Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Microsoft Security Bulletin Advance Notification - April 2007

Closed Thread
 
Thread Tools Display Modes
Old 04-01-2007   #1 (permalink)
Donna Buenaventura
Guest
 
Posts: n/a

Microsoft Security Bulletin Advance Notification - April 2007

On Tuesday 3 April 2007 Microsoft is planning to release:

Security Updates
* One Microsoft Security Bulletin affecting Microsoft Windows. The highest
Maximum Severity rating for these is Critical. These updates will require a
restart. These updates will be detectable using the Microsoft Baseline
Security Analyzer.


Microsoft Windows Malicious Software Removal Tool
* Microsoft will not release an updated version of the Microsoft Windows
Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows
Server Update Services and the Download Center on Tuesday 3 April 2007.

Non-security High Priority updates on MU, WU, WSUS and SUS
* Microsoft will not release any NON-SECURITY High-Priority Updates for
Windows on Windows Update (WU) and Software Update Services (SUS) on Tuesday
3 April 2007.

* Microsoft will not release any NON-SECURITY High-Priority Updates on
Microsoft Update (MU) and Windows Server Update Services (WSUS) on Tuesday 3
April 2007.

http://www.microsoft.com/technet/sec...n/advance.mspx

--
Regards,

Donna Buenaventura
Windows Security MVP
w: http://cou.dozleng.com
b: http://msmvps.com/donna

 
Old 04-01-2007   #2 (permalink)
Ottmar Freudenberger
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"Donna Buenaventura" <dbuenaventura@mvps.org> schrieb:

> On Tuesday 3 April 2007 Microsoft is planning to release:
>
> Security Updates
> * One Microsoft Security Bulletin affecting Microsoft Windows. The highest
> Maximum Severity rating for these is Critical. These updates will require a
> restart. These updates will be detectable using the Microsoft Baseline
> Security Analyzer.


This will be a very, very important patch to be released out of the
normal Patch Day cycle. For more details see
http://www.microsoft.com/technet/sec...ry/935423.mspx
http://blogs.technet.com/msrc/archiv...ry-935423.aspx
http://isc.sans.org/diary.html?storyid=2534 and
http://www.kb.cert.org/vuls/id/191609

Bye,
Freudi
 
Old 04-01-2007   #3 (permalink)
Rock
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"Donna Buenaventura" <dbuenaventura@mvps.org> wrote
> On Tuesday 3 April 2007 Microsoft is planning to release:
>
> Security Updates
> * One Microsoft Security Bulletin affecting Microsoft Windows. The highest
> Maximum Severity rating for these is Critical. These updates will require
> a restart. These updates will be detectable using the Microsoft Baseline
> Security Analyzer.
>
>
> Microsoft Windows Malicious Software Removal Tool
> * Microsoft will not release an updated version of the Microsoft Windows
> Malicious Software Removal Tool on Windows Update, Microsoft Update,
> Windows Server Update Services and the Download Center on Tuesday 3 April
> 2007.
>
> Non-security High Priority updates on MU, WU, WSUS and SUS
> * Microsoft will not release any NON-SECURITY High-Priority Updates for
> Windows on Windows Update (WU) and Software Update Services (SUS) on
> Tuesday 3 April 2007.
>
> * Microsoft will not release any NON-SECURITY High-Priority Updates on
> Microsoft Update (MU) and Windows Server Update Services (WSUS) on Tuesday
> 3 April 2007.
>
> http://www.microsoft.com/technet/sec...n/advance.mspx


Shouldn't that be April 10th, the second Tuesday of the month?

--
Rock [MS-MVP User/Shell]

 
Old 04-01-2007   #4 (permalink)
Ottmar Freudenberger
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"Rock" <Rock@nospam.net> schrieb:

> Shouldn't that be April 10th, the second Tuesday of the month?


April 10th is/will be the regular Patch Day, while MS is going to
release a very, very important security update out of the normal
Patch Day cycle on April 3rd. That does *not* mean, that there won't
be any other updates to be released on April 10th.

http://blogs.technet.com/msrc/archiv...ry-935423.aspx

| This update was previously scheduled for release as part of the
| April monthly release on April 10, 2007. Due to the increased risk
| to customers from these latest attacks, we were able to expedite
| our testing to ensure an update is ready for broad distribution
| sooner than April 10.

Bye,
Freudi
 
Old 04-01-2007   #5 (permalink)
Donna Buenaventura
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

Maybe they change the plan because of Vulnerability in Windows Animated
Cursor
Handling -http://www.microsoft.com/technet/security/advisory/935423.mspx
I'm not sure though but the above security issue made Infocon turn Yellow -
http://isc.sans.org/diary.html

MS said "no additional information on these bulletins such as details
regarding severity or details regarding the vulnerability will be made
available until 3 April 2007." so the above is just a guess.

:-)
Donna

"Rock" <Rock@nospam.net> wrote in message
news:O%23qLu7NdHHA.4868@TK2MSFTNGP06.phx.gbl...
> Shouldn't that be April 10th, the second Tuesday of the month?
>
> --
> Rock [MS-MVP User/Shell]


 
Old 04-02-2007   #6 (permalink)
Rock
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"Donna Buenaventura" <dbuenaventura@mvps.org> wrote in message
news:5B841E04-A76C-458A-AEE3-CE34D2616ECF@microsoft.com...
> Maybe they change the plan because of Vulnerability in Windows Animated
> Cursor
> Handling -http://www.microsoft.com/technet/security/advisory/935423.mspx
> I'm not sure though but the above security issue made Infocon turn
> Yellow - http://isc.sans.org/diary.html
>
> MS said "no additional information on these bulletins such as details
> regarding severity or details regarding the vulnerability will be made
> available until 3 April 2007." so the above is just a guess.
>
> :-)
> Donna
>
> "Rock" <Rock@nospam.net> wrote in message
> news:O%23qLu7NdHHA.4868@TK2MSFTNGP06.phx.gbl...
>> Shouldn't that be April 10th, the second Tuesday of the month?




Ahh I see it's one of those non monthly releases. Thanks.

--
Rock [MS-MVP User/Shell]

 
Old 04-02-2007   #7 (permalink)
PA Bear
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

Ottmar Freudenberger wrote:
> "Donna Buenaventura" <dbuenaventura@mvps.org> schrieb:
>
>> On Tuesday 3 April 2007 Microsoft is planning to release:
>>
>> Security Updates
>> * One Microsoft Security Bulletin affecting Microsoft Windows. The
>> highest
>> Maximum Severity rating for these is Critical. These updates will require
>> a
>> restart. These updates will be detectable using the Microsoft Baseline
>> Security Analyzer.

>
> This will be a very, very important patch to be released out of the
> normal Patch Day cycle. For more details see
> http://www.microsoft.com/technet/sec...ry/935423.mspx
> http://blogs.technet.com/msrc/archiv...ry-935423.aspx
> http://isc.sans.org/diary.html?storyid=2534 and
> http://www.kb.cert.org/vuls/id/191609


We might /assume/ that
http://blogs.technet.com/msrc/archiv...ry-935423.aspx
is related to this Security Bulletin Advanced Notification, but...
--
~PA Bear

 
Old 04-02-2007   #8 (permalink)
Ottmar Freudenberger
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"PA Bear" <PABearMVP@gmail.com> schrieb:

> We might /assume/ that
> http://blogs.technet.com/msrc/archiv...ry-935423.aspx
> is related to this Security Bulletin Advanced Notification, but...


.... we *know* that this will be the update to be released. Yes, indeed ;-)

| In light of these points, and based on customer feedback, we have
| been working around the clock to test this update and are currently
| planning to release the security update that addresses this issue on
| Tuesday April 3, 2007.
[...]
| This update was previously scheduled for release as part of the
| April monthly release on April 10, 2007. Due to the increased risk
| to customers from these latest attacks, we were able to expedite
| our testing to ensure an update is ready for broad distribution
| sooner than April 10.

Bye,
Freudi
 
Old 04-02-2007   #9 (permalink)
PA Bear
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

I /swear/ that the content you quoted was *not* on the blog page when I read
it c. 0500 UTC, 02 Apr-07 (c. 10:00 PM Pacific Time, 01 Apr-07) and posted
my reply to this thread, nor did
http://www.microsoft.com/technet/sec...n/advance.mspx contain "On
Tuesday 3 April 2007 Microsoft is planning to release" and below when I
viewed the page around the same time.

/Mea culpa/. <w>
--
~Robear

Ottmar Freudenberger wrote:
> "PA Bear" <PABearMVP@gmail.com> schrieb:
>
>> We might /assume/ that
>> http://blogs.technet.com/msrc/archiv...ry-935423.aspx
>> is related to this Security Bulletin Advanced Notification, but...

>
> ... we *know* that this will be the update to be released. Yes, indeed ;-)
>
>> In light of these points, and based on customer feedback, we have
>> been working around the clock to test this update and are currently
>> planning to release the security update that addresses this issue on
>> Tuesday April 3, 2007.

> [...]
>> This update was previously scheduled for release as part of the
>> April monthly release on April 10, 2007. Due to the increased risk
>> to customers from these latest attacks, we were able to expedite
>> our testing to ensure an update is ready for broad distribution
>> sooner than April 10.

>
> Bye,
> Freudi


 
Old 04-02-2007   #10 (permalink)
Ottmar Freudenberger
Guest
 
Posts: n/a

Re: Microsoft Security Bulletin Advance Notification - April 2007

"PA Bear" <PABearMVP@gmail.com> schrieb:

>I /swear/ that the content you quoted was *not* on the blog page when I read
> it c. 0500 UTC, 02 Apr-07 (c. 10:00 PM Pacific Time, 01 Apr-07) and posted
> my reply to this thread,


Well, are you accessing "the web" via a proxy server? That one may not
have had the actual version of the sit|de. I can only assure you, that
the content didn't change since at least 0245 UTC. Really. I did update
the info on my site at that time and informed some german languaged
newsgroups (news:euq22g.1ao.1@news.messageid.de), ISC and US-CERT after-
wards by mail. Mark H from ISC replied on 0400 UTC that he has updated
the diary (which he really did, although this has been superseded without
further notice by an entry of Kevin dated 1245 UTC lately with the same
content, claiming to be Version 1 of the entry for whatever reason),
while US-CERT played dead man and still doesn't mention the announced
update "planned" to be released via WU/MU/AU some 13 hours or so from now.

> nor did
> http://www.microsoft.com/technet/sec...n/advance.mspx contain "On
> Tuesday 3 April 2007 Microsoft is planning to release" and below when I
> viewed the page around the same time.


See above. I've received the mail announcement of the Advance Notification
on 0142 UTC and it has been there on the web side too at that time (at
least an hour later when I "waked" up).

> /Mea culpa/. <w>


Nothing to apologize for or feel sorry about. It's just strange. Remake
of "X-Files" anyone?

FWIW,
Freudi
 
 
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Security Bulletin Advance Notification for August 2007 Brink Vista News 0 08-10-2007 03:32 AM
Microsoft Security Bulletin Summary for July 2007 Brink System Security 1 07-18-2007 05:18 PM
Microsoft Security Bulletin Advance Notification for July 2007 Donna Buenaventura Vista security 0 07-05-2007 02:27 PM
Microsoft Security Bulletin Summary for June 2007 Brink System Security 0 06-13-2007 11:01 AM
Microsoft Security Bulletin Advance Notification - June 2007 Donna Buenaventura Vista security 1 06-07-2007 11:45 PM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49