Microsoft Security Updates - October 2008
There are definitely lots of important and critical updates to Windows, IE, Office, etc. These updates should be pilot tested and deployed quickly, as some of these vulnerabilities have been exploited in the past. So far, these updates are working well at both home and work.
MS08-056: Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)
Affects: Microsoft Office XP
Link: http://www.microsoft.com/technet/security/bulletin/ms08-056.mspx
MS08-057: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Affects: Microsoft Excel 2000/XP/2003/2007, Excel Viewer, Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats, Sharepoint Server 2007, Office 2004/2008 for Mac
Link: http://www.microsoft.com/technet/security/bulletin/ms08-057.mspx
MS08-058: Cumulative Security Update for Internet Explorer (956390)
Affects: Internet Explorer
Link: http://www.microsoft.com/technet/security/bulletin/ms08-058.mspx
MS08-059: Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695)
Affects: Host Integration Server 2000/2004/2006
Link: http://www.microsoft.com/technet/security/bulletin/ms08-059.mspx
MS08-060: Vulnerability in Active Directory Could Allow Remote Code Execution (957280)
Affects: Windows 2000 Server
Link: http://www.microsoft.com/technet/security/bulletin/ms08-060.mspx
MS08-061: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (954211)
Affects: Windows 2000, XP, Server 2003, Vista, Server 2008
Link: http://www.microsoft.com/technet/security/bulletin/ms08-061.mspx
MS08-062: Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)
Affects: Windows 2000, XP, Server 2003, Vista, Server 2008
Link: http://www.microsoft.com/technet/security/bulletin/ms08-062.mspx
MS08-063: Vulnerability in SMB Could Allow Remote Code Execution (957095)
Affects: Windows 2000, XP, Server 2003, Vista, Server 2008
Link: http://www.microsoft.com/technet/security/bulletin/ms08-063.mspx
MS08-064: Vulnerability in Virtual Address Descriptor Manipulation Could Allow Elevation of Privilege (956841)
Affects: Windows 2000, XP, Server 2003, Vista, Server 2008
Link: http://www.microsoft.com/technet/security/bulletin/ms08-064.mspx
MS08-065: Vulnerability in Message Queuing Could Allow Remote Code Execution (951071)
Affects: Windows 2000 Service Pack 4
Link: http://www.microsoft.com/technet/security/bulletin/ms08-065.mspx
MS08-066: Vulnerability in the Microsoft Ancillary Function Driver Could Allow Elevation of Privilege (956803)
Affects: Windows XP, Server 2003
Link: http://www.microsoft.com/technet/security/bulletin/ms08-066.mspx
KB956391: Cumulative security update for ActiveX Killbits
Affects: Windows 2000, XP, Server 2003, Vista, Server 2008
Link: http://support.microsoft.com/kb/956391
Additional links below:
Microsoft: http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx
ISC: http://isc.sans.org/diary.html?storyid=5180