Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

February 13, 2008 12:00 AM

11 Microsoft Security Bulletins for February 2008

Windows IT Pro
InstantDoc ID #98273
Rating: (0)

Microsoft released 11 security updates for February, rating six of them as critical. Here's a brief description of each update; for more information, go to http://www.microsoft.com/technet/security/bulletin/ms08-feb.mspx

MS08-003: Vulnerability in Active Directory Could Allow Denial of Service

The attack vector for this vulnerability is a Denial of Service (DoS) attack against Active Directory Application Mode (ADAM) on client computers and Active Directory on servers. The most severe consequence from an attack leveraging this vulnerability is an affected computer halting and then automatically restarting. This bulletin replaces previous bulletin MS07-039.

Applies to: Windows 2000, Windows XP, Windows Server 2003

Recommendation: Microsoft rates this update as important. You should perform testing and deployment of this update as part of your organization’s regular patch management routine.

MS08-004: Vulnerability in Windows TCP/IP Could Allow Denial of Service

The attack vector for this privately reported vulnerability is a specially crafted DHCP server response that corrupts TCP/IP structures that cause the affected system to stop responding and restart automatically. This bulletin replaces previous bulletin MS08-001.

Applies to: Windows Vista

Recommendation: Microsoft rates this update as important. You should perform testing and deployment of this update as part of your organization’s regular patch management routine.

MS08-005: Vulnerability in Internet Information Services Could Allow Elevation of Privilege

The attack vector for this privately reported vulnerability is the way that Microsoft IIS handles file change notifications in the default FTP and WWW folders. The most severe consequence from an attack leveraging this vulnerability is the execution of arbitrary code, allowing the attacker to take full control of an affected computer.

Applies to: Windows 2000, Windows XP, Windows Vista, Windows Server 2008

Recommendation: Microsoft rates this update as important. You should perform testing and deployment of this update as part of your organization’s regular patch management routine.

MS08-006: Vulnerability in Internet Information Services Could Allow Remote Code Execution

The attack vector for this privately reported vulnerability is the way that Microsoft IIS handles input to Active Server Pages (ASP) Web pages. An attacker who exploits this vulnerability could perform actions on the IIS server with the same rights as the Worker Process Identity. This bulletin replaces previous bulletin MS06-034.

Applies to: Windows XP, Windows Server 2003

Recommendation: Microsoft rates this update as important. You should perform testing and deployment of this update as part of your organization’s regular patch management routine.

MS08-007: Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution

The attack vector for this vulnerability is the way the WebDAV Mini-Redirector handles responses. The most severe consequence from an attack leveraging this vulnerability is complete control of an affected system.

Applies to: Windows XP, Windows Server 2003, Windows Vista

Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

MS08-008: Vulnerability in OLE Automation Could Allow Remote Code Execution

The attack vector for this vulnerability is a specially crafted Web page. The most severe consequence from an attack leveraging this vulnerability is remote code execution with the privileges of the currently logged on user. This bulletin replaces previous bulletin MS07-043.

Applies to: Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Office 2004 for Mac

Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

MS08-009: Vulnerability in Microsoft Word Could Allow Remote Code Execution

The attack vector for this vulnerability is a specially crafted Microsoft Word file. The most severe consequence from an attack leveraging this vulnerability is complete control of an affected system. This bulletin replaces previous bulletin MS07-060.

Applies to: Office 2000, Office XP, Office 2003 Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

MS08-010: Cumulative Security Update for Internet Explorer

This cumulative update addresses several vulnerabilities, the most serious of which involves an attacker using a specially crafted Web page to take control of an affected system. This bulletin replaces previous bulletin MS07-069.

Applies to: All versions of Windows

Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

MS08-011: Vulnerability in Microsoft Works File Converter Could Allow Remote Code Execution

The attack vector for this privately reported vulnerability is a specially crafted Microsoft Works file. The most severe consequence from an attack leveraging this vulnerability is complete control of an affected computer.

Applies to: Microsoft Office 2003, Microsoft Works 8, Microsoft Works Suite 2005

Recommendation: Microsoft rates this update as important. You should perform testing and deployment of this update as a part of your organization’s regular patch management routine.

MS08-012: Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution

The attack vector for this vulnerability is a specially crafted Microsoft Publisher file. The most severe consequence from an attack leveraging this vulnerability is an attacker taking complete control of an affected computer. This bulletin replaces previous bulletin MS06-054.

Applies to: Office 2000, Office XP, Office 2003

Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

MS08-013: Vulnerability in Microsoft Office Could Allow Remote Code Execution

The attack vector for this vulnerability is a specially crafted Microsoft Office file with a malformed object inserted into the document. The most severe consequence from an attack leveraging this vulnerability is complete control of an affected system. This bulletin replaces previous bulletin MS06-047.

Applies to: Office 2000, Office XP, Office 2003

Recommendation: Microsoft rates this update as critical. You should perform accelerated testing and deployment of this update.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.