Overview of the June 2008 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS08-030 | A vulnerabilities in the Bluetooth stack allows code execution when a large number of SDP (Service Discover Protocol) requests are made. | |||||
| Bluetooth CVE-2008-1453 |
KB 951376 | No publicly known exploits | Critical | Critical | Important | |
| MS08-031 | Multiple vulnerabilities in MSIE allow code execution and cross domain information leaks. The memory corruption gives access to the same rights as the logged-on user has. The vulnerability in parsing headers allows for HTTP Request Splitting, HTTP Request Smuggling and more (See CVE-2008-1544 for more details). Replaces MS08-024. |
|||||
| MSIE CVE-2008-1442 CVE-2008-1544 |
KB 950759 |
Details on attacking CVE-2008-1544 are publicly available | Critical | PATCH NOW | Important | |
| MS08-032 |
A vulnerability in the Speech API accepts commands sent to it over the speakers of the computer, allowing an attacker access to the same rights as the user has. The speach recognition must be enabled for this to work. |
|||||
| ActiveX Kill Bits CVE-2007-0675 |
KB 950760 | Publicly discussed | Moderate | Important | Less Urgent | |
| MS08-033 |
Multiple input validation vulnerabilities allow code execution in DirectX. Affected are MPEG streams in ASF and AVI files and parameters of SAMI (Synchronized Accessible Media Interchange) files. |
|||||
|
DirectX |
KB 951698 |
No publicly known exploits | Critical | Critical | Important | |
| MS08-034 |
Privilege escalation vulnerability in WINS allows an attacker to gain complete control of a vulnerable system by sending crafted packets to the WINS server. |
|||||
|
WINS |
KB 948745 |
No publicly known exploits | Important | Less Urgent | Critical | |
| MS08-035 |
Input validation failure in the LDAP implementation part of AD leads to a Denial of Service. |
|||||
| Active Directory CVE-2008-1445 |
KB 953235 | No publicly known exploits | Important | Less Urgent | Critical | |
| MS08-036 |
Multiple input validation failures in the PGM packets allow a Denial of Service. PGM is active when MSMQ (Microsoft Message Queuing) is installed on a system. |
|||||
| PGM (Pragmatic General Multicast) CVE-2008-1440 CVE-2008-1441 |
KB 950762 | No publicly known exploits | Important | Important | Important | |
--
Swa Frantzen -- Gorilla Security
Login here to post a comment. Diary Archive
Microsoft Security Bulletin MS08-030 Revised June 19 , 2008.
http://www.microsoft.com/technet/security/bulletin/MS08-030.mspx
http://support.microsoft.com/kb/951376