Overview of the April 2008 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS08-018 | Input validation vulnerability allows code execution when opening a malicious file. | |||||
| Project CVE-2008-1088 |
KB 950183 | No publicly known exploits | Critical | Critical | Important | |
| MS08-019 | Multiple input validation vulnerabilities allow code execution. Replaces MS07-030. |
|||||
| Visio CVE-2008-1089 CVE-2008-1090 |
KB 949032 |
No publicly known exploits | Important | Critical | Important | |
| MS08-020 | Windows' DNS client vulnerable to spoofing due to lack of entropy in a random number generator. | |||||
| DNS client CVE-2008-0087 |
KB 945553 | Update well published problem | Important | Critical | Critical | |
| MS08-021 |
Heap overflows in opening EMF and WMF images and file name based stack overflow in opening EMF files allow code execution. |
|||||
| GDI CVE-2008-1083 CVE-2008-1087 |
KB 948590 |
PoC available in for pay program Update April 10th: Symantec have reported non-working exploits in the wild. Update April 11th: Arbor networks is reporting exploits in the wild |
Critical | Update PATCH NOW |
Important | |
| MS08-022 | Javascript and visual basic script engines allow code execution. Replaces MS06-023. |
|||||
|
Scripting engines |
KB 944338 | Update PoC available in for pay program | Critical | Critical | Important | |
| MS08-023 | Memory corruption vulnerability in hxvz.dll and 3rd party killbit for a Yahoo! Music Jukebox activeX control that could allow code execution. | |||||
| ActiveX CVE-2008-1086 |
KB 948881 |
PoC exploits were posted on the internet | Critical | Critical | Important | |
| MS08-024 | Cumulative Internet Explorer patch. Adds protection for a memory corruption vulnerability leading to code execution when visiting a compromised or malicious web site. Replaces MS08-010. |
|||||
| MSIE CVE-2008-1085 |
KB 947864 | No publicly known exploits | Critical | Critical | Important | |
| MS08-025 | Input validation vulnerability in the windows kernel allows privilege escalation. | |||||
| Windows kernel CVE-2008-1084 |
KB 941693 |
Proof of concept available in a for pay program | Important | Critical | Critical | |
--
Swa Frantzen -- Gorilla Security
Login here to post a comment. Diary Archive