Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

February 11th, 2009, 16:40 GMT · By

4 Security Bulletins Patch IE in Vista SP1 and XP SP3, Exchange, SQL Server and Visio

SHARE:

Adjust text size:


Windows Update
Enlarge picture
As an integral part of its monthly patch cycle, Microsoft made available on February 10, 2009, a total of four security bulletins patching vulnerabilities in a range of software products including Internet Explorer running on Windows Vista SP1 and Windows XP SP3, but also Exchange, SQL Server and Visio. Two of the security bulletins are labeled with a maximum severity rating of Critical with the remaining two just Important. In February 2009 Microsoft patched no less than eight security vulnerabilities, three of which considered Critical, and five just Important.

“We’re releasing four new security bulletins as part of our regular monthly release process.  MS09-002 rated Critical that addresses two code execution vulnerabilities in Internet Explorer. MS09-003 rated Critical that addresses one code execution vulnerability and one denial of service vulnerability in Exchange Server. MS09-004 rated Important that addresses one code execution vulnerability in SQL Server. MS09-005 rated Important that addresses three code execution vulnerabilities in Visio. We’re also releasing Microsoft Security Advisory 960715 that announces the release of a new cumulative update for killbits on third-party ActiveX controls,” revealed a member of the Microsoft Security Response Center (MSRC).

MS09-002 fixes two Critical vulnerabilities (Uninitialized Memory Corruption, and CSS Memory Corruption) in Internet Explorer 7 and Internet Explorer 8 on all supported Windows operating systems and even on Windows 7 and Windows Vista SP2. MS09-003 also deals with two vulnerabilities involving Memory Corruption and Literal Processing. The SQL Server sp_replwritetovarbin Limited Memory Overwrite vulnerability is the sole patched by MS09-004 with MS09-005 resolving three flaws related to memory corruption and validation.

The Microsoft Security Advisory (960715) Update Rollup for ActiveX Kill Bits “includes kill bits for the following third-party software: Akamai Download Manager - this security update sets a kill bit for an ActiveX control developed by Akamai Technologies. Research in Motion (RIM) AxLoader - this security update sets a kill bit for an ActiveX control developed by Research In Motion (RIM),” Microsoft revealed.

TELL US WHAT YOU THINK:

2,999 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Windows 7 Kills Ultimate Extras, Even Vista's

2 Critical Holes Plugged in IE7 on Vista SP1 and XP SP3

IE8 SmartScreen Filter RC Update

Microsoft to Kill Windows 7 Beta Build 7000 Downloads

New Windows Live Hotmail Update Adds Fresh Features

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM