Microsoft Security Bulletins for April 2008
5 Critical
- MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)
- MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution (948590)
- MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)
- MS08-023 - Security Update of ActiveX Kill Bits (948881)
- MS08-024 - Cumulative Security Update for Internet Explorer (947864)
3 Important
- MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)
- MS08-020 - Vulnerability in DNS Client Could Allow Spoofing (945553)
- MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of Privilege (941693)
For information about non-security releases on Windows Update and Microsoft update, please see:
http://support.microsoft.com/kb/894199/en-us
http://technet.microsoft.com/en-us/wsus/bb466214.aspx
The monthly security bulletin webcast is scheduled tomorrow, April 9, 2008 at 11 a.m., PST.
Please scan your system using Microsoft Baseline Security Analyzer for missing security updates as well as common security misconfigurations:
Customers in the U.S. and Canada can receive technical support from Microsoft Product Support Services at 1-866-PCSAFETY. International customers can receive support from their local Microsoft subsidiaries http://support.microsoft.com/common/international.aspx
There is no charge for support that is associated with security updates.
Security Bulletin Summary:
http://www.microsoft.com/technet/security/bulletin/ms08-apr.mspx
http://www.microsoft.com/protect/computer/updates/bulletins/200804.mspx
Microsoft Security Response Center Blog: http://blogs.technet.com/msrc/archive/2008/04/08/april-2008-monthly-release.aspx
Microsoft Security Vulnerability Research and Defense Blog: http://blogs.technet.com/swi/
For other Microsoft security tools and resources, visit http://www.microsoft.com/security/portal/resources.aspx