<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Security Updates</title>
	<atom:link href="http://www.winadmin.ro/tag/security-updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Wed, 28 Jul 2010 15:34:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Black Tuesday &#8211; Feb 2010</title>
		<link>http://www.winadmin.ro/2010/02/06/black-tuesday-feb-2010/</link>
		<comments>http://www.winadmin.ro/2010/02/06/black-tuesday-feb-2010/#comments</comments>
		<pubDate>Sat, 06 Feb 2010 19:33:53 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Diverse]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/02/06/black-tuesday-feb-2010/</guid>
		<description><![CDATA[&#160; Se apropie. Sunt anuntate 13 buletine – 26 de vulnerabilitati, multe cu remote code execution. Pazea! http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Se apropie. Sunt anuntate 13 buletine – 26 de vulnerabilitati, multe cu remote code execution. Pazea!</p>
<p><a title="http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx" href="http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx">http://blogs.technet.com/msrc/archive/2010/02/04/february-2010-bulletin-release-advance-notification.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/02/06/black-tuesday-feb-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>December Security Updates &#8211; Microsoft and Adobe</title>
		<link>http://www.winadmin.ro/2009/12/09/december-security-updates-microsoft-and-adobe/</link>
		<comments>http://www.winadmin.ro/2009/12/09/december-security-updates-microsoft-and-adobe/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 12:41:53 +0000</pubDate>
		<dc:creator>Bogdan Morosan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=294</guid>
		<description><![CDATA[&#160; Si a venit “Patch Tuesday” pentru luna Decembrie: Microsoft a publicat un numar de 6 buletine de securitate in care sunt detaliate metodele de rezolvare pentru 12 vulnerabilitati. Una dintre vulnerabilitati a fost deja exploatata pentru a compromite sistemele, folosind un atac de tip “zero-day” indreptat impotriva Internet Explorer-ului. &#160; Bulletin No. Description Impact [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Si a venit “Patch Tuesday” pentru luna Decembrie: Microsoft a publicat un numar de 6 buletine de securitate in care sunt detaliate metodele de rezolvare pentru 12 vulnerabilitati. Una dintre vulnerabilitati a fost deja exploatata pentru a compromite sistemele, folosind un atac de tip “<a href="http://en.wikipedia.org/wiki/Zero_day_attack">zero-day</a>” indreptat impotriva Internet Explorer-ului.</p>
<p>&#160;</p>
<table cellspacing="0" cellpadding="2" width="683" border="0">
<tbody>
<tr>
<td valign="top" width="91"><strong>Bulletin No.</strong></td>
<td valign="top" width="206"><strong>Description</strong></td>
<td valign="top" width="109"><strong>Impact</strong></td>
<td valign="top" width="132"><strong>Client Severity Rating</strong></td>
<td valign="top" width="143"><strong>Server Severity Rating</strong></td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkID=177727">MS09-071</a></td>
<td valign="top" width="206">Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)</td>
<td valign="top" width="109">Remote Code Execution</td>
<td valign="top" width="132">Moderate          <br />Important</td>
<td valign="top" width="143">Important          <br />Critical</td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkId=141642">MS09-074</a></td>
<td valign="top" width="206">Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)</td>
<td valign="top" width="109">Remote Code Execution</td>
<td valign="top" width="132">Important          <br />Critical</td>
<td valign="top" width="143">N/A</td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkId=169404">MS09-072</a></td>
<td valign="top" width="206">Cumulative Security Update for Internet Explorer (976325)</td>
<td valign="top" width="109">Remote Code Execution</td>
<td valign="top" width="132">Critical</td>
<td valign="top" width="143">Moderate</td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkId=177555">MS09-069</a></td>
<td valign="top" width="206">Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)</td>
<td valign="top" width="109">Denial of Service</td>
<td valign="top" width="132">Important</td>
<td valign="top" width="143">Important          <br />N/A</td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkID=163844">MS09-070</a></td>
<td valign="top" width="206">Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)</td>
<td valign="top" width="109">Remote Code Execution</td>
<td valign="top" width="132">N/A</td>
<td valign="top" width="143">Important</td>
</tr>
<tr>
<td valign="top" width="91"><a href="http://go.microsoft.com/fwlink/?LinkID=163833">MS09-073</a></td>
<td valign="top" width="206">Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)</td>
<td valign="top" width="109">Remote Code Execution</td>
<td valign="top" width="132">Important</td>
<td valign="top" width="143">Important          <br />(cu mentiunea ca pe servere in general nu se folosesc extensiv aceste aplicatii)</td>
</tr>
</tbody>
</table>
<p>&#160;</p>
<p>In ordinea criticalitatii:</p>
<p><b></b></p>
<p><b><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-072.mspx" target="_blank">MS09-072</a></b> </p>
<p>Acest update de securitate rezolva cinci vulnerabilitati din Internet Explorer; aceste vulnerabilitati pot fi exploatate de la distanta daca utilizatorul acceseaza folosind Internet Explorer o pagina web special conceputa. Un atacator poate exploata aceste vulnerabilitati si poate obtine aceleasi drepturi pe sistem cu cele ale utilizatorului local; este evident ca daca utilizatorul local nu are drepturi de administrator impactul poate fi mult mai redus.</p>
<p>Update-ul este considerat critic pentru toate versiunile de Internet Explorer: IE 5.01, 6, 6 SP1, IE 7 (cu exceptia situatiei in care ruleaza pe Windows Server 2003 si 2008) si IE 8 (de asemeni cu exceptia situatiei in care ruleaza pe Windows Server 2003, 2008 si 2008 R2). Pentru IE 7 si IE 8 care ruleaza pe Windows Server 2003, 2008, 2008 R2, update-ul este considerat important dar nu critic.</p>
<p>Sunt afectate toate versiunile de Windows pe care este instalat Internet Explorer, bineinteles cu exceptia Server Core.</p>
<p>&#160;</p>
<p><a href="http://go.microsoft.com/fwlink/?LinkID=177727">MS09-071</a><b></b></p>
<p>Doua vulnerabilitati in serviciul IAS (Internet Authentication Service – MS RADIUS) pot fi exploatate de la distanta. Vulnerabilitatile afecteaza serviciul IAS numai daca se folosesc protocoalele de autentificare <strong>PEAP</strong> si <strong>MS-CHAP v2</strong>.</p>
<p>Acest update este critic pentru Windows Server 2008 32 bit si x64 SP2, pentru Windows 2000 SP4, Windows Server 2003 toate versiunile si SP-urile este important, iar pentru Windows XP si Windows Vista este moderat, cu exceptia Vista SP2 in care caz este important.</p>
<p>Nu sunt afectate Windows 7 si Windows Server 2008 R2.</p>
<p>&#160;</p>
<p><a href="http://go.microsoft.com/fwlink/?LinkId=141642">MS09-074</a></p>
<p>Aceasta vulnerabilitate poate fi exploatata de la distanta daca un utilizator primeste si deschide un fisier tip Project (.mpp) special modificat. </p>
<p>Update-ul este considerat critic pentru Microsoft Project 2000 SR1, important pentru Microsoft Project 2002 SP1 si Microsoft Office Project 2003 SP3.</p>
<p>&#160;</p>
<p><a href="http://go.microsoft.com/fwlink/?LinkID=163844">MS09-070</a></p>
<p>Acest update rezolva doua vulnerabilitati ce pot fi explotatate de un atacator de la distanta prin intermediul unei cereri special construita catre in server web ce are activat serviciul ADFS. Atacatorul trebuie sa fie user autentificat pentru a exploata oricare dintre vulnerabilitati.</p>
<p>Update-ul este important pentru Windows Server 2003, Windows Server 2003 x64 Edition, Windows Server 2008 si Windows Server 2008 x64 Edition. </p>
<p>&#160;</p>
<p><a href="http://go.microsoft.com/fwlink/?LinkId=177555">MS09-069</a></p>
<p>Vulnerabiltatea rezolvata de acest update poate produce DOS (denial of service) daca un atacator autentificat trimite prin intermediul IPsec un pachet alterat de tip ISAKMP catre serviciul LSASS (Local Security Authority Subsystem Service) de pe sistemul afectat.</p>
<p>Update-ul este considerat important pentru Windows 2000, XP si Server 2003.</p>
<p>&#160;</p>
<p><a href="http://go.microsoft.com/fwlink/?LinkID=163833">MS09-073</a></p>
<p>Aceasta vulnerabilitate poate fi exploatata de la distanta daca un fisier special alterat, de tip Word 97, este deschis cu WordPad sau Microsoft Office Word. Atacatorul poate obtine aceleasi drepturi pe sistem cu cele ale utilizatorului local; este evident ca daca utilizatorul local nu are drepturi de administrator impactul poate fi mult mai redus.</p>
<p>Vulnerabilitatea este considerata importanta pentru WordPad pe Windows 2000, Windows XP si Windows Server 2003; de asemeni pentru Microsoft Office Word 2002 si Microsoft Office Word 2003, Microsoft Office Converter Pack si Microsoft Works 8.5.</p>
<p>&#160;</p>
<p>Adobe a publicat un <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_blank">buletin de securitate</a> referitor la un numar de vulnerabilitati considerate critice in Adobe Flash Player si Adobe Air. Se recomanda upgrade-ul la Adobe Flash Player 10.0.42.34 si Adobe Air 1.5.3. Toate vulnerabilitatile pot fi exploatate de la distanta si sunt considerate critice. Sunt afectate toate platformele &#8211; Windows, Linux si Mac.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/12/09/december-security-updates-microsoft-and-adobe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft November Security Updates &#8211; Review</title>
		<link>http://www.winadmin.ro/2009/11/15/microsoft-november-security-updates-review/</link>
		<comments>http://www.winadmin.ro/2009/11/15/microsoft-november-security-updates-review/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 17:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/11/15/microsoft-november-security-updates-review/</guid>
		<description><![CDATA[  Postul asta vine cam tarziu, insa mai bine mai tarziu decat niciodata. O sa incercam ca in viitor sa avem asa ceva pentru fiecare serie de update-uri de securitate scoase de Microsoft.   Bulletin No. Description Impact Client Severity Rating Server Severity Rating MS09-063 Vulnerability in Web Services on Devices API Could Allow Remote [...]]]></description>
			<content:encoded><![CDATA[<p> </p>
<p>Postul asta vine cam tarziu, insa mai bine mai tarziu decat niciodata. O sa incercam ca in viitor sa avem asa ceva pentru fiecare serie de update-uri de securitate scoase de Microsoft.</p>
<p> </p>
<table border="1" cellspacing="0" cellpadding="2" width="600">
<tbody>
<tr>
<td width="120" valign="top">Bulletin No.</td>
<td width="120" valign="top">Description</td>
<td width="120" valign="top">Impact</td>
<td width="120" valign="top">Client Severity Rating</td>
<td width="120" valign="top">Server Severity Rating</td>
</tr>
<tr>
<td width="120" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkID=163840">MS09-063</a></td>
<td width="120" valign="top"><strong>Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)</strong></td>
<td width="120" valign="top">Remote Code Execution</td>
<td width="120" valign="top">Critical</td>
<td width="120" valign="top">Critical</td>
</tr>
<tr>
<td width="120" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkID=163841">MS09-064</a></td>
<td width="120" valign="top"><strong>Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)</strong></td>
<td width="120" valign="top">Remote Code Execution</td>
<td width="120" valign="top">N/A</td>
<td width="120" valign="top">Critical</td>
</tr>
<tr>
<td width="120" valign="top">  <a href="http://www.microsoft.com/technet/security/Bulletin/MS09-065.mspx">MS09-065</a></td>
<td width="120" valign="top"><strong>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)</strong></td>
<td width="120" valign="top">Remote Code Execution</td>
<td width="120" valign="top">Critical</td>
<td width="120" valign="top">Critical<br />
(depinde,explicam mai jos)</td>
</tr>
<tr>
<td width="120" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkID=157862">MS09-066</a></td>
<td width="120" valign="top"><strong>Vulnerability in Active Directory Could Allow Denial of Service (973309)</strong></td>
<td width="120" valign="top">Denial of Service</td>
<td width="120" valign="top">N/A</td>
<td width="120" valign="top">Critical</td>
</tr>
<tr>
<td width="120" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=165431">MS09-067</a></td>
<td width="120" valign="top"><strong>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)</strong></td>
<td width="120" valign="top">Remote Code Execution</td>
<td width="120" valign="top">Critical</td>
<td width="120" valign="top">Depinde</td>
</tr>
<tr>
<td width="120" valign="top"><a href="http://go.microsoft.com/fwlink/?LinkId=165890">MS09-068</a></td>
<td width="120" valign="top"><strong>Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)</strong></td>
<td width="120" valign="top">Remote Code Execution</td>
<td width="120" valign="top">Critical</td>
<td width="120" valign="top">Depinde</td>
</tr>
</tbody>
</table>
<p> </p>
<p>Primul din lista este <a href="http://go.microsoft.com/fwlink/?LinkID=163840">MS09-063</a> care datorita unei vulnerabilitati in WSDAPI afecteaza Vista si 2008 Server (inclusiv Core). Se poate folosi Windows Firewall pentru a inchide porturile pe care asculta acest serviciu.</p>
<p>Urmatorul se refera numai la Windows 2000 server pentru ca afecteaza serviciul License Logging – credeam ca toata luma a oprit acest serviciu pana acum.</p>
<p>Si acum vine cireasa de pe tort, <a href="http://www.microsoft.com/technet/security/Bulletin/MS09-065.mspx">MS09-065</a>, in care sunt mai multe probleme dar cea mai mare e ca datorita unor elemente din kernel care proceseaza fonturile, un atacator ar putea face remote remote code execution pe masina “victimei”. Trebuie totusi sa redirectioneze victima catre o pagina web in care are continut special facut pentru acest scenariu (e doar un mod, exista si altele). Aici putem comenta putin severity rating-ul pentru servere: daca nu browsezi de pe server, sansele sa fii afectat sunt minime. Windows 7 si 2008 R2 nu sunt afectate. Atentie ca exista probleme cu acest update. Check here: <a title="http://support.microsoft.com/kb/969947" href="http://support.microsoft.com/kb/969947">http://support.microsoft.com/kb/969947</a></p>
<p>PS: 2008 Server core e afectat si el <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Urmatorul se refera strict la Active Directory, ADAM sau AD LDS, facand exceptie AD &amp; AD LDS de pe Windows 2008 R2. Sfatul meu e sa testati update-ul si sa-l instalati.</p>
<p>Ultimele doua se refera strict la Office si sunt importante pe partea de client. Macuserii sunt afectati si ei. Pe servere, daca nu rulezi produsele descrise in buletin, nu esti afectat.</p>
<p>Tacamul complet il gasiti aici: <a title="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx</a></p>
<p> </p>
<p>Si acum cate putin din teoria conspiratiei: mi se pare suspect ca imediat dupa lansarea Windows 7 apar update-uri care sa demonstreze ca 7 &amp; R2 sunt mult mai <em>secure. </em>Pai produsele astea erau in development de mult timp si au fost gata din vara. Daca producatorul a identificat problemele si le-a corectat in noile versiuni, de ce nu a scos patchurile in acel moment? La fel si cu BSOD-ul din SMBv2. E oare o strategie de marketing pentru a impinge clientii catre un anumit produs? Nu stiu, e doar un gand care mi-a venit acum in minte.</p>
<p>Insa un lucru e clar – <a title="http://isc.sans.org/diary.html?storyid=7573" href="http://isc.sans.org/diary.html?storyid=7573">http://isc.sans.org/diary.html?storyid=7573</a>. Povestea de aici e pe bune si afecteaza numai Windows 7 si 2008 R2.  Indiferent ca dezactivati SMBv2 sau nu.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/11/15/microsoft-november-security-updates-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
