http://www.ukfast.co.uk/hyper-v-server.html" target="_blank">Microsoft Hyper-V Cloud</a>- as they announce it at their main customer event for 2010 &#8211; at <a href="http://www.microsoft.com/europe/teched/" target="_blank">TechEd Europe</a> 2010 in Berlin today.</p>
<p>Microsoft <a href="http://www.microsoft.com/Presspass/press/2010/nov10/11-08MSTEEPR.mspx" target="_blank">press statements </a>go into significant detail on the offerings and it is intended that the new offerings will take on the mantle from the previous &#8216;DDC&#8217; (Dynamic DataCenter) to help push the Hyper-V based cloud solutions to the next level.</p>
<p>UKFast are a founder member of the <a href="http://www.microsoft.com/hosting/dynamicdatacenter/cloudproviders.html" target="_blank">Microsoft Dynamic Datacenter alliance</a> and are an accredited Microsoft Hyper-V Cloud Service Provider having rolled out tens of Private Cloud solutions supporting hundreds of organisations.</p>
<p>Contact one of our solutions sales specialists for more information!</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/11/08/microsoft-hyper-v-cloud-launch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/11/05/november-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/11/05/november-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 09:35:59 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[bulletin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7599</guid>
		<description><![CDATA[This 'Patch Tuesday' for November 2010, sees the release of 3 bulletins addressing 11 vulnerabilities.

No bulletins directly affect Windows; only 1 bulletin is considered Critical severity rating.

]]></description>
			<content:encoded><![CDATA[<p>This <a title="November 2010 Security Bulletin Release" href="http://blog.ukfast.co.uk/2010/11/10/november-2010-security-bulletin-release/">&#8216;</a><strong><a title="November 2010 Security Bulletin Release" href="http://blog.ukfast.co.uk/2010/11/10/november-2010-security-bulletin-release/">Patch Tuesday&#8217; for November 2010</a>,</strong> sees the release of<strong> 3 </strong><strong>bulletins addressing 11 vulnerabilities.</strong></p>
<p><strong>No bulletins directly affect</strong> <strong>Windows;</strong> only 1 bulletin is considered Critical severity rating.</p>
<table id="E5C" border="1" cellspacing="0" cellpadding="0" width="86%">
<thead>
<tr valign="top">
<td id="colEBD" width="16%"><strong>Bulletin ID</strong></td>
<td id="colEFD" width="31%"><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td id="colEJD" width="23%"><strong>Restart Requirement</strong></td>
<td id="colEND" width="28%"><strong>Affected Software</strong></td>
</tr>
</thead>
<tbody>
<tr valign="top">
<td>Bulletin 1</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Critical</a><br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td>Bulletin 2</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td>Bulletin 3</td>
<td><a href="http://go.microsoft.com/fwlink/?LinkId=21140">Important</a><br />
Elevation of Privilege</td>
<td>May require restart</td>
<td>Microsoft Forefront Unified Access Gateway</td>
</tr>
</tbody>
</table>
<p>It should be noted that whilst these bulletins do not directly affect Windows, <strong>if you have Office</strong> components installed <strong>on your Operating System</strong>, you <strong>may</strong> <strong>be</strong> <strong>affected.</strong></p>
<p>In addition, November has also already seen announcement of a <a href="http://www.microsoft.com/technet/security/advisory/2458511.mspx" target="_blank">Security Advisory</a> for Internet Explorer which should certainly concern those using the product or developing sites to be viewed by it.</p>
<p>We will issue further information on the impact of this months updates once they have been released for testing early next week.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for November 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-nov.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates are to affect your servers or solutions when <strong>released on 9th November </strong><em>(as usual, as a UKFast customer, you benefit from these <a href="http://www.ukfast.co.uk/patch-updates-predeployment-testing.html">updates being applied automatically</a> unless you have opted out of this service.)</em></p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/11/05/november-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tech tip? Or Top Tech?</title>
		<link>http://blog.ukfast.co.uk/2010/10/26/tech-tip-or-top-tech/</link>
		<comments>http://blog.ukfast.co.uk/2010/10/26/tech-tip-or-top-tech/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 11:55:03 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[ebook]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7564</guid>
		<description><![CDATA[I've previously posted up links to free downloadable eBooks regarding techologies and thanks to the guys over at Microsoft Press - there are now a plethora of new ones available to help you.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve previously posted up links to free downloadable eBooks regarding techologies and thanks to the guys over at Microsoft Press &#8211; there are now a plethora of new ones available to help you.</p>
<p>Take a look at the following top tech picks from the site below &#8211; there are plenty more on the site if you want to take a look <a href="http://blogs.msdn.com/b/microsoft_press/" target="_blank">here</a>.</p>
<p>MC.</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2010/09/13/free-ebook-moving-to-microsoft-visual-studio-2010.aspx" target="_blank">Free ebook: Moving to Microsoft Visual Studio 2010</a> (10 chapters by by Patrice Pelland, Pascal Paré, and Ken Haines)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2009/10/20/free-ebook-introducing-windows-server-2008-r2.aspx" target="_blank">Free ebook: Introducing Windows Server 2008 R2</a> (9 chapters by Charlie Russel and Craig Zacker)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2010/04/14/free-ebook-introducing-microsoft-sql-server-2008-r2.aspx" target="_blank">Free ebook: Introducing Microsoft SQL Server 2008 R2</a> (10 chapters by Ross Mistry and Stacia Misner)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2010/02/16/free-ebook-understanding-microsoft-virtualization-r2-solutions.aspx" target="_blank">Free ebook: Understanding Microsoft Virtualization Solutions (Second Edition)</a> (6 chapters by Mitch Tulloch)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2010/01/20/free-ebook-first-look-microsoft-office-2010.aspx" target="_blank">Free ebook: First Look Microsoft Office 2010</a> (14 chapters by Katherine Murray)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2009/10/26/free-e-book-windows-7-troubleshooting-tips.aspx" target="_blank">Free ebook: Windows 7 troubleshooting tips</a> (short ebook by Mitch Tulloch)</p>
<p><a href="http://blogs.msdn.com/b/microsoft_press/archive/2009/10/16/free-e-book-deploying-windows-7-essential-guidance.aspx" target="_blank">Free ebook: Deploying Windows 7, Essential Guidance</a> (10 chapters from the <em><a href="http://blogs.msdn.com/b/microsoft_press/archive/2009/10/07/new-book-windows-7-resource-kit.aspx" target="_blank">Windows 7 Resource Kit</a></em> and 6 TechNet articles)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/10/26/tech-tip-or-top-tech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/10/13/october-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/10/13/october-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 13:21:32 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7484</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are now confirmed to be 16 security bulletins, addressing 49 vulnerabilities.]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/10/08/october-2010-security-bulletin-release-advance-notification/" target="_blank">previous post</a> on this months security bulletin releases, there are now confirmed to be<strong> 16 security bulletins, addressing 49 vulnerabilities</strong>.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms10-oct.mspx" target="_blank">This month</a> is a milestone for Microsoft in that it reaches a new high for both the number of bulletins released and vulnerabilites being addressed.</p>
<p>Of the 16 security bulletins, 12 address Windows, 3 Office, 1 .NET and 1 Internet Explorer. Whilst all should be given due attention in their relevant environments, our primary focus is those affecting Windows Server Operating Systems.</p>
<p>As such, the following table focuses on affected Server OS&#8217;s by bulletin and the likelihood of a Operating System restart being required and hence impacting on services provided.</p>
<table border="1" cellspacing="0" cellpadding="0" width="630">
<colgroup span="1">
<col span="1" width="81"></col>
<col span="1" width="101"></col>
<col span="5" width="128"></col>
</colgroup>
<tbody>
<tr height="41">
<td width="55" height="41"><strong>Bulletin Identifier</strong></td>
<td width="85"><strong>Aggregate Severity Rating</strong></td>
<td width="85"><strong>Windows Server 2003 32-bit</strong></td>
<td width="85"><strong>Windows Server 2003 x64</strong></td>
<td width="85"><strong>Windows Server 2008 32-bit</strong></td>
<td width="85"><strong>Windows Server 2008 x64</strong></td>
<td width="85"><strong>Windows Server 2008 R2</strong></td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-071.mspx">MS10-071</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-073.mspx">MS10-073</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-074.mspx">MS10-074</a></td>
<td>Moderate</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-075.mspx">MS10-075</a></td>
<td>None</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-076.mspx">MS10-076</a></td>
<td>Critical</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-077.mspx">MS10-077</a></td>
<td>Critical</td>
<td>Not applicable</td>
<td>May restart</td>
<td>Not applicable</td>
<td>May restart</td>
<td>May restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-078.mspx">MS10-078</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-081.mspx">MS10-081</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-082.mspx">MS10-082</a></td>
<td>Important</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
<td>May restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-083.mspx">MS10-083</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-084.mspx">MS10-084</a></td>
<td>Important</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-085.mspx">MS10-085</a></td>
<td>None</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Restart required</td>
<td>Restart required</td>
<td>Restart required</td>
</tr>
<tr height="21">
<td height="21"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-086.mspx">MS10-086</a></td>
<td>None</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Not applicable</td>
<td>Restart required</td>
</tr>
</tbody>
</table>
<p>As can be seen, there are a large number of <strong>updates affecting 2003, 2008 &amp; 2008 R2</strong> but most importantly we are <strong>highly likely to see widespread requirement for Operating System restarts</strong>. Typically where &#8216;May restart&#8217; is listed, this will require a restart if components being updated are in use at the time of update or if services cannot for some reason be stopped &#8211; so planning for a restart is highly recommended.</p>
<p>In addition to reviewing the official Security Bulletin, it is also worth reviewing the information on the <a href="http://blogs.technet.com/b/msrc/archive/2010/10/11/october-2010-security-bulletin-release.aspx" target="_blank">Microsoft Security Response Center blog</a> regarding this months updates where more detail on real world scenarios is discussed.  The below slides are from the blog and show the Deployment Priority and Severity and Exploitability Index ratings for this months updates.</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-7487" title="october-10 deploy" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/10/october-10-deploy-1024x576.png" alt="" width="581" height="327" /><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/10/october-10-severity.png"><img class="aligncenter size-large wp-image-7488" title="october-10 severity" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/10/october-10-severity-1024x576.png" alt="" width="581" height="327" /></a></p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/10/13/october-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/10/08/october-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/10/08/october-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 08:41:40 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[bulletin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7437</guid>
		<description><![CDATA[This 'Patch Tuesday' for October 2010, sees the release of 16 bulletins addressing 49 vulnerabilities. All bulletins affect Windows; 4 carrying Critical severity rating.]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; for October 2010</strong>, sees the release of<strong> 16 </strong><strong>bulletins addressing 49 vulnerabilities.</strong> All bulletins affect Windows; 4 carrying Critical severity rating.</p>
<p>The limited information available at this pre-release stage is as follows:</p>
<table id="E5C" style="width: 600px; height: 512px;" border="1" cellspacing="0" cellpadding="0" width="600">
<colgroup span="1">
<col span="1" width="40"></col>
<col span="1" width="120"></col>
<col span="3" width="80"></col>
</colgroup>
<tbody>
<tr valign="top">
<td><strong>Bulletin ID</strong></td>
<td><strong>Maximum Severity Rating and Vulnerability Impact</strong></td>
<td><strong>Restart Requirement</strong></td>
<td><strong>Affected Software</strong></td>
</tr>
<tr valign="top">
<td>Bulletin 1</td>
<td>Critical<br />
Remote Code Execution</td>
<td>Requires restart</td>
<td>Microsoft Windows,<br />
Internet Explorer</td>
</tr>
<tr valign="top">
<td>Bulletin 2</td>
<td>Critical<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 3</td>
<td>Critical<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 4</td>
<td>Critical<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 5</td>
<td>Important<br />
Information Disclosure</td>
<td>May require restart</td>
<td>Microsoft Server Software</td>
</tr>
<tr valign="top">
<td>Bulletin 6</td>
<td>Important<br />
Elevation of Privilege</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 7</td>
<td>Important<br />
Elevation of Privilege</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 8</td>
<td>Important<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td>Bulletin 9</td>
<td>Important<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Office</td>
</tr>
<tr valign="top">
<td>Bulletin 10</td>
<td>Important<br />
Remote Code Execution</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 11</td>
<td>Important<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 12</td>
<td>Important<br />
Remote Code Execution</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 13</td>
<td>Important<br />
Elevation of Privilege</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 14</td>
<td>Important<br />
Denial of Service</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 15</td>
<td>Moderate<br />
Remote Code Execution</td>
<td>May require restart</td>
<td>Microsoft Windows</td>
</tr>
<tr valign="top">
<td>Bulletin 16</td>
<td>Moderate<br />
Tampering</td>
<td>Requires restart</td>
<td>Microsoft Windows</td>
</tr>
</tbody>
</table>
<p>In addition, September also saw the release of an out-of-band bulletin by Microsoft (<a href="http://www.ukfastblog.co.uk/2010/09/29/september-out-of-band-update-released/" target="_blank">MS10-070</a>) which we issued guidance on last week and should be considered a critical update for .net based web services.</p>
<p>We will issue further information on the impact of this months updates once they have been released for testing early next week.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for October 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-oct.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates are to affect your servers or solutions when <strong>released on 12th October </strong><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/10/08/october-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>September Out-of Band update released</title>
		<link>http://blog.ukfast.co.uk/2010/09/29/september-out-of-band-update-released/</link>
		<comments>http://blog.ukfast.co.uk/2010/09/29/september-out-of-band-update-released/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 10:30:23 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[out-of-band]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7326</guid>
		<description><![CDATA[[UPDATE 01/10/2010: MS10-070 was released to Windows Update overnight]
On September 28th 2010, Microsoft released MS10-070 - a windows update released outside of the normal update schedule.

This update addresses vulnerabilities in the .NET framework and affects all versions of .NET on Server Operating Systems.
]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;"><em>[UPDATE 01/10/2010: MS10-070 was released to Windows Update overnight last night and will be being applied to computers configured with Automatic updates. As usual, as a UKFast customer, you benefit from updates being applied automatically unless you have opted out of this service.]</em></span></p>
<p>On September 28th 2010, Microsoft released MS10-070 &#8211; a windows update released <strong><span style="text-decoration: underline;">outside of the normal update schedule.</span></strong></p>
<p>This update addresses vulnerabilities in the .NET framework and affects all versions of .NET on Server Operating Systems.</p>
<p><em>&#8220;The vulnerability could allow information disclosure. An attacker who successfully exploited this vulnerability could read data, such as the view state, which was encrypted by the server. This vulnerability can also be used for data tampering, which, if successfully exploited, could be used to decrypt and tamper with the data encrypted by the server. Microsoft .NET Framework versions prior to Microsoft .NET Framework 3.5 Service Pack 1 are not affected by the file content disclosure portion of this vulnerability.&#8221; &#8211; </em>from <a href="http://www.microsoft.com/technet/security/bulletin/ms10-070.mspx" target="_blank">Microsoft Security Bulletin MS10-070</a>.</p>
<p>As the vulnerability has been publically disclosed, the update is classified as important and Microsoft (whilst not yet releasing to Windows Update) are advising implementation of the update at the &#8216;earliest&#8217; convenience.  The update will be released to the broader audience via Windows Update over the next few days and we will report on this here when we are informed.</p>
<p>Because this is an update to the .NET framework, the update applies across the board to Windows XP, Vista, Windows 7, <strong><span style="text-decoration: underline;">Windows Server 2003, 2008 and 2008 R2</span></strong>.</p>
<p>Once applied, the update does not require a reboot <strong><span style="text-decoration: underline;">unless</span></strong> the update process was unable to stop services or access files associated.  This will therefore <strong><span style="text-decoration: underline;">require</span></strong> interuption to services for applications which utilise .NET, regardless of whether a reboot is necessary.</p>
<p>There are known issues associated with updating the .NET framework code and any issues experienced in applying this update should first refer to the Microsoft knowledge base article <a href="http://support.microsoft.com/kb/2418042" target="_blank">2418042</a>.</p>
<p>For the time being, prior to release via Windows Update, the update can be located via the Microsoft Download site by searching on MS10-070 or .. clicking <a href="http://www.microsoft.com/downloads/en/results.aspx?freetext=MS10-070&amp;displaylang=en&amp;stype=s_basic" target="_blank">here</a>.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/09/29/september-out-of-band-update-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>September 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/09/15/september-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/09/15/september-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 10:49:18 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[bulletin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7300</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are now confirmed to be 9 security bulletins, addressing 11 vulnerabilities.  Refer to this page for details on all updates released this month.]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/09/10/september-2010-security-bulletin-release-advance-notification/" target="_blank">previous post</a> on this months security bulletin releases, there are now confirmed to be <strong>9 security bulletins, addressing 11 vulnerabilities</strong>.  Refer to <a href="http://www.microsoft.com/technet/security/bulletin/ms10-sep.mspx" target="_blank">this</a> page for details on all updates released this month.  Affected Server OS&#8217;s are listed below:</p>
<table border="1" cellspacing="0" cellpadding="0" width="640">
<colgroup span="1">
<col span="1" width="119"></col>
<col span="1" width="79"></col>
<col span="2" width="141"></col>
<col span="1" width="160"></col>
</colgroup>
<tbody>
<tr height="21">
<td width="119" height="21"><strong>Bulletin Identifier</strong></td>
<td width="79"><strong>Severity</strong></td>
<td width="141"><strong>Windows Server 2003</strong></td>
<td width="141"><strong>Windows Server 2008</strong></td>
<td width="160"><strong>Windows Server 2008 R2</strong></td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-061.mspx">MS10-061</a></td>
<td>(Important)</td>
<td>Requires restart</td>
<td>Requires restart</td>
<td>Requires restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-062.mspx">MS10-062</a></td>
<td>(Critical)</td>
<td>May require restart</td>
<td>May require restart</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx">MS10-063</a></td>
<td>(Critical)</td>
<td>Requires restart</td>
<td>Requires restart</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx">MS10-065</a></td>
<td>(Important)</td>
<td>May require restart</td>
<td>May require restart</td>
<td>May require restart</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/ms10-066.mspx">MS10-066</a></td>
<td>(Important)</td>
<td>Requires restart</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-067.mspx">MS10-067</a></td>
<td>(Important)</td>
<td>May require restart</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
<tr height="20">
<td height="20"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-068.mspx">MS10-068</a></td>
<td>(Important)</td>
<td>Requires restart</td>
<td>Requires restart</td>
<td>Requires restart</td>
</tr>
<tr height="21">
<td height="21"><a href="http://www.microsoft.com/technet/security/bulletin/MS10-069.mspx">MS10-069</a></td>
<td>(Important)</td>
<td>Requires restart</td>
<td>Not applicable</td>
<td>Not applicable</td>
</tr>
</tbody>
</table>
<p>In addition to the above, if you have previously installed the update relating to MS10-53 (vulnerability in IE), <a href="http://support.microsoft.com/?kbid=2398632" target="_blank">another update</a> <em>- which requires a reboot -</em> to this has been released this month to fix issues with the launch of IE on W7 and W2008 R2.</p>
<p>Since these have been released, limited testing has been undertaken and we can confirm that we are <strong>expecting</strong> <strong>reboots</strong> to be required for <strong>Windows Server 2003, 2008</strong> and <strong>2008 R2</strong>.</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/09/15/september-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/09/10/september-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/09/10/september-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 08:49:13 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7274</guid>
		<description><![CDATA[This 'Patch Tuesday' for September 2010, sees the release of 9 bulletins addressing 11 vulnerabilities. All bulletins affect Windows; 2 carrying Critical severity rating.]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; for September 2010</strong>, sees the release of<strong> 9 </strong><strong>bulletins addressing 11 vulnerabilities.</strong> All bulletins affect Windows; 2 c<strong></strong>arrying Critical severity rating.</p>
<p>The limited information available at this pre-release stage is as follows:</p>
<table border="1" cellspacing="0" cellpadding="0" width="616">
<colgroup span="1">
<col span="1" width="160"></col>
<col span="1" width="104"></col>
<col span="3" width="128"></col>
</colgroup>
<tbody>
<tr height="41">
<td width="128" height="41"><strong>Bulletin Identifier</strong></td>
<td width="104"><strong>Severity</strong></td>
<td width="128"><strong>Windows Server 2003</strong></td>
<td width="128"><strong>Windows Server 2008</strong></td>
<td width="128"><strong>Windows Server 2008 R2</strong></td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 1</td>
<td width="104">(Important)</td>
<td width="128">requires restart</td>
<td width="128">requires restart</td>
<td width="128">requires restart</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 2</td>
<td width="104">(Critical)</td>
<td width="128">may require restart</td>
<td width="128">may require restart</td>
<td width="128">Not applicable</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 3</td>
<td width="104">(Critical)</td>
<td width="128">may require restart</td>
<td width="128">may require restart</td>
<td width="128">Not applicable</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 5</td>
<td width="104">(Important)</td>
<td width="128">may require restart</td>
<td width="128">may require restart</td>
<td width="128">may require restart</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 6</td>
<td width="104">(Important)</td>
<td width="128">requires restart</td>
<td width="128">Not applicable</td>
<td width="128">Not applicable</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 7</td>
<td width="104">(Important)</td>
<td width="128">may require restart</td>
<td width="128">Not applicable</td>
<td width="128">Not applicable</td>
</tr>
<tr height="20">
<td width="160" height="20">Bulletin 8</td>
<td width="104">(Important)</td>
<td width="128">requires restart</td>
<td width="128">requires restart</td>
<td width="128">requires restart</td>
</tr>
<tr height="21">
<td width="160" height="21">Bulletin 9</td>
<td width="104">(Important)</td>
<td width="128">requires restart</td>
<td width="128">Not applicable</td>
<td width="128">Not applicable</td>
</tr>
</tbody>
</table>
<p>We will issue further information on the impact of these updates once they have been released for testing.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for September 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-sep.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates affect your servers or solutions when <strong>released on 14th September </strong><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/09/10/september-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Virtualization Certifications</title>
		<link>http://blog.ukfast.co.uk/2010/08/23/microsoft-virtualization-certifications/</link>
		<comments>http://blog.ukfast.co.uk/2010/08/23/microsoft-virtualization-certifications/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 16:20:40 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[qualification]]></category>
		<category><![CDATA[system center]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7253</guid>
		<description><![CDATA[With all the buzz currently in the industry about 'cloud' technology it's worth keeping up to speed with industry certifications and, especially, ones which provide the core understanding for cloud based solutions.]]></description>
			<content:encoded><![CDATA[<p>With all the buzz currently in the industry about &#8216;cloud&#8217; technology it&#8217;s worth keeping up to speed with industry certifications and, especially, ones which provide the core understanding for cloud based solutions.</p>
<p>Microsoft have many varied certification routes and I will not go in to detail on these here (their <a href="http://www.microsoft.com/learning/en/us/certification/mcitp.aspx" target="_blank">learning portal</a> is worth a visit however) but one route of key interest for cloudy types is Windows Server 2008 R2 Virtualization.</p>
<p>A bit of an overview of Microsoft certifications &#8211; the old school may remember MCP, MCSE etc &#8211; nowadays, we are in the age of MCTS and MCITP.  These are loosely the equivalent of their older counterparts, the former being a lower end single exam and the latter being a qualification or certification gained through a combination the single exams.</p>
<p>So &#8211; to achieve the latest MCITP (Microsoft Certified IT Pro) qualification, you&#8217;ll need to have passed several base MCTS (Technology Specialist) examinations.</p>
<p>In the case of cloudy certifications, this is the &#8221;Microsoft Certified IT Professional: Windows Server 2008 R2, Virtualization Administrator&#8221; qualification and requires:</p>
<ol>
<li>Exam <a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-652&amp;locale=en-us" target="_blank">70-652</a>: TS: Windows Server Virtualization, Configuring OR Exam <a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-659&amp;locale=en-us" target="_blank">70-659</a>: TS: Windows Server 2008 R2, Server Virtualization</li>
<li>Exam <a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-669&amp;locale=en-us" target="_blank">70-669</a>: TS: Windows Server 2008 R2, Desktop Virtualization</li>
<li>Exam <a href="http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-693&amp;locale=en-us" target="_blank">70-693</a>: Pro: Windows Server 2008 R2, Virtualization Administrator</li>
</ol>
<p>All very worth looking at as they will help with core understanding of the technologies and go to prove an individuals ability with the technologies and&#8230;as they say these days at MS&#8230;<a href="http://www.microsoft.com/cloud/" target="_blank">we&#8217;re all in</a>!</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/08/23/microsoft-virtualization-certifications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer 9 coming to a computer near you</title>
		<link>http://blog.ukfast.co.uk/2010/08/18/internet-explorer-9-coming-to-a-computer-near-you/</link>
		<comments>http://blog.ukfast.co.uk/2010/08/18/internet-explorer-9-coming-to-a-computer-near-you/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 10:46:10 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[browsing]]></category>
		<category><![CDATA[web 2.0]]></category>
		<category><![CDATA[world wide web]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=7196</guid>
		<description><![CDATA[Microsoft and its partner developers are gearing up for the release of the latest in their incarnation of web browser, Internet Explorer.  This release, in the 15th year since IE 1, will be the 9th instalment of the much used (51% market share) browser.]]></description>
			<content:encoded><![CDATA[<p>Microsoft and its partner developers are gearing up for the release of the latest in their incarnation of web browser, Internet Explorer. This <strong>release</strong>, in the 15th year since IE 1, will be the <strong>9th instalment</strong> of the much used (<a href="http://en.wikipedia.org/wiki/Usage_share_of_web_browsers" target="_blank">51%</a> market share) browser.</p>
<p>Microsoft openly announced commitments to the audience at their PDC09 (<a href="http://www.microsoftpdc.com/" target="_blank">professional developer conference</a>) including:</p>
<li>Internet Explorer 9 would help enable the same markup to work across browsers</li>
<li>Internet Explorer 9 would be all-round fast</li>
<li>Through Windows and modern hardware, Internet Explorer 9 would unlock the next class of experiences for the web</li>
<p>And the browser looks set to feature in a big way at this years PDC as well as in the public arena where it is <strong>due for beta release on September 15th</strong> (before the PDC).</p>
<p>The release is being marked in a <a href="http://windowsteamblog.com/ie/b/ie/archive/2010/08/12/announcing-the-beauty-of-the-web-event-for-ie9-beta-launch.aspx" target="_blank">big way</a> (ok maybe not <a href="http://www.microsoft.com/presspass/features/2010/jun10/06-13kinectintroduced.mspx" target="_blank">Kinect big</a>) with Microsoft throwing a &#8216;beauty of the web&#8217; event for a select group of VIP web developers, designers, bloggers and press.</p>
<p>You can get your hands on the latest (currently 4th public) release of the <strong>IE9 preview </strong><a href="http://ie.microsoft.com/testdrive/" target="_blank"><strong>here</strong></a>.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/08/18/internet-explorer-9-coming-to-a-computer-near-you/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>August 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/08/11/august-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/08/11/august-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 11:53:23 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6988</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are confirmed to be 14 security bulletins, addressing 34 vulnerabilities. Eight of those bulletins have a Critical severity rating, and four of those are considered to be high-priority deployments. Refer to this page for details on all updates released this month]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/08/06/august-2010-security-bulletin-release-advance-notification/" target="_blank">previous post </a>on this months security bulletin releases, there are confirmed to be <strong>14 security bulletins, addressing 34 vulnerabilities</strong>. Eight of those bulletins have a Critical severity rating, and four of those are considered to be high-priority deployments. Refer to <a href="http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx" target="_blank">this</a> page for details on all updates released this month.</p>
<p><em>Of these updates, for the Windows Server operating systems, 3 are listed as requires restart and apply to </em><em>Windows Server 2003, 2008 &amp; 2008 R2.</em></p>
<ul>
<li><a href="http://go.microsoft.com/fwlink/?LinkID=197393" target="_blank">MS10-046</a> &#8211; kb2286198</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=196549" target="_blank">MS10-053</a> &#8211; kb2183461</li>
<li><a href="http://go.microsoft.com/fwlink/?LinkId=179830" target="_blank">MS10-060</a> &#8211; kb2265906</li>
</ul>
<p>Since these have been released, limited testing has been undertaken and we can confirm that we are <strong>expecting</strong> <strong>reboots</strong> to be required for <strong>Windows Server 2003, 2008</strong> and <strong>2008 R2</strong>.</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010DeploymentPriority.png"></a></p>
<p style="text-align: center;"><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/08/august-10-deploy.png"><img class="aligncenter size-large wp-image-7000" title="august-10 deploy" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/08/august-10-deploy-1024x576.png" alt="" width="614" height="346" /></a></p>
<p style="text-align: center;"><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/08/august-10-deploy.png"></a><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/08/august-10-severity.png"><img class="aligncenter size-large wp-image-7001" title="august-10 severity" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/08/august-10-severity-1024x576.png" alt="" width="614" height="346" /></a><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010SeverityandExploitability.png"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/08/11/august-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/08/06/august-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/08/06/august-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 06 Aug 2010 10:59:58 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6890</guid>
		<description><![CDATA[This 'Patch Tuesday' - for August 2010 - sees the release of 14 bulletins addressing 34 vulnerabilities. 12 of the bulletins affect Windows; 4 carrying Critical severity rating.]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; for August 2010</strong>, sees the release of<strong> 14</strong> <strong>bulletins addressing 34 vulnerabilities.</strong> 12 of the bulletins affect Windows; 4<strong> </strong>carrying Critical severity rating.</p>
<p>All are listed at least as &#8216;may require a restart&#8217;. Of note:</p>
<ul>
<li><strong>&#8216;requires restart&#8217;:</strong>
<ul>
<li>2 critical updates affecting Windows Server 2003 32bit and x64 Service Pack 2.</li>
<li>1 critical update affecting Windows Server 2008 32bit and x64 &amp; 2008 R2.</li>
</ul>
</li>
</ul>
<p>We will issue further information on the impact of these updates once they have been released for testing.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for August 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates affect your servers or solutions when <strong>released on 10th August </strong><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/08/06/august-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>August Out-of Band update released</title>
		<link>http://blog.ukfast.co.uk/2010/08/03/august-out-of-band-update-released/</link>
		<comments>http://blog.ukfast.co.uk/2010/08/03/august-out-of-band-update-released/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 08:38:34 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6868</guid>
		<description><![CDATA[On August 2nd 2010, Microsoft released MS10-046 - a windows update released outside of the normal update schedule.]]></description>
			<content:encoded><![CDATA[<p>On August 2nd 2010, Microsoft released MS10-046 &#8211; a windows update released <strong><span style="text-decoration: underline;">outside of the normal update schedule.</span></strong></p>
<p>This update addresses vulnerabilities in handling of shortcuts (.lnk&#8217;s) in the Windows Shell. Microsoft are now <strong><span style="text-decoration: underline;">seeing active exploits </span></strong>and hence have released this update 1 week prior to the usual &#8216;patch tuesday&#8217; updates &#8211; which are released on the second Tuesday of every month.</p>
<p>This update applies to Windows XP, Vista, Windows 7, <strong><span style="text-decoration: underline;">Windows Server 2003, 2008 and 2008 R2</span></strong>.  A more detailed list of affected OS&#8217;s and information on the update and how it affects you can be found on <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx" target="_blank">Microsoft Technet</a>.</p>
<p>Initial spot checks of the server OS&#8217;s above show that once KB2286198 is applied, <strong><span style="text-decoration: underline;">a reboot is necessary</span></strong>.</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/08/03/august-out-of-band-update-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS Assessment and Planning toolkit 5 released</title>
		<link>http://blog.ukfast.co.uk/2010/07/26/ms-assessment-and-planning-toolkit-5-released/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/26/ms-assessment-and-planning-toolkit-5-released/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 16:55:48 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[inventory]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6830</guid>
		<description><![CDATA[Microsoft Assessment and Planning (MAP) Toolkit 5.0 is now available for download. MAP 5.0 is a tool designed to simplify IT infrastructure planning processes via automated discovery and assessments of network-wide devices. It performs an inventory of heterogeneous server environments and in addition will gather usage information for Windows operating systems, SQL Server and other [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft Assessment and Planning (MAP) Toolkit 5.0 is now available for download.</p>
<p>MAP 5.0 is a tool designed to simplify IT infrastructure planning processes via automated discovery and assessments of network-wide devices. It performs an inventory of heterogeneous server environments and in addition will gather usage information for Windows operating systems, SQL Server and other MS software products. Migration assessment tools also allow for planning with regards to moving from previous technology versions to the latest versions.</p>
<p><strong>What&#8217;s new with MAP Toolkit 5.0?</strong></p>
<ul>
<li>Heterogeneous server environment inventory</li>
<li>Software usage tracking for Windows Server, SharePoint Server, System Center Configuration Manager, Exchange Server, and SQL Server</li>
<li>Microsoft Office 2010 readiness assessment</li>
<li>SQL Server discovery and assessment for consolidation</li>
<li>Windows 2000 Server migration assessment</li>
</ul>
<p>More information on this tool can be found at the MS technet site <a href="http://technet.microsoft.com/en-us/library/bb977556.aspx" target="_blank">here</a>.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/26/ms-assessment-and-planning-toolkit-5-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LINX connectivity causes problems for UK internet</title>
		<link>http://blog.ukfast.co.uk/2010/07/21/linx-connectivity-causes-problems-for-uk-internet/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/21/linx-connectivity-causes-problems-for-uk-internet/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 14:13:04 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[UKFast]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6816</guid>
		<description><![CDATA[At approximately 14.25 on Wednesday 21st July the London Internet Exchange (LINX) experienced a power outage in one of its data centres, causing connectivity issues for internet users logging into services and onto the World Wide Web. For around 20 minutes the service disruption was intermittent for users, causing confusion in relation to the actual [...]]]></description>
			<content:encoded><![CDATA[<p>At approximately 14.25 on Wednesday 21st July the London Internet Exchange (LINX) experienced a power outage in one of its data centres, causing connectivity issues for internet users logging into services and onto the World Wide Web.</p>
<p>For around 20 minutes the service disruption was intermittent for users, causing confusion in relation to the actual problem. Websites were loading slowly or timing out, while businesses logging into web based applications are likely to have lost connection.</p>
<p>Neil Lathwood our IT Director here at UKFast, was quick to recognise the problem, having analysed traffic graphs on the LINX website. At approximately 14.45, traffic on the graphs dropped off considerably as LINX was able to re-route services through an alternative stable channel.</p>
<p>&#8220;Because we manage the hosting for mission critical websites day in day out, we were initially inundated with calls from clients worried about their services,&#8221; says Neil. Our team have had to explain that the connectivity issues people are experiencing have no bearing on the stability of their hosting solutions which remain online and available.&#8221;</p>
<p>Neil noticed that the phones stopped ringing with such ferocity at the point that the traffic graphs dropped &#8211; showing that users had been redirected and were now able to once again access their services.</p>
<p>One of the world&#8217;s largest exchange points, LINX is used by many connectivity ISPs across the UK. So a great many businesses and consumers connecting to the internet through a UK ISP are likely to be affected today.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/21/linx-connectivity-causes-problems-for-uk-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Migrate sites the easier way</title>
		<link>http://blog.ukfast.co.uk/2010/07/20/migrate-sites-the-easier-way/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/20/migrate-sites-the-easier-way/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:41:21 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[world wide web]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6790</guid>
		<description><![CDATA[Currently on Microsoft Windows 2003?  Running IIS 6?]]></description>
			<content:encoded><![CDATA[<p>Currently on Microsoft Windows 2003? Running IIS 6? If so, methods of migrating to newer operating systems can include laborious reconfiguration of websites and migration of data.</p>
<p>However, a little known tool from Microsoft does speed this process somewhat, zipping up all data and settings in to a single file which can be transported to your new server running IIS7 and imported in very few clicks.</p>
<p>Hopefully something which will make all our lives a little easier &#8211; especially if you aren&#8217;t already with us and are looking to move to the fastest network in the UK!</p>
<p>For information on the migration tool see: <a href="http://www.iis.net/download/WebDeploy">http://www.iis.net/download/WebDeploy</a></p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/20/migrate-sites-the-easier-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/07/14/july-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/14/july-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 14:35:11 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6775</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are confirmed to be 4 bulletins addressing 5 vulnerabilities.]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/07/12/july-2010-security-bulletin-release-advance-notification/" target="_blank">previous post </a>on this months security bulletin releases, there are confirmed to be <strong>4</strong> <strong>bulletins addressing 5 vulnerabilities</strong>. Refer to <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jul.mspx" target="_blank">this</a> page for details on all updates released this month.</p>
<p>3 have a severity rating of critical and an <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx" target="_blank">exploitability index</a> rating of 1 <em>- see below for deployment priority and severity/exploitability charts.</em></p>
<p>Following on from the previous posts, we are <strong>expecting</strong> <strong>reboots</strong> for <strong>Windows Server 2003</strong> and <strong>Windows Server 2008 R2</strong> due to  2 of the updates released to be automatically installed this week (<a href="http://go.microsoft.com/fwlink/?LinkId=194729" target="_blank">MS10-042</a> &amp; <a href="http://go.microsoft.com/fwlink/?LinkId=194164" target="_blank">MS10-043</a>).</p>
<p>MC.</p>
<p><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010DeploymentPriority.png"><img class="aligncenter size-large wp-image-6777" title="July2010DeploymentPriority" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010DeploymentPriority-1024x576.png" alt="" width="597" height="336" /></a></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010SeverityandExploitability.png"><img class="aligncenter size-large wp-image-6778" title="July2010SeverityandExploitability" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/July2010SeverityandExploitability-1024x576.png" alt="" width="597" height="363" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/14/july-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/07/12/july-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/12/july-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 09:26:59 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6757</guid>
		<description><![CDATA[This 'Patch Tuesday' - for July 2010 - sees the release of 4 bulletins addressing 5 vulnerabilities. Two of the bulletins affect Windows;  both carrying Critical severity rating.]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; &#8211; for July 2010</strong> &#8211; sees the release of <strong>4</strong> <strong>bulletins addressing 5 vulnerabilities. </strong>Two of the bulletins affect Windows;  both carrying Critical severity rating.</p>
<p>All 4 are listed as at least &#8216;may require a restart&#8217;.  Of note:</p>
<ul>
<li><strong>&#8216;requires restart&#8217;</strong>
<ul>
<li>1 affecting Windows Server 2008 R2 .</li>
</ul>
</li>
<li><strong>&#8216;may require restart&#8217;</strong>
<ul>
<li>1 affecting Windows Server 2003 and XP.</li>
<li>2 affecting MS Office products.</li>
</ul>
</li>
</ul>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for July 2010&#8242; page <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-jul.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates affect your servers or solutions when <strong>released on 13th July </strong><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>To re-iterate the end of support for MS products, Microsoft also remind customers that the following products <strong>have now fallen from mainstream support</strong> and customers should actively seek out either a supported operating system or the latest service pack in order to keep receiving necessary security updates:</p>
<ul>
<li>Windows XP Service Pack 2 will no longer be supported after July 13, 2010. Many customers are still on this version, so we encourage upgrading to Service Pack 3 or to Windows 7 as soon as possible.</li>
<li>Extended support for Windows 2000 will also be retired as of July 13, 2010. After that time, we will no longer provide security or any other updates for Windows 2000.</li>
</ul>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/12/july-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IIS Express</title>
		<link>http://blog.ukfast.co.uk/2010/07/06/iis-express/</link>
		<comments>http://blog.ukfast.co.uk/2010/07/06/iis-express/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 08:49:08 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[world wide web]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6743</guid>
		<description><![CDATA[II&#8217;S Express&#8217; No &#8211; not a revival of the 80&#8242;s British dance act but a new release from Microsoft &#8230;. IIS Express is a lightweight installable version of the popular web hosting platform Internet Information Services (IIS) 7, which can run on XP and above operating systems.  Features and benefits include: Lightweight and easy to [...]]]></description>
			<content:encoded><![CDATA[<p>II&#8217;S Express&#8217;</p>
<p>No &#8211; not a revival of the 80&#8242;s British dance act but a new release from Microsoft &#8230;.</p>
<p>IIS Express is a lightweight installable version of the popular web hosting platform Internet Information Services (IIS) 7, which can run on XP and above operating systems. </p>
<p>Features and benefits include:</p>
<li>Lightweight and easy to install (less than 10Mb download and a super quick install)</li>
<li><span style="text-decoration: underline;">Does not</span> require an administrator account to run/debug applications from Visual Studio</li>
<li>Enables a <span style="text-decoration: underline;">full web-server feature set</span> – including SSL, URL Rewrite, Media Support, and all other IIS 7.x modules</li>
<li>Supports and enables the same extensibility model and web.config file settings that IIS 7.x support</li>
<li>Can be installed side-by-side with the full IIS web server as well as the ASP.NET Development Server (they do not conflict at all)</li>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/IISExpress.png"><img class="aligncenter size-full wp-image-6745" title="IISExpress" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/07/IISExpress.png" alt="" width="463" height="109" /></a></p>
<p>Beta to be released shortly and more detailed information available over at <a href="http://weblogs.asp.net/scottgu/archive/2010/06/28/introducing-iis-express.aspx" target="_blank">Scott Guthrie&#8217;s blog</a>.</p>
<p>Let&#8217;s hope its a chart topper&#8230;.</p>
<p>MC</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/07/06/iis-express/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/06/10/june-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/06/10/june-2010-security-bulletin-release/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 08:40:54 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6690</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are confirmed to be 10 bulletins addressing 34 vulnerabilities. Refer to this page for details on all updates released this month. 3 have a severity rating of critical and an exploitability index rating of 1 - see below for deployment priority chart. [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/06/07/june-2010-security-bulletin-release-advance-notification/" target="_blank">previous post </a>on this months security bulletin releases, there are confirmed to be <strong>10 bulletins addressing 34 vulnerabilities</strong>. Refer to <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx" target="_blank">this</a> page for details on all updates released this month.</p>
<p><strong>3 have a severity rating of critical</strong> and an <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx" target="_blank">exploitability index</a> rating of 1 <em>- see below for deployment priority chart.</em></p>
<p>Following on from the previous posts, <strong>we are expecting</strong> <strong>mandatory reboots</strong> for 2 of the updates released to be automatically installed this week (<a href="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" target="_blank">MS10-035</a> &amp;<a href="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx" target="_blank"> MS10-032</a>).  Both of which <strong>affect pretty much all commonly deployed Windows operating systems</strong> (see links above for details).</p>
<p>All remaining updates are listed as &#8216;may require restart&#8217; which commonly means that they will indeed require a restart.</p>
<p>MC.</p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010DeploymentPriority.png"></a></p>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/06/June2010DeploymentPriority.png"><img class="aligncenter size-full wp-image-6692" title="June2010DeploymentPriority" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/06/June2010DeploymentPriority.png" alt="" width="550" height="309" /></a><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010RiskandImpact.png"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/06/10/june-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/06/07/june-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/06/07/june-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 16:30:03 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6682</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; &#8211; for June 2010 &#8211; sees the release of 10 bulletins addressing 34 vulnerabilities. Six of the bulletins affect Windows; of those, two carry a Critical severity rating and four are rated Important. Two of the bulletins, both with a severity rating of Important, affect Microsoft Office. One bulletin, again with a [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; &#8211; for June 2010</strong> &#8211; sees the release of <strong>10</strong> <strong>bulletins addressing 34 vulnerabilities. </strong>Six of the bulletins affect Windows; of those, two carry a Critical severity rating and four are rated Important. Two of the bulletins, both with a severity rating of Important, affect Microsoft Office. One bulletin, again with a severity rating of Important, affects both Windows and Office. Finally, one bulletin, with a severity rating of Critical, affects Internet Explorer.</p>
<p>All of these are listed as at least &#8216;may require a restart&#8217; with 2 listed as &#8216;requires restart&#8217;.  <strong>The 2 requiring a restart <span style="text-decoration: underline;">do</span> affect Server operating systems.</strong></p>
<p>Also, the June bulletin addresses the previously advisory regarding sharepoint (<a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">983438</a>), and this will now be closed.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for June 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates affect your servers or solutions when <strong>released on 8th June </strong><em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>To re-iterate the end of support for MS products, Microsoft also remind customers that the following products will end mainstream support NEXT MONTH:</p>
<ul>
<li>Windows XP Service Pack 2 will no longer be supported after July 13, 2010. Many customers are still on this version, so we encourage upgrading to Service Pack 3 or to Windows 7 as soon as possible.</li>
<li>Extended support for Windows 2000 will also be retired as of July 13, 2010. After that time, we will no longer provide security or any other updates for Windows 2000.</li>
</ul>
<p>and for products recently ending support:</p>
<ul>
<li>Windows Vista RTM is no longer be supported as it has passed the April 13, 2010 returement date. Service Pack 1 will still be supported until July 12, 2011 but we recommend customers update to Service Pack 2 or Windows 7 at this time.</li>
</ul>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/06/07/june-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Server Memory Investigation Tool</title>
		<link>http://blog.ukfast.co.uk/2010/05/20/server-memory-investigation-tool/</link>
		<comments>http://blog.ukfast.co.uk/2010/05/20/server-memory-investigation-tool/#comments</comments>
		<pubDate>Thu, 20 May 2010 09:47:40 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6653</guid>
		<description><![CDATA[If you ever had any desire to work out what was loaded in to memory or what the breakdown of memory usage is, then this new tool by the MS Sysinternals team will certainly set you on the right track. RAMMap by Sysinternals presents data in a compact windows application within a series of tabs: [...]]]></description>
			<content:encoded><![CDATA[<p>If you ever had any desire to work out what was loaded in to memory or what the breakdown of memory usage is, then this new tool by the MS Sysinternals team will certainly set you on the right track.</p>
<p>RAMMap by Sysinternals presents data in a compact windows application within a series of tabs:</p>
<li><em>Use Counts:</em> usage summary by type and paging list</li>
<li><em>Processes:</em> process working set sizes</li>
<li><em>Priority Summary:</em> prioritized standby list sizes</li>
<li><em>Physical Pages:</em> per-page use for all physical memory</li>
<li><em>Physical Ranges:</em> physical memory addresses</li>
<li><em>File Summary:</em> file data in RAM by file</li>
<li><em>File Details:</em> individual physical pages by file</li>
<p><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/rammap_thumben-usMSDN_10.jpg"><img class="aligncenter size-full wp-image-6654" title="rammap_thumb(en-us,MSDN_10)" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/rammap_thumben-usMSDN_10.jpg" alt="" width="420" height="244" /></a></p>
<p>The application runs on Vista/Server 2008 OS and later and is available for download &amp; install <a href="http://download.sysinternals.com/Files/RAMMap.zip" target="_blank">here</a> as well as click and run live <a href="http://live.sysinternals.com/rammap.exe" target="_blank">here</a>.</p>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/05/20/server-memory-investigation-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2010 Security Bulletin Release</title>
		<link>http://blog.ukfast.co.uk/2010/05/12/may-2010-security-bulletin-release/</link>
		<comments>http://blog.ukfast.co.uk/2010/05/12/may-2010-security-bulletin-release/#comments</comments>
		<pubDate>Wed, 12 May 2010 08:46:13 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6639</guid>
		<description><![CDATA[As mentioned in the previous post on this months security bulletin releases, there are confirmed to be only 2 bulletins this month. Both have a severity rating of critical and an exploitability index rating of 2 - see below for charts of vulnerability and severity. MS10-030addresses an issue on operating systems installed with mail clients [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned in the <a href="http://www.ukfastblog.co.uk/2010/05/07/may-2010-security-bulletin-release-advance-notification/">previous post </a>on this months security bulletin releases, there are confirmed to be only 2 bulletins this month.</p>
<p>Both have a severity rating of critical and an <a href="http://technet.microsoft.com/en-us/security/cc998259.aspx">exploitability index</a> rating of 2 <em>- see below for charts of vulnerability and severity.</em></p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms10-030.mspx">MS10-030</a>addresses an issue on operating systems installed with mail clients such as Outlook express, Windows Mail and Windows Live mail. As such, not all OSes are affected &#8211; Windows 7 and Server 2008 R2 do not have a mail client installed as default.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms10-031.mspx">MS10-031</a>addresses a vulnerability in Microsoft Visual Basic for Applications (VBA).  This is specific to VBA SDK 6.0.  On affected systems software should be recompiled and redistributed once the update has been applied to ensure this remote code execution vulnerability is removed.</p>
<p>The ongoing sharepoint security advisory (<a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">983438</a>) is available for those affected and covers workarounds to cross site scripting (XSS) vulnerability.</p>
<p>As echoed in the <a href="http://www.ukfastblog.co.uk/category/microsoft/">last two</a> security bulletin posts, MS are taking Windows XP SP2 to end of support on July 13th, 2010 and Windows 2000 is retired on the same date &#8211; the latter meaning they will provide no further security updates, potentially leaving production versions of the operating systems vulnerable if not update to a later OS.</p>
<p>MC.</p>
<p style="text-align: center;"><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010DeploymentPriority.png"><img class="aligncenter size-large wp-image-6642" title="May2010DeploymentPriority" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010DeploymentPriority-1024x576.png" alt="" width="602" height="386" /></a></p>
<p style="text-align: center;"><a href="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010RiskandImpact.png"><img class="aligncenter size-large wp-image-6646" title="May2010RiskandImpact" src="http://www.ukfastblog.co.uk/wp-content/uploads/2010/05/May2010RiskandImpact-1024x576.png" alt="" width="603" height="338" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/05/12/may-2010-security-bulletin-release/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>May 2010 Security Bulletin Release Advance Notification</title>
		<link>http://blog.ukfast.co.uk/2010/05/07/may-2010-security-bulletin-release-advance-notification/</link>
		<comments>http://blog.ukfast.co.uk/2010/05/07/may-2010-security-bulletin-release-advance-notification/#comments</comments>
		<pubDate>Fri, 07 May 2010 15:55:42 +0000</pubDate>
		<dc:creator>Micro-Clouseau</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.ukfastblog.co.uk/?p=6625</guid>
		<description><![CDATA[This &#8216;Patch Tuesday&#8217; &#8211; for May 2010 &#8211; sees the release of 2 Critical bulletins addressing 2 vulnerabilities in Windows, Microsoft Office, and Microsoft Exchange. In addition to the bulletins Microsoft also announced that in the wake of the recent security advisory regarding sharepoint (983438), they will not be releasing an update in the May [...]]]></description>
			<content:encoded><![CDATA[<p>This <strong>&#8216;Patch Tuesday&#8217; &#8211; for May 2010</strong> &#8211; sees the release of 2 <strong>Critical bulletins addressing 2 vulnerabilities</strong> in Windows, Microsoft Office, and Microsoft Exchange.</p>
<p>In addition to the bulletins Microsoft also announced that in the wake of the recent security advisory regarding sharepoint (<a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">983438</a>), they will not be releasing an update in the May bulletin. MS Teams are still working on an update for this issue and recommend reviewing the advisory for advice.</p>
<p>The &#8216;Microsoft Security Bulletin Advance Notification for May 2010&#8242; page <a href="http://www.microsoft.com/technet/security/bulletin/ms10-may.mspx" target="_blank">here</a> should be referenced for detailed information on how these updates affect your servers or solutions when <strong>released on 11th May</strong> <em>(as usual, as a UKFast customer, you benefit from these updates being applied automatically unless you have opted out of this service.)</em></p>
<p>To re-iterate the end of support for MS products, Microsoft also remind customers that the following products will end mainstream support shortly:</p>
<ul>
<li>Windows XP Service Pack 2 will no longer be supported after July 13, 2010. Many customers are still on this version, so we encourage upgrading to Service Pack 3 or to Windows 7 as soon as possible.</li>
<li>Extended support for Windows 2000 will also be retired as of July 13, 2010. After that time, we will no longer provide security or any other updates for Windows 2000.</li>
<li>Windows Vista RTM will no longer be supported after the April 13, 2010 bulletin release. Service Pack 1 will still be supported until July 12, 2011 but we recommend customers update to Service Pack 2 or Windows 7 at this time.</li>
</ul>
<p>MC.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ukfast.co.uk/2010/05/07/may-2010-security-bulletin-release-advance-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

