UNSOLVED

snowshine

updated

18 years ago

S

snowshine

2 Intern

1095 Posts

0

9495

April 8th, 2008 18:00

Another big update from Automatic WU

I just had another big 34.6MB down load through the windows update.

After the installment it requested for a re-start.

When I agreed to it, I noticed this time it had same steps as when the SP-1 was installed. Went through 3 stages!! I do not normally see this three stage on WU.

 

snow

  • bacillus

    2 Intern

    14378 Posts

    781

    0

    Posted April 8th, 2008 18:00

    same here...
  • 781

    0

    Posted April 8th, 2008 18:00

    same here

    7 updates

    16.2mb

  • ky331

    5 Journeyman

    15623 Posts

    45050 Points

    781

    0

    Posted April 8th, 2008 18:00

    I've listed the 10 potential new windows updates for April here:

    http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&thread.id=67377

     

    depending on your particular system, there can up to:

    5 critical

    3 important

    2 standard (windows malicious software removal tool, outlook junk e-mail filter)

     

    =================================================================================

     

    in addition to the 10 updates mentioned in that thread, microsoft has just re-released automatic update of

    KB937287, the Vista Service Pack 1 prerequisite update that previously sent some users of the operating system into an endless reboot cycle during installation.   This update had been released in Feb., but because of the reboot problem, was  "pulled" until now.

    http://news.zdnet.co.uk/software/0,1000000121,39381817,00.htm

     

    "A fix is being released on Tuesday which will install prior to the problematic update and prevent the system from rebooting during installation. Changes have also been made to the Servicing Stack Update installer code so it checks for the fix before installing. Both updates will install in the proper order through Windows Update."

     

    Perhaps this explains the multiple phases your installation had to go through (???).

    Message Edited by ky331 on 04-08-2008 03:54 PM
  • mombodog

    2 Intern

    12735 Posts

    781

    0

    Posted April 9th, 2008 00:00

    I wish they did this for cars and other products, updates and improvements for the next 4 years or more, for free!

     

     

  • jmwills

    2 Intern

    11984 Posts

    781

    0

    Posted April 9th, 2008 04:00

    Microsoft Patch Disclosure - April 2008

    This month Microsoft released eight bulletins which repair a total of 10 vulnerabilities. None of these vulnerabilities has been seen within in-the-wild zero-day attacks.

     

    Patch Precedence
    Out of the eight patches this month, six of the vulnerabilities are related to client-side vulnerabilities. Because of the complex nature of file-format parsing, network-based IPS systems will typically be unable to fully protect end-users. Administrators and users are urged to apply the client-side updates as soon as possible to avoid potential exploitation.

     


    This Month's Bulletins

    Critical
    MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code Execution
    MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution
    MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution
    MS08-023 - Security Update of ActiveX Kill Bits
    MS08-024 - Cumulative Security Update for Internet Explorer
    Important
    MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution
    MS08-020 - Vulnerability in DNS Client Could Allow Spoofing
    MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of Privilege

    Bulletin Summary

    MS08-018
    Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)
    http://www.microsoft.com/technet/security/bulletin/MS08-018.mspx

    Microsoft Severity Rating: Critical
    eEye Severity Rating: High

    Description
    This patch fixes one vulnerability within the Microsoft Project. This vulnerability allows an attacker to create a malformed Project file so that when it is opened by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.

    CVE-2008-1088 - Project Memory Validation Vulnerability
    A remote code execution vulnerability exists in the way Microsoft Project handles specially crafted Project files.

    This vulnerability requires user-interaction by viewing a malicious Project file. This file could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.

    Recommendations
    Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-019
    Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)
    http://www.microsoft.com/technet/security/bulletin/MS08-019.mspx

    Microsoft Severity Rating: Important
    eEye Severity Rating: Medium

    Description
    This patch fixes two vulnerabilities within Microsoft Visio. These vulnerabilities allow an attacker to create a malformed Visio file so that when it is opened by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.

    CVE-2008-1089 - Visio Object Header Vulnerability
    A remote code execution vulnerability exists in the way Microsoft Visio validates object header data in specially crafted files.

    CVE-2008-1090 - Visio Memory Validation Vulnerability
    A remote code execution vulnerability exists in the way Microsoft Visio validates memory allocations when loading specially-crafted .DXF files from disk into memory.

    These vulnerabilities require user-interaction by viewing a malicious Visio document. This document could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.

    Recommendations
    Although public exploit code or details for these vulnerabilities have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-020
    Vulnerability in DNS Client Could Allow Spoofing (945553)
    http://www.microsoft.com/technet/security/bulletin/MS08-020.mspx

    Microsoft Severity Rating: Important
    eEye Severity Rating: High

    Description
    This patch fixes one vulnerability within the Microsoft DHCP client. This allows an attacker to potentially respond to a DNS query from a client with a malicious response, thereby directing traffic from a legitimate source to a malicious one.

    CVE-2008-0087 - DNS Spoofing Attack Vulnerability
    A spoofing vulnerability exists in Windows DNS clients. The vulnerability could allow an unauthenticated attacker to send malicious responses to DNS requests made by vulnerable clients, thereby spoofing or redirecting Internet traffic from legitimate locations.

    This vulnerability requires no user interaction. However, it does require that the attacker has network connectivity to the requesting DHCP client which could be difficult in many enterprise environments.

    Recommendations
    Although public exploit code for this vulnerability has not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-021
    Vulnerabilities in GDI Could Allow Remote Code Execution (948590)
    http://www.microsoft.com/technet/security/bulletin/MS08-021.mspx

    Microsoft Severity Rating: Critical
    eEye Severity Rating: High

    Description
    This patch fixes two vulnerabilities within the Microsoft Graphics Device Interface (GDI). These vulnerabilities allow an attacker to create a malformed image so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.

    CVE-2008-1083 - GDI Heap Overflow Vulnerability
    A remote code execution vulnerability exists in the way that GDI handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted EMF or WMF image file.

    CVE-2008-1087 - Office Web Components DataSource Vulnerability
    A remote code execution vulnerability exists in the way that GDI handles filename parameters in EMF files. The vulnerability could allow remote code execution if a user opens a specially crafted EMF image file.

    These vulnerabilities require user-interaction by viewing a malicious image. This image could be delivered via many means including: Email, Website, internal network shares, or any number of other delivery methods.

    Recommendations
    Although public exploit code for these vulnerabilities has not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch. For systems that might not be able to accept this patch because of internal custom-developed applications, a registry modification may provide mitigation. This can be performed by creating the following registry key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles = 1 (DWORD)


    --------------------------------------------------------------------------------

    MS08-022
    Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)
    http://www.microsoft.com/technet/security/bulletin/MS08-022.mspx

    Microsoft Severity Rating: Critical
    eEye Severity Rating: High

    Description
    This patch fixes one vulnerability within the Microsoft VBScript and JScript scripting engines. This vulnerability allows an attacker to create a malformed website so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.

    CVE-2008-0083 - VBScript/JScript Remote Code Execution Vulnerability
    A remote code execution vulnerability exists in the way that the VBScript and JScript scripting engines decode script in Web pages. This vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running specially crafted script.

    This vulnerability requires user-interaction by viewing a malicious website.

    Recommendations
    Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-023
    Security Update of ActiveX Kill Bits (948881)
    http://www.microsoft.com/technet/security/bulletin/MS08-023.mspx

    Microsoft Severity Rating: Critical
    eEye Severity Rating: High

    Description
    This patch fixes one vulnerability within a Microsoft ActiveX control as well as adding extra mitigation for Yahoo! Jukebox users. These vulnerabilities allow for remote code execution under the context of the logged in user if that user was tricked into viewing a malicious website.

    CVE-2008-1086 - ActiveX Object Memory Corruption Vulnerability
    A remote code execution vulnerability exists in the ActiveX control hxvz.dll.

    Third Party Kill-Bits
    Microsoft has rolled out kill-bit protection for known Yahoo! Jukebox ActiveX controls. The CLSID's (5f810afc-bb5f-4416-be63-e01dd117bd6c;22fd7c0a-850c-4a53-9821-0b0915c96139) are now officially disabled by Yahoo! as well.

    These vulnerabilities require user-interaction by viewing a malicious website.

    Recommendations
    Although public exploit code or details for these vulnerabilities have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for these vulnerabilities as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-024
    Cumulative Security Update for Internet Explorer (947864)
    http://www.microsoft.com/technet/security/bulletin/MS08-024.mspx

    Microsoft Severity Rating: Critical
    eEye Severity Rating: High

    Description
    This patch fixes one vulnerability within Microsoft Internet Explorer. This vulnerability allows an attacker to create a malformed web-page so that when it is viewed by an unsuspecting user, could allow for the execution of arbitrary code under the context of the logged in user.

    CVE-2008-1085 - Data Stream Handling Memory Corruption Vulnerability
    A remote code execution vulnerability exists in Internet Explorer because of the way that it processes data streams. An attacker could exploit the vulnerability by constructing a specially crafted Web page.

    This vulnerability requires user-interaction by viewing a malicious website.

    Recommendations
    Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.


    --------------------------------------------------------------------------------

    MS08-025
    Vulnerability in Windows Kernel Could Allow Elevation of Privilege (941693)
    http://www.microsoft.com/technet/security/bulletin/MS08-025.mspx

    Microsoft Severity Rating: Important
    eEye Severity Rating: Medium

    Description
    This patch fixes one vulnerability within the Windows kernel. This vulnerability allows an attacker to create a malicious binary that, when executed, could allow for the elevation of privileges to SYSTEM. This could be launched by interactive users or by malware looking to elevate the privileges of the malicious tool to SYSTEM to allow for full system compromise.

    CVE-2008-1084 - Windows Kernel Vulnerability
    An elevation of privilege vulnerability exists due to the Windows kernel improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges.

    This vulnerability requires user-interaction to execute a binary, or to be potentially infected by malware that would be able to exploit this vulnerability.

    Recommendations
    Although public exploit code or details for this vulnerability have not been released in a public forum, eEye Research suggests that vulnerable hosts be patched for this vulnerability as soon as possible after internal applications have been verified to not be adversely affected by this patch.