NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Microsoft Plugs Fresh Round of Vista SP1 and XP SP3 Holes

Nine Important vulnerabilities

By Marius Oiaga, Technology News Editor

9th of July 2008, 11:43 GMT

Adjust text size:


Windows Update
Enlarge picture
On July 8, 2008, Microsoft released a total of four security bulletins plugging soles in both its Windows operating systems as well as in its Server solutions. Even the latest versions of the supported Windows clients, namely Windows Vista Service Pack 1 and Window XP Service Pack 3 are affected. However, the Redmond giant labeled all the patches issued in July with a maximum severity rating of Important, and a scale where the highest risk is associated with the Critical level.

"The July 2008 release contains 4 new bulletins, all with maximum severities
of 'Important'. MS08-037: vulnerabilities in DNS Could Allow Spoofing (953230). MS08-038: vulnerability in Windows Explorer Could Allow Remote Code Execution (950582). MS08-039: vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747). MS08-040: vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)," revealed the Release Manager for the Microsoft Security Response Center.

The four security bulletins are designed to patch no less than nine vulnerabilities. Four security holes affect various versions of SQL Server, including Windows components such as Windows Internal Database (Wyukon) and can allow an attacker to gain elevation of privileges. In this context, the list of affected software is not limited to SQL Server, but spans to encompass operating systems such as Windows 2000, Windows Server 2003, and Windows Server 2008 (with the exception of the core installation). In the eventuality of a successful exploit, targeting two vulnerabilities in Outlook Web Access for Exchange Server, elevation of privileges is also a possibility.

Two security flaws in Windows Domain Name System (DNS) permit spoofing following exploitation, and only 32-bit and 64-bit Windows Vista SP1 along with Windows Server 2008 for Itanium-based Systems are not affected. "The security update addresses the vulnerabilities by using strongly random DNS transaction IDs, using random sockets for UDP queries, and updating the logic used to manage the DNS cache," Microsoft informed.

All the editions of Windows Vista SP1 along with Windows Server 2008 (both x86 and x64) are instead impacted by a patch set up to resolve a vulnerability in Windows Explorer which puts users at risk of remote code execution. The flaw, related to malicious crafted saved-search files is the only vulnerability which was not privately reported to the Redmond giant.

"If you have the Windows Internal Database (Microsoft Windows 2003 or Microsoft Windows 2008) installed on or enabled without SQL Server 2005 SP2 and you have are opt-into Microsoft Update, the SQL Server 2005 service pack 2 update may be offered incorrectly and fail to install. The Windows Internal Database will be updated as expected, since the Windows Internal Database update is also offered. Microsoft is working on resolving this issue and will be updating the detection logic to avoid the incorrect offering," the MSRC Release Manager added.

TAGS:

Windows Vista SP1 | Windows XP SP3 | security bulletin | patch | vulnerability
Read by 1,514 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Poor (1.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Mozilla: Firefox Is Superior to IE, Opera and Safari

Microsoft Warns of New Attacks Targeting ActiveX

Beyond Firefox 3.0 - Firefox 3.0.1 Build 1 Available for Download

Major Update Coming to Vista SP1 and XP SP3, but Users Won't Feel a Thing

Forget Opera 9.5 - Opera 9.51 Final Available for Download

The Ghost in Internet Explorer 8 Beta 1

Windows and Me Taking a Shot at What Vista SP1 and XP SP3 Have Failed to Do

Windows Kernel Patch Causes Vista SP1 to Restart Randomly

Vista SP1 Solution Accelerator Available for Download

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM