ms09 001
Download the updates for your home computer or laptop from the Microsoft Update Web site now. [1]
Microsoft today shipped a solitary bulletin with patches for at least three documented security flaws in the Microsoft Server Message Block (SMB) Protocol. [2]
If you are using Windows Vista you can manage your updates through the control panel. [...] We recommend you install all High-Priority Security and Critical updates immediately. [1]
An attacker who successfully exploited these vulnerabilities could install programs; view, change, or delete data; or create new accounts with full user rights. [...] This bulletin summary lists security bulletins released for January 2009. [3]
“An attacker who successfully exploited these vulnerabilities could install programs; view, change, or delete data; or create new accounts with full user rights.” [2]
This security update resolves two privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. [...] The vulnerabilities could allow remote code execution on affected systems. [3]
If a worm is released, and that worm makes it into a corporate network, it will make swiss cheese of that network relatively quickly. [2]
Recommended Actions: Windows System Administrators/users are encouraged to read the security bulletin and (if appropriate) install the updated bulletins as soon as possible. [4]
To learn how to turn on automatic updating for your particular operating system, see Update your computer automatically. [...] To manually download available updates, go to Microsoft Update or in Windows Vista go to your control panel. [...] IT professionals and systems administrators - Go to Microsoft TechNet for detailed information about these updates. [...] When your computer is on and connected to the Internet, the most current security updates are automatically downloaded and installed. [1]
Sources:
[1] Microsoft security updates for January 2009
[2] MS Patch Tuesday: 3 critical SMB vulnerabilities | Zero Day | ZDNet.com
[3] Microsoft Security Bulletin Advance Notification for January 2009
[4] Information Technology Services