Microsoft Patches Critical Vulnerability for XP, Vista, Windows 7, and Others
Posted 10/24/08 at 10:53:38 AM | by Mark Edward Soper

Redmond usually releases security patches once a month, on Patch Tuesday, but Microsoft's security experts are worried enough about a newly reported vulnerability in the Server service to post an "out-of-band" security update, MS08-067, yesterday for all versions of Windows from Windows 2000 SP4 through Windows Server 2008 and Windows 7 pre-beta. Microsoft hasn't issued a security update between Patch Tuesday releases since April 2007, so this is a significant security issue.
Although all supported versions of Windows are vulnerable, Windows 2000 SP4, Windows XP, and Windows Server 2003 versions are especially vulnerable to this flaw, which can permit remote code execution via a specially crafted RFC request.
According to the Security Bulletin summary for October, the vulnerability described in MS08-067 receives the highest Exploitability Index Assessment: 1 - Consistent exploit code likely. From the notes for MS08-067:
Consistent exploit code has been discovered in limited, targeted attacks, affecting Windows XP and Windows Server 2003. While this service is enabled by default on all affected platforms, exploitation is most likely on Microsoft Windows 2000, Windows XP, and Windows Server 2003....
If you're running Windows Update, install the update labeled KB958644. If you need to download and install the update manually, open the Windows Operating System and Components section of the October security bulletin and click the link for your operating system. The Windows 7 pre-beta updates for 32-bit and 64-bit versions are not listed in the October security bulletin, but can be obtained by clicking the links provided here.
They should label it somethin else.
Submitted by winmaster on Sat, 2008-11-01 10:52
When it showed up in automatic updates for me (Win XP Sp3), i thought it was just automatic updates not updating itself. I had recently done a reinstall and had to repatch Windows. So after downloading like 8 "Security Update for Windows Xp"'s, I thought that it would go away. They should call it "Critical Update for Windows XP Service Pack 2 and 3".
I wondered why...
Submitted by CTskifreak on Fri, 2008-10-24 09:25
I wondered why I had that update yesterday. (Vista Ultimate 32 bit) Well, it is good that they caught this.
I've been a long time member of the CCleaner forum as well, and they had a topic about this as well. I find it interesting when topics such as this over lap on tech forums across the web.
1 NEW COMMENT(S) | 54 TOTAL COMMENTS









