Microsoft Baseline Security Analyzer: Difference between revisions

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
Content deleted Content added
m Updating links from HTTP→HTTPS for Microsoft TechNet
Rescuing 1 sources and tagging 0 as dead. #IABot (v1.6.2)
Line 24: Line 24:
Version 2.0 retained the hard-coded VA checks, but replaced the Shavlik security assessment engine with Microsoft Update technologies which adds dynamic support for all Microsoft products supported by [[Windows Update|Microsoft Update]]. MBSA 2.0.1 was released to support the revised Windows Update (WU) offline scan file (WSUSSCN2.CAB). MBSA 2.1 added Vista and Windows Server 2008 support, a new Vista-styled GUI interface, support for the latest Windows Update Agent (3.0), a new Remote Directory (/rd) feature and extended the VA checks to x64 platforms.
Version 2.0 retained the hard-coded VA checks, but replaced the Shavlik security assessment engine with Microsoft Update technologies which adds dynamic support for all Microsoft products supported by [[Windows Update|Microsoft Update]]. MBSA 2.0.1 was released to support the revised Windows Update (WU) offline scan file (WSUSSCN2.CAB). MBSA 2.1 added Vista and Windows Server 2008 support, a new Vista-styled GUI interface, support for the latest Windows Update Agent (3.0), a new Remote Directory (/rd) feature and extended the VA checks to x64 platforms.


In the August 2012 Security Bulletin Webcast Q&A on Technet it was announced that "The current version of MBSA (2.2) will not support Windows 8 and Microsoft currently has no plans to release an updated version of the tool."<ref>{{cite web|title=August 2012 Security Bulletin Webcast Q&A|url=http://blogs.technet.com/b/msrc/p/august-2012-security-bulletin-q-a.aspx|publisher=Microsoft|accessdate=20 August 2012}}</ref>
In the August 2012 Security Bulletin Webcast Q&A on Technet it was announced that "The current version of MBSA (2.2) will not support Windows 8 and Microsoft currently has no plans to release an updated version of the tool."<ref>{{cite web|title=August 2012 Security Bulletin Webcast Q&A|url=http://blogs.technet.com/b/msrc/p/august-2012-security-bulletin-q-a.aspx|publisher=Microsoft|accessdate=20 August 2012|deadurl=yes|archiveurl=https://web.archive.org/web/20120824093611/http://blogs.technet.com/b/msrc/p/august-2012-security-bulletin-q-a.aspx|archivedate=24 August 2012|df=}}</ref>


In November 2013 MBSA 2.3 was released. This release adds support for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2. Windows 2000 will no longer be supported with this release.<ref>{{cite web|title=Microsoft Baseline Security Analyzer (MBSA) 2.3&#124MBSA|url=http://www.microsoft.com/mbsa<publisher=Microsoft|accessdate=12 November 2013}}</ref>
In November 2013 MBSA 2.3 was released. This release adds support for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2. Windows 2000 will no longer be supported with this release.<ref>{{cite web|title=Microsoft Baseline Security Analyzer (MBSA) 2.3&#124MBSA|url=http://www.microsoft.com/mbsa<publisher=Microsoft|accessdate=12 November 2013}}</ref>

Revision as of 10:15, 29 January 2018

Microsoft Baseline Security Analyzer
Developer(s)Microsoft
Initial release16 August 2004 (2004-08-16)[1]
Stable release
2.3 / 9 January 2015 (2015-01-09)[2]
Operating systemWindows 7, Windows Server 2008, Windows Vista, Windows Server 2003, Windows XP and Windows 2000[2]
PlatformIA-32 and x86-64[2]
Size1.5 ~ 1.7 MB[2]
Available inEnglish, German, French and Japanese[2]
TypeComputer security
LicenseFreeware
Websitewww.microsoft.com/mbsa

Microsoft Baseline Security Analyzer (MBSA) is a software tool released by Microsoft to determine security state by assessing missing security updates and less-secure security settings within Microsoft Windows, Windows components such as Internet Explorer, IIS web server, and products Microsoft SQL Server, and Microsoft Office macro settings. Security updates are determined by the current version of MBSA using the Windows Update Agent present on Windows computers since Windows 2000 Service Pack 3. The less-secure settings, often called Vulnerability Assessment (VA) checks, are assessed based on a hard-coded set of registry and file checks. An example of a VA might be that permissions for one of the directories in the /www/root folder of IIS could be set at too low a level, allowing unwanted modification of files from outsiders.

Version history

Versions 1.2.1 and below run on NT4, Windows 2000, Windows XP, and Windows Server 2003, provide support for IIS versions 5 through 6, SQL Server 7 and 2000, Internet Explorer 5.01 and 6.0 only, and Microsoft Office 2000 through 2003. Security update assessment is provided by an integrated version of Shavlik's HFNetChk 3.8 scan tool. MBSA 1.2.1 was localized into English, German, French and Japanese versions and supported security assessment for any locale.

Version 2.0 retained the hard-coded VA checks, but replaced the Shavlik security assessment engine with Microsoft Update technologies which adds dynamic support for all Microsoft products supported by Microsoft Update. MBSA 2.0.1 was released to support the revised Windows Update (WU) offline scan file (WSUSSCN2.CAB). MBSA 2.1 added Vista and Windows Server 2008 support, a new Vista-styled GUI interface, support for the latest Windows Update Agent (3.0), a new Remote Directory (/rd) feature and extended the VA checks to x64 platforms.

In the August 2012 Security Bulletin Webcast Q&A on Technet it was announced that "The current version of MBSA (2.2) will not support Windows 8 and Microsoft currently has no plans to release an updated version of the tool."[3]

In November 2013 MBSA 2.3 was released. This release adds support for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2. Windows 2000 will no longer be supported with this release.[4]

How MBSA differs from Microsoft Update

MBSA only scans for 3 classes of updates, security updates, service packs and update rollups. Critical and optional updates are left aside.[5]

See also

References

  1. ^ "Download Details: Microsoft Baseline Security Analyzer v1.2.1 (for IT Professionals)". Microsoft Download Center. Microsoft Corporation. Archived from the original on 18 June 2009. Retrieved 13 October 2009. {{cite web}}: Unknown parameter |deadurl= ignored (|url-status= suggested) (help)
  2. ^ a b c d e "Download Details: Microsoft Baseline Security Analyzer 2.2 (for IT Professionals)". Microsoft Download Center. Microsoft Corporation. 6 August 2010. Retrieved 21 November 2009.
  3. ^ "August 2012 Security Bulletin Webcast Q&A". Microsoft. Archived from the original on 24 August 2012. Retrieved 20 August 2012. {{cite web}}: Unknown parameter |deadurl= ignored (|url-status= suggested) (help)
  4. ^ <publisher=Microsoft "Microsoft Baseline Security Analyzer (MBSA) 2.3&#124MBSA". Retrieved 12 November 2013.
  5. ^ "Microsoft Baseline Security Analyzer - FAQ". Microsoft. Retrieved 4 April 2016.