Windows: MS09-032 (973346) Released for IE 0-day Fix

Reported on: July 20, 2009

Description: If you ran "windows update" on or after Patch Tuesday (7/14/09), it should be "safe" to use Internet Explorer. [On a personal note, I discourage users from using IE, unless it is required to do your work. IE is frequently targeted by attackers.]

Action: Verify if MS09-032 is Installed. If it is not, please contact TDS at extension 333 for assistance. Here are the instructions to check for WinXP:

Click Start > Control Panel > Add or Remove Programs.
Click "show updates".
Scroll to Windows XP - Software Updates section.
"Security Update for Windows XP (KB973346)" should be listed on or after 7/14/2009.

Warning Message From UH Information Technology Services:

SUMMARY: Windows: MS09-032 (973346) Released for IE 0-day Fix
POSTED ON: 7/20/2009
DESCRIPTION: Microsoft released Security Bulletin MS09-032 on Patch Tuesday (7/14/09) to address security issue (972890), active attacks on Internet Explorer (IE), exploiting the unpatched vulnerability in Microsoft Video ActiveX control (part of DirectX).
http://www.microsoft.com/technet/security/advisory/972890.mspx

Microsoft Security Bulletin MS09-032 (973346)
http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx

Users running IE 6 or IE 7 on Windows XP and Windows Server 2003 are vulnerable. Vista and Windows Server 2008 was not affected. The reports of attacks on IE were posted at http://www.hawaii.edu/its under Security Alerts or
http://www.hawaii.edu/technews/item/elog/22821

If you ran "windows update" on or after Patch Tuesday (7/14/09), it should be "safe" to use Internet Explorer. [On a personal note, I discourage users from using IE, unless it is required to do your work. IE is frequently targeted by attackers.]

To run windows update manually:
Open Internet Explorer to http://windowsupdate.microsoft.com
Select Custom.
If no updates are offered, you're done.
If you're offered updates, select Review Updates.
Select updates to install (if any).

How to Verify if MS09-032 is Installed:

For WinXP:
Click Start > Control Panel > Add or Remove Programs.
Click "show updates".
Scroll to Windows XP - Software Updates section.
"Security Update for Windows XP (KB973346)" should be listed on or after 7/14/2009.

If you have questions or need assistance, please contact the ITS Help Desk at 956-8883, email help@hawaii.edu, or call (800) 558-2669 toll free from the neighbor islands.
REPORTED BY: jocelyn