Overview of the March 2008 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS08-014 | Multiple vulnerabilities allow code execution when opening a malicious file. Replaces MS07-044, MS07-036 and MS08-013. |
|||||
|
Excel |
At least one vulnerability was abused in targeted attacks. MSRC blog Past diary |
Critical | PATCH NOW | Important | ||
| MS08-015 | Vulnerability in parsing of "mailto:" URIs allows Remote Code Execution. Replaces MS07-003. |
|||||
| Outlook CVE-2008-0110 |
KB 949031 |
No publicly known exploits | Critical | Critical | Important | |
| MS08-016 | Multiple vulnerabilities allow for code execution upon opening a malicious document. Replaces MS07-015, MS07-025 and MS08-013. |
|||||
| Office CVE-2008-0113 CVE-2008-0118 |
KB 949030 | No publicly known exploits | Critical | Critical | Important | |
| MS08-017 | Multiple vulnerabilities allow Remote Code Execution. Affects clients through the web vector and for as of yet, unexplained reasons also certain versions of BizTalk, Commerce and ISA servers. | |||||
| Office web components CVE-2006-4695 CVE-2007-1201 |
KB 933103 |
No publicly known exploits | Critical | Critical | Critical(**) | |
(**): Default classification due to lack of information at this point in time
--
Swa Frantzen -- Gorilla Security
Login here to post a comment. Diary Archive