Overview of the Aug 2010 Microsoft Patches and their status.
Update: Microsoft also released an advisory for an unpatched privilege escalation vulnerability
# | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
---|---|---|---|---|---|---|
clients | servers | |||||
MS10-047 | Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (Replaces MS10-021 ) | |||||
Windows Kernel CVE-2010-1888 CVE-2010-1889 CVE-2010-1890 |
KB 981852 | no known exploits. | Severity:Important Exploitability: 1,2,? |
Important | Important | |
MS10-048 | Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (Replaces MS10-032 ) | |||||
Windows Kernel CVE-2010-1887 CVE-2010-1894 CVE-2010-1895 CVE-2010-1896 CVE-2010-1897 |
KB 2160329 | no known exploits. | Severity:Important Exploitability: ?,1,1,1,1 |
Important | Impoortant | |
MS10-049 | Vulnerabilities in SChannel could allow Remote Code Execution | |||||
IIS and SChannel CVE-2009-3555 CVE-2010-2566 |
KB 980436 | no known exploits. | Severity:Important Exploitability: 3,2 |
Important | Critical | |
MS10-050 | Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (Replaces MS10-016 ) | |||||
Windows Movie Maker CVE-2010-2564 |
KB 981997 | no known exploits. | Severity:Important Exploitability: 1 |
Critical | Important | |
MS10-051 | Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (Replaces MS08-069 ) | |||||
Microsoft XML core services CVE-2010-2561 |
KB 2079403 | no known exploits. | Severity:Critical Exploitability: 2 |
Critical | Critical | |
MS10-052 | Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution | |||||
Microsoft MPEG Layer-3 Codecs CVE-2010-1882 |
KB 2115168 | no known exploits. | Severity:Critical Exploitability: 1 |
Critical | Important | |
MS10-053 | Cumulative Security Update for Internet Explorer (Replaces MS10-035 ) | |||||
Internet Explorer CVE-2010-1258 CVE-2010-2556 CVE-2010-2557 CVE-2010-2558 CVE-2010-2559 CVE-2010-2560 |
KB 2183461 | no known exploits. | Severity:Critical Exploitability: 3,2,1,2,2,1 |
Critical | Important | |
MS10-054 | Vulnerabilities in SMB Server Could Allow Remote Code Execution | |||||
SMB server CVE-2010-2550 CVE-2010-2551 CVE-2010-2552 |
KB 982214 | no known exploits. | Severity:Critical Exploitability: 2,3,3 |
Critical | Critical | |
MS10-055 | Vulnerability in Cinepak Codec Could Allow Remote Code Execution | |||||
Cinepak codec CVE-2010-2553 |
KB 982665 | no known exploits. | Severity:Critical Exploitability: 1 |
Critical | Important | |
MS10-056 | Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (Replaces MS09-068 M009-027 MS10-036 ) | |||||
Word CVE-2010-1900 CVE-2010-1901 CVE-2010-1902 CVE-2010-1903 |
KB 2269707 | no known exploits. | Severity:Important Exploitability: 1,1,2,2 |
Critical | Important | |
MS10-057 | Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (Replaces MS10-036 MS10-038 ) | |||||
Excel CVE-2010-2562 |
KB 2269707 | no known exploits. | Severity:Important Exploitability: 1 |
Critical | Important | |
MS10-058 | Vulnerabilities in TCP/IP Could Allow Elevation of Privilege | |||||
Windows Networking (TCP/IP) CVE-2010-1892 CVE-2010-1893 |
KB 978886 | no known exploits. | Severity:Important Exploitability: 3,1 |
Important | Important | |
MS10-059 | Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege | |||||
Tracing Facility for Services CVE-2010-2554 CVE-2010-2555 |
KB 982799 | no known exploits. | Severity:Important Exploitability: ?,1 |
Important | Important | |
MS10-060 | Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (Replaces MS09-061 ) | |||||
.NET and Silverlight CVE-2010-0019 CVE-2010-1898 |
KB 2265906 | no known exploits. | Severity:Critical Exploitability: 1,1 |
Critical | Critical |
---------------
Jim Clausing, jclausing --at-- isc [dot] sans (dot) org
FOR408 coming to central OH in Sep, see http://www.sans.org/mentor/details.php?nid=22353