Advertisement
Promo

Security threats Toolkit

Microsoft patches four security flaws

Robert Vamosi CNET News.com

Published: 12 Nov 2008 10:08 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Tuesday released its November 2008 security bulletin, including one patch rated 'critical'.

The critical bulletin affects Microsoft XML Core Services and Internet Explorer, while the 'important' bulletin affects Microsoft Server Message Block (SMB) Protocol. Both affect all versions of Windows.

From October, Microsoft began sharing the technical details of new vulnerabilities to give software developers a chance to update affected products before the public announcement. Microsoft is including within each bulletin an 'exploitability index' to help system administrators prioritise the patches. All Microsoft security patches for both Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS08-068: Important
Exploitability index: 1. Microsoft recommends customers apply the update at the earliest opportunity. Titled 'Vulnerability in SMB could allow remote code execution (957097)', this bulletin is important for all supported editions of Microsoft Windows 2000, Windows XP and Windows Server 2003, and moderate for all supported editions of Windows Vista and Windows Server 2008. This bulletin addresses the vulnerability detailed in CVE-2008-4037. Microsoft said an attacker "who successfully exploited this vulnerability could install programs; view, change or delete data; or create new accounts with full user rights".

MS08-069: Critical
Exploitability index: 1-2. Microsoft recommends customers apply this update immediately. Titled 'Vulnerabilities in Microsoft XML Core Services could allow remote code execution (955218)", this bulletin is rated critical for Microsoft XML Core Services 3.0 and important for Microsoft XML Core Services 4.0, Microsoft XML Core Services 5.0 and Microsoft XML Core Services 6.0. This bulletin replaces MS07-042 and addresses the three vulnerabilities detailed in CVE-2007-0099, CVE-2008-4029 and CVE-2008-4033. Microsoft said: "The most severe vulnerability could allow remote code execution if a user viewed a specially crafted web page using Internet Explorer".

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
3 out of 3 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters