Published on Maximum PC (http://www.maximumpc.com)


Microsoft Patches Critical Vulnerability for XP, Vista, Windows 7, and Others
Created 10/24/2008 - 7:53am

Maximum IT
    • Cisco Cranks Out iPhone Security App for IT Managers
    • Verizon Puts Together Telehealth Collaboration Services
    • Ciena Coughs Up $530 Million in Cash for a Slice of Nortel Networks

    Sponsored
SEE MORE MAXIMUM IT
News
  • BenQ and Fujitsu to Jump on E-Book Bandwagon
  • At Least Five Countries Arming Themselves for Cyberwar
  • eBay Giving Out Coupons and Other Compensation after Website Crash
  • Beautiful Curved Monitor Now Available for Sale to Tycoons, Fatcats
  • Another Day, Another Promising New Battery Technology
SEE MORE NEWS
News

Microsoft Patches Critical Vulnerability for XP, Vista, Windows 7, and Others

Posted 10/24/08 at 10:53:38 AM  by Mark Edward Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Microsoft patches Server service vulnerability, doesn't wait for November Patch Tuesday

 

Redmond usually releases security patches once a month, on Patch Tuesday, but Microsoft's security experts are worried enough about a newly reported vulnerability in the Server service to post an "out-of-band" security update, MS08-067, yesterday for all versions of Windows from Windows 2000 SP4 through Windows Server 2008 and Windows 7 pre-beta. Microsoft hasn't issued a security update between Patch Tuesday releases since April 2007, so this is a significant security issue.

Although all supported versions of Windows are vulnerable, Windows 2000 SP4, Windows XP, and Windows Server 2003 versions are especially vulnerable to this flaw, which can permit remote code execution via a specially crafted RFC request.

According to the Security Bulletin summary for October, the vulnerability described in MS08-067 receives the highest Exploitability Index Assessment: 1 - Consistent exploit code likely. From the notes for MS08-067:

Consistent exploit code has been discovered in limited, targeted attacks, affecting Windows XP and Windows Server 2003. While this service is enabled by default on all affected platforms, exploitation is most likely on Microsoft Windows 2000, Windows XP, and Windows Server 2003....

If you're running Windows Update, install the update labeled KB958644. If you need to download and install the update manually, open  the Windows Operating System and Components section of the October security bulletin  and click the link for your operating system. The Windows 7 pre-beta updates for 32-bit and 64-bit versions are not listed in the October security bulletin, but can be obtained by clicking the links provided here.

COMMENTS:2
TAGS: microsoft, operating system, Security, windows xp, Windows Vista, Windows 2000, vulnerability, Patch Tuesday, Operating Systems, windows 7, Windows Server 2008, Windows Server 2003, MS08-067
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/news/microsoft_patches_critical_vulnerability_xp_vista_windows_7_and_others

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
[3] http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx
[4] http://support.microsoft.com/kb/958644
[5] http://www.microsoft.com/downloads/details.aspx?FamilyID=e877d9c1-3e7c-4551-a899-c3fcc5175bb6&DisplayLang=en
[6] http://www.microsoft.com/downloads/details.aspx?FamilyID=0fa96b25-90e3-46ab-bcd5-051f4b2b881b&DisplayLang=en
[7] http://www.maximumpc.com/article/news/fake_microsoft_security_update_email_includes_haxdoor_trojan
[8] http://www.maximumpc.com/article/news/patch_tuesday_also_intros_redmonds_new_active_protection_and_exploitability_index_wmc_updates
[9] http://www.maximumpc.com/article/news/microsoft_fights_back_against_zeroday_exploits_with_mapp_exploitability_index