I just had another big 34.6MB down load through the windows update.
After the installment it requested for a re-start.
When I agreed to it, I noticed this time it had same steps as when the SP-1 was installed. Went through 3 stages!! I do not normally see this three stage on WU.
in addition to the 10 updates mentioned in that thread, microsoft has just re-released automatic update of
KB937287, the Vista Service Pack 1 prerequisite update that previously sent some users of the operating system into an endless reboot cycle during installation. This update had been released in Feb., but because of the reboot problem, was "pulled" until now.
"A fix is being released on Tuesday which will install prior to the problematic update and prevent the system from rebooting during installation. Changes have also been made to the Servicing Stack Update installer code so it checks for the fix before installing. Both updates will install in the proper order through Windows Update."
Perhaps this explains the multiple phases your installation had to go through (???).
This month Microsoft released eight bulletins which repair a total of 10 vulnerabilities. None of these vulnerabilities has been seen within in-the-wild zero-day attacks.
Patch Precedence Out of the eight patches this month, six of the vulnerabilities are related to client-side vulnerabilities. Because of the complex nature of file-format parsing, network-based IPS systems will typically be unable to fully protect end-users. Administrators and users are urged to apply the client-side updates as soon as possible to avoid potential exploitation.
This Month's Bulletins
Critical MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code Execution MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution MS08-023 - Security Update of ActiveX Kill Bits MS08-024 - Cumulative Security Update for Internet Explorer Important MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution MS08-020 - Vulnerability in DNS Client Could Allow Spoofing MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of Privilege
Microsoft Severity Rating: Critical eEye Severity Rating: High
Description This patch fixes one vulnerability within the Microsoft Project. This vulnerability allows an attacker to create a malformed Project file so that when it is opened by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.
CVE-2008-1088 - Project Memory Validation Vulnerability A remote code execution vulnerability exists in the way Microsoft Project handles specially crafted Project files.
This vulnerability requires user-interaction by viewing a malicious Project file. This file could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.
Recommendations Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Important eEye Severity Rating: Medium
Description This patch fixes two vulnerabilities within Microsoft Visio. These vulnerabilities allow an attacker to create a malformed Visio file so that when it is opened by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.
CVE-2008-1089 - Visio Object Header Vulnerability A remote code execution vulnerability exists in the way Microsoft Visio validates object header data in specially crafted files.
CVE-2008-1090 - Visio Memory Validation Vulnerability A remote code execution vulnerability exists in the way Microsoft Visio validates memory allocations when loading specially-crafted .DXF files from disk into memory.
These vulnerabilities require user-interaction by viewing a malicious Visio document. This document could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.
Recommendations Although public exploit code or details for these vulnerabilities have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Important eEye Severity Rating: High
Description This patch fixes one vulnerability within the Microsoft DHCP client. This allows an attacker to potentially respond to a DNS query from a client with a malicious response, thereby directing traffic from a legitimate source to a malicious one.
CVE-2008-0087 - DNS Spoofing Attack Vulnerability A spoofing vulnerability exists in Windows DNS clients. The vulnerability could allow an unauthenticated attacker to send malicious responses to DNS requests made by vulnerable clients, thereby spoofing or redirecting Internet traffic from legitimate locations.
This vulnerability requires no user interaction. However, it does require that the attacker has network connectivity to the requesting DHCP client which could be difficult in many enterprise environments.
Recommendations Although public exploit code for this vulnerability has not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Critical eEye Severity Rating: High
Description This patch fixes two vulnerabilities within the Microsoft Graphics Device Interface (GDI). These vulnerabilities allow an attacker to create a malformed image so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.
CVE-2008-1083 - GDI Heap Overflow Vulnerability A remote code execution vulnerability exists in the way that GDI handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted EMF or WMF image file.
CVE-2008-1087 - Office Web Components DataSource Vulnerability A remote code execution vulnerability exists in the way that GDI handles filename parameters in EMF files. The vulnerability could allow remote code execution if a user opens a specially crafted EMF image file.
These vulnerabilities require user-interaction by viewing a malicious image. This image could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.
Recommendations Although public exploit code for these vulnerabilities has not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch. For systems that might not be able to accept this patch because of internal custom-developed applications, a registry modification may provide mitigation. This can be performed by creating the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles = 1 (DWORD)
Microsoft Severity Rating: Critical eEye Severity Rating: High
Description This patch fixes one vulnerability within the Microsoft VBScript and JScript scripting engines. This vulnerability allows an attacker to create a malformed website so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.
CVE-2008-0083 - VBScript/JScript Remote Code Execution Vulnerability A remote code execution vulnerability exists in the way that the VBScript and JScript scripting engines decode script in Web pages. This vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running specially crafted script.
This vulnerability requires user-interaction by viewing a malicious website.
Recommendations Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Critical eEye Severity Rating: High
Description This patch fixes one vulnerability within a Microsoft ActiveX control as well as adding extra mitigation for Yahoo! Jukebox users. These vulnerabilities allow for remote code execution under the context of the logged in user if that user was tricked into viewing a malicious website.
CVE-2008-1086 - ActiveX Object Memory Corruption Vulnerability A remote code execution vulnerability exists in the ActiveX control hxvz.dll.
Third Party Kill-Bits Microsoft has rolled out kill-bit protection for known Yahoo! Jukebox ActiveX controls. The CLSID's (5f810afc-bb5f-4416-be63-e01dd117bd6c;22fd7c0a-850c-4a53-9821-0b0915c96139) are now officially disabled by Yahoo! as well.
These vulnerabilities require user-interaction by viewing a malicious website.
Recommendations Although public exploit code or details for these vulnerabilities have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for these vulnerabilities as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Critical eEye Severity Rating: High
Description This patch fixes one vulnerability within Microsoft Internet Explorer. This vulnerability allows an attacker to create a malformed web-page so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.
CVE-2008-1085 - Data Stream Handling Memory Corruption Vulnerability A remote code execution vulnerability exists in Internet Explorer because of the way that it processes data streams. An attacker could exploit the vulnerability by constructing a specially crafted Web page.
This vulnerability requires user-interaction by viewing a malicious website.
Recommendations Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
Microsoft Severity Rating: Important eEye Severity Rating: Medium
Description This patch fixes one vulnerability within the Windows kernel. This vulnerability allows an attacker to create a malicious binary that, when executed, could allow for the elevation of privileges to SYSTEM. This could be launched by interactive users or by malware looking to elevate the privileges of the malicious tool to SYSTEM to allow for full system compromise.
CVE-2008-1084 - Windows Kernel Vulnerability An elevation of privilege vulnerability exists due to the Windows kernel improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges.
This vulnerability requires user-interaction to execute a binary, or to be potentially infected by malware that would be able to exploit this vulnerability.
Recommendations Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.
bacillus
2 Intern
•
14378 Posts
781
0
Posted April 8th, 2008 18:00