Overview of the December 2009 Microsoft patches and their status.
# | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
---|---|---|---|---|---|---|
clients | servers | |||||
MS09-069 | Remote code execution vulnerability could allow denial of service if a remote, authenicated attacker sends a specially crafted ISAKMP message while communicating through IPSEC to LSASS. (Replaces MS09-025) | |||||
LSASS CVE-2009-3675 |
KB 974392 | No known exploits. | Severity:Important Exploitability: 3 |
Important | Important | |
MS09-070 | Multiple vulnerabilities allow remote code execution if an attacker sent a specially crafted HTTP request to an ADFS-enabled Web Server. | |||||
ADFS CVE-2009-2508 CVE-2009-2509 |
KB 971726 |
No known exploits. | Severity:Important Exploitability: 3,1 |
N/A | Critical | |
MS09-071 |
Authentication Bypass Vulnerability in MS-CHAP and memory corruption (code execution) |
|||||
Internet Authentication Service CVE-2009-2505 CVE-2009-3677 |
KB 974318 |
No known exploits. | Severity:Critical Exploitability: 2,3 |
N/A | Critical | |
MS09-072 | Multiple vulnerabilities allow remote code execution if a user views a specially crafted web page using Internet Explorer. Higher risk with Higher user rights. Replaces MS09-054. |
|||||
Internet Explorer |
KB 976325 | CVE-2009-3672 known. | Severity:Critical Exploitability: 1,1,1,1 |
PATCH NOW | Important | |
MS09-073 |
Remote code execution vulnerability if a specially crafted file is opened in WordPad or Microsoft Office Word a user could gain the same privileges as the logged in user. |
|||||
WordPad and Office Text Converters CVE-2009-2506 |
KB 975539 | No known exploits. | Severity:Important Exploitability: 2 |
Critical | Important | |
MS09-074 | Remote code execution vulnerability if a user opens a specially crafted Project file allowing the attacker to take complete control of the afftected system. Replaces MS08-018. |
|||||
Microsoft Office Project CVE-2009-0102 |
KB 967183 |
No known exploits. | Severity:Important Exploitability:2 |
Critical | Important |