Newsgab  
     

Left Nav Register FAQ Members List Calendar Search Today's Posts Mark Forums Read Right Nav

Left Container Right Container
 

Go Back   Newsgab » News » Tech News

Notices

About this page:

Discuss the post Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws made within our Tech News forum; Post Snippet: Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws The updates address vulnerabilities in Internet ...

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11th February 2009, 01:43 AM
tjw61's Avatar
Super Moderator


 
Join Date: May 2006
Location: New Jersey U.S.A.
Posts: 4,002
Rep Points : 4146
Rep Power: 28
tjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond reputetjw61 has a reputation beyond repute
Default Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws

Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws

The updates address vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.


By Thomas Claburn, InformationWeek
Feb. 10, 2009
Code:
http://www.informationweek.com/story/showArticle.jhtml?articleID=213402816


As part of its February patch cycle, Microsoft on Tuesday released four security bulletins addressing eight vulnerabilities in its software.

Two of the bulletins are designated "critical" and two are designated "important." They aim to fix vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.


MS09-002 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Internet Explorer that could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.

MS09-003 (maximum severity of critical): This update resolves two newly discovered and privately reported vulnerabilities in Microsoft Exchange. The first vulnerability could allow remote code execution and the second could allow denial of service.

MS09-004 (maximum severity of important): This update resolves a newly discovered and privately reported vulnerability in SQL Server, which could allow remote code execution if untrusted users access an affected system or if a SQL injection attack occurs to an affected system.

MS09-005 (maximum severity of important): This update resolves three newly discovered and privately reported vulnerabilities in Microsoft Office Visio that could allow remote code execution if a user opens a specially crafted Visio file.
Microsoft also released Security Advisory 960715, which updates a set of previously published ActiveX kill bits. The new kill bits follow from Microsoft security bulletin MS08-070 and affect Akamai Download Manager and Research in Motion AxLoader.

Eric Schultze, CTO of Shavlik Technologies, considers MS09-004 to be the most interesting patch this month. "This patch addresses the zero-day SQL Server flaw reported by Sec-Consult" on Dec. 9, he said in a statement. "This flaw enables attackers to execute code of their choice on the affected SQL Server. The bar for exploitation is raised slightly in that the attacker must already have authenticated access to the SQL Server in order to pull off this exploit."

Because proof-of-concept exploit code for this vulnerability has been published already, Schultze suggests MS09-004 ought to be rated "critical." He advises patching MS09-003 and MS09-004 as soon as possible; MS09-002 and MS09-005, he says, can wait until a more convenient time.

Paul Zimski, VP of market strategy for Lumension, argues that MS09-002, the Internet Explorer patch, also needs to be dealt with right away. "The remote code execution vulnerabilities exist in IE7 on both Windows XP and Windows Vista -- probably the most prevalent Windows configurations in use today," he said in a statement. Microsoft, he added, gives this vulnerability a score of one on its Exploitability Index, meaning that exploit code can be created easily.
__________________
''Life's tough........it's even tougher if you're stupid.'' -John Wayne

"The main difference between the wise man and a fool is that a fool's mistakes never teach him anything." -Unknown

"With age comes the realization of mortality" -Tom Woods
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote


Reply

Tags
brings, fixes, flaws, microsoft, patch, tuesday

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Top 10 Microsoft Stories Of 2008 tjw61 Tech News 1 15th December 2008 12:58 PM
Microsoft After Gates. (And Bill After Microsoft.) tjw61 Tech News 1 25th June 2008 01:53 PM
Microsoft Recalls Mac Office Patch tjw61 Tech News 0 14th December 2006 10:27 PM
Quickest Patch Ever wildwood Slightly Odd and Funny News 1 8th September 2006 12:06 AM


All times are GMT +1. The time now is 02:32 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
 
 




1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32