Advance Notification Service for the April 2011 Bulletin Release

Hello everyone,

My name is Pete Voss, and I’m a senior response communications manager with Microsoft Trustworthy Computing. I’ll be joining the rest of the team on the MSRC blog and @MSFTSecResponse Twitter handle to help provide you with the latest information and guidance for Microsoft security.

Today, we’re providing advanced notification on the release of 17 security bulletins, nine rated Critical and eight rated Important. This month’s bulletin release will address 64 vulnerabilities across Microsoft Windows, Microsoft Office, Internet Explorer, Visual Studio, .NET Framework and GDI+.

This month we’ll be closing some issues that Microsoft has already previously spoken to, including the SMB Browser (Critical) issue publicly disclosed Feb. 15. Microsoft assessed the situation and reported that although the vulnerability could theoretically allow Remote Code Execution, that was extremely unlikely.  To this day, we have seen no evidence of attacks.

We are also planning a fix for the MHTML vulnerability in Windows, rated Important. We alerted people to this issue with Security Advisory 2501696 (including a Fix-It that fully protected customers once downloaded) back in late January. In March, we updated the advisory to let people know we were aware of limited, targeted attacks.

The bulletin release scheduled for the second Tuesday of the month, April 12, at approximately 10 a.m. PDT. Come back to this blog then for our official risk and impact analysis, as well as deployment guidance and a brief video overview of the month’s highlights. Meanwhile, customers are encouraged to review Microsoft’s advanced notification and assess it for their particular environment. Additionally, we recommend that administrators reference our Security Update Guide for help preparing for the bulletin release.

The monthly technical webcast is scheduled for Wednesday, April 13, hosted by Jerry Bryant and Jonathan Ness. I invite you to tune in and learn more about the security bulletins. The webcast is scheduled for Wednesday, April 13, 2011 at 11 a.m. PDT, and the registration can be found here.

For all the latest information, you can also follow the MSRC team on Twitter at @MSFTSecResponse.

Pete Voss
Sr. Response Communications Manager
Microsoft Trustworthy Computing