Overview of the October 2009 Microsoft patches and their status.
# | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
---|---|---|---|---|---|---|
clients | servers | |||||
MS09-050 | Vulnerabilities in SMBv2 Could Allow Remote Code Execution (Vista and Windows Server 2008 SP2 only) | |||||
SMBv2 CVE-2009-2526 CVE-2009-2532 CVE-2009-3103 |
KB 975517 first mentioned in KB 975497 |
CVE-2009-3103 is publicly known! see our diary here. |
Severity:Critical Exploitability:3,1,1 |
Critical | Critical | |
MS09-051 | Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution | |||||
Windows Media Runtime CVE-2009-0555 CVE-2009-2525 |
KB 975682 | CVE-2009-0555 known publically |
Severity:Critical Exploitability:1,2 |
Critical | Important | |
MS09-052 | Vulnerability in Windows Media Player Could Allow Remote Code Execution Replaces MS08-076 |
|||||
Windows Media Format CVE-2009-2527 |
KB 974112 | No known exploits. | Severity:Critical Exploitability:1 |
Critical | Critical | |
MS09-053 | Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution | |||||
IIS FTP Service CVE-2009-2521 CVE-2009-3023 |
KB 975254 | Exploits Known for both vulnerabilities! |
Severity:Important Exploitability:3,1 |
Important | Critical | |
MS09-054 | Cumulative Security Update for Internet Explorer Replaces MS09-034 |
|||||
Internet Explorer CVE-2009-1547 CVE-2009-2529 CVE-2009-2530 CVE-2009-2531 |
KB 974455 | Exploits known for CVE-2009-2529 |
Severity: Critical Exploitability: 2,1,2,2 |
Critical | Critical | |
MS09-055 | Cumulative Secuirty Update of ActiveX Kill Bits Replaces MS09-032 |
|||||
ActiveX Killbits CVE-2009-2493 |
KB 973525 | No known exploits. | Severity:Critical Exploitability: N/A |
Critical | Important | |
MS09-056 | Vulnerabiliites in Windows CryptoAPI Could Allow Spoofing Replaces MS04-007 |
|||||
Windows CryptoAPI CVE-2009-2510 CVE-2009-2511 |
KB 974571 | publically known (NULL exploits) |
Severity:Important Exploitability:3,3 |
Critical | Important | |
MS09-057 | Vulnerability in Indexing Service could allow remote code execution if user browses to a malicious page. Replaces MS06-053 |
|||||
Indexing Service CVE-2009-2507 |
KB 969059 | No known exploits. | Severity:Important Exploitability:2 |
Critical | Important | |
MS09-058 | Vulnerability in Windows Kernel could allow privilege escalation. Replaces MS06-022 and MS08-064 |
|||||
Windows Kernel CVE-2009-2515 CVE-2009-2516 CVE-2009-2517 |
KB 971486 | No known exploits. | Severity:Important Exploitability:2,3,3 |
Important | Important | |
MS09-059 | Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service | |||||
LSASS CVE-2009-2524 |
KB 975467 | No known exploits. | Severity:Important Exploitability:3 |
Important | Important | |
MS09-060 |
Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Office Remote Code Execution |
|||||
Active Template Library |
KB 973965 | No known exploits. | Severity:Critical Exploitability:2 |
Critical | Important | |
MS09-061 |
Vulnerabiliites in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution |
|||||
.Net Runtime / Silverlight |
KB 974378 | CVE-2009-2497 is public. |
Severity:Critical Exploitability:1,1,1 |
Critical | Critical | |
MS09-062 | Multiple vulnerabilities allow arbitrary code execution. This affect windows, Office (including the viewer), SQLserver and various developer tools. Also affects Forefront Client Security on Windows 2000 SP 4. Replaces MS08-052. |
|||||
GDI+ CVE-2009-2500 CVE-2009-2501 CVE-2009-2502 CVE-2009-2503 CVE-2009-2504 CVE-2009-2518 CVE-2009-2528 CVE-2009-3126 |
KB 957488 | No publicly known exploits. | Severity:Critical Exploitability:2,2,2,1,2,2,1,2 |
Critical | Critical |
------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter
Thanks!