Home > Microsoft Releases 8 Security Patches, 4 Deemed 'Critical'

News

Microsoft Releases 8 Security Patches, 4 Deemed 'Critical'

4/8/2008

Microsoft released its latest security update, which includes eight cumulative patches addressing vulnerabilities in Office applications, Windows, and Internet Explorer.

MS08-022, considered critical by the company, secures a vulnerability in the VBScript and JScript scripting engines in Windows 2000, XP and Windows Server 2003. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

MS08-023 and MS08-024, considered critical, address holes that could allow remote code execution if a user viewed specially crafted Web pages using Internet Explorer. Users with administrative rights would be more greatly affected than those with fewer user rights on the system.

MS08-021, also pegged as critical, addresses vulnerabilities in GDI, which could allow remote code execution if a user opened a specially crafted EMF or WMF image file.

MS08-025, considered important, resolves a privately reported vulnerability in the Windows kernel. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. It affects Windows 2000, Windows Server 2003 and 2008, XP and Vista.

MS08-020 addresses a spoofing vulnerability that exists in Windows DNS clients, in which an attacker could send specially crafted responses to DNS requests, thereby spoofing or redirecting Internet traffic from legitimate locations.

MS08-018 and MS08-019 address vulnerabilities in Office Project and Visio, respectively, in which the programs could allow code execution if a user opens a specially crafted file.


Dian Schaffhauser is a writer who covers technology and business. Send your higher education technology news to her at dian@dischaffhauser.com.

Cite this Site

Dian Schaffhauser, "Microsoft Releases 8 Security Patches, 4 Deemed 'Critical'," Campus Technology, 4/8/2008, http://www.campustechnology.com/article.aspx?aid=60711

copy text (above) for proper citation



Recommended Reading
  • IBM Unveils New Software Designed To Streamline eDiscovery

    IBM has announced the release of new Enterprise Content Management (ECM) software specifically designed to meet the needs of clients dealing with complex legal discovery requirements. The eDiscovery solutions expand on IBM's ECM platform and are intended to give organizations greater control of digitally stored documents in an effort to reduce costs and streamline the discovery process involved in litigation.

  • Microsoft Releases SQL Server 2008 to Manufacturing

    Microsoft has released SQL Server 2008 to manufacturing (RTM) and, as an evaluation edition, to subscribers of its Microsoft Development Network and TechNet services, the company announced Wednesday.

  • Security Woes Up, as PHP and OSS Make the List

    Software vulnerabilities are up this year, especially Web browser-based ones, according to a new report from IBM Internet Security Systems. The X-Force 2008 Mid-Year Trend Statistics Report, released in late July, defined the problem broadly. A vulnerability is anything that results "in a weakening or breakdown of the confidentiality, integrity, or accessibility of the computing system."

  • Textbook Publishing in a Flat World

    According to the National Association of College Stores in a 2007 survey, the average cost of a new college textbook was $53. The founders of Flat World Knowledge, which launches with its first run of college textbooks this fall, consider that too high--so high, in fact, that they'll be offering textbooks for free, at least in versions that can be read online.

  • CourseCast 2.0 Adds Podcasting, Streaming Media Features to Free Lecture Capture System

    Panopto has released CourseCast 2.0, an update to the company's classroom capture system that's available free to academic users. CourseCast 2.0 had previously been available as part of Panopto's beta program for educators since June.

  • It IS about Technology: Integrating Higher Ed into Knowledge Culture

    For more than twenty years, we educational technologists have talked about "integrating information technology into higher education." The implication was that education would stay the same and information technology would benignly slip in and cause no ruckus at all. This rhetoric no longer applies, if it ever did, and does a disservice to us as we work through the intricacies of this age.