Overview of the November 2009 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS09-063 | Random code execution due to a memory corruption vulnerability in a service for working with PDAs. Only affects Vista and Server 2008. This service listens on ports TCP port 5357 and 5358 and outbound UDP port 3702 and is enabled when a user browses for devices on their network. | |||||
| WSDAPI CVE-2009-2512 |
KB 973565 | No known exploits. | Severity:Critical Exploitability:2 |
Critical | Critical | |
| MS09-064 | Random code execution due to an input validation failure. Only affects Windows 2000. This license server is enabled by default, it uses RPC over TCP ports 139 and 445. | |||||
| License logging Server CVE-2009-2523 |
KB 974783 | No known exploits. | Severity:Critical Exploitability:2 |
N/A | Critical | |
| MS09-065 | Multiple vulnerabilities allow random code execution or privilege escalation. Replaces MS09-025. |
|||||
| Kernel-mode drivers CVE-2009-1127 CVE-2009-2513 CVE-2009-2514 |
KB 969947 | No known exploits, part of the vulnerability in CVE-2009-2514 was made public. | Severity:Critical Exploitability:2,1,1 |
Critical | Critical | |
| MS09-066 | Denial of Service vulnerability in the LSASS service. This uses TCP ports 389, 636, 3268, 3269 Replaces MS09-021 and MS09-035. |
|||||
| Active Directory CVE-2009-1928 |
KB 973309 | No known exploits. | Severity:Important Exploitability:3 |
N/A | Important | |
| MS09-067 |
Multiple vulnerabilities allow random code execution. |
|||||
| Office: Excel CVE-2009-3127 CVE-2009-3128 CVE-2009-3129 CVE-2009-3130 CVE-2009-3131 CVE-2009-3132 CVE-2009-3133 CVE-2009-3134 |
KB 972652 | No known exploits. | Severity:Important Exploitability:2,2,1,1,1,2,2,2 |
Critical | Important | |
| MS09-068 |
An input validation vulnerability allows random code execution. |
|||||
| Office: Word CVE-2009-3135 |
KB 976307 | No known exploits | Severity:Important Exploitability:1 |
Critical | Important | |
--
Swa Frantzen -- Section 66