<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rssdatehelper="urn:rssdatehelper"><channel><title>Microsoft Security Bulletins</title><link>http://technet.microsoft.com/security/bulletin</link><dc:date>Wed, 15 May 2013 08:00:00 GMT</dc:date><generator>umbraco</generator><description></description><language>en-US</language><copyright>Copyright (C) 2011 Microsoft Corporation</copyright><image><link>http://technet.microsoft.com/security/bulletin</link><title>Microsoft Security Bulletins</title><url>http://www.microsoft.com/library/toolbar/3.0/images/banners/TechNetB_masthead_ltr.gif</url><height>42</height><width>225</width></image><item><title>MS13-045 - Important : Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-045</link><dc:date>2013-05-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-045</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (May 15, 2013): Corrected link to the download location in the Detection and Deployment Tools and Guidance section. This is an informational change only.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows Writer. The vulnerability could allow information disclosure if a user opens Writer using a specially crafted URL. An attacker who successfully exploited the vulnerability could override Windows Writer proxy settings and overwrite files accessible to the user on the target system. In a web-based attack scenario, a website could contain a specially crafted link that is used to exploit this vulnerability. An attacker would have to convince users to visit the website and open the specially crafted link.]]></content:encoded></item><item><title>MS13-046 - Important : Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2840221) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-046</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-046</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves three reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs onto the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.]]></content:encoded></item><item><title>MS13-044 - Important : Vulnerability in Microsoft Visio Could Allow Information Disclosure (2834692) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-044</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-044</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow information disclosure if a user opens a specially crafted Visio file. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise an affected system.]]></content:encoded></item><item><title>MS13-043 - Important : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-043</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-043</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted file or previews a specially crafted email message in an affected version of Microsoft Office software. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-042 - Important : Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-042</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-042</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user open a specially crafted Publisher file with an affected version of Microsoft Publisher. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-041 - Important : Vulnerability in Lync Could Allow Remote Code Execution (2834695) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-041</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-041</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Lync. The vulnerability could allow remote code execution if an attacker shares a specially crafted program in a Lync or Communicator session and convinces a user to accept an invitation to launch the program content. In all cases, an attacker would have no way to force users to view or share the attacker-controlled file or program. Instead, an attacker would have to convince users to take action, typically by getting them to accept an invitation in Lync or Communicator to view or share the presentable content.]]></content:encoded></item><item><title>MS13-040 - Important : Vulnerabilities in .NET Framework Could Allow Spoofing (2836440) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-040</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-040</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in the .NET Framework. The more severe of the vulnerabilities could allow spoofing if a .NET application receives a specially crafted XML file. An attacker who successfully exploited the vulnerabilities could modify the contents of an XML file without invalidating the file's signature and could gain access to endpoint functions as if they were an authenticated user.]]></content:encoded></item><item><title>MS13-039 - Important : Vulnerability in HTTP.sys Could Allow Denial of Service (2829254) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-039</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-039</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker sends a specially crafted HTTP packet to an affected Windows server or client.]]></content:encoded></item><item><title>MS13-038 - Critical : Security Update for Internet Explorer (2847204) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-038</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-038</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-037 - Critical : Cumulative Security Update for Internet Explorer (2829530) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-037</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-037</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves eleven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited the most severe of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-009 - Critical : Cumulative Security Update for Internet Explorer (2792100) - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-009</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-009</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.2 (May 14, 2013): Revised this bulletin to announce a detection change to correct an offering issue for Windows Server 2012 (Server Core installation). This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves thirteen privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS12-043 - Critical : Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479) - Version: 4.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-043</link><dc:date>2013-04-26T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-043</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V4.2 (April 26, 2013): Corrected update replacement. This is an informational change only. There were no changes to the security update files or detection logic.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft XML Core Services. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.]]></content:encoded></item><item><title>MS13-036 - Important : Vulnerabilities in Kernel-Mode Driver Could Allow Elevation Of Privilege (2829996) - Version: 3.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-036</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-036</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V3.1 (April 24, 2013): Corrected KB article hyperlink and incorrect KB numbers for Windows 7 for x64-based Systems and Windows Server 2008 R2 for Itanium-based Systems in the Affected Software table. These are bulletin changes only.<br />
          Summary: This security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-031 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2813170) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-031</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-031</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 24, 2013): Corrected update replacement. This is an informational change only. There were no changes to the security update files or detection logic.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.]]></content:encoded></item><item><title>MS13-028 - Critical : Cumulative Security Update for Internet Explorer (2817183) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-028</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-028</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (April 24, 2013): Added CVE-2013-1338 as a vulnerability addressed by this update. In addition, corrected update replacement and clarified why this update replaces MS13-010. These are informational changes only.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Internet Explorer. These vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-034 - Important : Vulnerability in Microsoft Antimalware Client Could Allow Elevation of Privilege (2823482) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-034</link><dc:date>2013-04-16T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-034</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 16, 2013): Bulletin revised to announce a detection change in the 2781197 package to correct a reoffering issue. This is a detection change only. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves a privately reported vulnerability in the Microsoft Antimalware Client. The vulnerability could allow elevation of privilege due to the pathnames used by the Microsoft Antimalware Client. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.]]></content:encoded></item><item><title>MS13-029 - Critical : Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2828223) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-029</link><dc:date>2013-04-10T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-029</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (April 10, 2013): Corrected the version number for Remote Desktop Connection Client on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 from 7.0 to 7.1. This is an informational change only. There were no changes to security update files.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user views a specially crafted webpage. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-035 - Important : Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-035</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-035</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Office. The vulnerability could allow elevation of privilege if an attacker sends specially crafted content to a user.]]></content:encoded></item><item><title>MS13-033 - Important : Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2820917) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-033</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-033</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in all supported editions of Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-032 - Important : Vulnerability in Active Directory Could Lead to Denial of Service (2830914) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-032</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-032</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sends a specially crafted query to the Lightweight Directory Access Protocol (LDAP) service.]]></content:encoded></item><item><title>MS13-030 - Important : Vulnerability in SharePoint Could Allow Information Disclosure (2827663) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-030</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-030</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft SharePoint and Microsoft SharePoint Foundation. The vulnerability could allow information disclosure if an attacker determined the address or location of a specific SharePoint list and gained access to the SharePoint site where the list is maintained. The attacker would need to be able to satisfy the SharePoint site's authentication requests to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-022 - Critical : Vulnerability in Silverlight Could Allow Remote Code Execution (2814124) - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-022</link><dc:date>2013-04-03T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-022</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.2 (April 3, 2013): Updated the Known Issues entry in the Knowledge Base Article section from "None" to "Yes" and clarified that installing the update will upgrade previous versions of Silverlight to Silverlight version 5.1.20125.0.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Silverlight. The vulnerability could allow remote code execution if an attacker hosts a website that contains a specially crafted Silverlight application that could exploit this vulnerability and then convinces a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. Such websites could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit a website. Instead, an attacker would have to convince users to visit a website, typically by getting them to click a link in an email message or in an Instant Messenger message that takes them to the attacker's website. It could also be possible to display specially crafted web content by using banner advertisements or by using other methods to deliver web content to affected systems.]]></content:encoded></item><item><title>MS13-007 - Important : Vulnerability in Open Data Protocol Could Allow Denial of Service (2769327) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-007</link><dc:date>2013-04-03T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-007</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 3, 2013): Added a mitigation to CVE-2013-0005 for systems running Windows Server 2012.<br />
          Summary: This security update resolves a privately reported vulnerability in the Open Data (OData) protocol. The vulnerability could allow denial of service if an unauthenticated attacker sends specially crafted HTTP requests to an affected site. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.]]></content:encoded></item><item><title>MS13-027 - Important : Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2807986) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-027</link><dc:date>2013-03-27T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-027</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (March 27, 2013): Revised bulletin to remove workaround steps for disabling USB mass storage devices because these steps are not necessary to block known attack vectors. Revised bulletin to remove workaround steps for disabling USB mass storage devices because these steps are not necessary to block known attack vectors. For more information, see Update FAQ.<br />
          Summary: This security update resolves three privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow elevation of privilege if an attacker gains access to a system.]]></content:encoded></item><item><title>MS13-026 - Important : Vulnerability in Microsoft Office for Mac Could Allow Information Disclosure (2813682) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-026</link><dc:date>2013-03-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-026</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (March 15, 2013): Corrected bulletin title and clarified affected version names in the vulnerability details and vulnerability FAQs.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Office for Mac. The vulnerability could allow information disclosure if a user opens a specially crafted email message.]]></content:encoded></item><item><title>MS13-023 - Critical : Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2801261) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-023</link><dc:date>2013-03-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-023</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (March 15, 2013): Clarified language in the vulnerability FAQ, How could an attacker exploit the vulnerability?<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-025 - Important : Vulnerability in Microsoft OneNote Could Allow Information Disclosure (2816264) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-025</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-025</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft OneNote. The vulnerability could allow information disclosure if an attacker convinces a user to open a specially crafted OneNote file.]]></content:encoded></item><item><title>MS13-024 - Critical : Vulnerabilities in SharePoint Could Allow Elevation of Privilege (2780176) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-024</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-024</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves four privately reported vulnerabilities in Microsoft SharePoint and Microsoft SharePoint Foundation. The most severe vulnerabilities could allow elevation of privilege if a user clicks a specially crafted URL that takes the user to a targeted SharePoint site.]]></content:encoded></item><item><title>MS13-021 - Critical : Cumulative Security Update for Internet Explorer (2809289) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-021</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-021</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves eight privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-003 - Important : Vulnerabilities in System Center Operations Manager Could Allow Elevation of Privilege (2748552) - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-003</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-003</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V2.0 (March 12, 2013): Rereleased this bulletin to announce availability of an update for Microsoft System Center Operations Manager 2007 Service Pack 1. No other update packages are affected by this rerelease.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft System Center Operations Manager. The vulnerabilities could allow elevation of privilege if a user visits an affected website by way of a specially crafted URL. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the affected website.]]></content:encoded></item><item><title>MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) - Version: 1.6</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-034</link><dc:date>2013-03-06T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-034</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.6 (March 6, 2013): Corrected update replacement information for the KB2676562 update.<br />
          Summary: This security update resolves three publicly disclosed vulnerabilities and seven privately reported vulnerabilities in Microsoft Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.]]></content:encoded></item><item><title>MS13-020 - Critical : Vulnerability in OLE Automation Could Allow Remote Code Execution (2802968) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-020</link><dc:date>2013-02-13T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-020</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (February 13, 2012): Clarified in the vulnerability FAQ what systems are primarily at risk for CVE-2013-1313. This is an informational change only.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code execution if a user opens a specially crafted file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-012 - Critical : Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2809279) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-012</link><dc:date>2013-02-13T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-012</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (February 13, 2013): Clarified that Microsoft Exchange Server 2010 Service Pack 3 is not affected by the vulnerabilities described in this bulletin. This is an informational change only.<br />
          Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document Viewing, and could allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA). The transcoding service in Exchange that is used for WebReady Document Viewing is running in the LocalService account. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.]]></content:encoded></item><item><title>MS13-019 - Important : Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2790113) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-019</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-019</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-018 - Important : Vulnerability in TCP/IP Could Allow Denial of Service (2790655) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-018</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-018</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2790655 under Known Issues<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an unauthenticated attacker sends a specially crafted connection termination packet to the server.]]></content:encoded></item><item><title>MS13-017 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2799494) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-017</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-017</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2799494 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves three privately reported vulnerabilities in all supported releases of Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-016 - Important : Vulnerabilities in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778344) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-016</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-016</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2778344 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves 30 privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-015 - Important : Vulnerability in .NET Framework Could Allow Elevation of Privilege (2800277) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-015</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-015</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in the .NET Framework. The vulnerability could allow elevation of privilege if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). The vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-014 - Important : Vulnerability in NFS Server Could Allow Denial of Service (2790978) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-014</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-014</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013) Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker attempts a file operation on a read only share. An attacker who exploited this vulnerability could cause the affected system to stop responding and restart. The vulnerability only affects Windows servers with the NFS role enabled.]]></content:encoded></item><item><title>MS13-013 - Important : Vulnerabilities in FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution (2784242) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-013</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-013</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft FAST Search Server 2010 for SharePoint. The vulnerabilities could allow remote code execution in the security context of a user account with a restricted token. FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled.]]></content:encoded></item><item><title>MS13-011 - Critical : Vulnerability in Media Decompression Could Allow Remote Code Execution (2780091) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-011</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-011</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (February 12, 2013) Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted media file (such as an .mpg file), opens a Microsoft Office document (such as a .ppt file) that contains a specially crafted embedded media file, or receives specially crafted streaming content. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-010 - Critical : Vulnerability in Vector Markup Language Could Allow Remote Code Execution (2797052) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-010</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-010</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2797052 under Known Issues in the Executive Summary. In addition, corrected the FAQ entry for Internet Explorer 10 Release Preview for Windows 7 and Windows Server 2008 R2.<br />
          Summary: This security update resolves a privately reported vulnerability in the Microsoft implementation of Vector Markup Language (VML). The vulnerability could allow remote code execution if a user viewed a specially crafted webpage using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-006 - Important : Vulnerability in Microsoft Windows Could Allow Security Feature Bypass (2785220) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-006</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-006</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2785220 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves a privately reported vulnerability in the implementation of SSL and TLS in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker intercepts encrypted web traffic handshakes. ]]></content:encoded></item><item><title>MS13-005 - Important : Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778930) - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-005</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-005</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.2 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2778930 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application.]]></content:encoded></item><item><title>MS13-004 - Important : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2769324) - Version: 2.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-004</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-004</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V2.1 (February 12, 2013): Bulletin revised to announce a detection change in the .NET Framework 1.1 Service Pack 1 update (KB2742597) to correct a Windows Update reoffering issue on certain systems that are running supported editions of Windows Vista or Windows Server 2008. This is a detection change only. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves four privately reported vulnerabilities in the .NET Framework. The most severe of these vulnerabilities could allow elevation of privilege if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). The vulnerabilities could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS12-060 - Critical : Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573) - Version: 2.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-060</link><dc:date>2013-01-30T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-060</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V2.1 (January 30, 2013): Clarified that customers with the KB2687323 update will be offered the KB2726929 update for Windows common controls on all affected variants of Microsoft Office 2003, Microsoft Office 2003 Web Components, and Microsoft SQL Server 2005. See the update FAQ for details.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows common controls. The vulnerability could allow remote code execution if a user visits a website containing specially crafted content designed to exploit the vulnerability. In all cases, however, an attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website. The malicious file could be sent as an email attachment as well, but the attacker would have to convince the user to open the attachment in order to exploit the vulnerability.]]></content:encoded></item><item><title>MS12-057 - Important : Vulnerability in Microsoft Office Could Allow Remote Code Execution (2731879) - Version: 2.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-057</link><dc:date>2013-01-30T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-057</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V2.1 (January 30, 2013): Clarified that customers with the KB2553260 and KB2589322 updates will be offered the KB2687501 and KB2687510 updates respectively for Microsoft Office 2010 Service Pack 1. See the update FAQ for details.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted file or embeds a specially crafted Computer Graphics Metafile (CGM) graphics file into an Office file. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-008 - Critical : Security Update for Internet Explorer (2799329) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-008</link><dc:date>2013-01-14T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-008</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (January 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited this vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-002 - Critical : Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (2756145) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-002</link><dc:date>2013-01-08T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-002</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (January 8, 2013): Corrected download links for Microsoft XML Core Services 3.0 on Windows Server 2003 with SP2 for Itanium-based Systems and for Microsoft XML Core Services 6.0 when installed on Windows Server 2003 with SP2 for Itanium-based Systems. Added Server Core installation entries to Affected Software for Microsoft XML Core Services 4.0 when installed on Windows Server 2008 for 32-bit Systems Service Pack 2 and Microsoft XML Core Services 6.0 on Windows Server 2008 for 32-bit Systems Service Pack 2. These are informational changes only. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft XML Core Services. The vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes the user to the attacker's website.]]></content:encoded></item><item><title>MS13-001 - Critical : Vulnerability in Windows Print Spooler Components Could Allow Remote Code Execution (2769369) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-001</link><dc:date>2013-01-08T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-001</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (January 8, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a print server received a specially crafted print job. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems connected directly to the Internet have a minimal number of ports exposed.]]></content:encoded></item></channel></rss>