Home > Enterprise Desktop Tips > > How to report a vulnerability to Microsoft
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


How to report a vulnerability to Microsoft


Robyn Lorusso, Editor, SearchWindowsSecurity.com
04.13.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


If you discover a vulnerability in a Windows operating system or application, it's essential that you make Microsoft aware of the weakness before it becomes a serious problem. How do you go about reporting the issue? One CISSP from the Microsoft Security Response Center offers the following advice:

The Microsoft Security Response Center investigates all reports of security vulnerabilities sent to us that affect Microsoft products. If you believe you have found a security vulnerability affecting a Microsoft product, we would like to work with you to investigate it.

We are concerned that you might not know the best way to report security vulnerabilities to Microsoft. You can contact the Microsoft Security Response Center to report a vulnerability by e-mailing secure@microsoft.com directly, or you can submit your report via our Web-based vulnerability reporting form.

Be as specific as possible in the report, including an exact description of the vulnerability, what products it affects, steps to reproduce the problem and what the result of a successful exploit may be.

Other information you'll need to report in the form includes:

  • Manufacturer and model of the affected computer
  • Additional hardware installed
  • Operating systems
  • Operating service packs installed
  • Which product is affected by the vulnerability
  • Explanation of how Microsoft can duplicate the flaw in its labs
  • For help reporting e-mail or IM flaws, use the following resources:

  • How to report spam or e-mail abuse
  • How to report MSN Messenger vulnerabilities

  • More information from SearchWindowsSecurity.com

  • Topic: Research Windows product flaws and vulnerabilities
  • Quiz: Test your knowledge of vulnerability management
  • Ask the Expert: Send Kevin Beaver your security threats questions today


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network intrusion detection and prevention and malware removal
    20 days to a more secure enterprise
    Improvements to offline file synchronization in Windows 7
    Underlying causes of inconsistent patch management
    Windows security tools for the busy desktop administrator
    Check IT List: Five steps for rootkit detection
    Top Windows client security tools for end users
    Hacking Exposed Windows: Windows security features and tools
    Tools for virus removal and detection
    Windows security testing: Five tips for the summer
    Buffer overflows can be prevented by GS cookies

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts