MS Sec Notification mailing list archives

Microsoft Security Update Minor Revisions


From: "Microsoft" <securitynotifications () e-mail microsoft com>
Date: Wed, 11 Oct 2017 13:50:16 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

********************************************************************
Title: Microsoft Security Update Minor Revisions
Issued: October 11, 2017
********************************************************************

Summary
=======

The following advisory has been revised in the October 2017 Security
Updates. 

* ADV170012


Revision Information:
=====================

ADV170012

 - Title: ADV170012 | Vulnerability in TPM could allow Security
   Feature Bypass
 - https://portal.msrc.microsoft.com/en-us/security-guidance
 - Reasons for Revision: v1.1: To keep the information in the advisory 
   up-to-date, made several corrections: corrected link to HP OEM site, 
   added link to Lenovo OEM site, added note that failure to run the 
   PowerShell script as an administrator will return incorrect results. 
   These are all informational changes only.
   v1.2: Added information about how to use the PowerShell script to 
   remotely check devices for affected TPMs. Clarified that BitLocker 
   protection is affected only if the TPM firmware version is 1.2. 
   These are informational changes only.
 - Originally posted: October 10, 2017  
 - Updated: October 11, 2017
 - CVE Severity Rating: Critical
 - Version: 1.2


Other Information
=================

Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing 
a Microsoft security update, it is a hoax that may contain 
malware or pointers to malicious websites. Microsoft does 
not distribute security updates via email. 

The Microsoft Security Response Center (MSRC) uses PGP to digitally 
sign all security notifications. However, PGP is not required for 
reading security notifications, reading security bulletins, or 
installing security updates. You can obtain the MSRC public PGP key
at <https://technet.microsoft.com/security/dn753714>.

********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

Microsoft respects your privacy. Please read our online Privacy
Statement at <http://go.microsoft.com/fwlink/?LinkId=81184>.

If you would prefer not to receive future technical security
notification alerts by email from Microsoft and its family of
companies please visit the following website to unsubscribe:
<https://profile.microsoft.com/RegSysProfileCenter/subscriptionwizar
d.aspx?wizid=5a2a311b-5189-4c9b-9f1a-d5e913a26c2e&%3blcid=1033>.

These settings will not affect any newsletters you’ve requested or
any mandatory service communications that are considered part of
certain Microsoft services.

For legal Information, see:
<http://www.microsoft.com/info/legalinfo/default.mspx>.

This newsletter was sent by:
Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.2.0 (Build 1950) - not licensed for commercial use: www.pgp.com
Charset: utf-8

wsFVAwUBWd5wz/sCXwi14Wq8AQjlvg/+Kvo8VVAxDS/G4Ronk2om1S9BqTWlc5Ls
uuLsUWPDo7L+Yjo0Bv0/d8F9yi6nzT9VCxO209u+n6AvNGy+rQCGfBK/fuqw+Mqb
o8xJ4CeelLLpUzdJWZ8f8A3HgYlmepAaZUljtlP7ws7YM/7J9RQsPTo/Q91yCe0P
N9XCcCT3/IvBrLSMuHLNkNoTG5jk/fIcHZmV9jqjYf54JjfL5w099kP0bb4g5pDb
gpCWECkxw+TZOIxrTU72mV2PaTrU6tfNGcmSOcNeWCWEMVbLrUeLlP7ZdDFDpYw/
VSPf6ZDEEYMnx5Dluv5uwVFoFYrAHxJ8dSPK9qPaX1yWlvfG9ePaJJeK8xsUFttj
plgmJ4i+QcYH2+x/yJNH3h1+X7NuBdA5memeEFiLGzNAIUtR0WbBuva6GLqzJs7W
qCNMPpWNTkSUNaFaYGGHw3BN9PnXi0OphIR3/94MJGjqNW3TsAqw9T1VzHCMPXno
UYvsp3jNNuMcSLvMaTIrdgW/ikyJMTSSKBeDa2M0Ih2zwcWStuQRtX2KE3rJ8G5B
bNa0INocw7xqk5lohoJ9gFiIGiR0Mfq16jZnCMEb04PPe21uW7Q9vg/Jn+35gvbX
TWxSbs9jgrBVRB8zNvtX2Yi//X5fkNdyQAqPtmVEGNeVW6BjgbcDLU2k7ph3cyeY
pZaMV/9dndQ=
=V0yA
-----END PGP SIGNATURE-----


Current thread: