Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
December 2009 Security Bulletin Webcast
December 12, 2009 06:41



    

Hello again. This is Jerry Bryant letting you know that the questions and answers from the December 2009 security bulletin webcast have now been posted here.

There is one question that I wanted to provide a little more information on and that references reports of KB973917 causing problems with Internet Information Services (IIS) 6.0 running on Windows Server 2003 SP2. There are scenarios where the system can be in a state where the correct core IIS .dll files are not in place. This may be the case if SP2 did not install correctly or if IIS 6.0 was installed on the system from a Windows Server 2003 Gold or SP1 CD after SP2 was installed. KB2009746 has more information on this and how to resolve the issue which is to essentially reinstall SP2 to get the right binaries on the machine.

To be clear, KB973917 references a non-security update that implements Extended Protection for Authentication in IIS. This is part of our overall work to address credential relaying attacks on Integrated Windows Authentication as described in Security Advisory 974926 that we released on Tuesday. The updates in question are not addressing vulnerabilities and I just wanted to clarify that point. To learn more about this work, please read the advisory and also this excellent blog post by Maarten Van Horenbeeck from the MSRC: http://blogs.technet.com/srd/archive/2009/12/08/extended-protection-for-authentication.aspx.

At this time, our Customer Service and Support group are not reporting any major issues with this month?s bulletins. If you do experience any issues obtaining or installing security updates, please visit https://consumersecuritysupport.microsoft.com for some great trouble shooting tips as well as various support options. You can also call 1-866-PCSafety (1-866-727-2338) in the US. For more regional contact numbers, please visit http://support.microsoft.com.

The video below is from the webcast where Adrian Stone and I went in to detail on each bulletin. As we have been saying, MS09-072 should have the highest priority this month. Especially for users of IE 6 and IE 7.

Get Microsoft Silverlight More listening and viewing options:
Windows Media Video (WMV) Windows Media Audio (WMA) iPod Video (MP4) MP3 Audio High Quality WMV (2.5 Mbps) Zune Video (WMV)

Our next webcast is scheduled for January 13 at 11:00 a.m. PST (UTC -8). Click HERE to register now.

Thank you!

Jerry Bryant

*This posting is provided "AS IS" with no warranties, and confers no rights*


All news for July 29, 2010
  19:30  Martin McKeay: BHDC2010: Mary Landesman, Cisco
  14:16  Schneier on Security: Security Vulnerabilities of Smart Electricity Meters

All news for July 28, 2010
  19:12  Schneier on Security: DNSSEC Root Key Split Among Seven People
  18:15  MSRC: Community-Based Defense: Looking Outward, Moving Forward

All news for July 27, 2010
  20:33  Schneier on Security: Pork-Filled Counter-Islamic Bomb Device
  17:31  Martin McKeay: Headed to Vegas!
  14:43  Schneier on Security: WPA Cracking in the Cloud

All news for July 26, 2010
  20:30  Schneier on Security: 1921 Book on Profiling
  14:12  Schneier on Security: Technology is Making Life Harder for Spies
Keywords: december, 2009, security, bulletin, webcast

All news for July, 2010


All news for 2008


All news for 2009


All news for 2010