With my DELL Inspiron 8200 running Windows XP Home, I am
using "Automatic Windows Update". As you well know there
has been quite a bit of update activity lately. Today,
however, I received an E-mail urging me to obtain the
latest "October 2003 Cumulative Patch." The content of
this E-mail is copied below:

"MS Partner

this is the latest version of security update, the "October
2003, Cumulative Patch" update which fixes all known
security vulnerabilities affecting MS Internet Explorer, MS
Outlook and MS Outlook Express as well as three new
vulnerabilities. Install now to protect your computer from
these vulnerabilities, the most serious of which could
allow an malicious user to run executable on your computer.
This update includes the functionality of all previously
released patches.


System requirements Windows 95/98/Me/2000/NT/XP
This update applies to MS Internet Explorer, version 4.01
and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch at the
earliest opportunity.
How to install Run attached file. Choose Yes on displayed
dialog box.
How to use You don't need to do anything after installing
this item.

Microsoft Product Support Services and Knowledge Base
articles can be found on the Microsoft Technical Support
web site. For security-related information about Microsoft
products, please visit the Microsoft Security Advisor web
site, or Contact Us.

Thank you for using Microsoft products.

Please do not reply to this message. It was sent from an
unmonitored e-mail address and we are unable to respond to
any replies.
The names of the actual companies and products mentioned
herein are the trademarks of their respective owners."


How can I be assured that this E-mail is from MicroSoft?
Why should I install this new patch if I have been
installing "Automatic Updates"?

October 2003 Cumulative Patch by JerryZ

JerryZ
Sun Oct 05 16:41:34 CDT 2003

As of Friday, AutoUpdate was not downloading this patch.
This patch is in response to the Qhost trojan horse
(http://securityresponse.symantec.com/avcenter/venc/data/t
rojan.qhosts.html). On Friday (as I do every Friday), I
went out to http://v4.windowsupdate.microsoft.com. I
notice the October 2003 IE6 cumulative patch. I also
noticed that there as another update for Windows Media
Player. I installed both.

BTW, I am on Technet e-mail notifications
(http://www.microsoft.com/technet/security/bulletin/notify
.asp). I believe in redundancy; I rely on AutoUpdate and
the e-mail notifications. I also go out every Friday and
check AutoUpdate. I also use hfnetchk and MSBA to scan
my machines after installing patches.


>-----Original Message-----
>With my DELL Inspiron 8200 running Windows XP Home, I am
>using "Automatic Windows Update". As you well know there
>has been quite a bit of update activity lately. Today,
>however, I received an E-mail urging me to obtain the
>latest "October 2003 Cumulative Patch." The content of
>this E-mail is copied below:
>
>"MS Partner
>
>this is the latest version of security update,
the "October
>2003, Cumulative Patch" update which fixes all known
>security vulnerabilities affecting MS Internet Explorer,
MS
>Outlook and MS Outlook Express as well as three new
>vulnerabilities. Install now to protect your computer
from
>these vulnerabilities, the most serious of which could
>allow an malicious user to run executable on your
computer.
>This update includes the functionality of all previously
>released patches.
>
>
> System requirements Windows 95/98/Me/2000/NT/XP
> This update applies to MS Internet Explorer,
version 4.01
>and later
>MS Outlook, version 8.00 and later
>MS Outlook Express, version 4.01 and later
> Recommendation Customers should install the
patch at the
>earliest opportunity.
> How to install Run attached file. Choose Yes on
displayed
>dialog box.
> How to use You don't need to do anything after
installing
>this item.
>
>Microsoft Product Support Services and Knowledge Base
>articles can be found on