On TV.com: SUPERNATURAL Breaks with a Bang
BNET Business Network:
BNET
TechRepublic
ZDNet

July 8th, 2008

Microsoft delivers 'important' patches

Posted by Larry Dignan @ 10:51 am

Categories: General, Microsoft, Security

Tags: Microsoft SQL Server, Vulnerability, Patch Management, Microsoft Corp., Microsoft Outlook Web Access, Microsoft Windows, Microsoft Outlook, Microsoft Office, Security, Databases

Microsoft on Tuesday delivered nine important patches to fix vulnerabilities in SQL Server, Exchange Server, Vista and Windows Server.

Among the details, which were previewed last week.

CVE-2008-0085: A vulnerability in the way SQL Server manages memory page reuse. An attacker with database operator access could get to customer data. The versions impacted are SQL Server 7.0, SQL Server 2000 and SQL Server 2005 on Windows 2000, Windows Server 2003 and 2008.

CVE-2008-0086: A convert function vulnerability could allow an attacker to take control of a system. Same deal with CVE-2008-0107 and CVE-2008-0106.

CVE-2008-1435: Microsoft says: “A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.” Operating systems impacted include Windows Vista and Windows Server 2008.

CVE-2008-1447 and CVE-2008-1454: Both of these fix vulnerabilities that allow DNS spoofing to redirect Internet traffic from legit sites. Windows 2000, XP, and Server 2003 impacted.

CVE-2008-2247 and CVE-2008-2248: Both of these vulnerabilities appear in Outlook Web Access for Exchange and involve cross-site scripting issues. Exchange Server 2003 and 2007 impacted. Microsoft sums up:

Exploitation of the vulnerability could lead to elevation of privilege on individual OWA clients connecting to Outlook Web Access for Exchange Server. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted e-mail that would run malicious script from within an individual OWA client. If the malicious script is executed, the script would run in the security context of the user’s OWA session and could perform any action the user could perform such as reading, sending, and deleting e-mail as the logged-on user.

Also see:

 

 

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 54 Talkback(s)
Re: I think i'll install Firefox.
Good for you, though I'm surprised you don't already have it. Though by now, I suppose you do.

Once you have Firefox installed, go to their add-ons site and look up WindizUpdate, and install it... (Read the rest)
Posted by: bart001fr Posted on: 07/16/08 You are currently: a Guest | | Terms of Use
Win XP Update 7-8-08  atimlin | 07/08/08
7-8 update (KB951748)  PromptJock | 07/08/08
KB951748 and Zonealarm...  Zorched | 07/09/08
Trashed my internet connection also  bernief9@... | 07/09/08
got me too  jimmurray1946 | 07/09/08
Trashed mine too  billfranke@... | 07/10/08
Win XP Update 7-8-08  FateJHedgehog@... | 07/10/08
RE: Microsoft delivers 'important' patches  affinity | 07/08/08
RE: Microsoft delivers 'important' patches  rascalrat | 07/08/08
RE: Microsoft delivers 'important' patches  MooMooMooMooMoo | 07/08/08
ZoneAlarm???  PromptJock | 07/08/08
RE: Microsoft delivers 'important' patches  rascalrat | 07/08/08
Uh, uh!  PromptJock | 07/09/08
Re: Automatic updates  bart001fr | 07/09/08
Did you actually read the article?  Pepper.dot.Net | 07/09/08
RE; Did you actually read the article?  bart001fr | 07/16/08
Re: Automatic updates  mlks | 07/09/08
alternate fix  Alzie | 07/09/08
alt fix  lynchjohn | 07/09/08
RE: Microsoft delivers 'important' patches-locks Zone Alarm  Trainsinthewoods | 07/09/08
Microsoft security update vs. Zone Alarm!  anthropologist816@... | 07/09/08
KB951748 & ZoneAlarm  guy@... | 07/09/08
ZoneAlarm  minnbrit@... | 07/09/08
RE: Microsoft delivers 'important' patches  jy.durocher@... | 07/09/08
RE: Microsoft delivers 'important' patches  jbyczkowski@... | 07/09/08
RE: Microsoft delivers 'important' patches  bobbyneuro | 07/09/08
RE: Microsoft delivers 'important' patches  chuck@... | 07/09/08
Changed my Internet Connection also  markorjj@... | 07/09/08
RE: Microsoft delivers 'important' patches  aftonborr@... | 07/09/08
Zonealarm blocks internet access  phala627@... | 07/09/08
Easy explanation  rickroberts_mcse@... | 07/10/08
Better than just a 'Workaround' Now...  mejohnsn | 07/11/08
Zone Alarm  tomcryar | 07/12/08
RE: Microsoft delivers 'important' patches  phala627@... | 07/09/08
RE: Microsoft delivers 'important' patches  docqualizer | 07/09/08
Importance of Forums, when Internet Breaks after MS Patches  hortnut@... | 07/09/08
remember to uncheck ccleaner's 'uninstaller reference'  phala627@... | 07/09/08
RE: Microsoft delivers 'important' patches  RFG_z | 07/09/08
RE: Microsoft delivers 'important' patches  Mostev20 | 07/09/08
It broke SBS 2003 R1  geek49203_z | 07/09/08
5th Patch Stealthed In  cquirke | 07/09/08
The Patch for SQL Server crashed mine  DaveMorris | 07/09/08
my SQL is mySQL  Mnighthawk | 07/11/08
RE: Microsoft delivers 'important' patches  mspark19@... | 07/09/08
RE: Microsoft delivers 'important' patches  azbigrich@... | 07/09/08
custom install  Alzie | 07/09/08
RE: Microsoft delivers 'crap' patches  dewey56 | 07/09/08
Re: I think i'll install Firefox.  bart001fr | 07/16/08
RE: Microsoft delivers 'important' patches  nwcurtis@... | 07/09/08
RE: Microsoft delivers 'important' patches  mlks | 07/09/08
RE: Microsoft delivers 'important' patches  kb0lkt@... | 07/09/08
KB950582 killed my Vista machine  michael56555@... | 07/10/08
RE: Microsoft delivers 'important' patches  Mnighthawk | 07/11/08
RE: Microsoft delivers 'important' patches  lobo1953 | 07/13/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads