• Home
  • Et Cetera

Infosecurity.US

Microsoft Releases Advanced Security Notification

By Marc Handelman on November 7th, 2008

Microsoft Corporation (NasdaqGS; MSFT) has released advanced notification of it’s famous Patch Tuesday effort (now slated for November 11, 2008 (Veterans Day in the United States, and Remembrance Day in Canada) – probably not the best choice of days to release major security patches….

The full text of the notification appears after the break.

Microsoft Security Bulletin Advance Notification for November 2008

**************************************
Microsoft Security Bulletin Advance Notification for November 2008
Issued: November 6, 2008
**************************************

This is an advance notification of security bulletins that
Microsoft is intending to release on November 11, 2008.

The full version of the Microsoft Security Bulletin Advance
Notification for November 2008 can be found at
http://www.microsoft.com/technet/security/bulletin/ms08-nov.mspx.

This bulletin advance notification will be replaced with the
November bulletin summary on November 11, 2008. For more information
about the bulletin advance notification service, see
http://www.microsoft.com/technet/security/Bulletin/advance.mspx.

To receive automatic notifications whenever Microsoft Security
Bulletins are issued, subscribe to Microsoft Technical Security
Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

Microsoft will host a webcast to address customer questions on
these bulletins on Wednesday, November 12, 2008,
at 11:00 AM Pacific Time (US & Canada). Register for the November
Security Bulletin Webcast at
http://www.microsoft.com/technet/security/bulletin/summary.mspx.

Microsoft also provides information to help customers prioritize
monthly security updates with any non-security, high-priority
updates that are being released on the same day as the monthly
security updates. Please see the section, Other Information.

This advance notification provides the software subject as the
bulletin identifier, because the official Microsoft Security
Bulletin numbers are not issued until release. The bulletin summary
that replaces this advance notification will have the proper
Microsoft Security Bulletin numbers (in the MSyy-xxx format) as the
bulletin identifier. The security bulletins for this month are as
follows, in order of severity:

Critical Security Bulletins
===========================

Windows Bulletin 1

- Affected Software:
- Microsoft XML Core Services 3.0 on
Microsoft Windows 2000 Service Pack 4
- Microsoft XML Core Services 4.0 when installed on
Microsoft Windows 2000 Service Pack 4
- Microsoft XML Core Services 6.0 when installed on
Microsoft Windows 2000 Service Pack 4
- Microsoft XML Core Services 3.0 on
Windows XP Service Pack 2 and
Windows XP Service Pack 3
- Microsoft XML Core Services 4.0 when installed on
Windows XP Service Pack 2 and
Windows XP Service Pack 3
- Microsoft XML Core Services 6.0 when installed on
Windows XP Service Pack 2 and
Windows XP Service Pack 3
- Microsoft XML Core Services 3.0 on
Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Microsoft XML Core Services 4.0 when installed on
Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Microsoft XML Core Services 6.0 when installed on
Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Microsoft XML Core Services 3.0 on
Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Microsoft XML Core Services 3.0 on
Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2003 x64 Edition 1 and
Windows Server 2003 x64 Edition Service Pack 2
- Microsoft XML Core Services 3.0 on
Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Microsoft XML Core Services 3.0 on
Windows Vista and
Windows Vista Service Pack 1
- Microsoft XML Core Services 4.0 when installed on
Windows Vista and
Windows Vista Service Pack 1
- Microsoft XML Core Services 6.0 when installed on
Windows Vista and
Windows Vista Service Pack 1
- Microsoft XML Core Services 3.0 on
Windows Vista x64 Edition and
Windows Vista x64 Edition Service Pack 1
- Microsoft XML Core Services 4.0 when installed on
Windows Vista x64 Edition and
Windows Vista x64 Edition Service Pack 1
- Microsoft XML Core Services 6.0 when installed on
Windows Vista x64 Edition and
Windows Vista x64 Edition Service Pack 1
- Microsoft XML Core Services 3.0 on
Windows Server 2008 for 32-bit Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2008 for 32-bit Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2008 for 32-bit Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 3.0 on
Windows Server 2008 for x64-based Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2008 for x64-based Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2008 for x64-based Systems
(Windows Server 2008 Server Core installation not affected)
- Microsoft XML Core Services 3.0 on
Windows Server 2008 for Itanium-based Systems
- Microsoft XML Core Services 4.0 when installed on
Windows Server 2008 for Itanium -based Systems
- Microsoft XML Core Services 6.0 when installed on
Windows Server 2008 for Itanium -based Systems
- Microsoft XML Core Services 5.0 on
Microsoft Office 2003 Service Pack 3
- Microsoft XML Core Services 5.0 on
Microsoft Word Viewer 2003 Service Pack 3
- Microsoft XML Core Services 5.0 on
2007 Microsoft Office System and
2007 Microsoft Office System Service Pack 1
- Microsoft XML Core Services 5.0 on
Microsoft Office Compatibility Pack for Word, Excel, and
PowerPoint 2007 File Formats and
Microsoft Office Compatibility Pack for Word, Excel, and
PowerPoint 2007 File Formats Service Pack 1
- Microsoft XML Core Services 5.0 on
Microsoft Expression Web and
Microsoft Expression Web 2
- Microsoft XML Core Services 5.0 on
Microsoft Office SharePoint Server 2007 and
Microsoft Office SharePoint Server 2007 Service Pack 1
(32-bit editions)
- Microsoft XML Core Services 5.0 on
Microsoft Office SharePoint Server 2007 and
Microsoft Office SharePoint Server 2007 Service Pack 1
(64-bit editions)
- Microsoft XML Core Services 5.0 on
Microsoft Office Groove Server 2007

- Impact: Remote Code Execution
- Version Number: 1.0

Important Security Bulletins
============================

Windows Bulletin 2

- Affected Software:
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2 and
Windows XP Service Pack 3
- Windows XP Professional x64 Edition and
Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and
Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition and
Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and
Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista and
Windows Vista Service Pack 1
- Windows Vista x64 Edition and
Windows Vista x64 Edition Service Pack 1
- Windows Server 2008 for 32-bit Systems
(Windows Server 2008 Server Core installation affected)
- Windows Server 2008 for x64-based Systems
(Windows Server 2008 Server Core installation affected)
- Windows Server 2008 for Itanium-based Systems

- Impact: Remote Code Execution
- Version Number: 1.0

Reblog this post [with Zemanta]

Categories: Infosecurity
Tags: Microsoft Security Bulletin, Software Patches

Related Headlines

    Related posts:

    1. Microsoft Releases September Security Notification
    2. Microsoft Issues Security February Bulletin
    3. Microsoft Releases Out-Of-Band Security Bulletin
    4. Microsoft Releases Out-of-Band August 2010 Advance Security Bulletin Notification
    5. Out-of-Band Security Patch for Microsoft IE 7 Critical Vulnerability Announced

Comments are closed.

« Microsoft Ends Windows For Workgroups Support Pakistan: Cyber Terrorism Conviction Will Net Death Penalty »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • iPhone Safari JavaScript Denial of Service
  • Dinosaur Comics: Forsooth
  • Great Wall of China Spreads Worldwide
  • Oracle Updates Enterprise Linux with Firefox Patches
  • United States Memorial Day 2009 – Honoring Those That Have Fallen
  • European Space Agency’s Mars500
  • Say It Ain’t So Redux: Twitter – The New Botnet Command and Control Vector
  • White House Trips Into Content Management Hell… Flawed Software, Development Practices Blamed
  • Wondermark: Barber
  • Wondermark: Oeufs Avec Vingt-Neuf
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe