Microsoft Vulnerability Research (MSVR) Advisories describe security vulnerabilities that Microsoft or security researchers discovered in third-party products or services, and which Microsoft has disclosed to the affected vendors. Microsoft performs this disclosure to the affected vendor under the procedures described in Coordinated Vulnerability Disclosure.
Apple QuickTime MPEG Parsing Memory Corruption
Published or Last Updated: Thursday, May 17, 2012
Vulnerability in RealNetworks Helix Universal Media Server Could Allow Denial of Service
Published or Last Updated: Tuesday, April 17, 2012
Vulnerabilities in RealNetworks Helix Server Could Allow Arbitrary Script Execution
Published or Last Updated: Tuesday, April 17, 2012
JPEG 2000 Memory Overwrite Vulnerability in OpenJPEG Could Allow Arbitrary Code Execution
Published or Last Updated: Tuesday, March 20, 2012
Vulnerability in DotNetNuke Could Allow Arbitrary Script Execution
Published or Last Updated: Tuesday, February 21, 2012
For the entire list of published MSVR advisories, visit the MSVR Advisory Archive Web site.
Q.<p>What kind of information do MSVR advisories contain?</p>
A.<p>MSVR advisories contain a top-level summary that states the reason for issuing the advisory, frequently asked questions, and suggested actions. MSVR advisories may be revised as required to reflect new information or guidance.</p>
A.<p>Our goal is to issue MSVR advisories for security vulnerabilities after we have disclosed them to the affected vendors, so that the vendors could develop remediation. Customers could then use this remediation to help protect themselves.</p>
Q.<p>Could an MSVR advisory become a security bulletin?</p>
A.<p>No. An MSVR advisory pertains to security vulnerabilities in third-party products or services. A Microsoft security bulletin pertains to security vulnerabilities in Microsoft software.</p>
A.<p>The <a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx"> Microsoft Security Bulletin Advance Notification</a> is about security bulletins that Microsoft is intending to release, and is therefore about vulnerabilities in Microsoft software and their remediation. MSVR advisories, in contrast, are about third-party products and services.</p>
Q.<p>How will customers know when there is a call to action associated with these MSVR advisories?</p>
A.<p>The MSVR advisory has a <strong>Suggested Actions</strong> section for describing any action that users may have to take to help protect themselves.</p>