Newsletter:

Skip Navigation LinksHome > News > Security > Eleven fixes for Patch Tuesday

Eleven fixes for Patch Tuesday

By Shaun Nichols
15 October 2008 03:37PM
Tags: remote | code | critical | bulletins | execution | fixes

Microsoft has issued the October installment of its monthly security update.

The latest 'Patch Tuesday' release includes eleven bulletins which address a total of 20 security vulnerabilties. Four of the bulletins are rated 'critical,' while six more are listed as 'important' and the remaining bulletin categorized and 'moderate.'

Among the critical patches are a fix for a remote code execution flaw in Excel which could an attacker to perform a remote malware installation by way of a speciall-crafted Excel file.

The second critical fix addresses a remote code flaw in Microsoft's Host Integration Server product, while another addresses a problem in the active directory component for Windows Server 2000.

The final critical bulletin is a cumulative update for Internet Explorer which includes remote code execution fixes for IE 5, 6 and 7.

Of the six bulletins rated as 'important,' three addressed remote code execution, including fixes for the Windows Server Message Block and Internet Printing Service, along with a flaw in the Message Queuing component for Windows 2000.

Three more 'important' bulletins fixed privilege-elevation flaws in the Windows Kernel, Virtual Address Descriptor and the Ancillary Function Driver.

The 'moderate' bulletin addresses a vulnerability in Microsoft Office XP SP3 which could be exploited for information disclosure.

According to McAfee security research and communications director David Marcus, the remote code flaws pose the biggest risk to users who do not apply the patch.

"It is the month of remote code execution bugs,” Marcus declared.

"Many of the vulnerabilities addressed by Microsoft's new fixes could allow an attacker to gain complete control over a vulnerable computer by tricking a user to visit a malicious web site or open a rigged Office file.”

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6603) -  internet
(6412) -  iinet
(6387) -  copyright
(6387) -  afact
(5988) -  servers
(5988) -  mipi
(4782) -  telstra
(4473) -  broadband
(4425) -  nbn
(2888) -  internode
(2432) -  microsoft
(1879) -  network
(1458) -  data
(1367) -  google
(1330) -  software