<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Arizona IT Management &#187; Microsoft</title>
	<atom:link href="http://www.azitmgmt.com/tag/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.azitmgmt.com</link>
	<description>Delivering Affordable Professional Solutions</description>
	<lastBuildDate>Sun, 15 Aug 2010 19:53:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>An Infographic on Microsoft</title>
		<link>http://www.azitmgmt.com/2010/08/an-infographic-on-microsoft/</link>
		<comments>http://www.azitmgmt.com/2010/08/an-infographic-on-microsoft/#comments</comments>
		<pubDate>Sun, 15 Aug 2010 19:51:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=374</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p><img src="http://onlinemba.com.s3.amazonaws.com/microsoft.jpg" alt="" width="550"/></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/08/an-infographic-on-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday</title>
		<link>http://www.azitmgmt.com/2010/06/microsoft-patch-tuesday/</link>
		<comments>http://www.azitmgmt.com/2010/06/microsoft-patch-tuesday/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 15:37:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=366</guid>
		<description><![CDATA[Please click here and read about what patches will be released.]]></description>
			<content:encoded><![CDATA[<p>Please click <a href="http://www.informationarmor.com/2010/06/07/patch-tuesday-for-microsoft/">here </a>and read about what patches will be released.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/06/microsoft-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacks, Exploits and Patches</title>
		<link>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/</link>
		<comments>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/#comments</comments>
		<pubDate>Wed, 12 May 2010 15:47:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=351</guid>
		<description><![CDATA[Widespread Web Site Attacks Reported Following the reports of high profile web sites like syfy.com and php-nuke.org being compromised, another widespread attack on web servers has been reported. The attacks compromise sites running WordPress and other popular blog software. The attack mechanism is not yet known, but clients should ensure that the latest WordPress version [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Widespread Web Site Attacks Reported</strong><br />
Following the reports of high profile web sites like syfy.com and php-nuke.org being compromised, another widespread attack on web servers has been reported. The attacks compromise sites running WordPress and other popular blog software. The attack mechanism is not yet known, but clients should ensure that the latest WordPress version is installed. Sites using shared hosting are especially susceptible as compromise of a neighboring site often spreads to the remaining virtual hosts. We also encourage clients to review their sites for signs of infection and take appropriate remediation steps. In particular, clients should look for modifications made to html source pages as well as database table changes.<br />
<a href="http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html" target="_blank"> http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html</a><br />
<a href="http://www.psychcomp.com/syfycom-hosts-malware/" target="_blank"> http://www.psychcomp.com/syfycom-hosts-malware/</a><br />
<a href="http://twitter.com/lordparody/status/13600067003" target="_blank"> http://twitter.com/lordparody/status/13600067003</a><br />
<a href="http://www.sophos.com/blogs/sophoslabs/?p=9585" target="_blank"> http://www.sophos.com/blogs/sophoslabs/?p=9585</a></p>
<p><strong>Microsoft Outlook Express Exploit</strong><br />
Exploit code has been made publicly available that triggers a vulnerability in Microsoft Outlook Express and Windows Mail. The integer overflow vulnerability could allow a remote attacker to execute arbitrary code, although the attacker would need to control the mail server being used by the victim. At this time, there is no known vendor patch available.<br />
<a href="http://www.exploit-db.com/exploits/12564" target="_blank"> http://www.exploit-db.com/exploits/12564</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816" target="_blank"> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816</a></p>
<p><strong>Microsoft&#8217;s May Security Patches</strong><br />
As a reminder, Microsoft will be issuing their May security release later today. The two scheduled bulletins will address remote code execution vulnerabilities in Windows and Office. We will update the assessment when more details are available.<br />
<a href="http://www.microsoft.com/technet/security/Bulletin/MS10-may.mspx" target="_blank"> http://www.microsoft.com/technet/security/Bulletin/MS10-may.mspx</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/05/attacks-exploits-and-patches/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>April Patches and Updates</title>
		<link>http://www.azitmgmt.com/2010/04/april-patches-and-updates/</link>
		<comments>http://www.azitmgmt.com/2010/04/april-patches-and-updates/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 16:09:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=337</guid>
		<description><![CDATA[1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP Service (MS10-024 CVE-2010-0024) Microsoft Windows SMTP Service and Microsoft Exchange are vulnerable to a denial of service, caused by the improper handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer Protocol component. As SMTP services are often exposed to the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>1. Denial of Service Conditions in Microsoft Exchange and Microsoft SMTP  Service (MS10-024 CVE-2010-0024)</strong><br />
Microsoft Windows SMTP Service and  Microsoft Exchange are vulnerable to a denial of service, caused by the improper  handling of DNS Mail Exchanger (MX) resource records by the Simple Mail Transfer  Protocol component. As SMTP services are often exposed to the Internet and email  is usually considered a business critical function, the business impact of this  vulnerability is more significant than for typical Denial of Service issues.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-024.mspx</a></p>
<p><strong>2. Microsoft DirectShow Remote Code Execution (MS10-026  CVE-2010-0480)</strong><br />
Microsoft Windows is vulnerable to a stack-based  buffer overflow, caused by improper bounds checking by the MPEG Layer-3 audio  codecs when handling malicious files. The vulnerable MPEG Layer-3 audio codecs  are the MPEG Layer-3 Audio Codec for Microsoft DirectShow. Successful  exploitation of this issue would provide an attacker with complete control over  the endpoint target. The use of malicious media files like images and movies has  been prevalent in the past years.</p>
<p><a title="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx">http://www.microsoft.com/technet/security/bulletin/MS10-026.mspx</a></p>
<p><strong>Adobe Reader and Acrobat Security Update</strong><br />
Adobe has  addressed multiple critical vulnerabilities affecting Adobe Reader 9.3.1 (and  earlier versions) for Windows, Macintosh, and UNIX, Adobe Acrobat 9.3.1 (and  earlier versions) for Windows and Macintosh, and Adobe Reader 8.2.1 (and earlier  versions) and Adobe Acrobat 8.2.1 (and earlier versions) for Windows and  Macintosh. The most severe of these issues could allow a remote attacker to  execute arbitrary code on a vulnerable system. Refer to the &#8220;Solution&#8221; section  of the Adobe Security Bulletin for information on remediating these issues.<br />
<a title="http://www.adobe.com/support/security/bulletins/apsb10-09.html" href="http://www.adobe.com/support/security/bulletins/apsb10-09.html"> http://www.adobe.com/support/security/bulletins/apsb10-09.html</a><br />
<strong><br />
Microsoft April 2010 Security Release</strong><br />
Microsoft released  eleven security bulletins today. There are five rated Critical, five rated  Important and one rated Moderate. We encourage our customers to apply the  patches and IBM product coverage where applicable. Please, review the break-down  below.<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-apr.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Critical</strong><br />
<strong>Microsoft Security Bulletin MS10-019: Vulnerabilities in Windows  Could Allow Remote Code Execution (981210)</strong><br />
Vulnerabilities in  Windows Authenticode Verification could allow a remote attacker execute  arbitrary code on a vulnerable system.<br />
CVE-2010-0486<br />
CVE-2010-0487<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-019.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-020: Vulnerabilities in SMB Client  Could Allow Remote Code Execution (980232)</strong><br />
Multiple vulnerabilities  affecting Microsoft Windows could allow remote code execution. Successful  exploitation can occur if an attacker can convince a user to initiate an SMB  connection to a specially crafted SMB server.<br />
CVE-2009-3676<br />
CVE-2010-0269<br />
CVE-2010-0270<br />
CVE-2010-0476<br />
CVE-2010-0477<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-020.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-025: Vulnerability in Microsoft  Windows Media Services Could Allow Remote Code Execution (980858)</strong><br />
A  remote code execution vulnerability affects Windows Media Services running on  Microsoft Windows 2000 Server. The Windows Media Unicast Service fails to  properly handle specially crafted transport information packets. On Microsoft  Windows 2000 Server Service Pack 4, Windows Media Services is an optional  component and is not installed by default.<br />
CVE-2010-0478<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-025.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-026: Vulnerability in Microsoft MPEG  Layer-3 Codecs Could Allow Remote Code Execution (977816)</strong><br />
<strong>2. Microsoft DirectShow Remote Code  Execution (MS10-026 CVE-2010-0480)</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-026.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-027: Vulnerability in Windows Media  Player Could Allow Remote Code Execution (979402)</strong><br />
The Windows Media  Player ActiveX control is affected by a remote code execution vulnerability.<br />
CVE-2010-0268<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-027.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Important</strong><br />
<strong>Microsoft Security Bulletin MS10-021: Vulnerabilities in Windows  Kernel Could Allow Elevation of Privilege (979683)</strong><br />
This bulletin  addresses two vulnerabilities in Microsoft Windows, the most severe of which  could allow elevation of privilege. In order to exploit these vulnerabilities,  an attacker must have valid logon credentials and be able to log on locally.<br />
CVE-2010-0236<br />
CVE-2010-0237<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-021.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-022: Vulnerability in VBScript  Scripting Engine Could Allow Remote Code Execution (981169)</strong><br />
A  vulnerability affecting VBScript on Microsoft Windows could allow remote code  execution. This vulnerability requires user interaction and cannot be exploited  on Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2.<br />
CVE-2010-0483<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-023: Vulnerability in Microsoft  Office Publisher Could Allow Remote Code Execution (981160)</strong><br />
Microsoft Office Publisher is vulnerable to a remote code execution issue.  An attacker could exploit this issue by creating a specially crafted Publisher  file and sending it in an email or hosting it on a Web site.<br />
CVE-2010-0479;  IBM Product Coverage: CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-023.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-024: Vulnerabilities in Microsoft  Exchange and Windows SMTP Service Could Allow Denial of Service  (981832)</strong><br />
<strong>1. Denial  of Service Conditions in Microsoft Exchange and Microsoft SMTP Service</strong><br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-024.mspx</a></p>
<p><strong>Microsoft Security Bulletin MS10-028: Vulnerabilities in Microsoft  Visio Could Allow Remote Code Execution (980094)</strong><br />
Vulnerabilities in  Microsoft Office Visio could allow remote code execution if a user opens a  specially crafted Visio file.<br />
CVE-2010-0254; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
CVE-2010-0256; IBM Product Coverage:  CompoundFile_Shellcode_Detected<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx</a></p>
<p><strong>Microsoft Maximum Severity Rating: Moderate</strong><br />
<strong>Microsoft Security Bulletin MS10-029: Vulnerability in Windows  ISATAP Component Could Allow Spoofing (978338) </strong><br />
A spoofing  vulnerability exists in the Microsoft Windows IPv6 stack which could allow an  attacker to impersonate an address to bypass edge or host firewalls.  CVE-2010-0812<br />
<a title="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx" href="http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx"> http://www.microsoft.com/technet/security/bulletin/ms10-029.mspx</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/04/april-patches-and-updates/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MS10-002</title>
		<link>http://www.azitmgmt.com/2010/01/ms10-002/</link>
		<comments>http://www.azitmgmt.com/2010/01/ms10-002/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 15:40:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patches]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=137</guid>
		<description><![CDATA[Microsoft has released MS10-002 today. The update addresses 7 privately reported and 1 publicly reported vulnerability which is associated with the widely publicized attacks associated with Security Advisory 979352. There are four (4) Uninitialized Memory Corruption Vulnerabilities, two (2) HTML Object Memory Corruption Vulnerabilities, one (1) XSS Filter Script Handling Vulnerability, and one (1) URL [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released MS10-002 today. The update addresses 7 privately reported and 1 publicly reported vulnerability which is associated with the widely publicized attacks associated with Security Advisory 979352. There are four (4) Uninitialized Memory Corruption Vulnerabilities, two (2) HTML Object Memory Corruption Vulnerabilities, one (1) XSS Filter Script Handling Vulnerability, and one (1) URL Validation Vulnerability. This single patch is considered Critical by Microsoft and covers the following CVE entries:</p>
<p>CVE-2009-4074</p>
<p>CVE-2010-0027</p>
<p>CVE-2010-0244</p>
<p>CVE-2010-0245</p>
<p>CVE-2010-0246</p>
<p>CVE-2010-0247</p>
<p>CVE-2010-0248</p>
<p>CVE-2010-0249</p>
<p>Customers should apply this update as soon as possible. The update will also be sent through the Automatic update mechanism.<br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a></p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/01/ms10-002/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Report</title>
		<link>http://www.azitmgmt.com/2010/01/security-report/</link>
		<comments>http://www.azitmgmt.com/2010/01/security-report/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 19:10:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Solutions]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[ISC]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=135</guid>
		<description><![CDATA[Microsoft Announces out of cycle Security Update schedule Microsoft issued their Advanced Notification Service (ANS) notification to inform customers of the impending release of MS10-002 on January 21st, 2010. The update will be cumulative, in advance of the normal February release Cycle, and is intended to protect customers from the known, widely publicized attacks associated [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Microsoft Announces out of cycle Security Update schedule<br />
</strong>Microsoft issued their Advanced Notification Service (ANS) notification to inform customers of the impending release of MS10-002 on January 21st, 2010. The update will be cumulative, in advance of the normal February release Cycle, and is intended to protect customers from the known, widely publicized attacks associated with Security Advisory 979352. Customers should apply this update as soon as possible. The update will also be sent through the Automatic update mechanism.<br />
<a href="http://blogs.technet.com/msrc/archive/2010/01/20/advance-notification-for-out-of-band-bulletin-release.aspx">http://blogs.technet.com/msrc/archive/2010/01/20/advance-notification-for-out-of-band-bulletin-release.aspx</a><br />
<a href="http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx">http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx</a></p>
<p>Additional Technical Detail</p>
<p><strong>Data Execution Prevention (DEP) Bypass</strong><br />
There is a report of a new exploit that bypasses Data Execution Prevention (DEP). We have analyzed the Proof-of-Concept (POC) exploit code and have found that Windows Vista and later versions of Windows offer more effective protections in blocking the exploit due to the improved security protection offered by Address Space Layout Randomization (ASLR). Windows XP does not currently benefit from ASLR and will be more susceptible.</p>
<p>Additional details on the DEP bypass exploit are provided in a Security Research and Defense Blog published today.<br />
<a href="http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx">http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx</a></p>
<p><strong>Microsoft E-Mail Products That Render using mshtml.dll Protected by Default<br />
</strong>There have been reports that supported versions of Outlook, Outlook Express and Windows Live Mail are affected by the vulnerability in Security Advisory 979352.</p>
<p>For customers using the default configuration of all supported versions of Outlook, Outlook Express and Windows Live Mail the risk of exploit using Outlook as an attack vector is low. We are unaware of active exploit against supported versions of Outlook, Outlook Express or Windows Live. If customers have modified their default configuration to not run in Restricted sites zone, their environments will be in a less secure, more vulnerable, state.</p>
<p>Please review the announcement described above for more detail.</p>
<p><strong>Office Applications with Active Scripting Enabled Potentially Vulnerable</strong><br />
Microsoft indicates that an ActiveX control in a Microsoft Access, Word, Excel, or PowerPoint file is a potentially exploitable vulnerability. Customers would have to open a malicious file to be at risk of exploitation, and Microsoft recommends disabling ActiveX Controls in Microsoft Office.</p>
<p><strong>Live Briefing<br />
</strong>On Thursday, January 21 at 1:00 p.m. PST (UTC – 8) Microsoft will host a public webcast where information on the bulletin will be presented.<br />
Registration: <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032440627">http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032440627</a></p>
<p>Original . . .</p>
<p>Yesterday we updated the assessment to reflect an impending out of cycle security update from Microsoft which will address the 0-day Microsoft Internet Explorer vulnerability highlighted in recent assessments. The update is announced in an MSRC blog posting, and timing for the release is expected to be explained today. The threat level remains at AlertCon 2 while we continue to encurage review of Microsoft Security Advisory for workaround information and X-Force Protection Alert for associated IBM product coverage.<br />
<a href="http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx">http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx</a><br />
<a href="https://portal.mss.iss.net/mss/xftas/alertAdvisory/details.mss?alertAdvisoryId=3382">https://portal.mss.iss.net/mss/xftas/alertAdvisory/details.mss?alertAdvisoryId=3382</a><br />
<a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></p>
<p>Shortly after the blog posting from MSRC appeared, a new posting on Neohapsis [Full Disclosure] began to be discussed. The posting explains how a restricted Windows user can exploit the Virtual DOS Machine (VDM) to gain command access in the system context (Ring 0). Microsoft was notified of the flaw in June 2009, but there currently is no patch. Exploit code that functions under Windows XP, 2003 Server, 2008 Server, Vista, and Windows 7 has been made available, and has been confirmed to function as described.</p>
<p>Mitigation steps requiring the Group Policy Editor for Windows 2003 Server systems are included in the Neohapsis article. For those systems that do not include the GPE the heise security team has provided instructions for a registry hack that should work until a patch is available.<br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html">http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html</a><br />
<a href="http://www.h-online.com/security/news/item/Windows-hole-discovered-after-17-years-Update-908917.html">http://www.h-online.com/security/news/item/Windows-hole-discovered-after-17-years-Update-908917.html</a></p>
<p>Apple Computer released their Security Update 2010-001 yesterday. The update addresses several multi-media applications, as well as printer handling, and a patch to suppress renegotiation in OpenSSL while the IETF works out final changes to the renegotiation protocol. The multi-media flaws relate to MP4, TIFF, and RAW(DNG) files, as well as multiple patches to the Adobe Flash player plug-in.<br />
<a href="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</a></p>
<p>Adobe has released an update for critical vulnerabilities in Adobe Shockwave Player 11.5.2.602 and earlier versions, on the Windows and Macintosh operating systems. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations to the latest version.<br />
<a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html">http://www.adobe.com/support/security/bulletins/apsb10-03.html</a></p>
<p>Additionally, the Internet Systems Consortium (ISC) announced the release of the BIND 9.6.1-P3 security patch to address two cache poisoning vulnerabilities, both of which could allow a validating recursive nameserver to cache data which had not been authenticated or was invalid. This patch targets nameservers that have DNSSEC validation enabled, which could potentially provide responses from unauthenticated records within the cache.<br />
<a href="http://isc.sans.org/diary.html?storyid=8029">http://isc.sans.org/diary.html?storyid=8029</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2010/01/security-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS and Symantec Alert Management System</title>
		<link>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/</link>
		<comments>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 17:20:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[iis]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=61</guid>
		<description><![CDATA[A vulnerability was recently reported in Microsoft IIS. Microsoft has since completed its investigation and &#8220;found that there is no vulnerability in IIS.&#8221; However, &#8220;there is an inconsistency in IIS 6 only in how it handles semicolons in URLs. It’s this inconsistency that the claims have focused on, saying this enables an attacker to bypass [...]]]></description>
			<content:encoded><![CDATA[<p>A vulnerability was recently reported in Microsoft IIS. Microsoft has since completed its investigation and &#8220;found that there is no vulnerability in IIS.&#8221; However, &#8220;there is an inconsistency in IIS 6 only in how it handles semicolons in URLs. It’s this inconsistency that the claims have focused on, saying this enables an attacker to bypass content filtering software to upload and execute code on an IIS server.&#8221; The issue only impacts IIS servers that are set up to allow both &#8220;write&#8221; and &#8220;execute&#8221; privileges on the same directory, which is not the default configuration for IIS. This issue can be mitigated through proper Web server configuration and Web application development best practices, including proper validation of user submitted file names, and by configuring Web server software so that it will not execute scripts or applications in directories where user uploaded files are stored. We would also like to note that an exploit targeting Microsoft IIS has been made publicly available. We encourage our customers to refer to the Microsoft Security Response Center (MSRC) blog post for additional information.<br />
<a href="http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx" target="_blank">http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx</a><br />
<a href="http://www.exploit-db.com/" target="_blank">http://www.exploit-db.com/</a></p>
<p>We would also like to inform our customers that a report has surfaced indicating there has been &#8220;an increase in probes to port 12174.&#8221; Our analysts have also observed an increase in activity on this port. Reportedly, these probes are targeting a vulnerability in the Intel LANDesk Common Base Agent (CBA) which is used by the Symantec Alert Management System. An attacker could exploit this issue by sending a specially-crafted packet to TCP Port 12174 and execute arbitrary code on the vulnerable system. The Alert Management System 2 (AMS2) is a component of the Symantec System Center console, Symantec AntiVirus Server, and of the Symantec AntiVirus Central Quarantine Server. To mitigate against this threat, ensure the Symantec Alert Management Systems running in your environment are up-to-date.<br />
<a href="http://isc.sans.org/diary.html?storyid=7834" target="_blank">http://isc.sans.org/diary.html?storyid=7834</a><br />
<a href="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02" target="_blank">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/microsoft-iis-and-symantec-alert-management-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Essentials</title>
		<link>http://www.azitmgmt.com/2009/12/microsoft-security-essentials/</link>
		<comments>http://www.azitmgmt.com/2009/12/microsoft-security-essentials/#comments</comments>
		<pubDate>Sat, 26 Dec 2009 17:12:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[essentials]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Solutions]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=54</guid>
		<description><![CDATA[Anti-malware testing group AV-Comparatives.org not only gave Microsoft Security Essentials a top rating for malware removal, but now they&#8217;ve given it their best ranking in their performance test as well. AV-Comparatives.org ran a series of real-world tests running through common scenarios like downloading, extracting, copying, and encoding files, installing and launching applications, and they also ran [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://cache.gawker.com/assets/images/lifehacker/2009/12/sshot-2009-12-23-15-00-33.jpg" alt="" width="340" /></p>
<p>Anti-malware testing group AV-Comparatives.org not only gave <a href="http://www.microsoft.com/Security_Essentials/" target="_blank">Microsoft Security Essentials</a> a top rating for malware removal, but now they&#8217;ve given it their best ranking in their performance test as well.</p>
<p>AV-Comparatives.org ran a series of real-world tests running through common scenarios like downloading, extracting, copying, and encoding files, installing and launching applications, and they also ran through an automated testing suite as well. Once the dust had settled, it became clear that not only is MSE <a href="http://arstechnica.com/security/news/2009/10/av-comparatives-picks-six-malware-removal-winners.ars" target="_blank">one of only three products that both blocks and removes malware well</a>, but it&#8217;s also very light on system resources.</p>
<p>Out of all the products tested, Microsoft Security Essentials was the best-performing free antivirus solution, and one of only two that received &#8220;very fast&#8221; on each of the real-world tests, earning it their top award: an &#8220;advanced+&#8221; ranking.  <a href="http://lifehacker.com/5401453/stop-paying-for-windows-security-microsofts-security-tools-are-good-enough" target="_blank">you don&#8217;t need to pay for Windows security</a>, and now with MSE ranked alongside the top paid apps in both malware removal and performance, you might want to consider making the switch.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/microsoft-security-essentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AZ IT Management and the Construction Industry</title>
		<link>http://www.azitmgmt.com/2009/12/az-it-management-and-the-construction-industry/</link>
		<comments>http://www.azitmgmt.com/2009/12/az-it-management-and-the-construction-industry/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 20:30:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Solutions]]></category>
		<category><![CDATA[construction]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Apps]]></category>
		<category><![CDATA[industry]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[netbooks]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=45</guid>
		<description><![CDATA[Arizona IT Management understands the construction industry and the impact the economy has taken on them. Many competitors have been estimating very low, near impossible estimates. Forcing many to rely on savings and having to cut the overhead costs of a fully staffed office. Arizona IT Management can help. We know the costs of running and [...]]]></description>
			<content:encoded><![CDATA[<p>Arizona IT Management understands the construction industry and the impact the economy has taken on them. Many competitors have been estimating very low, near impossible estimates. Forcing many to rely on savings and having to cut the overhead costs of a fully staffed office.</p>
<p>Arizona IT Management can help. We know the costs of running and supporting an office, with finance, accounting, superintendents, foremen, project managers, project coordinators, estimators, virtual construction, fab, warehouse, hr, payroll, and the most about information technology!</p>
<p>With new advances in technology along with proven old school methods with a new twist, we can assist in cutting down the costs and keeping you worrying on the business and not the technology that supports it. New advances in products and technology can completely wow your customers with items such as netbooks running Windows 7, Google OS, or Ubuntu Linux, and using Google Apps. Google Apps helps the workforce become mobile without all the hardware costs and Microsoft licensing.</p>
<p>Contracting with Arizona IT Management brings you and your company peace of mind with full solutions development, contract support, top level security and information technology management.</p>
<p>Whether you are starting your construction business, having to realign your business focus, or just need some help, <a href="http://www.azitmgmt.com/contact/" target="_self">contact Arizona IT Management</a>.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/az-it-management-and-the-construction-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Threats</title>
		<link>http://www.azitmgmt.com/2009/12/adobe-threats/</link>
		<comments>http://www.azitmgmt.com/2009/12/adobe-threats/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 15:31:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.azitmgmt.com/?p=39</guid>
		<description><![CDATA[Adobe is indicating they have received reports of active exploitation of a 0day vulnerability affecting Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). We encourage our clients to use caution when opening PDF files. Links to malicious documents can easily be sent through spam or through links on seemingly non-malicious Web sites. We also [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe is indicating they have received reports of active exploitation of a 0day vulnerability affecting Adobe Reader and Acrobat 9.2 and earlier versions (CVE-2009-4324). <strong>We encourage our clients to use caution when opening PDF files</strong>. Links to malicious documents can easily be sent through spam or through links on seemingly non-malicious Web sites. We also recommend referring to the Adobe PSIRT blog for the latest information on this threat.<br />
<span title="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html"><a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_blank">http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html</a></span><br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214 " target="_blank"><span title="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214</span> </a></p>
<p>Some of the common predictions are: increased attacks targeting <strong>Microsoft 7 platforms and smartphones</strong>, more tailored and targeted attacks and continued targeting of <strong>social networking sites to distribute malware and obtain information</strong>. We have seen attackers become increasingly sophisticated over the years and their attacks harder to detect. And if you&#8217;re not technically savy? Script kiddies have professionally produced products readily available to them on the Internet. In other words, be prepared for another cyber threat filled environment in 2010.<br />
<a href="http://securitylabs.websense.com/content/Blogs/3509.aspx " target="_blank"><span title="http://www.f-secure.com/weblog/archives/00001835.html">http://www.f-secure.com/weblog/archives/00001835.html</span><br />
<span title="http://securitylabs.websense.com/content/Blogs/3509.aspx">http://securitylabs.websense.com/content/Blogs/3509.aspx</span> </a><br />
<a href="http://blog.trendmicro.com/trend-micro-2010-future-threat-report/ " target="_blank"><span title="http://blog.trendmicro.com/trend-micro-2010-future-threat-report/">http://blog.trendmicro.com/trend-micro-2010-future-threat-report/</span> </a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.azitmgmt.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.azitmgmt.com/2009/12/adobe-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
