Microsoft Releases 8 Security Patches, 4 Deemed 'Critical'

Microsoft released its latest security update, which includes eight cumulative patches addressing vulnerabilities in Office applications, Windows, and Internet Explorer.

MS08-022, considered critical by the company, secures a vulnerability in the VBScript and JScript scripting engines in Windows 2000, XP and Windows Server 2003. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

MS08-023 and MS08-024, considered critical, address holes that could allow remote code execution if a user viewed specially crafted Web pages using Internet Explorer. Users with administrative rights would be more greatly affected than those with fewer user rights on the system.

MS08-021, also pegged as critical, addresses vulnerabilities in GDI, which could allow remote code execution if a user opened a specially crafted EMF or WMF image file.

MS08-025, considered important, resolves a privately reported vulnerability in the Windows kernel. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. It affects Windows 2000, Windows Server 2003 and 2008, XP and Vista.

MS08-020 addresses a spoofing vulnerability that exists in Windows DNS clients, in which an attacker could send specially crafted responses to DNS requests, thereby spoofing or redirecting Internet traffic from legitimate locations.

MS08-018 and MS08-019 address vulnerabilities in Office Project and Visio, respectively, in which the programs could allow code execution if a user opens a specially crafted file.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • student reading a book with a brain, a protective hand, a computer monitor showing education icons, gears, and leaves

    4 Steps to Responsible AI Implementation

    Researchers at the University of Kansas Center for Innovation, Design & Digital Learning (CIDDL) have published a new framework for the responsible implementation of artificial intelligence at all levels of education.

  • glowing digital brain interacts with an open book, with stacks of books beside it

    Federal Court Rules AI Training with Copyrighted Books Fair Use

    A federal judge ruled this week that artificial intelligence company Anthropic did not violate copyright law when it used copyrighted books to train its Claude chatbot without author consent, but ordered the company to face trial on allegations it used pirated versions of the books.

  • server racks, a human head with a microchip, data pipes, cloud storage, and analytical symbols

    OpenAI, Oracle Expand AI Infrastructure Partnership

    OpenAI and Oracle have announced they will develop an additional 4.5 gigawatts of data center capacity, expanding their artificial intelligence infrastructure partnership as part of the Stargate Project, a joint venture among OpenAI, Oracle, and Japan's SoftBank Group that aims to deploy 10 gigawatts of computing capacity over four years.

  • laptop displaying a phishing email icon inside a browser window on the screen

    Phishing Campaign Targets ED Grant Portal

    Threat researchers at cybersecurity company BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.