Microsoft fixes 20 flaws with Patch Tuesday updates
Published: 15 Oct 2008 11:01 BST
Microsoft on Tuesday released its October 2008 security bulletin summary.
The four critical bulletins concern Windows, Internet Explorer, Microsoft Host Integration Server and Microsoft Excel. The patch for Internet Explorer is cumulative.
Microsoft is now sharing the technical details of new vulnerabilities in advance of so-called 'Patch Tuesday', to give software developers a chance to update affected products before the public announcement.
Microsoft is also including within each bulletin this month an 'Exploitability Index' to help system administrators prioritise the patches '1' denotes consistently functioning exploits (of most concern), '2' denotes inconsistently functioning exploits (of moderate concern), and '3' denotes vulnerabilities that are unlikely to produce functioning exploits (of least concern).
All Microsoft security patches for both Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.
MS08-056 Moderate
Exploitability index: 2. Microsoft recommended that customers consider applying the security update.
Entitled 'Vulnerability in Microsoft Office could allow information disclosure (957699)', this bulletin only affects Microsoft Office XP Service Pack 3; all other supported versions of Microsoft Office are not affected.
This bulletin addresses the vulnerability detailed in CVE-2008-4020. Microsoft said an attacker "who successfully exploited this vulnerability could inject a client side script in the user's browser that could spoof content, disclose information or take any action that the user could take on the affected website."
MS08-057: Critical
Exploitability index: 1-2. Microsoft recommended that customers apply this update immediately.
Entitled 'Vulnerabilities in Microsoft Excel could allow remote code execution (956416)', this bulletin affects Microsoft Office Excel 2000 and is rated 'important' for all supported editions of Microsoft Office Excel 2002, Microsoft Office Excel 2003, Microsoft Office Excel Viewer 2003, Microsoft Office Excel 2007, Microsoft Office Compatibility Pack , Microsoft Office Excel Viewer, and Microsoft Office SharePoint Server 2007.
This bulletin addresses the vulnerability detailed in CVE-2008-4019, CVE-2008-3471 and CVE-2008-3477. Microsoft said an attacker who exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
MS08-058: Critical
Exploitability index: 1-3. Microsoft recommended that customers apply this update immediately.
Entitled 'Cumulative security update for Internet Explorer (956390)', this bulletin affects Internet Explorer 5.01 and Internet Explorer 6 Service Pack 1, running on all supported editions of Microsoft Windows 2000, and for Internet Explorer 6 running on all supported editions of Windows XP. For Internet Explorer 7 running on all supported editions of Windows XP and Windows Vista, this security update is rated 'important'. Otherwise, this security update is rated 'moderate' or 'low'.
This bulletin addresses the issues detailed in CVE-2008-2947, CVE-2008-3472, CVE-2008-3473, CVE-2008-3474, CVE-2008-3475 and CVE-2008-3476. Microsoft said that "the vulnerabilities could allow information disclosure or remote code execution if a user views a specially crafted web page using Internet Explorer."
MS08-059: Critical
Exploitability index: 1. Microsoft recommended that customers apply the update immediately.
Entitled 'Vulnerability in Host Integration Server RPC Service could allow remote code execution (956695)', this bulletin affects Microsoft Host Integration Server 2000, Microsoft Host Integration Server 2004, and Microsoft Host Integration Server 2006.
This bulletin addresses the vulnerability detailed in CVE- 2008-3466. Microsoft said this "vulnerability could allow remote code execution if an attacker sent a specially crafted Remote Procedure Call (RPC) request to an affected system. Customers who follow best practices and configure the SNA RPC service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights."
MS08-060: Critical
Exploitability index: 2. Microsoft recommended that customers apply the update immediately.
Entitled 'Vulnerability in Active Directory could allow remote code execution (957280)', this bulletin affects implementations of Active Directory on Microsoft Windows 2000 Server.
This update addresses the vulnerability detailed in CVE-2008-4023. Microsoft said that "this vulnerability only affects Microsoft Windows 2000 servers configured to be domain controllers. If a Microsoft Windows 2000 server has not been promoted to a domain controller, it will not be listening to Lightweight Directory Access Protocol (LDAP) or LDAP over SSL (LDAPS) queries, and will not be exposed to this vulnerability."
MS08-061: Important
Exploitability index: 1-3. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerabilities in Windows Kernel could allow elevation of privilege (954211)', this bulletin affects users of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
This update addresses the vulnerability detailed in CVE-2008-2250, CVE-2008-2251, and CVE-2008-2252. Microsoft said a "local attacker who successfully exploited these vulnerabilities could take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users".
MS08-062: Important
Exploitability index: 1. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerability in Windows Internet Printing Service could allow remote code execution (953155)', this bulletin affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
This update addresses the vulnerability detailed in CVE-2008-1446. Microsoft said an "attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
MS08-063: Important
Exploitability index: 2. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerability in SMB could allow remote code execution (957095)', this bulletin affects all supported versions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
This update addresses the vulnerability detailed in CVE-2008-4038. Microsoft said the "vulnerability could allow remote code execution on a server that is sharing files or folders. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights".
MS08-064: Important
Exploitability index: 2. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerability in Virtual Address Descriptor manipulation could allow elevation of privilege (956841)', this bulletin affects Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
Read this
Microsoft gears up for victory in the virtual battle
ZDNet talks to Zane Adam, Microsoft's senior director for virtualisation product management
This update addresses the vulnerability detailed in CVE-2008-4036. Microsoft said that "the vulnerability could allow elevation of privilege if a user runs a specially crafted application. An authenticated attacker who successfully exploited this vulnerability could gain elevation of privilege on an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights".
MS08-065: Important
Exploitability index: 3. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerability in Message Queuing [MSMQ] could allow remote code execution (951071)', this bulletin affects Microsoft Windows 2000.
This update addresses the vulnerability detailed in CVE-2008-3479. Microsoft said the "vulnerability could allow remote code execution on Microsoft Windows 2000 systems with the MSMQ service enabled".
MS08-066: Important
Exploitability index: 1. Microsoft recommended that customers apply the update at the earliest opportunity.
Entitled 'Vulnerability in the Microsoft Ancillary Function Driver could allow elevation of privilege (956803)', this bulletin affects Windows XP and Windows Server 2003.
The update addresses the vulnerabilities detailed in CVE-2008-3464. Microsoft said "a local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights".
Credit: Microsoft fixes 20 flaws with 11 patches from CNET News












