Home > Windows Security News > Microsoft releases April trove of patches
Windows Security News:
EMAIL THIS LICENSING & REPRINTS

Microsoft releases April trove of patches

By Margie Semilof, Senior News Director
08 Apr 2008 | SearchWindowsSecurity.com

News on enterprise Windows platforms and applications
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft will release five critical and three important vulnerabilities previewed last week as part of its April rollout of security bulletins.

Windows patch management
Microsoft patch management policy

The week in Microsoft Windows Security

All of the vulnerabilities this month are end-user initiated, said Eric Schultze, chief technology officer at Shavlik Technologies LLC, in Roseville, Minn. Also notable about April's patches is that they impact Vista and Windows Server 2008 -- the first for the server since its release in late February.

In its monthly Microsoft patch notice, Microsoft said the five critical vulnerabilities, which could leave users open to remote code executions, target Office Project, Windows vis-à-vis Graphics Device Interface (GDI), VBScript and JScript scripting engines, and Internet Explorer.

Regarding the Windows desktop and server platforms, the critical vulnerability involving GDI -- MS08-021 -- will affect Windows 2000 SP4, Windows XP SP2, Windows XP Professional x64 SP2, Windows Server 2003 SP1 and 2 plus the x64-bit edition, Vista and Vista SP1, plus Windows Server 2008.

Schultze deems this particular vulnerability as the worst on the list for April. It is an image file bug that enables an attacker to take control of a system while a user is "visiting an evil website, opening an evil document or reading an evil email."

Schultze said it's the third such graphic file attack since January 2006.

The three important security bulletins touch on Windows through a spoofing vulnerability in Windows DNS clients, a vulnerability in the Windows kernel where a local attacker could gain access to an affected system, and a vulnerability in Office Visio.

An updated version of the Windows Malicious Software Removal Tool is available on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.



Sound Off! -   Be the first to post a message to Sound Off!


Tags: IndustryProductPatch Maintenance Patching ToolsPost-Patch ProblemsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts