<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NVDi Support News &#38; Alerts &#187; Patch Tuesday</title>
	<atom:link href="http://news.nvdi.net/tag/patch-tuesday/feed/" rel="self" type="application/rss+xml" />
	<link>http://news.nvdi.net</link>
	<description>&#160;&#160;Support information and alerts for NVDi customers and friends</description>
	<lastBuildDate>Sun, 04 Apr 2010 20:54:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>July 14th is &#8220;Patch Tuesday&#8221;</title>
		<link>http://news.nvdi.net/2009/07/july-14th-is-patch-tuesday/</link>
		<comments>http://news.nvdi.net/2009/07/july-14th-is-patch-tuesday/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 02:15:24 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[QuickTime]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=132</guid>
		<description><![CDATA[July 14th is &#8220;Patch Tuesday,&#8221; the day each month when Microsoft issues patches for Windows and other Microsoft products. (It also happens to fall on Bastille Day this year.) Two of the three critical patches released this month are very high priority because they are already being exploited in the wild. Both deal with ActiveX-related [...]]]></description>
			<content:encoded><![CDATA[<p>July 14th is &#8220;Patch Tuesday,&#8221; the day each month when Microsoft issues patches for Windows and other Microsoft products. (It also happens to fall on Bastille Day this year.)</p>
<p>Two of the three critical patches released this month are very high priority because they are already being exploited in the wild. Both deal with ActiveX-related video handling in Internet Explorer. One of them permits &#8220;drive-by&#8221; infection of a visitor viewing an infected web page. The other works by tricking people into viewing a malformed QuickTime video. These vulnerabilities affect users running Internet Explorer under Windows XP, but not Vista and Windows 7. Microsoft is less forthcoming about the third critical patch but, word is, it impacts all Windows versions.</p>
<p>Bottom line: When Windows Update offers you these critical updates, you should install them. <em>Immediately</em>.</p>
<p><em>Updates and clarifications . . .</em></p>
<p>If you are riding herd on any Windows-based servers, Internet Explorer running under Windows Server 2003 is vulnerable to the ActiveX exploits mentioned above; the Server 2008 environment is safe.</p>
<p>And, just to make myself perfectly clear, you have to be running Internet Explorer directly to be affected by these issues. Although other applications &#8212; the Outlook email client, for instance &#8212; use Internet Explorer components to view web content, they do so in a more restricted environment that blocks ActiveX exploits.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/07/july-14th-is-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alert: May 12th is &#8220;Patch Tuesday&#8221;</title>
		<link>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/</link>
		<comments>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/#comments</comments>
		<pubDate>Fri, 08 May 2009 17:27:24 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[PowerPoint]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=128</guid>
		<description><![CDATA[May 12th is &#8220;Patch Tuesday,&#8221; the day Microsoft traditionally issues security updates. Adobe is also issuing a patch for Adobe Reader and Acrobat. The sole Microsoft patch fixes a &#8220;critical&#8221; flaw in PowerPoint. &#8220;Critical&#8221; means it&#8217;s a big deal. In this case, opening a maliciously crafted PowerPoint presentation could allow an attacker to execute code [...]]]></description>
			<content:encoded><![CDATA[<p>May 12th is &#8220;Patch Tuesday,&#8221; the day Microsoft traditionally issues security updates. Adobe is also issuing a patch for Adobe Reader and Acrobat.</p>
<p>The sole Microsoft patch fixes a &#8220;critical&#8221; flaw in PowerPoint. &#8220;Critical&#8221; means it&#8217;s a big deal. In this case, opening a maliciously crafted PowerPoint presentation could allow an attacker to execute code remotely on a victim&#8217;s computer. All versions of PowerPoint released in the past 10 years are vulnerable to this one.</p>
<p>Adobe is patching Reader/Acrobat to fix yet another problem associated with embedded JavaScript. This issue, as well as a work-around, was <a href="http://news.nvdi.net/2009/04/alert-more-adobe-reader-flaws-surface/">discussed in an earlier post here</a>.</p>
<p>You can safely assume that the bad guys, knowing that people are often sloppy about security updates, will try to take advantage of both vulnerabilities. The Adobe Reader bug will likely be the primary target. Almost everyone has Adobe Reader installed on their computer and most folks are used to encountering PDF files on web sites.</p>
<p>Be careful out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/05/alert-may-12th-is-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday looms</title>
		<link>http://news.nvdi.net/2009/04/patch-tuesday-looms/</link>
		<comments>http://news.nvdi.net/2009/04/patch-tuesday-looms/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 23:35:52 +0000</pubDate>
		<dc:creator>wkwalker</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[critical patches]]></category>
		<category><![CDATA[critical updates]]></category>
		<category><![CDATA[Patch Tuesday]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://news.nvdi.net/?p=90</guid>
		<description><![CDATA[April 14th is &#8220;Patch Tuesday.&#8221; Barring a major panic, Microsoft issues security updates for its products on the second Tuesday of the month. This month, we&#8217;re looking at eight patches, five of them rated &#8220;critical.&#8221; Microsoft&#8217;s offical security bulletin has all the details they&#8217;re willing to share so far. It&#8217;s generally a good idea not [...]]]></description>
			<content:encoded><![CDATA[<p>April 14th is &#8220;Patch Tuesday.&#8221; Barring a major panic, Microsoft issues security updates for its products on the second Tuesday of the month. This month, we&#8217;re looking at eight patches, five of them rated &#8220;critical.&#8221; <a href="http://www.microsoft.com/technet/security/bulletin/ms09-apr.mspx">Microsoft&#8217;s offical security bulletin</a> has all the details they&#8217;re willing to share so far.</p>
<p>It&#8217;s generally a good idea not to let security updates slide for very long. Once the word is out, the bad guys try to reverse-engineer the patches. If they find anything particularly juicy, they take advantage of the fact that many people are remiss about applying the patches. For instance, the primary mode of infection used by the currently infamous Conficker worm is a vulnerability that was fixed several months ago.</p>
<p>A little side-note: April 14, 2009 is also <a href="http://whertra.nvdi.net/2009/04/windows-xp-goes-on-life-support/">the day Windows XP goes on &#8220;extended support.&#8221;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://news.nvdi.net/2009/04/patch-tuesday-looms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

