10/15/2008
Microsoft updates : Internet Storm Center ratings
# | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
clients | servers | |||||
Cross site scripting (XSS) in the way Office XP SP3 handles the dialog window for the content-disposition:download and the cdo: protocol. | ||||||
Office | No publicly known exploits | Moderate | Important | Less Urgent | ||
Multiple vulnerabilities in Excel lead to random code execution. This also affect sharepoint server. | ||||||
No publicly known exploits | Critical | Critical | Critical | |||
Multiple vulnerabilities in MSIE lead to random code execution and or information leaks. | ||||||
IE | CVE-2008-2947 is publicly known | Critical | Critical | Important | ||
RPC requests can bypass authentication and lead to random code execution. | ||||||
Host Integration Server (HIS) | No publicly known exploits | Critical | Important | Critical | ||
A buffer | ||||||
Windows active directory | No publicly known exploits | Critical | N/A | Critical | ||
Multiple vulnerabilities in the windows kernel allow privilege escalation. | ||||||
Windows kernel | No publicly known exploits | Important | Important | Important | ||
An Interger | ||||||
Windows internet printing (IIS) | Actively exploited in targeted attacks | Important | Less Urgent (****) | Critical | ||
Crafted filenames lead to random code execution in the SMB protocol. | ||||||
Windows file sharing | No publicly known exploits | Important | Important | Critical | ||
An integer | ||||||
Windows virtual address descriptor | No publicly known exploits | Important | Important | Important | ||
An input validation failure in an RPC of MSQS allows random code execution. | ||||||
Windows 2000 message queuing | No publicly known exploits | Important | Important | Important | ||
An input validation failure allows privilege escalation. | ||||||
Windows ancillary function driver | No publicly known exploits | Important | important | Less Urgent | ||
Killbits for 3rd party (Microgaming, System Requirements Lab, PhotostockPro) as well as Microsoft ActiveX controls mentioned in MS02-044, MS08-017, MS08-041 and MS08-052. | ||||||
| - | Critical | Important | |||
10:03 | Permalink | Comments (0) | Email this
|
|
del.icio.us
|
|
Digg |
Facebook




Post a comment