On TV.com: Why Is Everyone in TV High School SO OLD
BNET Business Network:
BNET
TechRepublic
ZDNet

December 9th, 2008

MS Patch Tuesday whopper: 28 vulnerabilities in Windows, IE, Office

Posted by Ryan Naraine @ 1:24 pm

Categories: Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Malware, Microsoft, Passwords, Patch Watch, Responsible disclosure, Spam and Phishing, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Microsoft Office, Vulnerability, Microsoft Windows, Microsoft Internet Explorer, Microsoft Corp., Security, Ryan Naraine

Microsoft slaps patch on 28 software vulnerabilitiesMicrosoft today dropped a monster Patch Tuesday release with fixes for at least 28 vulnerabilities affecting Windows, Office, Internet Explorer, Visual Basic Active Controls and Windows Media Player.

Of the 28 flaws, 23 carry a “critical” rating, meaning they could be used to launch remote code execution attacks with minimal user action.  It is the largest patch batch from Redmond since the company implemented the Patch Tuesday schedule five years ago.

Most of the bulletins address client-side flaws that could be exploited via the browser or if a user opens a booby-trapped file.

[ SEE: Hackers exploiting (unpatched) IE 7 flaw to launch drive-by attacks ]

The bulletin with the most patches (MS08-072) addresses a total of 8 flaws in the ubiquitous Microsoft Office software suite.  According to Microsoft, the bugs could be exploited if a user is tricked into opening a rigged Word of RTF (Rich Text Format) file.

Another major bulletin is MS08-073, which covers 4 flaws in Internet Explorer, the world’s most widely deployed browser.  These could be exploited if a user simply surfs to a specially crafted page in IE, making it a perfect target for drive-by download attacks.

Here are the raw details on all the patches:

  • MS08-070 (critical; 6 vulnerabilities fixed): This update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls), which could allow remote code execution if a user browsed a Web site that contains specially crafted content.
  • MS08-071 (critical; 2 vulnerabities fixed): This update resolves two privately reported vulnerability in Windows, which could allow remote code execution if a user opens a specially crafted WMF image file.
  • MS08-072 (critical; 8 vulnerabilities): This update resolves eight privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Word or Rich Text Format (RTF) file.
  • MS08-073 (critical; 4 vulnerabilities fixed): This update resolves four privately reported vulnerabilities in Internet Explorer, which could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
  • MS08-074 (critical; 3 vulnerabilities): This update resolves three privately reported vulnerabilities in Microsoft Office, which could allow remote code execution if a user opens a specially crafted Excel file.
  • MS08-075 (critical; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution if a user opens and saves a specially crafted saved-search file within Windows Explorer or if a user clicks a specially crafted search URL.
  • MS08-076 (important; 2 vulnerabilities): This update resolves two privately reported vulnerabilities in Windows, which could allow remote code execution.
  • MS08-077 (important; 1 vulnerability): This update resolves one privately reported vulnerability in Microsoft Office SharePoint, which could allow elevation of privilege if an attacker bypasses authentication by browsing to an administrative URL on a SharePoint site. A successful attack could result in denial of service or information disclosure.

[ SEE: Coming on Patch Tuesday: 8 bulletins, 6 critical ]

According to Eric Schultze, CTO of patch-management firm Shavlik Technologies, Windows users should prioritize around the MS08-76 as well as MS08-070 through MS08-075, as soon as possible.

“Corporations and hosting services that use Sharepoint 2007 should install MS08-077 as soon as they can,” Schultze said.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 45 Talkback(s)
Yes Bravo to MS.. buuutt..
I am very pleased with the monster fixes MS did. I just have one complaint, or rather series of complaints.. since the tuesday update, I am having major blue screen issues with all non MS software.. ... (Read the rest)
Posted by: junkmailstone@... Posted on: 12/26/08 You are currently: a Guest | | Terms of Use
MS Patch Tuesday whopper: 28 vulnerabilities in Windows, IE, Office  Loverock Davidson | 12/09/08
Agreed.  jamesrayg | 12/09/08
They all have them....  daMan25 | 12/09/08
You stink at logic.  kozmcrae | 12/09/08
As were the 40 or so...  Sleeper Service | 12/10/08
Speaking of logic  frgough | 12/10/08
It's only a tu quoque...  Sleeper Service | 12/10/08
Holy crap!  kozmcrae | 12/10/08
Settle. And why is this called a "whopper"? It's very small compared to...  xuniL_z | 12/10/08
you are a nipple head  ragingpanda | 12/10/08
Nope  crypt2121 | 12/10/08
@ravingpanda  xuniL_z | 12/15/08
RE: @ravingpanda  richdave | 12/16/08
same same  ThinkFairer | 12/09/08
Put Your Postings Where Your Mouth Is  itanalyst2@... | 12/10/08
agreed  cwallen19803@... | 12/10/08
Yes Bravo to MS.. buuutt..  junkmailstone@... | 12/26/08
Wow.....  todbran@... | 12/09/08
Better late than ' Version N+1'  V@... | 12/09/08
Zune Phone?? Wow, Microsoft Innovation Strikes Again!  itanalyst2@... | 12/10/08
I'd buy a Zune phone  davidhayes | 12/10/08
Too Little, Too Late  itanalyst2@... | 12/10/08
haha  tikigawd | 12/10/08
DUMBEST POST OF THE DAY  itanalyst2@... | 12/10/08
If i remember correctly  rtk | 12/11/08
Why Are You Using ITunes Anyway??  itanalyst2@... | 12/10/08
Incrementally...  arminw | 12/10/08
Carrier?  jsargent | 12/11/08
Hmm  tikigawd | 12/10/08
Hmm...Another Idiot Post  itanalyst2@... | 12/10/08
NOT IDIOTIC POST  SLOVEHEART1 | 12/10/08
You missed Hawkeye.  kozmcrae | 12/10/08
Sure you have.  rtk | 12/11/08
You should know, shill...  hasta la Vista, bah-bie | 12/12/08
??  rtk | 12/12/08
Too cryptic for the anonymous shill?  hasta la Vista, bah-bie | 12/14/08
So you are the one zune owner?  ralphrides | 12/10/08
Er.. Did I miss something?  Wolfie2K3 | 12/10/08
So, When does it...  parrotshark | 12/10/08
yawn  subl33t | 12/10/08
RE: MS Patch Tuesday whopper: 28 vulnerabilities in Windows, IE, Office  SLOVEHEART1 | 12/10/08
LOL  crypt2121 | 12/10/08
I'm on dial up  Greenknight_z | 12/11/08
Patch Tuesday  trm1945 | 12/13/08
Maybe the people of this study need to look at MS again...  dinosaur_z | 12/16/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads