Microsoft Releases 8 Security Patches, 4 Deemed 'Critical'

Microsoft released its latest security update, which includes eight cumulative patches addressing vulnerabilities in Office applications, Windows, and Internet Explorer.

MS08-022, considered critical by the company, secures a vulnerability in the VBScript and JScript scripting engines in Windows 2000, XP and Windows Server 2003. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

MS08-023 and MS08-024, considered critical, address holes that could allow remote code execution if a user viewed specially crafted Web pages using Internet Explorer. Users with administrative rights would be more greatly affected than those with fewer user rights on the system.

MS08-021, also pegged as critical, addresses vulnerabilities in GDI, which could allow remote code execution if a user opened a specially crafted EMF or WMF image file.

MS08-025, considered important, resolves a privately reported vulnerability in the Windows kernel. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. It affects Windows 2000, Windows Server 2003 and 2008, XP and Vista.

MS08-020 addresses a spoofing vulnerability that exists in Windows DNS clients, in which an attacker could send specially crafted responses to DNS requests, thereby spoofing or redirecting Internet traffic from legitimate locations.

MS08-018 and MS08-019 address vulnerabilities in Office Project and Visio, respectively, in which the programs could allow code execution if a user opens a specially crafted file.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • hand touching glowing connected dots

    Registration Now Open for Tech Tactics in Education: Thriving in the Age of AI

    Tech Tactics in Education has officially opened registration for its May 7 virtual conference on "Thriving in the Age of AI." The annual event, brought to you by the producers of Campus Technology and THE Journal, offers hands-on learning and interactive discussions on the most critical technology issues and practices across K–12 and higher education.

  • glowing shield hovers above a digital cloud platform with abstract data streams and cloud icons in the background

    Google to Acquire Cloud Security Firm Wiz

    Google has announced it will acquire cloud security startup Wiz. If completed, the acquisition — an all-cash deal valued at $32 billion — would mark the largest in Google's history.

  •  laptop on a clean desk with digital padlock icon on the screen

    Study: Data Privacy a Top Concern as Orgs Scale Up AI Agents

    As organizations race to integrate AI agents into their cloud operations and business workflows, they face a crucial reality: while enthusiasm is high, major adoption barriers remain, according to a new Cloudera report. Chief among them is the challenge of safeguarding sensitive data.

  • From the Kuali Days 2025 Conference: A CEO's View of Planning for AI

    How can a company serving higher education navigate the changes AI brings to ed tech? What will customers expect? CT talks with Kuali CEO Joel Dehlin, who shared his company's AI strategies with attendees at Kuali Days 2025 in Anaheim.