<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rssdatehelper="urn:rssdatehelper"><channel><title>Microsoft Security Content: Comprehensive Edition</title><link>http://technet.microsoft.com/security/bulletin</link><dc:date>Wed, 15 May 2013 08:00:00 GMT</dc:date><generator>umbraco</generator><description>Microsoft Security Content: Comprehensive Edition</description><language>en-US</language><item><title>MS13-045 - Important : Vulnerability in Windows Essentials Could Allow Information Disclosure (2813707) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-045</link><dc:date>2013-05-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-045</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (May 15, 2013): Corrected link to the download location in the Detection and Deployment Tools and Guidance section. This is an informational change only.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows Writer. The vulnerability could allow information disclosure if a user opens Writer using a specially crafted URL. An attacker who successfully exploited the vulnerability could override Windows Writer proxy settings and overwrite files accessible to the user on the target system. In a web-based attack scenario, a website could contain a specially crafted link that is used to exploit this vulnerability. An attacker would have to convince users to visit the website and open the specially crafted link.]]></content:encoded></item><item><title>Microsoft Security Advisory (2846338): Vulnerability in Microsoft Malware Protection Engine Could Allow Remote Code Execution - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2846338</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2846338</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (May 14, 2013): Advisory published.<br />
          Summary: Microsoft is releasing this security advisory to help ensure customers are aware that an update to the Microsoft Malware Protection Engine also addresses a security vulnerability reported to Microsoft. The update addresses a vulnerability that could allow remote code execution if the Microsoft Malware Protection Engine scans a specially crafted file. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take complete control of the system.]]></content:encoded></item><item><title>Microsoft Security Advisory (2820197): Update Rollup for ActiveX Kill Bits - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2820197</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2820197</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (May 14, 2013): Advisory published.<br />
          Summary: Microsoft is releasing a new set of ActiveX kill bits with this advisory.]]></content:encoded></item><item><title>MS13-046 - Important : Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2840221) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-046</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-046</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves three reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs onto the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.]]></content:encoded></item><item><title>MS13-044 - Important : Vulnerability in Microsoft Visio Could Allow Information Disclosure (2834692) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-044</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-044</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow information disclosure if a user opens a specially crafted Visio file. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise an affected system.]]></content:encoded></item><item><title>MS13-043 - Important : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-043</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-043</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted file or previews a specially crafted email message in an affected version of Microsoft Office software. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-042 - Important : Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-042</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-042</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user open a specially crafted Publisher file with an affected version of Microsoft Publisher. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-041 - Important : Vulnerability in Lync Could Allow Remote Code Execution (2834695) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-041</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-041</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Lync. The vulnerability could allow remote code execution if an attacker shares a specially crafted program in a Lync or Communicator session and convinces a user to accept an invitation to launch the program content. In all cases, an attacker would have no way to force users to view or share the attacker-controlled file or program. Instead, an attacker would have to convince users to take action, typically by getting them to accept an invitation in Lync or Communicator to view or share the presentable content.]]></content:encoded></item><item><title>MS13-040 - Important : Vulnerabilities in .NET Framework Could Allow Spoofing (2836440) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-040</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-040</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in the .NET Framework. The more severe of the vulnerabilities could allow spoofing if a .NET application receives a specially crafted XML file. An attacker who successfully exploited the vulnerabilities could modify the contents of an XML file without invalidating the file's signature and could gain access to endpoint functions as if they were an authenticated user.]]></content:encoded></item><item><title>MS13-039 - Important : Vulnerability in HTTP.sys Could Allow Denial of Service (2829254) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-039</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-039</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker sends a specially crafted HTTP packet to an affected Windows server or client.]]></content:encoded></item><item><title>MS13-038 - Critical : Security Update for Internet Explorer (2847204) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-038</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-038</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves one publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-037 - Critical : Cumulative Security Update for Internet Explorer (2829530) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-037</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-037</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (May 14, 2013): Bulletin published.<br />
          Summary: This security update resolves eleven privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited the most severe of these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title> Summary for May 2013 - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-may</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-may</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (May 14, 2013): Bulletin Summary published.<br />
          Summary: This bulletin summary lists security bulletins released for May 2013.]]></content:encoded></item><item><title>Microsoft Security Advisory (2847140): Vulnerability in Internet Explorer Could Allow Remote Code Execution - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2847140</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2847140</guid><content:encoded><![CDATA[
            Revision Note: V2.0 (May 14, 2013): Advisory updated to reflect publication of security bulletin.<br />
          Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS13-038 to address this issue. For more information about this issue, including download links for an available security update, please review MS13-038. The vulnerability addressed is the Internet Explorer Use After Free Vulnerability - CVE-2013-1347.]]></content:encoded></item><item><title>MS13-009 - Critical : Cumulative Security Update for Internet Explorer (2792100) - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-009</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-009</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.2 (May 14, 2013): Revised this bulletin to announce a detection change to correct an offering issue for Windows Server 2012 (Server Core installation). This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves thirteen privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>Microsoft Security Advisory (2755801): Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10 - Version: 12.1</title><link>http://technet.microsoft.com/en-us/security/advisory/2755801</link><dc:date>2013-05-14T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2755801</guid><content:encoded><![CDATA[
            Revision Note: V12.1 (May 14, 2013): Revised advisory to show the correct update and KB article numbers for update 2837385 released on May 14, 2013.<br />
          Summary: Microsoft is aware of vulnerabilities in Adobe Flash Player in Internet Explorer 10 on all supported editions of Windows 8, Windows Server 2012, and Windows RT. Microsoft provides updates that address the vulnerabilities in Adobe Flash Player by updating the affected Adobe Flash libraries contained within Internet Explorer 10.]]></content:encoded></item><item><title>MS12-043 - Critical : Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479) - Version: 4.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-043</link><dc:date>2013-04-26T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-043</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V4.2 (April 26, 2013): Corrected update replacement. This is an informational change only. There were no changes to the security update files or detection logic.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft XML Core Services. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.]]></content:encoded></item><item><title>MS13-036 - Important : Vulnerabilities in Kernel-Mode Driver Could Allow Elevation Of Privilege (2829996) - Version: 3.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-036</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-036</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V3.1 (April 24, 2013): Corrected KB article hyperlink and incorrect KB numbers for Windows 7 for x64-based Systems and Windows Server 2008 R2 for Itanium-based Systems in the Affected Software table. These are bulletin changes only.<br />
          Summary: This security update resolves three privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Windows. The most severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-031 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2813170) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-031</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-031</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 24, 2013): Corrected update replacement. This is an informational change only. There were no changes to the security update files or detection logic.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.]]></content:encoded></item><item><title>MS13-028 - Critical : Cumulative Security Update for Internet Explorer (2817183) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-028</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-028</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (April 24, 2013): Added CVE-2013-1338 as a vulnerability addressed by this update. In addition, corrected update replacement and clarified why this update replaces MS13-010. These are informational changes only.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Internet Explorer. These vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title> Summary for April 2013 - Version: 3.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-apr</link><dc:date>2013-04-24T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-apr</guid><content:encoded><![CDATA[
            Revision Note: V3.1 (April 24, 2013): For MS13-028, added an Exploitability Assessment in the Exploitability Index for CVE-2013-1338. This is an informational change only.<br />
          Summary: This bulletin summary lists security bulletins released for April 2013.]]></content:encoded></item><item><title>MS13-034 - Important : Vulnerability in Microsoft Antimalware Client Could Allow Elevation of Privilege (2823482) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-034</link><dc:date>2013-04-16T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-034</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 16, 2013): Bulletin revised to announce a detection change in the 2781197 package to correct a reoffering issue. This is a detection change only. Customers who have already successfully updated their systems do not need to take any action.<br />
          Summary: This security update resolves a privately reported vulnerability in the Microsoft Antimalware Client. The vulnerability could allow elevation of privilege due to the pathnames used by the Microsoft Antimalware Client. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.]]></content:encoded></item><item><title>MS13-029 - Critical : Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2828223) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-029</link><dc:date>2013-04-10T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-029</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (April 10, 2013): Corrected the version number for Remote Desktop Connection Client on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 from 7.0 to 7.1. This is an informational change only. There were no changes to security update files.<br />
          Summary: This security update resolves a privately reported vulnerability in Windows Remote Desktop Client. The vulnerability could allow remote code execution if a user views a specially crafted webpage. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-035 - Important : Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-035</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-035</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Office. The vulnerability could allow elevation of privilege if an attacker sends specially crafted content to a user.]]></content:encoded></item><item><title>MS13-033 - Important : Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2820917) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-033</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-033</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in all supported editions of Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-032 - Important : Vulnerability in Active Directory Could Lead to Denial of Service (2830914) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-032</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-032</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Active Directory. The vulnerability could allow denial of service if an attacker sends a specially crafted query to the Lightweight Directory Access Protocol (LDAP) service.]]></content:encoded></item><item><title>MS13-030 - Important : Vulnerability in SharePoint Could Allow Information Disclosure (2827663) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-030</link><dc:date>2013-04-09T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-030</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (April 9, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft SharePoint and Microsoft SharePoint Foundation. The vulnerability could allow information disclosure if an attacker determined the address or location of a specific SharePoint list and gained access to the SharePoint site where the list is maintained. The attacker would need to be able to satisfy the SharePoint site's authentication requests to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-022 - Critical : Vulnerability in Silverlight Could Allow Remote Code Execution (2814124) - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-022</link><dc:date>2013-04-03T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-022</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.2 (April 3, 2013): Updated the Known Issues entry in the Knowledge Base Article section from "None" to "Yes" and clarified that installing the update will upgrade previous versions of Silverlight to Silverlight version 5.1.20125.0.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Silverlight. The vulnerability could allow remote code execution if an attacker hosts a website that contains a specially crafted Silverlight application that could exploit this vulnerability and then convinces a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. Such websites could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit a website. Instead, an attacker would have to convince users to visit a website, typically by getting them to click a link in an email message or in an Instant Messenger message that takes them to the attacker's website. It could also be possible to display specially crafted web content by using banner advertisements or by using other methods to deliver web content to affected systems.]]></content:encoded></item><item><title>MS13-007 - Important : Vulnerability in Open Data Protocol Could Allow Denial of Service (2769327) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-007</link><dc:date>2013-04-03T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-007</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (April 3, 2013): Added a mitigation to CVE-2013-0005 for systems running Windows Server 2012.<br />
          Summary: This security update resolves a privately reported vulnerability in the Open Data (OData) protocol. The vulnerability could allow denial of service if an unauthenticated attacker sends specially crafted HTTP requests to an affected site. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.]]></content:encoded></item><item><title>MS13-027 - Important : Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2807986) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-027</link><dc:date>2013-03-27T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-027</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (March 27, 2013): Revised bulletin to remove workaround steps for disabling USB mass storage devices because these steps are not necessary to block known attack vectors. Revised bulletin to remove workaround steps for disabling USB mass storage devices because these steps are not necessary to block known attack vectors. For more information, see Update FAQ.<br />
          Summary: This security update resolves three privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow elevation of privilege if an attacker gains access to a system.]]></content:encoded></item><item><title>Microsoft Security Advisory (2819682): Security Updates for Microsoft Windows Store Applications - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/advisory/2819682</link><dc:date>2013-03-26T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/advisory/2819682</guid><content:encoded><![CDATA[
            Revision Note: V1.0 (March 26, 2013): Announced availability of update 2832006 for Windows Modern Mail.<br />
          Summary: Microsoft is announcing the availability of security updates for Windows Store applications running on Windows 8, Windows RT, and Windows Server 2012 (Windows Server 2012 Server Core installations are not affected). The updates address vulnerabilities that are detailed in the Knowledge Base articles associated with each update.]]></content:encoded></item><item><title>MS13-026 - Important : Vulnerability in Microsoft Office for Mac Could Allow Information Disclosure (2813682) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-026</link><dc:date>2013-03-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-026</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (March 15, 2013): Corrected bulletin title and clarified affected version names in the vulnerability details and vulnerability FAQs.<br />
          Summary: This security update resolves one privately reported vulnerability in Microsoft Office for Mac. The vulnerability could allow information disclosure if a user opens a specially crafted email message.]]></content:encoded></item><item><title>MS13-023 - Critical : Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2801261) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-023</link><dc:date>2013-03-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-023</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (March 15, 2013): Clarified language in the vulnerability FAQ, How could an attacker exploit the vulnerability?<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted Visio file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title> Summary for March 2013 - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-mar</link><dc:date>2013-03-15T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-mar</guid><content:encoded><![CDATA[
            Revision Note: V1.1 (March 15, 2013) For MS13-026, corrected bulletin title in the Executive Summaries section.<br />
          Summary: This bulletin summary lists security bulletins released for March 2013.]]></content:encoded></item><item><title>MS13-025 - Important : Vulnerability in Microsoft OneNote Could Allow Information Disclosure (2816264) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-025</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-025</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft OneNote. The vulnerability could allow information disclosure if an attacker convinces a user to open a specially crafted OneNote file.]]></content:encoded></item><item><title>MS13-024 - Critical : Vulnerabilities in SharePoint Could Allow Elevation of Privilege (2780176) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-024</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-024</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves four privately reported vulnerabilities in Microsoft SharePoint and Microsoft SharePoint Foundation. The most severe vulnerabilities could allow elevation of privilege if a user clicks a specially crafted URL that takes the user to a targeted SharePoint site.]]></content:encoded></item><item><title>MS13-021 - Critical : Cumulative Security Update for Internet Explorer (2809289) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-021</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-021</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.0 (March 12, 2013): Bulletin published.<br />
          Summary: This security update resolves eight privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-003 - Important : Vulnerabilities in System Center Operations Manager Could Allow Elevation of Privilege (2748552) - Version: 2.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-003</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-003</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V2.0 (March 12, 2013): Rereleased this bulletin to announce availability of an update for Microsoft System Center Operations Manager 2007 Service Pack 1. No other update packages are affected by this rerelease.<br />
          Summary: This security update resolves two privately reported vulnerabilities in Microsoft System Center Operations Manager. The vulnerabilities could allow elevation of privilege if a user visits an affected website by way of a specially crafted URL. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the affected website.]]></content:encoded></item><item><title> Summary for January 2013 - Version: 4.0 </title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-jan</link><dc:date>2013-03-12T07:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-jan</guid><content:encoded><![CDATA[
            Revision Note: V4.0 (March 12, 2013): For MS13-003, bulletin rereleased to announce the availability of an update for Microsoft System Center Operations Manager 2007 Service Pack 1. No other update packages are affected by this rerelease. See the bulletin for more information.<br />
          Summary: This bulletin summary lists security bulletins released for January 2013.]]></content:encoded></item><item><title>MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) - Version: 1.6</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms12-034</link><dc:date>2013-03-06T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms12-034</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.6 (March 6, 2013): Corrected update replacement information for the KB2676562 update.<br />
          Summary: This security update resolves three publicly disclosed vulnerabilities and seven privately reported vulnerabilities in Microsoft Office, Microsoft Windows, the Microsoft .NET Framework, and Microsoft Silverlight. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a malicious webpage that embeds TrueType font files. An attacker would have no way to force users to visit a malicious website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes them to the attacker's website.]]></content:encoded></item><item><title>MS13-020 - Critical : Vulnerability in OLE Automation Could Allow Remote Code Execution (2802968) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-020</link><dc:date>2013-02-13T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-020</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (February 13, 2012): Clarified in the vulnerability FAQ what systems are primarily at risk for CVE-2013-1313. This is an informational change only.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation. The vulnerability could allow remote code execution if a user opens a specially crafted file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-012 - Critical : Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2809279) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-012</link><dc:date>2013-02-13T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-012</guid><content:encoded><![CDATA[
            Severity Rating: Critical<br />
            Revision Note: V1.1 (February 13, 2013): Clarified that Microsoft Exchange Server 2010 Service Pack 3 is not affected by the vulnerabilities described in this bulletin. This is an informational change only.<br />
          Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document Viewing, and could allow remote code execution in the security context of the transcoding service on the Exchange server if a user previews a specially crafted file using Outlook Web App (OWA). The transcoding service in Exchange that is used for WebReady Document Viewing is running in the LocalService account. The LocalService account has minimum privileges on the local computer and presents anonymous credentials on the network.]]></content:encoded></item><item><title> Summary for February 2013 - Version: 1.2</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-feb</link><dc:date>2013-02-13T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-feb</guid><content:encoded><![CDATA[
            Revision Note: V1.2 (February 13, 2013): For MS13-014, corrected the Exploitability Assessment for Latest Software Release in the Exploitability Index for CVE-2013-1281.<br />
          Summary: This bulletin summary lists security bulletins released for February 2013.]]></content:encoded></item><item><title>MS13-019 - Important : Vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) Could Allow Elevation of Privilege (2790113) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-019</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-019</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.]]></content:encoded></item><item><title>MS13-018 - Important : Vulnerability in TCP/IP Could Allow Denial of Service (2790655) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-018</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-018</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2790655 under Known Issues<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an unauthenticated attacker sends a specially crafted connection termination packet to the server.]]></content:encoded></item><item><title>MS13-017 - Important : Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2799494) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-017</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-017</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2799494 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves three privately reported vulnerabilities in all supported releases of Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-016 - Important : Vulnerabilities in Windows Kernel-Mode Driver Could Allow Elevation of Privilege (2778344) - Version: 1.1</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-016</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-016</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.1 (February 12, 2013): Added a link to Microsoft Knowledge Base Article 2778344 under Known Issues in the Executive Summary.<br />
          Summary: This security update resolves 30 privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerabilities.]]></content:encoded></item><item><title>MS13-015 - Important : Vulnerability in .NET Framework Could Allow Elevation of Privilege (2800277) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-015</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-015</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves one privately reported vulnerability in the .NET Framework. The vulnerability could allow elevation of privilege if a user views a specially crafted webpage using a web browser that can run XAML Browser Applications (XBAPs). The vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.]]></content:encoded></item><item><title>MS13-014 - Important : Vulnerability in NFS Server Could Allow Denial of Service (2790978) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-014</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-014</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013) Bulletin published.<br />
          Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow denial of service if an attacker attempts a file operation on a read only share. An attacker who exploited this vulnerability could cause the affected system to stop responding and restart. The vulnerability only affects Windows servers with the NFS role enabled.]]></content:encoded></item><item><title>MS13-013 - Important : Vulnerabilities in FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution (2784242) - Version: 1.0</title><link>http://technet.microsoft.com/en-us/security/bulletin/ms13-013</link><dc:date>2013-02-12T08:00:00.0000000Z</dc:date><guid>http://technet.microsoft.com/en-us/security/bulletin/ms13-013</guid><content:encoded><![CDATA[
            Severity Rating: Important<br />
            Revision Note: V1.0 (February 12, 2013): Bulletin published.<br />
          Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft FAST Search Server 2010 for SharePoint. The vulnerabilities could allow remote code execution in the security context of a user account with a restricted token. FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled.]]></content:encoded></item></channel></rss>