Microsoft fixes 20 flaws with Patch Tuesday updates

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Microsoft on Tuesday released its October 2008 security bulletin summary.

The four critical bulletins concern Windows, Internet Explorer, Microsoft Host Integration Server and Microsoft Excel. The patch for Internet Explorer is cumulative.

Microsoft is now sharing the technical details of new vulnerabilities in advance of so-called 'Patch Tuesday', to give software developers a chance to update affected products before the public announcement.

Microsoft is also including within each bulletin this month an 'Exploitability Index' to help system administrators prioritise the patches — '1' denotes consistently functioning exploits (of most concern), '2' denotes inconsistently functioning exploits (of moderate concern), and '3' denotes vulnerabilities that are unlikely to produce functioning exploits (of least concern).

All Microsoft security patches for both Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS08-056 Moderate
Exploitability index: 2. Microsoft recommended that customers consider applying the security update.

Entitled 'Vulnerability in Microsoft Office could allow information disclosure (957699)', this bulletin only affects Microsoft Office XP Service Pack 3; all other supported versions of Microsoft Office are not affected.

This bulletin addresses the vulnerability detailed in CVE-2008-4020. Microsoft said an attacker "who successfully exploited this vulnerability could inject a client side script in the user's browser that could spoof content, disclose information or take any action that the user could take on the affected website."

MS08-057: Critical
Exploitability index: 1-2. Microsoft recommended that customers apply this update immediately.

Entitled 'Vulnerabilities in Microsoft Excel could allow remote code execution (956416)', this bulletin affects Microsoft Office Excel 2000 and is rated 'important' for all supported editions of Microsoft Office Excel 2002, Microsoft Office Excel 2003, Microsoft Office Excel Viewer 2003, Microsoft Office Excel 2007, Microsoft Office Compatibility Pack , Microsoft Office Excel Viewer, and Microsoft Office SharePoint Server 2007.

This bulletin addresses the vulnerability detailed in CVE-2008-4019, CVE-2008-3471 and CVE-2008-3477. Microsoft said an attacker who exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.

MS08-058: Critical
Exploitability index: 1-3. Microsoft recommended that customers apply this update immediately.

Entitled 'Cumulative security update for Internet Explorer (956390)', this bulletin affects Internet Explorer 5.01 and Internet Explorer 6 Service Pack 1, running on all supported editions of Microsoft Windows 2000, and for Internet Explorer 6 running on all supported editions of Windows XP. For Internet Explorer 7 running on all supported editions of Windows XP and Windows Vista, this security update is rated 'important'. Otherwise, this security update is rated 'moderate' or 'low'.

This bulletin addresses the issues detailed in CVE-2008-2947, CVE-2008-3472, CVE-2008-3473, CVE-2008-3474, CVE-2008-3475 and CVE-2008-3476. Microsoft said that "the vulnerabilities could allow information disclosure or remote code execution if a user views a specially crafted web page using Internet Explorer."

MS08-059: Critical
Exploitability index: 1. Microsoft recommended that customers apply the update immediately.

Entitled 'Vulnerability in Host Integration Server RPC Service could allow remote code execution (956695)', this bulletin affects Microsoft Host Integration Server 2000, Microsoft Host Integration Server 2004, and Microsoft Host Integration Server 2006.

This bulletin addresses the vulnerability detailed in CVE- 2008-3466. Microsoft said this "vulnerability could allow remote code execution if an attacker sent a specially crafted Remote Procedure Call (RPC) request to an affected system. Customers who follow best practices and configure the SNA RPC service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights."

MS08-060: Critical
Exploitability index: 2. Microsoft recommended that customers apply the update immediately.

Entitled 'Vulnerability in Active Directory could allow remote code execution (957280)', this bulletin affects implementations of Active Directory on Microsoft Windows 2000 Server.

This update addresses the vulnerability detailed in CVE-2008-4023. Microsoft said that "this vulnerability only affects Microsoft Windows 2000 servers configured to be domain controllers. If a Microsoft Windows 2000 server has not been promoted to a domain controller, it will not be listening to Lightweight Directory Access Protocol (LDAP) or LDAP over SSL (LDAPS) queries, and will not be exposed to this vulnerability."

MS08-061: Important
Exploitability index: 1-3. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerabilities in Windows Kernel could allow elevation of privilege (954211)', this bulletin affects users of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

This update addresses the vulnerability detailed in CVE-2008-2250, CVE-2008-2251, and CVE-2008-2252. Microsoft said a "local attacker who successfully exploited these vulnerabilities could take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users".

MS08-062: Important
Exploitability index: 1. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerability in Windows Internet Printing Service could allow remote code execution (953155)', this bulletin affects all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

This update addresses the vulnerability detailed in CVE-2008-1446. Microsoft said an "attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."

MS08-063: Important
Exploitability index: 2. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerability in SMB could allow remote code execution (957095)', this bulletin affects all supported versions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

This update addresses the vulnerability detailed in CVE-2008-4038. Microsoft said the "vulnerability could allow remote code execution on a server that is sharing files or folders. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights".

MS08-064: Important
Exploitability index: 2. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerability in Virtual Address Descriptor manipulation could allow elevation of privilege (956841)', this bulletin affects Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

This update addresses the vulnerability detailed in CVE-2008-4036. Microsoft said that "the vulnerability could allow elevation of privilege if a user runs a specially crafted application. An authenticated attacker who successfully exploited this vulnerability could gain elevation of privilege on an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights".

Read this

Q&A
Microsoft gears up for victory in the virtual battle

ZDNet talks to Zane Adam, Microsoft's senior director for virtualisation product management

Read more +

MS08-065: Important
Exploitability index: 3. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerability in Message Queuing [MSMQ] could allow remote code execution (951071)', this bulletin affects Microsoft Windows 2000.

This update addresses the vulnerability detailed in CVE-2008-3479. Microsoft said the "vulnerability could allow remote code execution on Microsoft Windows 2000 systems with the MSMQ service enabled".

MS08-066: Important
Exploitability index: 1. Microsoft recommended that customers apply the update at the earliest opportunity.

Entitled 'Vulnerability in the Microsoft Ancillary Function Driver could allow elevation of privilege (956803)', this bulletin affects Windows XP and Windows Server 2003.

The update addresses the vulnerabilities detailed in CVE-2008-3464. Microsoft said "a local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights".

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

6 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

7 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

8 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

10 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

11 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

13 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

14 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

16 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

22 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

24 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

24 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?