MICROSOFT SECURITY PATCHING FOR FY2009 No. Release Date Security Bulletin Patch Severity Rating 1 January 13, 2009 MS09-001 KB958687 Critical Vulnerabilities in SMB Could Allow Remote Code Execution 2 February 10, 2009 MS09-002 KB961260 Critical 3 February 10, 2009 MS09-003 KB959239 4 February 10, 2009 MS09-004 KB959420 5 February 10, 2009 MS09-005 KB957634 Important MICROSOFT WINDOWS SERVERS SECURITY PATCHES DESCRIPTION Impact of Vulnerability Software Affected (Based on Relevance) January 2009 Security Patches Remote Code Execution Microsoft Windows Server 2008 for x64-based Systems Cumulative Security Update for Internet Explorer Remote Code Execution Microsoft Windows Internet Explorer 7/8 Critical Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution Remote Code Execution Microsoft Exchange Server 2000/2003/2007 Important Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution Remote Code Execution Microsoft SQL Server 2000/2005/2007 Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution Remote Code Execution Microsoft Office Visio 2002/2003/2007 Remote Code Execution Microsoft Windows Server 2003/2008 Spoofing Microsoft Windows Server 2003/2008 Spoofing Microsoft Windows Server 2003/2008 February 2009 Security Patches March 2009 Security Patches 6 March 11, 2009 MS09-006 KB958690 Critical 7 March 11, 2009 MS09-007 KB960225 Important Vulnerabilities in Windows Kernel Could Allow Remote Code Execution Vulnerability in SChannel Could Allow Spoofing 8 March 11, 2009 MS09-008 KB962238 Important Vulnerabilities in DNS and WINS Server Could Allow Spoofing April 2009 Security Patches 9 April 14, 2009 MS09-012 KB959454 Important Elevation of Privilege Microsoft Windows Server 2003/2008 10 April 14, 2009 MS09-013 KB960803 Critical Vulnerabilities in Windows Could Allow Elevation of Privilege Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 11 April 14, 2009 MS09-014 KB963027 Critical Cumulative Security Update for Internet Explorer Remote Code Execution Microsoft Windows Server 2003/2008 12 April 14, 2009 MS09-015 KB959426 Moderate Elevation of Privilege Microsoft Windows Server 2003/2008 13 June 9,2009 MS09-018 KB971055 Critical Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055) Remote Code Execution Microsoft Windows Server 2003 14 June 9,2009 MS09-019 KB969897 Critical Cumulative Security Update for Internet Explorer (969897) Remote Code Execution Microsoft Windows Internet Explorer 7/8 15 June 9,2009 MS09-020 KB970483 16 June 9,2009 MS09-022 KB961501 17 June 9,2009 18 June 9,2009 MS09-023 MS09-025 KB963093 KB968537 19 June 9,2009 MS09-026 KB970238 Important 20 June 9,2009 MS09-026 KB969514 Critical Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514) July 2009 Security Patches Remote Code Execution Microsoft Office 2000/2003/2007 21 July 14, 2009 MS09-028 KB971633 Critical Vulnerabilities in Microsoft DirectShow Could Allow Remote Code Execution (971633) Remote Code Execution Microsoft Windows Server 2003 22 July 14, 2009 MS09-029 KB961371 Critical Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371) Remote Code Execution Microsoft Windows Server 2003/2008 23 July 14, 2009 MS09-030 KB969516 Important Vulnerability in Microsoft Office Publisher Could Allow Remote Code Execution (969516) Remote Code Execution Microsoft Office 2000/2003/2007 24 July 14, 2009 MS09-031 KB970953 Important Vulnerability in Microsoft ISA Server 2006 Could Cause Elevation of Privilege (970953) 25 July 14, 2009 MS09-032 KB973346 Critical 26 July 14, 2009 MS09-033 KB969856 Important 27 July 28, 2009 MS09-034 KB972260 Critical Cumulative Security Update for Internet Explorer (972260) Remote Code Execution Microsoft Windows Internet Explorer 7/8 28 July 28, 2009 MS09-035 KB969706 Moderate Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706) Remote Code Execution Microsoft Visual Studio 2005/2008 29 August 11, 2009 MS09-036 KB970957 Important Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957) 30 August 11, 2009 MS09-037 KB973908 Critical Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908) Remote Code Execution Microsoft Windows Server 2003/2008 31 August 11, 2009 MS09-038 KB971557 Critical Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557) Remote Code Execution Microsoft Windows Server 2003/2008 32 August 12, 2009 MS09-039 KB969883 Critical Vulnerabilities in WINS Could Allow Remote Code Execution (969883) Remote Code Execution Microsoft Windows Server 2003 33 August 11, 2009 MS09-040 KB971032 Important Vulnerability in Message Queuing Could Allow Elevation of Privilege Elevation of Privilege Microsoft Windows Server 2003 34 August 11, 2009 MS09-041 KB971657 Important Vulnerability in Workstation Service Could Allow Elevation of Privilege Elevation of Privilege Microsoft Windows Server 2003/2008 35 August 12, 2009 MS09-042 KB960859 Important Vulnerability in Telnet Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 36 August 11, 2009 MS09-043 KB957638 Critical Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003 37 August 11, 2009 MS09-044 KB970927 Critical Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 38 September 8, 2009 MS09-045 KB971961 Critical Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 39 September 8, 2009 MS09-046 KB956844 Critical Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003 40 September 8, 2009 MS09-047 KB973812 Critical Vulnerabilities in Windows Media Format Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003 41 September 10, 2009 MS09-048 KB967723 Critical Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 42 September 8, 2009 MS09-049 KB970710 Critical Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003 Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege June 2009 Security Patches Important Critical Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) Elevation of Privilege Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501) Elevation of Privilege Moderate Vulnerability in Windows Search Could Allow Information Disclosure (963093) Information Disclosure Important Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537) Elevation of Privilege Microsoft Windows Server 2003/2008 Vulnerability in RPC Could Allow Elevation of Privilege (970238) Elevation of Privilege Microsoft Windows Server 2003/2008 Cumulative Security Update of ActiveX Kill Bits (973346) Elevation of Privilege Remote Code Execution Vulnerability in Virtual PC and Virtual Server Could Allow Elevation of Privilege (969856) Elevation of Privilege Microsoft Internet Information Services 6.0 Microsoft Windows Server 2003 Microsoft Windows Server 2003 Microsoft Internet Security and Acceleration Server 2006 Microsoft Windows Server 2003 Microsoft Virtual PC 2007, Virtual Server 2005 August 2009 Security Patches Denial of Service Microsoft Windows Server 2008 September 2009 Security Patches chinwhei.wordpress.com MICROSOFT SECURITY PATCHING FOR FY2009 No. Release Date Security Bulletin Patch Severity Rating 43 October 13, 2009 MS09-050 KB975517 Critical Vulnerabilities in SMBv2 Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2008 44 October 13, 2009 MS09-051 KB975682 Critical Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 45 October 13, 2009 MS09-052 KB974112 Critical Vulnerability in Windows Media Player Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003 46 October 13, 2009 MS09-053 KB975254 Important Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 47 October 13, 2009 MS09-054 KB974455 Critical Cumulative Security Update for Internet Explorer Remote Code Execution Microsoft Windows Server 2003/2008 48 October 13, 2009 MS09-055 KB973525 Critical Cumulative Security Update of ActiveX Kill Bits Remote Code Execution Microsoft Windows Server 2003/2008 49 October 13, 2009 MS09-056 KB974571 Important Vulnerabilities in Windows CryptoAPI Could Allow Spoofing Spoofing Microsoft Windows Server 2003/2008 50 October 13, 2009 MS09-057 KB969059 Important Vulnerability in Indexing Service Could Allow Remote Code Execution 51 October 13, 2009 MS09-058 KB971486 Important Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege 52 October 13, 2009 MS09-059 KB975467 Important Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service 53 October 13, 2009 MS09-060 KB973965 Critical Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution Remote Code Execution Microsoft Office 2000/2003/2007 54 October 13, 2009 MS09-061 KB974378 Critical Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 55 October 13, 2009 MS09-062 KB957488 Critical Vulnerabilities in GDI+ Could Allow Remote Code Execution Remote Code Execution Microsoft Windows Server 2003/2008 56 November 10, 2009 MS09-063 KB973565 Critical Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565) Remote Code Execution Microsoft Windows Server 2008 57 November 10, 2009 MS09-064 KB974783 Critical Vulnerability in License Logging Server Could Allow Remote Code Execution (974783) Remote Code Execution Microsoft Windows Server 2000 58 November 10, 2009 MS09-065 KB969947 Critical Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947) Remote Code Execution Microsoft Windows Server 2003/2008 59 November 10, 2009 MS09-066 KB973309 Important Vulnerability in Active Directory Could Allow Denial of Service (973309) Denial of Service Microsoft Windows Server 2003/2008 60 November 10, 2009 MS09-067 KB972652 Important Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652) Remote Code Execution Microsoft Office 2000/2003/2007 61 November 10, 2009 MS09-068 KB976307 Important Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307) Remote Code Execution Microsoft Office 2000/2003/2007 MICROSOFT WINDOWS SERVERS SECURITY PATCHES DESCRIPTION Impact of Vulnerability Software Affected (Based on Relevance) October 2009 Security Patches Remote Code Execution Microsoft Windows Server 2003 Elevation of Privilege Microsoft Windows Server 2003/2008 Denial of Service Microsoft Windows Server 2003/2008 November 2009 Security Patches December 2009 Security Patches 62 December 8, 2009 MS09-069 KB974392 Important Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392) 63 December 8, 2009 MS09-070 KB971726 Important Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) Remote Code Execution Denial of Service Microsoft Windows Server 2003 Microsoft Windows Server 2003/2008 64 December 8, 2009 MS09-071 KB974318 Critical Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318) Remote Code Execution Microsoft Windows Server 2003/2008 65 December 8, 2009 MS09-072 KB976325 Critical Cumulative Security Update for Internet Explorer (976325) Remote Code Execution Microsoft Windows Server 2003/2008 66 December 8, 2009 MS09-073 KB975539 Important Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539) Remote Code Execution Microsoft Windows Server 2003 67 December 8, 2009 MS09-074 KB967183 Critical Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) Remote Code Execution Microsoft Office 2000/2003/2007 THIS DOCUMENT IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS DOCUMENT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. chinwhei.wordpress.com