Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Microsoft Security Bulletins for

= Check Point has provided a protection to this bulletin

Microsoft Security Bulletin MS08-067:
Vulnerability in Server Service Could Allow Remote Code Execution (958644)

Severity: Critical

CVE-2008-4250: Server Service Vulnerability

A remote code execution vulnerability exists in the Server service on Windows systems. The vulnerability is due to the service not properly handling specially crafted RPC requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS08-066:
Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)

Severity: High

CVE-2008-3464: AFD Kernel Overwrite Vulnerability

An elevation of privilege vulnerability exists in the Ancillary Function Driver (afd.sys) due to Windows improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. A local attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS08-065:
Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)

Severity: High

CVE-2008-3479: Message Queuing Service Remote Code Execution Vulnerability

remote code execution vulnerability exists in the Message Queuing Service due to a specific flaw in the parsing of an RPC request to the Message Queuing service.

Microsoft Security Bulletin MS08-064:
Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)

Severity: High

CVE-2008-4036: Virtual Address Descriptor Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that Memory Manager handles memory allocation and Virtual Address Descriptors (VADs). The vulnerability could allow elevation of privilege if an authenticated attacker runs a specially crafted program on an affected system. An attacker who successfully exploited this vulnerability could gain elevation of privilege on an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.

Microsoft Security Bulletin MS08-063:
Vulnerability in SMB Could Allow Remote Code Execution (957095)

Severity: High

CVE-2008-4038: SMB Buffer Underflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles specially crafted file names. An attempt to exploit the vulnerability would require authentication because the vulnerable function is only reachable when the share type is a disk, and by default, all disk shares require authentication. An attacker who successfully exploited this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS08-062:
Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)

Severity: High

CVE-2008-1446: Integer Overflow in IPP Service Vulnerability

A remote code execution vulnerability exists on Windows systems running IIS with the internet printing service enabled. This issue could allow a remote, authenticated attacker to execute arbitrary code on an affected system.

Microsoft Security Bulletin MS08-061:
Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)

Severity: High

CVE-2008-2250: Windows Kernel Window Creation Vulnerability

An elevation of privilege vulnerability exists because the Windows kernel does not properly validate properties of a window passed during the new window creation process. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2008-2251: Windows Kernel Unhandled Exception Vulnerability

An elevation of privilege vulnerability exists due to a possible "Double Free" condition in the Windows kernel. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2008-2252: Windows Kernel Memory Corruption Vulnerability

An elevation of privilege vulnerability exists due to the Windows kernel improperly validating input passed from user mode to the kernel. The vulnerability could allow an attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft Security Bulletin MS08-060:
Vulnerability in Active Directory Could Allow Remote Code Execution (957280)

Severity: Critical

CVE-2008-4023: Active Directory Overflow Vulnerability

A remote code execution vulnerability exists in implementations of Active Directory on Microsoft Windows 2000 Server. The vulnerability is due to incorrect memory allocation when receiving specially crafted LDAP or LDAPS requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS08-059:
Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)

Severity: Critical

CVE- 2008-3466: HIS Command Execution Vulnerability

A remote code execution vulnerability exists in the SNA Remote Procedure Call (RPC) service for Host Integration Server. An attacker could exploit the vulnerability by constructing a specially crafted RPC request. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS08-058:
Cumulative Security Update for Internet Explorer (956390)

Severity: Critical

CVE-2008-2947: Window Location Property Cross-Domain Vulnerability

A remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow an attacker to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow remote code execution or information disclosure, depending on the operating system, if a user viewed the Web page.

CVE-2008-3472: HTML Element Cross-Domain Vulnerability

A remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow remote code execution or information disclosure, depending on the operating system, if a user viewed the Web page.

CVE-2008-3473: Event Handling Cross-Domain Vulnerability

A remote code execution or information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow remote code execution or information disclosure, depending on the operating system, if a user viewed the Web page.

CVE-2008-3474: Cross-Domain Information Disclosure Vulnerability

An information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to a browser window in another domain or Internet Explorer zone. An attacker could exploit the vulnerability by constructing a specially crafted Web page that could allow information disclosure if a user viewed the Web page.

CVE-2008-3475: Uninitialized Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or that has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CVE-2008-3476: HTML Objects Memory Corruption Vulnerability

A remote code execution vulnerability exists in Internet Explorer due to attempts to access uninitialized memory in certain situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

Microsoft Security Bulletin MS08-057:
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)

Severity: Critical

CVE-2008-3477: Calendar Object Validation Vulnerability

A remote code execution vulnerability exists in the way Excel processes a VBA Performance Cache. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file in a VBA Performance Cache. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2008-3471: File Format Parsing Vulnerability

A remote code execution vulnerability exists in Microsoft Excel as a result of improper memory allocation when loading Excel objects. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed object. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVE-2008-4019: Formula Parsing Vulnerability

The specific flaw exists when parsing Microsoft Excel documents containing a specially crafted formula embedded inside a cell. This can result in a remote compromise of the system under the context of the currently logged in user.

Microsoft Security Bulletin MS08-056:
Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)

Severity: Medium

CVE-2008-4020: Vulnerability in Content-Disposition Header Vulnerability

vulnerability exists in the way that Office processes documents using the CDO Protocol (cdo:) and the Content-Disposition: Attachment header. These documents may be incorrectly rendered in the web browser, leading to cross-site scripting.

Microsoft Security

2008 Microsoft Security Bulletins by Month