<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure Tomorrow &#187; Microsoft</title>
	<atom:link href="http://www.securetomorrow.org/tag/microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securetomorrow.org</link>
	<description>Kevin Blanchard's Information Security Blog</description>
	<lastBuildDate>Thu, 30 Jul 2009 20:51:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Words the word</title>
		<link>http://www.securetomorrow.org/2006/12/words-the-word/</link>
		<comments>http://www.securetomorrow.org/2006/12/words-the-word/#comments</comments>
		<pubDate>Wed, 06 Dec 2006 22:33:00 +0000</pubDate>
		<dc:creator>Kevin Blanchard</dc:creator>
				<category><![CDATA[post]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Office]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://www.securetomorrow.org/wp/?p=18</guid>
		<description><![CDATA[Microsoft recently released an announcement about a zero-day vulnerability affecting several versions of Microsoft Word. &#8220;Microsoft is investigating new public reports of limited &#8216;zero-day&#8217; attacks using a vulnerability in Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft recently released an announcement about a zero-day vulnerability affecting several versions of Microsoft Word.</p>
<p><em>&#8220;Microsoft is investigating new public reports of limited &#8216;zero-day&#8217; attacks using a vulnerability in Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac, as well as Microsoft Works 2004, 2005, and 2006.  In order for this attack to be carried out, a user must first open a malicious Word file attached to an e-mail or otherwise provided to them by an attacker.&#8221;</em></p>
<p>The kicker is the nugget of wisdom Microsoft passes along to us while they sort it all out, <em>&#8220;Do not open or save Word files that you receive from un-trusted sources or that you receive unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a specially crafted Word file.&#8221;</em></p>
<p><em>&#8220;&#8230;or that you receive unexpectedly from trusted sources&#8221;</em><br />
So basically that limits me to documents I already have in my possession and Bob from down the hall giving me a solid heads up he&#8217;ll be emailing me a document later in the day *smirk*</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securetomorrow.org/2006/12/words-the-word/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS05-017 Exploit</title>
		<link>http://www.securetomorrow.org/2005/05/ms05-017-exploit/</link>
		<comments>http://www.securetomorrow.org/2005/05/ms05-017-exploit/#comments</comments>
		<pubDate>Fri, 13 May 2005 04:45:00 +0000</pubDate>
		<dc:creator>Kevin Blanchard</dc:creator>
				<category><![CDATA[post]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.securetomorrow.org/wp/?p=6</guid>
		<description><![CDATA[Hot off the SANS presses. An exploit for MS05-017 (that place-holder &#8220;0&#8243; in front of the 17 inspires confidence, doesn&#8217;t it?) is now available as part of the Metasploit Framework, so if you aren&#8217;t patched&#8230; well, why aren&#8217;t you? MS05-017 (Vulnerability in Message Queuing Could Allow Code Execution / CAN-2005-0059 / KB892944) was part of [...]]]></description>
			<content:encoded><![CDATA[<p>Hot off the <a href="http://isc.sans.org/diary.html?date=2005-05-11">SANS presses</a>.</p>
<p><em>An exploit for MS05-017 (that place-holder &#8220;0&#8243; in front of the 17 inspires confidence, doesn&#8217;t it?) is now available as part of the Metasploit Framework, so if you aren&#8217;t patched&#8230; well, why aren&#8217;t you?</em></p>
<p><em>MS05-017 (Vulnerability in Message Queuing Could Allow Code Execution / CAN-2005-0059 / KB892944) was part of Microsoft&#8217;s April 2005 release and more information can be found <a href="http://www.microsoft.com/technet/security/bulletin/MS05-017.mspx">here</a>;. I&#8217;ve not had a chance to test this yet, but H.D. is pretty amazing, so I don&#8217;t have much question that it works.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securetomorrow.org/2005/05/ms05-017-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

