Microsoft Announces Out-of-Band Patch for Internet Explorer Zero Day Exploit

Microsoft has just updated their advanced notification page for January 2010. They will be releasing an out-of-band patch for the Internet Explorer zero day exploit tomorrow, January 21.

More information can be found here.

They have also updated the Security Advisory with more details and clarification around the vulnerability.

New Patch Data Available (1.1.3.5284)

XML data version = 1.1.3.5284 Last modified on 01/19/2010

Security

– Updated SUN-JAVA(QJAVA60): Sun Java JRE 6 Update 18.

Non Security

– Added MSWU-368(Q973917): Description of the update that implements Extended Protection for Authentication in Internet Information Services (IIS).

– Added MSWU-372(Q978551): Update for Microsoft Office 2003 (KB978551).

Revisions

– Modified MSWU-357(Q970430): Fixed an issue where patch would show as missing after installation of KB973917.

New Patch Data Available (1.1.3.5274)

XML data version = 1.1.3.5274 Last modified on 01/13/2010

Products

– Added support for Acrobat Reader 9.3.0.

– Added support for Acrobat Reader 8.2.0.

– Added support for Adobe Acrobat 9.3.0 Professional.

– Added support for Adobe Acrobat 9.3.0 Standard.

– Added support for Adobe Acrobat 9.3.0 Pro Extended.

– Added support for Adobe Acrobat 8.2.0 Professional.

– Added support for Adobe Acrobat 8.2.0 Standard.

Security

– Added APSB-1002(QAR0930): Security Updates Available for Adobe Reader and Acrobat.

Non Security

– Added MSWU-370(Q977839): Office Outlook 2007 Junk E-mail Filter update: January 12, 2010.

– Added MSWU-371(Q977840): Office Outlook 2003 Junk E-mail Filter update: January 12, 2010.

New Patch Data Available (1.1.3.5266)

XML data version = 1.1.3.5266 Last modified on 01/07/2010

Products

– Added support for Firefox 3.5.7.

– Added support for Firefox 3.0.17.

Security

– Added FF10-001(QFF3570): Firefox 3.5.7.

– Added FF10-002(QFF3171): Firefox 3.0.17.

– Added Windows XP Embedded Security patches.

Non Security

– Added MSWU-369(Q978557): Update for Microsoft Office Excel Viewer 2003 (KB978557).

– Added MSWU-270(Q959108): An update is available that disables the collection and transfer of Software Quality Metrics data by the Windows Portable Device (WPD) API.

Revisions

– Modified MSWU-356(Q976098): Fixed an issue where patch would show as missing after installation.

New Patch Data Available (1.1.3.5254)

XML data version = 1.1.3.5254 Last modified on 01/05/2010

Non Security

– Added MSWU-364(Q971513): This updates Windows Automation API.

Revisions

– Modified MS05-053 (Q896424): Updated v2 revision of Windows Server 2003 package.

– Modified MSWU-347 (Q972145): Fixed patch deployment issues on systems running window server 2008.

– Modified MSWU-352 (Q976470): Fixed patch deployment issues on systems running window server 2008.

New Patch Data Available (1.1.3.5250)

XML data version = 1.1.3.5250 Last modified on 12/30/2009

Non Security

– Added MSWU-365 (Q976573): Update Rollup 1 for Exchange Server 2010 (KB976573).

– Added MSWU-366 (Q971737): Description of the update that implements Extended Protection for Authentication in Microsoft Windows HTTP Services (WinHTTP).

– Added MSWU-367 (Q970430): Description of the update that implements Extended Protection for Authentication in the HTTP Protocol Stack (http.sys).

Revisions

– Modified MS09-062 (Q972222): Fixed an issue where patch did not show as missing on systems running Microsoft Visual Studio 2008 Shell.

– Modified MS09-070 (Q971726): Fixed an issue where patch showed as missing on systems not running Active Directory FS.

New Patch Data Available (1.1.3.5244)

XML data version = 1.1.3.5244 Last modified on 12/23/2009

Products

– Added support for Exchange Server 2010.

– Added support for Adobe Flash Player 9.0.260.0.

Security

– Added APSB-0919 (QAF9260): Adobe Flash Player 9.0.260.0.

Non Security

– Added MS09-A05 (Q955759): Microsoft Security Advisory: Description of the AppCompat update for Indeo codec: December 08, 2009.

– Added MSWU-355(Q976092): An update is available for Windows 7 to fix a data corruption issue for Secure Digital (SD) cards.

– Added MSWU-362(Q973685): When an application uses MSXML to process XHTML, redundant retrieval requests for well-known DTD files from the W3C Web server cause XHTML parsing to fail on a Windows-based computer.

– Added MSWU-363(Q975364): A Compatibility View list update is available for Windows Internet Explorer 8: October 27, 2009.

Revisions

– Modified MS09-074 (Q961079): Fixed an issue where patch would show as missing after installation.

– Modified MS08-072 (Q956358): Fixed an issue where patch would show as missing twice on some systems.

– Modified MSWU-341 (Q963678): Fixed an issue where patch would show as missing after installation on some systems.

– Modified MSWU-342 (Q963677): Fixed an issue where patch would show as missing after installation on some systems.

– Modified MSWU-343 (Q963665): Fixed an issue where patch would show as missing after installation on some systems.

– Modified MSWU-344 (Q963669): Fixed an issue where patch would show as missing after installation on some systems.

– Modified MSWU-345 (Q963673): Fixed an issue where patch would show as missing after installation on some systems.

– Modified MSWU-346 (Q963671): Fixed an issue where patch would show as missing after installation on some systems.

New Patch Data Available (1.1.3.5234)

XML data version = 1.1.3.5234 Last modified on 12/17/2009

Products

– Added support for Firefox 3.5.6.

– Added support for Firefox 3.0.16.

Security

– Added FF09-017 (QFF3560): Firefox 3.5.6.

– Added FF09-018 (QFF3161): Firefox 3.0.16.

Non Security

– Added MSWU-358 (Q976882): Outlook 2003 Junk E-mail Filter update: December 08, 2009.

– Added MSWU-359 (Q976884): Outlook 2007 Junk E-mail Filter update: December 08, 2009.

– Added MSWU-360 (Q973686): When an application uses MSXML to process XHTML, redundant retrieval requests for well-known DTD files from the W3C Web server cause XHTML parsing to fail on a Windows-based computer.

– Added MSWU-361 (Q973687): When an application uses MSXML to process XHTML, redundant retrieval requests for well-known DTD files from the W3C Web server cause XHTML parsing to fail on a Windows-based computer.

Revisions

– Modified MSWU-218 (Q947518): Fixed an issue where patch would show as missing after installation of MS09-072 on some systems.

– Modified MSWU-210 (Q938371): Fixed an issue where patch would show as missing after installation on systems running Vista Gold.

– Modified MSWU-329 (Q938371): Fixed an issue where patch would not deploy correctly on some systems running Windows Vista.

New Patch Data Available (1.1.3.5224)

XML data version = 1.1.3.5224 Last modified on 12/11/2009

Products

– Added support for Business Contact Manager for Outlook 2003 SP1.

– Added support for Microsoft Office Outlook 2003 with Business Contact Manager Update.

– Added support for BizTalk 2006.

Revisions

– Modified MSRC-001 (Q931125): Update for Root Certificates [November 2009].

– Modified MSWU-348 (Q976749): Fixed an issue where patch would show as missing after installation of MS09-072.

– Modified MS07-063 (Q942624): Fixed an issue where patch would show as missing after installation of MS09-050.

– Modified MSWU-215 (Q943899): Fixed an issue where patch would show as missing after installation of later patch that updates oleaut32.dll.

– Modified MSWU-352 (Q976470): Fixed an issue where patch could not be downloaded on some systems.

– Modified MSWU-356 (Q976098): Fixed an issue where patch was not detected correctly on foreign langague machines.

New Patch Data Available (1.1.3.5220)

XML data version = 1.1.3.5220 Last modified on 12/8/2009

Security

MS09-069: Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)

MS09-070: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)

MS09-071: Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)

MS09-072: Cumulative Security Update for Internet Explorer (976325)

MS09-073: Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)

MS09-074: Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)

– Added APSB-0919 (QAF1042): Security updates available for Adobe Flash Player.

Revisions

– Modified MS08-037 (Q951748): Microsoft rereleased this bulletin to reoffer the update for the DNS client on Microsoft Windows 2000 Service Pack 4.

Non Security

– Added MSWU-356 (Q976098): December 2009 cumulative time zone update for Microsoft Windows operating systems.

– Added MSWU-357 (Q974431): An update is available to improve the stability and reliability of Windows 7 and of Windows Server 2008 R2.

New Patch Data Available (1.1.3.5202)

XML data version = 1.1.3.5202 Last modified on 12/03/2009

Products

– Added support for Windows XP Embedded SP2.

– Added support for Windows XP Embedded SP2 Feature Pack 2007.

– Added support for Windows XP Embedded SP2 Update Rollup 1.

– Added support for Windows XP Embedded SP3.

Non Security

– Added MSWU-353 (Q973688): When an application uses MSXML to process XHTML, redundant retrieval requests for well-known DTD files from the W3C Web server cause XHTML parsing to fail on a Windows-based computer.

– Added MSWU-354 (Q971534): Update Rollup 1 for Exchange Server 2007 Service Pack 2 (KB971534).

New Patch Data Available (1.1.3.5194)

XML data version = 1.1.3.5194 Last modified on 11/24/2009

Products

– Added support for QuickTime 7.6.5.

Security

– Added AQ09-004 (QAQ7650): QuickTime 7.6.5.

Revisions

– Modified MSWU-342 (Q963677):   Fixed an issue where patches were not properly detected on some Windows x64 systems.

– Modified MSWU-343 (Q963665):   Fixed an issue where patches were not properly detected on some Windows x64 systems.

– Modified MSWU-344 (Q963669):   Fixed an issue where patches were not properly detected on some Windows x64 systems.

– Modified MSWU-345 (Q963673):   Fixed an issue where patches were not properly detected on some Windows x64 systems.

– Modified MSWU-346 (Q963671):   Fixed an issue where patches were not properly detected on some Windows x64 systems.

– Modified MS09-055 (Q973525):  Fixed an issue where this patch was incorrectly showing as needed on Windows Server 2008 Core.