October Summary
http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx

Critical Bulletins:

MS04-032 - Security Update for Microsoft Windows (840987)
http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx

MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
(886836)
http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx

MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
Execution (873376)
http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx

MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
(885881)
http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx

MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx

MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
Execution (841356)
http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx

MS04-038 - Cumulative Security Update for Internet Explorer (834707)
http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx


Important Bulletins:

MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
Disclosure and Denial of Service (873350)
http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx

MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
Could Lead to a Denial of Service (824151)
http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx

MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
(841533)
http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx

Re-Released Bulletins:

MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
Execution (833987)
http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx

This represents our regularly scheduled monthly bulletin release (second
Tuesday of each month). Please note that Microsoft may release bulletins
out side of this schedule if we determine the need to do so.
--
http://www.sbslinks.com/really.htm
http://www.msmvps.com/bradley
http://www.threatcode.com
[let's get vendors to step up to the plate too]
https://www.ecora.com/ecora/jump/pm99.asp

RE: <<< SECURITY BULLETINS THIS MONTH>>> by Adam

Adam
Tue Oct 12 16:39:11 CDT 2004

Do most of you apply the critical updates from Microsoft on your SBS 2003? I
have been a little apprehensive, thinking they may break some component.

"Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:

> October Summary
> http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx
>
> Critical Bulletins:
>
> MS04-032 - Security Update for Microsoft Windows (840987)
> http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx
>
> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
> (886836)
> http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx
>
> MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
> Execution (873376)
> http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx
>
> MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
> (885881)
> http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
>
> MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
> http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx
>
> MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
> Execution (841356)
> http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx
>
> MS04-038 - Cumulative Security Update for Internet Explorer (834707)
> http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx
>
>
> Important Bulletins:
>
> MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
> Disclosure and Denial of Service (873350)
> http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx
>
> MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
> Could Lead to a Denial of Service (824151)
> http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx
>
> MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
> (841533)
> http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx
>
> Re-Released Bulletins:
>
> MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
> Execution (833987)
> http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx
>
> This represents our regularly scheduled monthly bulletin release (second
> Tuesday of each month). Please note that Microsoft may release bulletins
> out side of this schedule if we determine the need to do so.
> --
> http://www.sbslinks.com/really.htm
> http://www.msmvps.com/bradley
> http://www.threatcode.com
> [let's get vendors to step up to the plate too]
> https://www.ecora.com/ecora/jump/pm99.asp
>
>

Re: <<< SECURITY BULLETINS THIS MONTH>>> by Susan

Susan
Tue Oct 12 19:14:14 CDT 2004

I apply ALL of the updates to my SBS box.

I use the critical rating to determine timing of application.

All of these patches that you see here have been tested on SBS systems.

If you like... wait just a bit... say a week. Those that have test beds
will report back issues.

I'll blog about my risk analysis and procedures on my blog tonight:
http://www.msmvps.com/bradley

Adam wrote:

> Do most of you apply the critical updates from Microsoft on your SBS 2003? I
> have been a little apprehensive, thinking they may break some component.
>
> "Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:
>
>
>>October Summary
>>http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx
>>
>>Critical Bulletins:
>>
>>MS04-032 - Security Update for Microsoft Windows (840987)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx
>>
>>MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
>>(886836)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx
>>
>>MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
>>Execution (873376)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx
>>
>>MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
>>(885881)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
>>
>>MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx
>>
>>MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
>>Execution (841356)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx
>>
>>MS04-038 - Cumulative Security Update for Internet Explorer (834707)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx
>>
>>
>>Important Bulletins:
>>
>>MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
>>Disclosure and Denial of Service (873350)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx
>>
>>MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
>>Could Lead to a Denial of Service (824151)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx
>>
>>MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
>>(841533)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx
>>
>>Re-Released Bulletins:
>>
>>MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
>>Execution (833987)
>>http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx
>>
>>This represents our regularly scheduled monthly bulletin release (second
>>Tuesday of each month). Please note that Microsoft may release bulletins
>>out side of this schedule if we determine the need to do so.
>>--
>>http://www.sbslinks.com/really.htm
>>http://www.msmvps.com/bradley
>>http://www.threatcode.com
>>[let's get vendors to step up to the plate too]
>>https://www.ecora.com/ecora/jump/pm99.asp
>>
>>

--
http://www.sbslinks.com/really.htm
http://www.msmvps.com/bradley
http://www.threatcode.com
[let's get vendors to step up to the plate too]
https://www.ecora.com/ecora/jump/pm99.asp


Re: <<< SECURITY BULLETINS THIS MONTH>>> by Kevin

Kevin
Tue Oct 12 21:40:41 CDT 2004

Susan's comments are equally true of many of us:
- DO install the WU critical updates
- DON'T install the other WU recommended updates
- Definitely DON'T install the WU reconmmend driver updates

- DO check these newsgroups regularly after a published critical patch is
released
- DON'T assume that WU will report all critical patches - it doesn't

- DO use alternate solutions for determining required updates (HFNetChkPro,
SUS, MBSA, etc.)
- DON'T think that because you don't check for updates that you are
protected -- you're not!

--
Kevin Weilbacher [SBS-MVP]
"The days pass by so quickly now, the nights are seldom long"


"Adam" <Adam@discussions.microsoft.com> wrote in message
news:D0F10595-1282-45AB-89AC-ADC439DD70B4@microsoft.com...
> Do most of you apply the critical updates from Microsoft on your SBS 2003?
> I
> have been a little apprehensive, thinking they may break some component.
>
> "Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:
>
>> October Summary
>> http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx
>>
>> Critical Bulletins:
>>
>> MS04-032 - Security Update for Microsoft Windows (840987)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx
>>
>> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
>> (886836)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx
>>
>> MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
>> Execution (873376)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx
>>
>> MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
>> (885881)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
>>
>> MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx
>>
>> MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
>> Execution (841356)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx
>>
>> MS04-038 - Cumulative Security Update for Internet Explorer (834707)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx
>>
>>
>> Important Bulletins:
>>
>> MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
>> Disclosure and Denial of Service (873350)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx
>>
>> MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
>> Could Lead to a Denial of Service (824151)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx
>>
>> MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
>> (841533)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx
>>
>> Re-Released Bulletins:
>>
>> MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
>> Execution (833987)
>> http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx
>>
>> This represents our regularly scheduled monthly bulletin release (second
>> Tuesday of each month). Please note that Microsoft may release bulletins
>> out side of this schedule if we determine the need to do so.
>> --
>> http://www.sbslinks.com/really.htm
>> http://www.msmvps.com/bradley
>> http://www.threatcode.com
>> [let's get vendors to step up to the plate too]
>> https://www.ecora.com/ecora/jump/pm99.asp
>>
>>



Re: <<< SECURITY BULLETINS THIS MONTH>>> by Susan

Susan
Tue Oct 12 22:44:41 CDT 2004

Handicappin' the Patches:
http://msmvps.com/bradley/archive/2004/10/12/15669.aspx


I don't WU drivers on my systems. Only critical security patches.

Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote:
> I apply ALL of the updates to my SBS box.
>
> I use the critical rating to determine timing of application.
>
> All of these patches that you see here have been tested on SBS systems.
>
> If you like... wait just a bit... say a week. Those that have test beds
> will report back issues.
>
> I'll blog about my risk analysis and procedures on my blog tonight:
> http://www.msmvps.com/bradley
>
> Adam wrote:
>
>> Do most of you apply the critical updates from Microsoft on your SBS
>> 2003? I have been a little apprehensive, thinking they may break some
>> component.
>>
>> "Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:
>>
>>
>>> October Summary
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx
>>>
>>> Critical Bulletins:
>>>
>>> MS04-032 - Security Update for Microsoft Windows (840987)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx
>>>
>>> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
>>> (886836)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx
>>>
>>> MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
>>> Execution (873376)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx
>>>
>>> MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
>>> (885881)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
>>>
>>> MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx
>>>
>>> MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
>>> Execution (841356)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx
>>>
>>> MS04-038 - Cumulative Security Update for Internet Explorer (834707)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx
>>>
>>>
>>> Important Bulletins:
>>>
>>> MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
>>> Disclosure and Denial of Service (873350)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx
>>>
>>> MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
>>> Could Lead to a Denial of Service (824151)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx
>>>
>>> MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
>>> (841533)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx
>>>
>>> Re-Released Bulletins:
>>>
>>> MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
>>> Execution (833987)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx
>>>
>>> This represents our regularly scheduled monthly bulletin release (second
>>> Tuesday of each month). Please note that Microsoft may release bulletins
>>> out side of this schedule if we determine the need to do so.
>>> --
>>> http://www.sbslinks.com/really.htm
>>> http://www.msmvps.com/bradley
>>> http://www.threatcode.com
>>> [let's get vendors to step up to the plate too]
>>> https://www.ecora.com/ecora/jump/pm99.asp
>>>
>>>
>

--
http://www.sbslinks.com/really.htm
http://www.msmvps.com/bradley
http://www.threatcode.com
[let's get vendors to step up to the plate too]
https://www.ecora.com/ecora/jump/pm99.asp


Re: <<< SECURITY BULLETINS THIS MONTH>>> by SuperGumby

SuperGumby
Wed Oct 13 06:29:13 CDT 2004

just throwin' it into the wild.

I'm looking at something in the office at the moment. Built SBS2003 and a
2000 Server as App Mode TS, both in VirtualPC. The media was original Action
Pack media but with a replacement CD3.

Finished both of them this afternoon doing all updates (critical,
recommended & drivers) via WU. We would not normally do recommended or
drivers via WU but HEY, it's a test thing. Everything worked in this 'ideal'
environment. I'll give credos where due, the guys, including the gal type
guys, at MS are doing well with WU at the moment. I'm looking forward to the
introduction of WUS so that applications are updated as well as the OS.

There's a few patches I'll be adding manually because they have not been
applied via WU, nothing major that I've noticed yet.

The thing I found curious was that I struck a problem where, after a certain
point, patches couldn't be applied via WU. TOOK ME AGES to remember the
EDNS0 fix which is pretty silly as I know 2003 behind the NetGear FVS318 on
my ISP (I use their DNS as forwarders) just can't do it.

Kevin didn't really mean to say this.
> - DON'T think that because you don't check for updates that you are
> protected -- you're not!
maybe it would make more sense if the 2nd occurrence of the word 'don't' was
removed.

I'm gonna raise Richard@shavlik's hackles when I install the 308974652104th
copy of hfnetchk onto a test system tomorrow.

"Kevin Weilbacher [SBS-MVP]" <kweilbacMVP@gte.net> wrote in message
news:ufwaM3MsEHA.2664@TK2MSFTNGP12.phx.gbl...
> Susan's comments are equally true of many of us:
> - DO install the WU critical updates
> - DON'T install the other WU recommended updates
> - Definitely DON'T install the WU reconmmend driver updates
>
> - DO check these newsgroups regularly after a published critical patch is
> released
> - DON'T assume that WU will report all critical patches - it doesn't
>
> - DO use alternate solutions for determining required updates
> (HFNetChkPro, SUS, MBSA, etc.)
> - DON'T think that because you don't check for updates that you are
> protected -- you're not!
>
> --
> Kevin Weilbacher [SBS-MVP]
> "The days pass by so quickly now, the nights are seldom long"
>
>
> "Adam" <Adam@discussions.microsoft.com> wrote in message
> news:D0F10595-1282-45AB-89AC-ADC439DD70B4@microsoft.com...
>> Do most of you apply the critical updates from Microsoft on your SBS
>> 2003? I
>> have been a little apprehensive, thinking they may break some component.
>>
>> "Susan Bradley, CPA aka Ebitz - SBS Rocks" wrote:
>>
>>> October Summary
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-oct.mspx
>>>
>>> Critical Bulletins:
>>>
>>> MS04-032 - Security Update for Microsoft Windows (840987)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-032.mspx
>>>
>>> MS04-033 - Vulnerability in Microsoft Excel Could Allow Code Execution
>>> (886836)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-033.mspx
>>>
>>> MS04-034 - Vulnerability in Compressed (zipped) Folders Could Allow Code
>>> Execution (873376)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-034.mspx
>>>
>>> MS04-035 - Vulnerability in SMTP Could Allow Remote Code Execution
>>> (885881)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-035.mspx
>>>
>>> MS04-036 - Vulnerability in NNTP Could Allow Code Execution (883935)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-036.mspx
>>>
>>> MS04-037 - Vulnerability in Windows Shell Could Allow Remote Code
>>> Execution (841356)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-037.mspx
>>>
>>> MS04-038 - Cumulative Security Update for Internet Explorer (834707)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-038.mspx
>>>
>>>
>>> Important Bulletins:
>>>
>>> MS04-029 - Vulnerability in RPC Runtime Library Could Allow Information
>>> Disclosure and Denial of Service (873350)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-029.mspx
>>>
>>> MS04-030 - Bulletin Title Vulnerability in WebDAV XML Message Handler
>>> Could Lead to a Denial of Service (824151)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-030.mspx
>>>
>>> MS04-031 - Vulnerability in NetDDE Could Allow Remote Code Execution
>>> (841533)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-031.mspx
>>>
>>> Re-Released Bulletins:
>>>
>>> MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code
>>> Execution (833987)
>>> http://www.microsoft.com/technet/security/Bulletin/ms04-028.mspx
>>>
>>> This represents our regularly scheduled monthly bulletin release (second
>>> Tuesday of each month). Please note that Microsoft may release bulletins
>>> out side of this schedule if we determine the need to do so.
>>> --
>>> http://www.sbslinks.com/really.htm
>>> http://www.msmvps.com/bradley
>>> http://www.threatcode.com
>>> [let's get vendors to step up to the plate too]
>>> https://www.ecora.com/ecora/jump/pm99.asp
>>>
>>>
>
>



Re: <<< SECURITY BULLETINS THIS MONTH>>> by Kevin

Kevin
Wed Oct 13 07:48:53 CDT 2004

Actually, SG, both are true statements:

1. DON'T think that because you DON'T check for updates that you are
protected -- you're not!
2. DON'T think that because you DO check for updates that you are
protected -- you're not!


--
Kevin Weilbacher [SBS-MVP]
"The days pass by so quickly now, the nights are seldom long"


"SuperGumby [SBS MVP]" <not@your.nellie> wrote in message
news:eJ$gNfRsEHA.2144@TK2MSFTNGP10.phx.gbl...
> just throwin' it into the wild.
>
> Kevin didn't really mean to say this.
>> - DON'T think that because you don't check for updates that you are
>> protected -- you're not!
> maybe it would make more sense if the 2nd occurrence of the word 'don't'
> was removed.
>