NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Vista SP1 Is Bulletproof Compared to Vista RTM

Just in case you needed a reason to upgrade

By Marius Oiaga, Technology News Editor

13th of February 2008, 10:14 GMT

Adjust text size:



Enlarge picture
Well, if you needed a reason to upgrade to Windows Vista SP1 from the RTM version of Microsoft's latest Windows client, then added security is by all means a catalyst of the service pack's deployment. Microsoft did tout the security enhancements synonymous with the evolution from Vista RTM to Vista SP1, and on February 12, 2008, the company gave ample examples of the fact that the addition of the service pack to the original fabric of the operating system all but bulletproofs the platform.

The February 2008 Monthly Bulletin Release does not affect Windows Vista SP1
in the least. Out of the 11 security bulletins made available on February 12, designed to patch a total of 17 security vulnerabilities, 10 of which labeled with a maximum severity rating of Critical, not a single one impacts Windows Vista SP1.

There are a total of six security bulletins designed to patch security vulnerabilities in Windows Vista, as well as in previously released versions of the Windows operating system, for both the client and server side. For all under the Non-Affected Software section of the documentation accompanying the security updates, it reads Windows Vista Service Pack 1 (all editions).

Windows Vista has not been so lucky. In fact, two security bulletins rated as Critical also address holes in the latest Windows Client. Microsoft Security Bulletin MS08-008 - Critical Vulnerability in OLE Automation Could Allow Remote Code Execution (947890) and Microsoft Security Bulletin MS08-007 - Critical Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution (946026) both plug Critical holes in Vista, that can allow an attacker to execute remote code on a compromised operating system and to completely takeover the platform.

"This critical security update resolves one privately reported vulnerability in the WebDAV Mini-Redirector. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This is a critical security update for all supported editions of Windows XP and Windows Vista and an important security update for all supported editions of Windows Server 2003," Microsoft revealed for MS08-007.

"This critical security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if a user viewed a specially crafted Web page. The vulnerability could be exploited through attacks on Object Linking and Embedding (OLE) Automation. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This is a critical security update for all supported editions of Microsoft Windows 2000, Windows XP, Windows Vista, Microsoft Office 2004 for Mac, and Visual Basic 6," the company added for MS08-008.

The remaining security bulletins affecting the Windows platform, Vista included, can be found via the links below:

- Microsoft Security Bulletin MS08-003 - Important Vulnerability in Active Directory Could Allow Denial of Service (946538)
- Microsoft Security Bulletin MS08-004 - Important Vulnerability in Windows TCP/IP Could Allow Denial of Service (946456)
- Microsoft Security Bulletin MS08-005 - Important Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)
- Microsoft Security Bulletin MS08-006 - Important Vulnerability in Internet Information Services Could Allow Remote Code Execution (942830)

TAGS:

Windows Vista | SP1 | vulnerability | patch | security bulletin
Read by 1,511 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.5/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft: No Windows Home Server Along Vista SP1 and Windows Server 2008

Windows Vista SP1 Crack

Windows Vista SP1 Automated System Recovery

No, You Can't Build Your Own Slipstreamed Installation of Windows Vista SP1

Microsoft Offers Official Hacks for Vista SP1 and Windows Server 2008 Free Rides

No Vista SP1! But How About a Performance, Responsiveness, and Reliability Boost for Vista?

Download Windows Performance Tools Kit for Vista SP1

Windows XP SP3 Release Candidate (RC) 2

Microsoft Already Cutting Features from Windows 7? DirectX 11 the First?

Leaked Vista SP1 RTM Torrents and Download Hacks, All for a Taste of the Service Pack

User opinions:


Comment #1 by: Mihai on 13 Feb 2008, 10:45 GMT reply to this comment

Check the dates and file versions and you will see why Vista SP1 is not affected.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM