X
Tech

Microsoft patches 31 Windows, IE, Office security holes

Microsoft's batch of patches this month is a big one: 10 bulletins covering a total of 31 documented vulnerabilities affecting the Windows OS, the Internet Explorer browser and the Microsoft Office productivity suite (Word, Works and Excel).Five of the 10 bulletins are rated "critical," Microsoft's highest severity rating.
Written by Ryan Naraine, Contributor

Microsoft's batch of patches this month is a big one: 10 bulletins covering a total of 31 documented vulnerabilities affecting the Windows OS, the Internet Explorer browser and the Microsoft Office productivity suite (Word, Works and Excel).

Five of the 10 bulletins are rated "critical," Microsoft's highest severity rating.  Among the patches this month are fixes for a pair of IIS WebDav flaws that were publicly disclosed last month and cover for the CanSecWest Pwn2Own vulnerability that was used to exploit Internet Explorer on Windows 7.

Here's the skinny on this month's updates:

  • MS08-018 (Critical): Fixes two privately reported vulnerabilities in implementations of Active Directory on Microsoft Windows 2000 Server and Windows Server 2003, and Active Directory Application Mode (ADAM) when installed on Windows XP Professional and Windows Server 2003. The more severe vulnerability could allow remote code execution.  It is rated Critical for all supported editions of Microsoft Windows 2000 Server, and rated Important for supported versions of Windows XP Professional and Windows Server 2003.
    followmeontwitter.png
  • MS09-019(Critical): Patches seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe of the vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Affects IE 5.01, IE 6, IE 7 and IE 8 running on all supported editions of Windows.
  • MS09-020(Important): Fixes one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Internet Information Services (IIS). The vulnerabilities could allow elevation of privilege if an attacker sent a specially crafted HTTP request to a Web site that requires authentication. These vulnerabilities allow an attacker to bypass the IIS configuration that specifies which type of authentication is allowed, but not the file system-based access control list (ACL) check that verifies whether a file is accessible by a given user.  Affects all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.
  • MS09-021(Critical): Patches seven privately reported vulnerabilities that could allow remote code execution if a user opens a specially crafted Microsoft Excel file that includes a malformed record object. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system.  It affects Excel 2000, Excel 2002, Excel 2003, Excel 2007, Office 2004 for Mac, and Microsoft Office 2008 for Mac; Open XML File Format Converter for Mac; and all supported versions of Microsoft Office Excel Viewer and Microsoft Office Compatibility Pack.
  • MS09-022(Critical): Covers three privately reported vulnerabilities in Windows Print Spooler. The most severe vulnerability could allow remote code execution if an affected server received a specially crafted RPC request.  It applies to Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
  • MS09-023 (Moderate): Patches a privately reported vulnerability in Windows Search. The vulnerability could allow information disclosure if a user performs a search that returns a specially crafted file as the first result or if the user previews a specially crafted file from the search results. This security update is rated Moderate for Windows Search installed on all supported editions of Windows XP and Windows Server 2003.
  • MS09-024 (Critical): Fixes a privately reported vulnerability in the Microsoft Works converters. The vulnerability could allow remote code execution if a user opens a specially crafted Works file. Affects Word 2000, Word 2002, Word 2003 with the Microsoft Works 6–9 File Converter,  Word 2007 Service Pack 1, Microsoft Works 8.5 and Microsoft Works 9.
  • MS09-025 (Important):Covers two publicly disclosed and two privately reported vulnerabilities in the Windows kernel that could allow elevation of privilege. An attacker who successfully exploited any of these vulnerabilities could execute arbitrary code and take complete control of an affected system. The vulnerabilities could not be exploited remotely or by anonymous users. Affects Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
  • MS09-026 (Important): Patches a publicly disclosed vulnerability in the Windows remote procedure call (RPC) facility where the RPC Marshalling Engine does not update its internal state appropriately. The vulnerability could allow an attacker to execute arbitrary code and take complete control of an affected system.  Rated Important for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
  • MS09-027(Critical): Covers two privately reported vulnerabilities that could allow remote code execution if a user opens a specially crafted Microsoft Word file. Rated Critical for all supported editions of Microsoft Office Word 2000. For all supported editions of Microsoft Office Word 2002, Microsoft Office Word 2003, Microsoft Office Word 2007, Microsoft Office 2004 for Mac, and Microsoft Office 2008 for Mac, and all supported versions of Open XML File Format Converter for Mac, Microsoft Office Compatibility Pack, and Microsoft Office Word Viewers, this security update is rated Important.

Shavlik's Eric Schultze provides valuable recommendations on which patches should be applied with the highest priorities.

Later today, Adobe will also ship security fixes for serious flaws in its Reader/Acrobat product lines.

Editorial standards