Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Microsoft Security Bulletins for

= Check Point has provided a protection to this bulletin

Microsoft Security Bulletin MS09-005:
Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)

Severity: High

CVE-2009-0097: Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Microsoft Office Visio handles memory when opening up Visio files. An attacker could exploit the vulnerability by sending a specially crafted file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site.

CVE-2009-0095: Memory Validation Vulnerability

A remote code execution vulnerability exists in the way Microsoft Office Visio validates object data when opening up Visio files. An attacker could exploit the vulnerability by sending a specially crafted file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site.

CVE-2009-0096: Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Microsoft Office Visio copies object data in memory. An attacker could exploit the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a specially crafted or compromised Web site.

Microsoft Security Bulletin MS09-004:
Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)

Severity: High

CVE-2008-5416: SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability

A remote code execution vulnerability exists in the way that SQL Server checks parameters in the "sp_replwritetovarbin" extended stored procedure. The vulnerability could allow remote code execution if untrusted users have access to an affected system or if a SQL injection vulnerability exists on an affected system. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.

Microsoft Security Bulletin MS09-003:
Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)

Severity: Critical

CVE-2009-0099: Literal Processing Vulnerability

A denial of service vulnerability exists in the EMSMDB2 (Electronic Messaging System Microsoft Data Base, 32 bit build) provider because of the way it handles invalid MAPI commands. An attacker could exploit the vulnerability by sending a specially crafted MAPI command to the application using the EMSMDB32 provider. An attacker who successfully exploited this vulnerability could cause the application to stop responding.

CVE-2009-0098: Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Microsoft Exchange Server decodes the Transport Neutral Encapsulation Format (TNEF) data for a message.

Microsoft Security Bulletin MS09-002:
Cumulative Security Update for Internet Explorer (961260)

Severity: Critical

CVE-2009-0075: Uninitialized Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CVE-2009-0076: CSS Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way Internet Explorer handles Cascading Style Sheets (CSS). An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.

Microsoft Security

2009 Microsoft Security Bulletins by Month