Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Wednesday, March 8, 2017
Microsoft Security Advisory 3046015 FREAK
Microsoft Security Advisory 3046015 FREAK
Microsoft released Security Advisory 3046015 which relates to the SSL/TLS issue referred being referred to as FREAK (Factoring attack on RSA-EXPORT Keys).
Most of the publicity surrounding FREAK has been addressing the vulnerability in the Safari, Chrome and Android browsers with OS X, iOS and Android. However, the flaw also affects many popular websites. As described in the Security Advisory:
"The vulnerability could allow a man-in-the-middle (MiTM) attacker to force the downgrading of the cipher used in an SSL/TLS connection on a Windows client system to weaker individual ciphers that are disabled but part of a cipher suite that is enabled."The problem is that it isnt only the browser that is vulnerable but websites as well. Are you or the sites you frequent vulnerable? To find out, do the following:
- Test your browser for the FREAK Vulnerability at https://freakattack.com/.
- A list of websites known to be vulnerable to FREAK is at https://freakattack.com/vulnerable.txt. You can also check websites you frequent at SSL Server Test, although if vulnerable, it is up to the website to update their server.
References:
- CVE Reference: CVE-2015-1637
- MSRC: Security Advisory 3046015 released
- Tech Net Advisory: Microsoft Security Advisory 3046015 Vulnerability in Schannel Could Allow Security Feature Bypass
- Tracking the FREAK Attack
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, March 7, 2017
Microsoft Security Bulletin Release for November 2015
Microsoft Security Bulletin Release for November 2015

Microsoft released twelve (12) bulletins. Four (4) bulletins are identified as Critical and the remaining eight (8) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft, Skype for Business, Microsoft .NET Framework, Microsoft Edge and Internet Explorer.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin. Watch for the November 2015 "monthly patch review" by Dustin Childs picking up where MSRC has left us hanging. The review can be found on the HP Security Research blog.
Critical:
- MS15-112 -- Cumulative Security Update for Internet Explorer (3104517)
- MS15-113 -- Cumulative Security Update for Microsoft Edge (3104519)
- MS15-114 -- Security Update for Windows Journal to Address Remote Code Execution (3100213)
- MS15-115 -- Security Update for Microsoft Windows to Address Remote Code Execution (3105864)
- MS15-116 -- Security Update for Microsoft Office to Address Remote Code Execution (3104540)
- MS15-117 -- Security Update for NDIS to Address Elevation of Privilege (3101722)
- MS15-118 -- Security Update for .NET Framework to Address Elevation of Privilege (3104507)
- MS15-119 -- Security Update for Winsock to Address Elevation of Privilege (3104521)
- MS15-120 -- Security Update for IPSec to Address Denial of Service (3102939)
- MS15-121 -- Security Update for Schannel to Address Spoofing (3081320)
- MS15-122 -- Security Update for Kerberos to Address Security Feature Bypass (3105256)
- MS15-123 -- Security Update for Skype for Business and Microsoft Lync to Address Information Disclosure (3105872)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the the following ransomware families: Crowti, Critroni, Teerac and Tescrypt . Details are available in the MMPC Blog Post.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for November 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Thursday, March 2, 2017
Membuka Update Server Yang Terkunci Pada NOD32 dan Eset Smart Security Versi 5
Membuka Update Server Yang Terkunci Pada NOD32 dan Eset Smart Security Versi 5
Tidak seperti versi-versi sebelumnya, pada NOD32 dan Eset Smart Security versi 5, pilihan update servernya terkunci, jadi anda tidak bisa mengubahnya untuk menentukan pilihan update offline dan mirror, dengan sedikit mengubah nilai registry kita dapat membukanya, berikut langkahnya :
Reboot komputer anda dan masuk ke safe mode dengan menekan tombol F8.
Setelah masuk dalam safe mode, buka registry windows dan cari key berikut :
HKEY_LOCAL_MACHINESOFTWAREESETESET SecurityCurrentVersionInfo
Kemudian cari key dengan nama PackageFeatures dan ubah nilai default nya 00000003? ganti dengan 00000001? dengan cara klik 2 kali dan ganti angka 3 menjadi angka 1.
Pada NOD32 angka defaultnya 00000002? sama seperti Eset Smart Security ganti dengan angka 1.
setelah selesai restart ulang komputer anda dan lihat hasilnya berikut penampakannya :
[sop14n]
Available link for download
Friday, February 17, 2017
Microsoft Security Bulletin Release for December 2015
Microsoft Security Bulletin Release for December 2015

Microsoft released twelve (12) bulletins. Eight (8) bulletins are identified as Critical and the remaining four (4) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Skype for Business, Microsoft Lync Silverlight and Microsoft Silverlight.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin. If you are prioritizing updates, the most critical is MS15-0131.
Also released today is Microsoft Security Advisory 3123040 which revokes a certificate for *.xboxlive.com where private keys were disclosed.
Critical:
- MS15-124 Cumulative Security Update for Internet Explorer (3116180
- MS15-125 Cumulative Security Update for Microsoft Edge (3116184)
- MS15-126 Cumulative Security Update for JScript and VBScript to Address Remote Code Execution (3116178)
- MS15-127 Security Update for Microsoft Windows DNS to Address Remote Code Execution (3100465)
- MS15-128 Security Update for Microsoft Graphics Component to Address Remote Code Execution (3104503)
- MS15-129 Security Update for Silverlight to Address Remote Code Execution (3106614)
- MS15-130 Security Update for Microsoft Uniscribe to Address Remote Code Execution (3108670)
- MS15-131 Security Update for Microsoft Office to Address Remote Code Execution (3116111)
Important:
- MS15-132 Security Update for Microsoft Windows to Address Remote Code Execution (3116162)
- MS15-133 Security Update for Windows PGM to Address Elevation of Privilege (3116130
- MS15-134 Security Update for Windows Media Center to Address Remote Code Execution (3108669)
- MS15-135 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3119075)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the Blakamba, Brambul, Diplugem, Drixed, Escad, Joanap and Tescrypt.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for December 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Wednesday, February 15, 2017
Microsoft Security Bulletin Release for March 2015
Microsoft Security Bulletin Release for March 2015

Microsoft released fourteen (14) bulletins. Five (5) bulletins are identified as Critical and the remaining nine (9) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Microsoft Exchange and Internet Explorer. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Security Bulletin MS15-031 addresses the vulnerability in Security Advisory 3046015 which relates to the SSL/TLS issue referred being referred to as FREAK (Factoring attack on RSA-EXPORT Keys).
In addition to providing information about the additional families added to the MSRT, information regarding Superfish and steps by Microsoft, Lenovo and others is available in the MMPC blog post, MSRT March: Superfish cleanup.
Updates:
Critical:
- MS15-022 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3038999)
- MS15-021 -- Vulnerabilities in Adobe Font Driver Could Allow Remote Code Execution (3032323)
- MS15-020 -- Vulnerability in Microsoft Windows Could Allow Remote Code Execution (3041836)
- MS15-019 -- Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3040297)
- MS15-018 -- Cumulative Security Update for Internet Explorer (3032359)
Important:
- MS15-031 -- Vulnerability in Schannel Could Allow Security Feature Bypass (3046049)
- MS15-030 -- Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (3039976)
- MS15-029 -- Vulnerability in Windows Photo Decoder Component Could Allow Information Disclosure (3035126)
- MS15-028 -- Vulnerability in Windows Task Scheduler Could Allow Security Feature Bypass (3030377)
- MS15-027 -- Vulnerability in NETLOGON Could Allow Spoofing (3002657)
- MS15-026 -- Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)
- MS15-025 -- Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (3038680)
- MS15-024 -- Vulnerability in PNG Processing Could Allow Information Disclosure (3035132)
- MS15-023 -- Vulnerabilities in Kernel-Mode Driver Could Allow Elevation of Privilege (3034344)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/CompromisedCert and Win32/Alinaos malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: March 2015 Updates
- TechNet: Microsoft Security Bulletin for March 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Sunday, February 12, 2017
Microsoft Security Bulletin Update for May 2016
Microsoft Security Bulletin Update for May 2016

Microsoft released sixteen (16) bulletins. Eight (8) bulletins are identified as Critical and the remaining eight (8) are rated Important in severity.
There are 37 CVEs addressed in the security updates, of which one is under active attack. Both MS16-015 and MS16-053 are needed to mitigate the vulnerability.
The updates address vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office Services and Web Apps, Microsoft Office, Microsoft .NET Framework.
Information about the update for Windows 10 is available at Windows 10 update history.
Critical:
- MS16-051 Cumulative Security Update for Internet Explorer (3155533)
- MS16-052 Cumulative Security Update for Microsoft Edge (3155538)
- MS16-053 Cumulative Security Update for JScript and VBScript (3156764)
- MS16-054 Security Update for Microsoft Office (3155544)
- MS16-055 Security Update for Microsoft Graphics Component (3156754)
- MS16-056 Security Update for Windows Journal (3156761)
- MS16-057 Security Update for Windows Shell (3156987)
- MS16-064 Security Update for Adobe Flash Player (3157993)
Important:
- MS16-058 Security Update for Windows IIS (3141083)
- MS16-059 Security Update for Windows Media Center (3150220)
- MS16-060 Security Update for Windows Kernel (3154846)
- MS16-061 Security Update for Microsoft RPC (3155520)
- MS16-062 Security Update for Windows Kernel-Mode Drivers (3158222)
- MS16-065 Security Update for .NET Framework (3156757)
- MS16-066 Security Update for Virtual Secure Mode (3155451)
- MS16-067 Security Update for Volume Manager Driver (3155784)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for May 2016
- Windows 10 Update History

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Microsoft Security Essential Antivirus Ringan Tapi Powerful
Microsoft Security Essential Antivirus Ringan Tapi Powerful
Microsoft Security Essentials (MSE) adalah aplikasi antivirus gratis besutan microsoft yang dirancang dengan tampilan yang sederhana dan mudah digunakan. Memiliki logo benteng dengan sebuah bendera, MSE akan menjadi sebuah benteng pelindung yang akan melindungi komputer Anda dari virus, malware, spyware, dan program lainnya yang membahayakan komputer Anda.

MSE memang masih kalah pamor dibandingkan dengan antivirus-antivirus terkenal seperti bitdefender, kaspersky, avast, dan yang lainnya. Tapi, MSE juga memiliki kelebihan yang membuat Anda akan tertarik untuk memasangnya di komputer Anda.
Salah satu kelebihannya adalah antarmuka-nya yang sederhana tanpa dijejali banyak istilah-istilah yang kurang dimengerti orang awam. Selain itu, MSE sangat ringan dan membuat komputer Anda berat. Anda akan merasa seolah-olah tidak memiliki antivirus di komputer Anda karena ringannya program ini. MSE akan berjalan di belakang layar, mendeteksi virus dan memblokirnya agar tidak membahayakan sistem. MSE tidak memunculkan banyak pop up yang bisa membuat Anda terganggu. Ringan, sederhana, gratis, tapi tidak murahan. Itulah antivirus Microsoft Security Essential (MSE).
Untuk masalah update database antivirusnya, MSE bisa update secara online dan otomatis. MSE juga bisa di update secara manual. Caranya lihat di sini.
Untuk download MSE silahkan klik di sini
Silahkan dicoba...
Available link for download
Thursday, February 9, 2017
Microsoft Out of Band Critical Security Update
Microsoft Out of Band Critical Security Update

One of the security updates that was delayed in the regular patch cycle last week has been released.
MS14-068 is a critical update that addresses a vulnerability in Kerbeos that could allow elevation of privilege. Microsoft is aware of limited, targeted attacks that attempt to exploit this vulnerability.
As described in the security bulletin:
"An attacker could use these elevated privileges to compromise any computer in the domain, including domain controllers. An attacker must have valid domain credentials to exploit this vulnerability. The affected component is available remotely to users who have standard user accounts with domain credentials; this is not the case for users with local account credentials only."
References:
- KB 3011780: MS14-068: Vulnerability in Kerberos could allow elevation of privilege: November 18, 2014
- TechNet: Microsoft Security Bulletin MS14-068 - Critical
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Thursday, February 2, 2017
Microsoft Security Essentials 4 2 223 0
Microsoft Security Essentials 4 2 223 0
Microsoft Security Essentials 4.2.223.0 Free Download
![]() |
| Microsoft Security Essentials 4,microsoft security essentials 4.1,microsoft security essentials 4.0.1526,microsoft security essentials 4.0.1512,microsoft security essentials 4,microsoft security essentials 4 release date,microsoft security essentials 4.0,microsoft security essentials 4 review,microsoft security essentials 4 beta 64 bits,microsoft security essentials 4 64 bits,microsoft security essentials 4.0 64 bit |
The Microsoft Security Essentials application provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software.
Microsoft Security Essentials is a free download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. Its easy to tell if your PC is secure - when youre green, youre good. Its that simple.
Microsoft Security Essentials 4,microsoft security essentials 4,microsoft security essentials 4.1,microsoft security essentials 4.0,microsoft security essentials 4.1 test,microsoft security essentials 4 test,microsoft security essentials 4.1.522.0,microsoft security essentials 4.0 test,microsoft security essentials 4.2,microsoft security essentials 4.1 deutsch,microsoft security essentials 4.0 download
Microsoft Security Essentials runs quietly and efficiently in the background so that you are free to use your Windows-based PC the way you want - without interruptions or long computer wait times.
Here are some features of Microsoft Security Essentials:
Microsoft Security Essentials 4,microsoft security essentials 4.0,microsoft security essentials 4,microsoft security essentials 4.1,microsoft security essentials 4.1.522.0,microsoft security essentials 4 review,microsoft security essentials 4.1.522.0 free download,microsoft security essentials 4.1 review,microsoft security essentials 4.2,microsoft security essentials 4.0 free download,microsoft security essentials 4shared.com
· Comprehensive malware protection
· Simple, free download
· Automatic updates
· Easy to use
Requirements:
· For XP - CPU with clock speed of 500 MHz or higher
· For XP - Memory: 256 MB RAM or higher
· For Vista / W7 - CPU with clock speed of 1.0 GHz or higher
· For Vista / W7 - Memory: 1 GB RAM or higher
· VGA (Display): 800 x 600 or higher
· Storage: 140 MB of available hard-disk space
· An Internet connection is required for installation and to download the latest virus and spyware definitions for Microsoft Microsoft Security Essentials
· Internet Browser (IE or Firefox)
Microsoft Security Essentials 4,microsoft security essentials 4 per windows xp,microsoft security essentials 4 recensione,microsoft security essentials 4.1,microsoft security essentials 4 download,microsoft security essentials 4 release date,microsoft security essentials 4 review,microsoft security essentials 4.1.204.0,microsoft security essentials 4.0 download,microsoft security essentials 4.0 beta download,microsoft security essentials 4 beta download
Whats New in This Release:
· Enhanced protection through automatic malware remediation: The Beta program will clean highly impacting malware infections automatically, with no required user interaction.
· Enhanced performance: The Beta includes many performance improvements to make sure your PC performance isnt compromised.
· Simplified UI Simplified UI makes Microsoft Security Essentials Beta easier to use.
· New and improved protection engine: The updated engine offers enhanced detection with cleanup capabilities and better performance.
Click to Download:
Microsoft Security Essentials 4.2.223.0 (x86)
Microsoft Security Essentials 4.2.223.0 (x64)
Available link for download
Saturday, January 28, 2017
Microsoft Security Bulletin Release for February 2016
Microsoft Security Bulletin Release for February 2016

Microsoft released thirteen (13) bulletins. Six (6) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft .NET Framework, Microsoft Office Services and Web Apps,
Microsoft Server Software and Microsoft .NET Framework.
For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and was included with the updates.
As a very welcome change in response to feedback, Microsoft is now providing more details about the Windows 10 updates delivered through Windows Update. A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
Critical:
- MS16-009 Cumulative Security Update for Internet Explorer (3134220)
- MS16-011 Cumulative Security Update for Microsoft Edge (3134225)
- MS16-012 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3138938)
- MS16-013 Security Update for Windows Journal to Address Remote Code Execution (3134811)
- MS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226)
- MS16-022 Security Update for Adobe Flash Player (3135782)
- MS16-014 Security Update for Microsoft Windows to Address Remote Code Execution (3134228)
- MS16-016 Security Update for WebDAV to Address Elevation of Privilege (3136041)
- MS16-017 Security Update for Remote Desktop Display Driver to Address Elevation of Privilege (3134700)
- MS16-018 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3136082)
- MS16-019 Security Update for .NET Framework to Address Denial of Service (3137893)
- MS16-020 Security Update for Active Directory Federation Services to Address Denial of Service (3134222)
- MS16-021 Security Update for NPS RADIUS Server to Address Denial of Service (3133043)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The update includes updated detections for the following malware families: Bladabindi, Gamarue, Sality, Kelihos and Diplugem??.
Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.References
- MSRC
- TechNet: Microsoft Security Bulletin for February 2016
- Windows 10 Update History
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Wednesday, January 25, 2017
Thursday, January 19, 2017
Microsoft Security Updates for June 2016
Microsoft Security Updates for June 2016

Microsoft released sixteen (16) bulletins addressing 44 CVEs. Five (5) bulletins are identified as Critical and the remaining eleven (11) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office and Microsoft Office Services and Web Apps and address Remote Code Execution, Elevation of Privilege. One Update for Microsoft Exchange Server addresses Information Disclosure.
Information about the update for Windows 10 is available at Windows 10 update history.
Critical:
- MS16-063 -- Cumulative Security Update for Internet Explorer (3163649)
- MS16-068 -- Cumulative Security Update for Microsoft Edge (3163656)
- MS16-069 -- Cumulative Security Update for JScript and VBScript (3163640)
- MS16-070 -- Security Update for Microsoft Office (3163610)
- MS16-071 -- Security Update for Microsoft Windows DNS Server (3164065)
Important:
- MS16-072 -- Security Update for Group Policy (3163622)
- MS16-073 -- Security Update for Windows Kernel-Mode Drivers (3164028)
- MS16-074 -- Security Update for Microsoft Graphics Component (3164036)
- MS16-075 -- Security Update for Windows SMB Server (3164038)
- MS16-076 -- Security Update for Netlogon (3167691)
- MS16-077 -- Security Update for WPAD (3165191)
- MS16-078 -- Security Update for Windows Diagnostic Hub (3165479)
- MS16-079 -- Security Update for Microsoft Exchange Server (3160339)
- MS16-080 -- Security Update for Microsoft Windows PDF (3164302)
- MS16-081 -- Security Update for Active Directory (3160352)
- MS16-082 -- Security Update for Microsoft Windows Search Component (3165270)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for June 2016
- Windows 10 Update History

Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, January 17, 2017
Microsoft Security Bulletin Advance Notice for October 2014
Microsoft Security Bulletin Advance Notice for October 2014
On Tuesday, October 14, 2014, Microsoft is planning to release nine (9) bulletins. Three bulletins are identified as Critical, five (5) as Important, and one is rated Moderate in severity.
These updates are for Microsoft Windows, Internet Explorer, Office, .NET Framework, and ASP.NET.with the remaining three as Important. As usual, my reminder if you have had problems with .NET Framework in the past is to install the update(s) separately with a shutdown/restart.
Reminder
As has been widely publicized, support ended for Windows XP and Office 2003 on April 8, 2014. See Tim Rains article, The Risk of Running Windows XP After Support Ends April 2014. Note also that Microsoft Security Essentials will no longer be available for download for Windows XP.As happens each month, Microsoft will also release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
References
- MSRC: Advance Notification Service for October 2014 Security Bulletin Release
- TechNet: Microsoft Security Bulletin Advance Notification for October 2014
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Wednesday, January 11, 2017
Microsoft Security Advisory 3010060 with Fixit Solution
Microsoft Security Advisory 3010060 with Fixit Solution
Microsoft released Security Advisory 3010060 which relates to a vulnerability affecting all supported releases of Microsoft Windows, excluding Windows Server 2003.
The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that contains an OLE object. Microsoft is aware of limited, targeted attacks.
Recommendations
Microsoft has made available a Fix it solution "OLE packager shim workaround" which prevents execution of the vulnerability. Below are direct links to both enable and disable the Fix it solution.Note: The Fix it solution is not at this time for 64-bit editions of PowerPoint on x64-based editions of Windows 8 and Windows 8.1.
| Enable Fix it | Disable Fix it |
|---|---|
Microsoft Fix it 51026 | Microsoft Fix it 51027 |
Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.
References:
- CVE Reference: CVE-2014-6352
- Microsoft KB Article 3010060: Microsoft security advisory: Vulnerability in Microsoft OLE could allow remote code execution: October 21, 2014
- MSRC: Security Advisory 3010060 released
- Tech Net Advisory: Microsoft Security Advisory 3010060 Vulnerability in Microsoft OLE Could Allow Remote Code Execution
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, January 10, 2017
Microsoft Security Bulletin Release for March 2016
Microsoft Security Bulletin Release for March 2016

Microsoft released thirteen (13) bulletins. Five (5) bulletins are identified as Critical and the remaining eight (8) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft Office, Microsoft Office Services and Web Apps, Microsoft Server Software and Microsoft .NET Framework.
Critical:
- MS16-023 Cumulative Security Update for Internet Explorer (3142015)
- MS16-024 Cumulative Security Update for Microsoft Edge (3142019)
- MS16-026 Security Update for Graphic Fonts to Address Remote Code Execution (3143148)
- MS16-027 Security Update for Windows Media to Address Remote Code Execution (3143146)
- MS16-028 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3143081)
- MS16-025 Security Update for Windows Library Loading to Address Remote Code Execution (3140709)
- MS16-029 Security Update for Microsoft Office to Address Remote Code Execution (3141806)
- MS16-030 Security Update for Windows OLE to Address Remote Code Execution (3143136)
- MS16-031 Security Update for Microsoft Windows to Address Elevation of Privilege (3140410)
- MS16-032 Security Update for Secondary Logon to Address Elevation of Privilege (3143141)
- MS16-033 Security Update for Windows USB Mass Storage Class Driver to Address Elevation of Privilege (3143142)
- MS16-034 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3143145)
- MS16-035 Security Update for .NET Framework to Address Security Feature Bypass (3141780)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for March 2016
- Windows 10 Update History
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Microsoft Security Essentials 4 1 522 0 4 2 216 0 Prerelease
Microsoft Security Essentials 4 1 522 0 4 2 216 0 Prerelease
Microsoft Security Essentials 4.1.522.0 / 4.2.216.0 Prerelease Free Download
![]() |
| Microsoft Security Essentials 4,microsoft security essentials 4.1,microsoft security essentials 4.0.1526,microsoft security essentials 4.0.1512,microsoft security essentials 4,microsoft security essentials 4 beta,microsoft security essentials 4.0,microsoft security essentials 4.0 beta,microsoft security essentials 4 beta download,microsoft security essentials 4 download,microsoft security essentials 4.2 |
The Microsoft Security Essentials application provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software.
Microsoft Security Essentials is a free download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. Its easy to tell if your PC is secure - when youre green, youre good. Its that simple.
Microsoft Security Essentials runs quietly and efficiently in the background so that you are free to use your Windows-based PC the way you want - without interruptions or long computer wait times.
Here are some features of Microsoft Security Essentials:
Microsoft Security Essentials 4,microsoft security essentials 4 per windows xp,microsoft security essentials 4 recensione,microsoft security essentials 4.1,microsoft security essentials 4 download,microsoft security essentials 4 beta,microsoft security essentials 4.0 beta,microsoft security essentials 4 beta download,microsoft security essentials 4.2,microsoft security essentials 4.0 download,microsoft security essentials 4 public beta
· Comprehensive malware protection
· Simple, free download
· Automatic updates
· Easy to use
Requirements:
· For XP - CPU with clock speed of 500 MHz or higher
· For XP - Memory: 256 MB RAM or higher
· For Vista / W7 - CPU with clock speed of 1.0 GHz or higher
· For Vista / W7 - Memory: 1 GB RAM or higher
· VGA (Display): 800 x 600 or higher
· Storage: 140 MB of available hard-disk space
· An Internet connection is required for installation and to download the latest virus and spyware definitions for Microsoft Microsoft Security Essentials
· Internet Browser (IE or Firefox)
Microsoft Security Essentials 4,microsoft security essentials 4.0,microsoft security essentials 4,microsoft security essentials 4.1.522.0,microsoft security essentials 4.1,microsoft security essentials 4 review,microsoft security essentials 4.1 review,microsoft security essentials 4.1.522.0 free download,microsoft security essentials 4.0 download,microsoft security essentials 4.2,microsoft security essentials 4.0 free download
Whats New in This Release:
· Enhanced protection through automatic malware remediation: The Beta program will clean highly impacting malware infections automatically, with no required user interaction.
· Enhanced performance: The Beta includes many performance improvements to make sure your PC performance isnt compromised.
· Simplified UI Simplified UI makes Microsoft Security Essentials Beta easier to use.
· New and improved protection engine: The updated engine offers enhanced detection with cleanup capabilities and better performance.
Click to Download:
Microsoft Security Essentials 4.1.522.0 (62bit)
Microsoft Security Essentials 4.1.522.0 (64bit)
Microsoft Security Essentials 4.2.216.0 Prerelease (32bit)
Microsoft Security Essentials 4.2.216.0 Prerelease (64bit)
Available link for download
Labels:
0,
1,
2,
216,
4,
522,
essentials,
microsoft,
prerelease,
security
Saturday, January 7, 2017
Microsoft Security Bulletin Release for April 2016
Microsoft Security Bulletin Release for April 2016

Microsoft released thirteen (13) bulletins. Six (6) bulletins are identified as Critical and the remaining eight (7) are rated Important in severity. Of particular note is MS16-039 which is under active attack.
The updates address vulnerabilities in Microsoft Windows, Microsoft Edge, Internet Explorer, Microsoft Office, Microsoft Office, Microsoft Office Services and Web Apps, Skype for Business, Microsoft Lync and Microsoft .NET Framework.
Information about the updates in KB 3147458 for Windows 10 is available at Windows 10 update history.
Critical:
- MS16-037 Cumulative Security Update for Internet Explorer (3148531)
- MS16-038 Cumulative Security Update for Microsoft Edge (3148532)
- MS16-039 Security Update for Microsoft Graphics Component (3148522)
- MS16-040 Security Update for Microsoft XML Core Services (3148541)
- MS16-042 Security Update for Microsoft Office (3148775)
- MS16-050 Security Update for Adobe Flash Player in IE/Edge on Win8.1/10 (3154132)
- MS16-041 Security Update for .NET Framework (3148789)
- MS16-044 Security Update for Windows OLE (3146706)
- MS16-045 Security Update for Windows Hyper-V (3143118)
- MS16-046 Security Update for Secondary Logon (3148538)
- MS16-047 Security Update for SAM and LSAD Remote Protocols (3148527)
- MS16-048 Security Update for CSRSS (3148528)
- MS16-049 Security Update for HTTP.sys (3148795)
Additional Update Notes
- Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates.
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
- Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.
References
- MSRC
- TechNet: Microsoft Security Bulletin for April 2016
- Windows 10 Update History
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Microsoft Security Bulletin Release for April 2015
Microsoft Security Bulletin Release for April 2015

Microsoft released fourteen (11) bulletins. Four (4) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft Server Software, Productivity Software and .NET Framework. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
For those who have had issues with .NET Framework updates, it is suggested that MS-041 be installed separately with a shut/down restart between other updates.
As part of the Internet Explorer update released today, SSL 3.0 has been disabled by default in Internet Explorer 11.
Critical:
- MS15-032 Cumulative Security Update for Internet Explorer (3038314)
- MS15-033 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3048019)
- MS15-034 Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)
- MS15-035 Vulnerability in Microsoft Graphics Component Could Allow Remote Code Execution (3046306)
- MS15-036 Vulnerabilities in Microsoft SharePoint Server Could Allow Elevation of Privilege (3052044)
- MS15-037 Vulnerability in Windows Task Scheduler Could Allow Elevation of Privilege (3046269)
- MS15-038 Vulnerabilities in Microsoft Windows Could Allow Elevation of Privilege (3049576)
- MS15-039 Vulnerability in XML Core Services Could Allow Security Feature Bypass (3046482)
- MS15-040 Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (3045711)
- MS15-041 Vulnerability in .NET Framework Could Allow Information Disclosure (3048010)
- MS15-042 Vulnerability in Windows Hyper-V Could Allow Denial of Service (3047234)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
The updated version includes the Win32/Saluchtra, Win32/Dexter, Win32/Unskal and Win32/IeEnablerCby malware families. Additional details ave available in the MMPC blog post. - Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: April 2015 Updates
- TechNet: Microsoft Security Bulletin for April 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Tuesday, January 3, 2017
Microsoft Security Bulletin Release for May 2015
Microsoft Security Bulletin Release for May 2015

Microsoft released thirteen (13) bulletins. Three (3) bulletins are identified as Critical and the remaining ten (10) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, Microsoft Lync, Microsoft Silverlight, Microsoft Server Software and .NET Framework. Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
For those who have had issues with .NET Framework updates, it is suggested that MS-041 be installed separately with a shut/down restart between other updates.
Also released was one new Security Advisory:
- Update to Default Cipher Suite Priority Order (3042058)
- Update for Adobe Flash Player in Internet Explorer (2755801)
Critical:
- MS15-043 -- Cumulative Security Update for Internet Explorer (3049563)
- MS15-044 -- Vulnerabilities in Microsoft Font Drivers Could Allow Remote Code Execution (3057110)
- MS15-045-- Vulnerability in Windows Journal Could Allow Remote Code Execution (3046002)
- MS15-046 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3057181)
- MS15-047 -- Vulnerabilities in Microsoft SharePoint Server Could Allow Remote Code Execution (3058083)
- MS15-048 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3057134)
- MS15-049 -- Vulnerability in Silverlight Could Allow Elevation of Privilege (3058985)
- MS15-050 -- Vulnerability in Service Control Manager Could Allow Elevation of Privilege (3055642)
- MS15-051 -- Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (3057191)
- MS15-052 -- Vulnerability in Windows Kernel Could Allow Security Feature Bypass (3050514)
- MS15-053 -- Vulnerabilities in JScript and VBScript Scripting Engines Could Allow Security Feature Bypass (3057263)
- MS15-054 -- Vulnerability in Microsoft Management Console File Format Could Allow Denial of Service (3051768)
- MS15-055 -- Vulnerability in Schannel Could Allow Information Disclosure (3061518)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.
- Internet Explorer -- For additional information about the blocking of out-of-date ActiveX controls see the TechNet article, Out-of-date ActiveX control blocking. Additional changes introduced this month include the blocking of outdated Silverlight. Additional information is available in the IE Blog.
- Windows 8.x -- Non-security new features and improvements for Windows 8.1 are now included with the second Tuesday of the month updates. Additional information about this change is available here.
- Windows XP -- Although Microsoft has stopped providing Microsoft Security Essentials for Windows XP, definitions will be available until July 15, 2015. See Microsoft antimalware support for Windows XP. The MSRT still works on Windows XP.
References
- MSRC: May 2015 Updates
- TechNet: Microsoft Security Bulletin for May 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Friday, December 30, 2016
Microsoft Security Bulletin Release for September 2015
Microsoft Security Bulletin Release for September 2015

Microsoft released twelve (12) bulletins. Five (5) bulletins are identified as Critical and the remaining seven (7) are rated Important in severity.
The updates address vulnerabilities in Microsoft Windows, Microsoft,.NET Framework, Microsoft Office, Microsoft Lync, Microsoft Silverlight, Skype for Business Server, Microsoft Lync Server, Microsoft Edge and Internet Explorer.
Details about the CVEs can be found in the below-referenced TechNet Security Bulletin.
Update: You wont want to miss the new Monthly Patch Review by Dustin Childs.
Critical:
- MS15-094 -- Cumulative Security Update for Internet Explorer (3089548)
- MS15-095 -- Cumulative Security Update for Microsoft Edge (3089665)
- MS15-097 --Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (3089656)
- MS15-098 -- Vulnerabilities in Windows Journal Could Allow Remote Code Execution (3089669)
- MS15-099 -- Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
- MS15-096 -- Vulnerability in Active Directory Service Could Allow Denial of Service (3072595)
- MS15-100 -- Vulnerability in Windows Media Center Could Allow Remote Code Execution (3087918)
- MS15-101 -- Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (3089662)
- MS15-102 -- Vulnerabilities in Windows Task Management Could Allow Elevation of Privilege (3089657)
- MS15-103 -- Vulnerabilities in Microsoft Exchange Server Could Allow Information Disclosure (3089250)
- MS15-104 -- Vulnerabilities in Skype for Business Server and Lync Server Could Allow Elevation of Privilege (3089952)
- MS15-105 -- Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass (3091287)
Additional Update Notes
- MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. The updated version includes detection for the prevalent ransomware family Win32/Teerac. Details are available in the MMPC Blog Post.
- Windows 8.x and Windows 10 -- Non-security new features and improvements for Windows 8.1 and Windows 10 are included with the updates.
References
- MSRC
- TechNet: Microsoft Security Bulletin for September 2015
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Subscribe to:
Posts (Atom)
