Submit a Story!
topics:

MS09-001: Prioritizing the deployment of the SMB bulletin
This month we released an update for SMB that addresses three vulnerabilities. This blog post provides additional information that might help prioritize the deployment of this update, and help explain the risk for code execution. In the bulletin you will see that the cumulative severity ...
Microsoft Security Bulletin MS09-001 - Critical: Vulnerabilities in SMB Could Allow Remote Code ...
microsoft.com — This security update resolves several privately reported vulnerabilities in Microsoft Server Message Block (SMB) Protocol. The vulnerabilities... could allow remote code execution on affected systems. An attacker who successfully exploited these ... (more) Microsoft Security Bulletin MS09-001 - Critical: ...
Comments
Blog Reactions

1 Security Patch for all Windows versions, also 2008 Core, no release for Windows 7 Beta
Bink.nu — ... . This bulletin is rated as ‘Critical' for Windows 2000, Windows XP and Windows Server 2003 and is rated as ‘Moderate' for Windows Vista and Windows Server 2008. My colleague Mark Wodrich has put together a posting over at the Security Vulnerability Research and Defense (SVRD) weblog which explains more about the vulnerability and the Exploitability Index rating. Also, as we do every month, we've released an updated version of our ...

Futility of Microsoft's Exploitability Index
InformationWeek - All Stories And Blogs — ... in Microsoft Server Message Block (SMB) Protocol. These vulnerabilities could allow remote code execution on at-risk Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, which is security-geek for saying you're owned, and an attacker could pretty much install whatever snoop-ware they wish on your system, or even create administration accounts and throw a party from your IP address. Yet, even with the "critical" risk rating, Microsoft Exploitability Index designates the vulnerability with its lowest rating, "Functioning exploit code unlikely." Holy Mixed ...

Microsoft Security Bulletin Jan ‘09 Release - Skips Windows 7
D' Technology Weblog — ... Software Removal Tool (MSRT), that remove the Win32/Conficker and Win32/Banload families of malware. Impacted customers will be interested in the addition of Win32/Conficker.B; which has had a significant and sudden impact on some customers. Windows 7 is affected only by the SMB Validation Denial of Service Vulnerability (CVE-2008-4114), and will be addressed in the next public release for Windows 7, reports MSRC Blog. More info: SVRD Blog ...

Related: ms09-001 exploit
Futility of Microsoft's Exploitability IndexInformationWeek - All Stories And Blogs
As far as Microsoft patch Tuesdays are concerned, 2009 treads in like a lamb, with the software maker issuing only one security bulletin in its MS09-001 January patch rollout. Yet, even as MS09-001 is rated as "critical" for popular versions of its ...