Tuesday, September 15, 2009

SMB - Once Again....V2 Only

Sept 8 2009 was a regular Microsoft Tuesday...Five Critical Patches expected to arrive...baring the one for FTP Service in Microsoft IIS 6.0.

Microsoft has released their Monthly Security Bulletin Notification for the month of September 2009. On Tuesday, September 8, Microsoft released five security bulletins. All five of the bulletins are rated "critical" because if exploited all five could be used to execute arbitrary code on user systems.

These bulletins will address various issues in all Windows platforms. All five are classified as remote code execution vulnerabilities in Microsoft Windows. The bulletins cover various editions of the operating system, ranging from Windows 2000 to Windows Server 2008.

The patches fix vulnerabilities in the JScript Scripting Engine (MS09-045), the DHTML Editing Component ActiveX control (MS09-46), the Windows Media Format runtime (MS09-47), the TCP/IP stack (MS09-48), and the Wireless LAN AutoConfig service (MS09-49).

http://www.microsoft.com/technet/security/advisory/975497.mspx

There was no Patch for the publicly disclosed Vulnerabilities in FTP Service in Microsoft IIS. The Vulnerability was disclosed on Sept 1 and Microsoft also published a Security Advisory