Overview of the October 2008 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS08-056 | Cross site scripting (XSS) in the way Office XP SP3 handles the dialog window for the content-disposition:download and the cdo: protocol. | |||||
| Office CVE-2008-4020 |
KB 957699 | No publicly known exploits | Moderate | Important | Less Urgent | |
| MS08-057 | Multiple vulnerabilities in Excel lead to random code execution. This also affect sharepoint server. Replaces MS08-043. |
|||||
| Office CVE-2008-4019 CVE-2008-3471 CVE-2008-3477 |
KB 956416 | No publicly known exploits | Critical | Critical | Critical (**) |
|
| MS08-058 | Multiple vulnerabilities in MSIE lead to random code execution and or information leaks. Replaces MS08-045. |
|||||
| IE CVE-2008-2947 CVE-2008-3472 CVE-2008-3473 CVE-2008-3474 CVE-2008-3475 CVE-2008-3476 |
KB 956390 | CVE-2008-2947 is publicly known | Critical | Critical | Important | |
| MS08-059 | RPC requests can bypass authentication and lead to random code execution. | |||||
| Host Integration Server (HIS) CVE-2008-3466 |
KB 956695 |
No publicly known exploits | Critical | Important | Critical | |
| MS08-060 | A buffer Replaces MS08-035. |
|||||
| Windows active directory CVE-2008-4023 |
KB 957280 | No publicly known exploits | Critical | N/A | Critical | |
| MS08-061 | Multiple vulnerabilities in the windows kernel allow privilege escalation. Replaces MS08-025. |
|||||
| Windows kernel CVE-2008-2250 CVE-2008-2251 CVE-2008-2252 |
KB 954211 | No publicly known exploits | Important | Important | Important (***) |
|
| MS08-062 | An Interger |
|||||
| Windows internet printing (IIS) CVE-2008-1446 |
KB 953155 | Actively exploited in targeted attacks | Important | Less Urgent (****) | Critical | |
| MS08-063 | Crafted filenames lead to random code execution in the SMB protocol. Replaces MS06-063. |
|||||
| Windows file sharing CVE-2008-4038 |
KB 957095 | No publicly known exploits | Important | Important | Critical | |
| MS08-064 | An integer Replaces MS07-066, MS07-022 and Advisory 932596. |
|||||
| Windows virtual address descriptor CVE-2008-4036 |
KB 956841 | No publicly known exploits | Important | Important | Important | |
| MS08-065 | An input validation failure in an RPC of MSQS allows random code execution. | |||||
| Windows 2000 message queuing CVE-2008-3479 |
KB 951071 | No publicly known exploits | Important | Important | Important | |
| MS08-066 | An input validation failure allows privilege escalation. | |||||
| Windows ancillary function driver CVE-2008-3464 |
KB 956803 | No publicly known exploits | Important | important | Less Urgent (***) |
|
| Advisory 956391 |
Killbits for 3rd party (Microgaming, System Requirements Lab, PhotostockPro) as well as Microsoft ActiveX controls mentioned in MS02-044, MS08-017, MS08-041 and MS08-052. | |||||
| IE Active X killbits |
KB 956391 | - | Critical | Important | ||
(**): For sharepoint servers. Important for others.
(***): for shared servers this is most likely critical.
(****): assuming no IIS was installed.
--
Swa Frantzen -- Section 66