November 2008 Microsoft Security Bulletin Summary

Today Microsoft issued two security updates one critical and one important.  More info below…

Microsoft Security Bulletin MS08-069 – Critical

Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

Executive Summary

This security update resolves several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Microsoft Security Bulletin MS08-068 – Important

Vulnerability in SMB Could Allow Remote Code Execution (957097)

Executive Summary

This security update resolves a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. The vulnerability could allow remote code execution on affected systems. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

 

Bulletin ID Bulletin Title CVE ID Exploitability Index Assessment Key Notes

MS08-068

Vulnerability in SMB Could Allow Remote Code Execution (957097)

CVE-2008-4037

1 - Consistent exploit code likely

Exploit code is currently public for this vulnerability on Windows XP.

MS08-069

Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

CVE-2008-4029

1 - Consistent exploit code likely

Exploit code for information disclosure is likely as this can be used in cross-domain attacks.

MS08-069

Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

CVE-2007-0099

2 - Inconsistent exploit code likely

This vulnerability involves a race condition in loading XML files. Therefore, it is difficult to exploit consistently.

MS08-069

Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218)

CVE-2008-4033

2 - Inconsistent exploit code likely

 


Posted Nov 11 2008, 06:07 PM by Josh Phillips

Follow Me on Twitter

Did you enjoy this article? If yes, then subscribe to our RSS 2.0 feed or

Windows is a registered trademark of Microsoft Corporation.
Powered by Community Server (Non-Commercial Edition), by Telligent Systems Themed By nb development