Executive Summary
| Summary | |
|---|---|
| Title | Microsoft Updates for Multiple Vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | TA08-288A | First vendor Publication | 2008-10-14 |
| Vendor | US-CERT | Last vendor Modification | 2008-10-14 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Microsoft has released updates that address vulnerabilities in Microsoft Windows, Internet Explorer, and Microsoft Office. I. Description Microsoft has released updates to address vulnerabilities that affect Microsoft Windows, Internet Explorer, and Microsoft Office as part of the Microsoft Security Bulletin Summary for October 2008. The most severe vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code. For more information, see the US-CERT Vulnerability Notes Database. II. Impact A remote, unauthenticated attacker could execute arbitrary code or cause a vulnerable application to crash. III. Solution Apply updates from Microsoft Microsoft has provided updates for these vulnerabilities in the October 2008 Security Bulletin Summary. The security bulletin describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. Administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS). |
Original Source
| Url : http://www.us-cert.gov/cas/techalerts/TA08-288A.html |
CAPEC : Common Attack Pattern Enumeration & Classification
| id | Name |
|---|---|
| CAPEC-3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters |
| CAPEC-7 | Blind SQL Injection |
| CAPEC-8 | Buffer Overflow in an API Call |
| CAPEC-9 | Buffer Overflow in Local Command-Line Utilities |
| CAPEC-10 | Buffer Overflow via Environment Variables |
| CAPEC-13 | Subverting Environment Variable Values |
| CAPEC-14 | Client-side Injection-induced Buffer Overflow |
| CAPEC-18 | Embedding Scripts in Nonscript Elements |
| CAPEC-22 | Exploiting Trust in Client (aka Make the Client Invisible) |
| CAPEC-24 | Filter Failure through Buffer Overflow |
| CAPEC-26 | Leveraging Race Conditions |
| CAPEC-28 | Fuzzing |
| CAPEC-29 | Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions |
| CAPEC-31 | Accessing/Intercepting/Modifying HTTP Cookies |
| CAPEC-32 | Embedding Scripts in HTTP Query Strings |
| CAPEC-42 | MIME Conversion |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
| CAPEC-45 | Buffer Overflow via Symbolic Links |
| CAPEC-46 | Overflow Variables and Tags |
| CAPEC-47 | Buffer Overflow via Parameter Expansion |
| CAPEC-52 | Embedding NULL Bytes |
| CAPEC-53 | Postfix, Null Terminate, and Backslash |
| CAPEC-63 | Simple Script Injection |
| CAPEC-64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic |
| CAPEC-66 | SQL Injection |
| CAPEC-67 | String Format Overflow in syslog() |
| CAPEC-71 | Using Unicode Encoding to Bypass Validation Logic |
| CAPEC-72 | URL Encoding |
| CAPEC-73 | User-Controlled Filename |
| CAPEC-78 | Using Escaped Slashes in Alternate Encoding |
| CAPEC-79 | Using Slashes in Alternate Encoding |
| CAPEC-80 | Using UTF-8 Encoding to Bypass Validation Logic |
| CAPEC-81 | Web Logs Tampering |
| CAPEC-83 | XPath Injection |
| CAPEC-85 | Client Network Footprinting (using AJAX/XSS) |
| CAPEC-86 | Embedding Script (XSS ) in HTTP Headers |
| CAPEC-88 | OS Command Injection |
| CAPEC-91 | XSS in IMG Tags |
| CAPEC-99 | XML Parser Attack |
| CAPEC-101 | Server Side Include (SSI) Injection |
| CAPEC-104 | Cross Zone Scripting |
| CAPEC-106 | Cross Site Scripting through Log Files |
| CAPEC-108 | Command Line Execution through SQL Injection |
| CAPEC-109 | Object Relational Mapping Injection |
| CAPEC-110 | SQL Injection through SOAP Parameter Tampering |
| CAPEC-171 | Variable Manipulation |
| CAPEC-172 | Time and State Attacks |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-20 | Improper Input Validation |
| CWE-665 | Improper Initialization |
| CWE-399 | Resource Management Errors |
| CWE-264 | Permissions, Privileges, and Access Controls |
| CWE-189 | Numeric Errors |
| CWE-287 | Improper Authentication |
| CWE-200 | Information Exposure |
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| CWE-20 | Improper Input Validation |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:5764 | |||
| Oval ID: | oval:org.mitre.oval:def:5764 | ||
| Title: | Integer Overflow in IPP Service Vulnerability | ||
| Description: | Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-1446 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5902 | |||
| Oval ID: | oval:org.mitre.oval:def:5902 | ||
| Title: | Windows Kernel Window Creation Vulnerability | ||
| Description: | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-2250 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6010 | |||
| Oval ID: | oval:org.mitre.oval:def:6010 | ||
| Title: | Windows Kernel Unhandled Exception Vulnerability | ||
| Description: | Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-2251 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6045 | |||
| Oval ID: | oval:org.mitre.oval:def:6045 | ||
| Title: | Windows Kernel Memory Corruption Vulnerability | ||
| Description: | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-2252 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5901 | |||
| Oval ID: | oval:org.mitre.oval:def:5901 | ||
| Title: | Window Location Property Cross-Domain Vulnerability | ||
| Description: | Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-2947 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 5.01 Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5825 | |||
| Oval ID: | oval:org.mitre.oval:def:5825 | ||
| Title: | Messaging Queue Service Remote Code Execution Vulnerability | ||
| Description: | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3464 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6075 | |||
| Oval ID: | oval:org.mitre.oval:def:6075 | ||
| Title: | HIS Command Execution Vulnerability | ||
| Description: | Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3466 |
Version: | 5 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Microsoft Host Integration Server 2000 Microsoft Host Integration Server 2004 Client Microsoft Host Integration Server 2004 Microsoft Host Integration Server 2006 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5750 | |||
| Oval ID: | oval:org.mitre.oval:def:5750 | ||
| Title: | File Format Parsing Vulnerability | ||
| Description: | Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a BIFF file with a malformed record that triggers a user-influenced size calculation, aka "File Format Parsing Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3471 |
Version: | 5 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | Microsoft Excel 2000 Microsoft Excel 2002 Microsoft Excel 2003 Microsoft Excel 2007 Microsoft Office Excel Viewer 2003 Microsoft Office Excel Viewer 2007 Microsoft Office Compatibility Pack |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:12364 | |||
| Oval ID: | oval:org.mitre.oval:def:12364 | ||
| Title: | Information disclosure vulnerability in Internet Explorer due to HTML element | ||
| Description: | Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3472 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:13255 | |||
| Oval ID: | oval:org.mitre.oval:def:13255 | ||
| Title: | Information disclosure vulnerability in Internet Explorer due to improper event-handling | ||
| Description: | Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3473 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:13299 | |||
| Oval ID: | oval:org.mitre.oval:def:13299 | ||
| Title: | Cross-Domain Information Disclosure Vulnerability in Internet Explorer | ||
| Description: | Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3474 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 6 Microsoft Internet Explorer 7 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:13151 | |||
| Oval ID: | oval:org.mitre.oval:def:13151 | ||
| Title: | Uninitialized Memory Corruption Vulnerability in Internet Explorer | ||
| Description: | Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3475 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 6 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:13344 | |||
| Oval ID: | oval:org.mitre.oval:def:13344 | ||
| Title: | HTML Objects Memory Corruption Vulnerability in Internet Explorer | ||
| Description: | Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3476 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Internet Explorer 5.01 Microsoft Internet Explorer 6 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5870 | |||
| Oval ID: | oval:org.mitre.oval:def:5870 | ||
| Title: | Calendar Object Validation Vulnerability | ||
| Description: | Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3477 |
Version: | 4 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | Microsoft Excel 2000 Microsoft Excel 2002 Microsoft Excel 2003 |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:5998 | |||
| Oval ID: | oval:org.mitre.oval:def:5998 | ||
| Title: | Messaging Queue Service Remote Code Execution Vulnerability | ||
| Description: | Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-3479 |
Version: | 1 |
| Platform(s): | Microsoft Windows 2000 |
Product(s): | |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:6102 | |||
| Oval ID: | oval:org.mitre.oval:def:6102 | ||
| Title: | Formula Parsing Vulnerability | ||
| Description: | Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file containing a formula within a cell, aka "Formula Parsing Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-4019 |
Version: | 8 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | Microsoft Excel 2000 Microsoft Excel 2002 Microsoft Excel 2003 Microsoft Excel 2007 Microsoft Office Excel Viewer 2003 Microsoft Office Excel Viewer 2007 Microsoft Office SharePoint Server 2007 Microsoft Office Compatibility Pack |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5969 | |||
| Oval ID: | oval:org.mitre.oval:def:5969 | ||
| Title: | Vulnerability in Content-Disposition Header Vulnerability | ||
| Description: | Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a "Content-Disposition: attachment" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka "Vulnerability in Content-Disposition Header Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-4020 |
Version: | 2 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 |
Product(s): | Microsoft Office XP |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:6107 | |||
| Oval ID: | oval:org.mitre.oval:def:6107 | ||
| Title: | Active Directory Overflow Vulnerability | ||
| Description: | Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-4023 |
Version: | 1 |
| Platform(s): | Microsoft Windows 2000 |
Product(s): | |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:5343 | |||
| Oval ID: | oval:org.mitre.oval:def:5343 | ||
| Title: | Virtual Address Descriptor Elevation of Privilege Vulnerability (MS08-064) | ||
| Description: | Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-4036 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5787 | |||
| Oval ID: | oval:org.mitre.oval:def:5787 | ||
| Title: | SMB Buffer Underflow Vulnerability | ||
| Description: | Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2008-4038 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application |
| 7 |
| Application | 1 | |
| Application | 3 | |
| Application | 5 | |
| Application | 4 | |
| Application | 8 | |
| Application | 2 | |
| Application | 3 | |
| Application | 4 | |
| Os | 1 | |
| Os | 6 | |
| Os | 6 | |
| Os | 4 | |
| Os | 4 | |
| Os | 6 |
SAINT Exploits
| Description | Link |
|---|---|
| Microsoft Host Integration Server SNA RPC authentication bypass | More info here |
| Microsoft Excel formula parsing integer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 49118 | Microsoft IE HTML Object Handling Memory Corruption |
| 49117 | Microsoft IE componentFromPoint Unitialized Memory Corruption |
| 49116 | Microsoft IE Unspecified Cross-domain Information Disclosure |
| 49115 | Microsoft IE Unspecified Cross-domain Arbitrary Script Execution |
| 49114 | Microsoft IE Unspecified HTML Element Cross-Domain Code Execution |
| 49113 | Microsoft IE Window Location Property Cross-Domain Code Execution |
| 49078 | Microsoft Excel Embedded Formula Parsing Arbitrary Code Execution |
| 49077 | Microsoft Excel Calendar Object Validation VBA Performance Cache Processing A... |
| 49076 | Microsoft Excel BIFF File Malformed Object Handling Arbitrary Code Execution |
| 49068 | Microsoft Host Integration Server (HIS) SNA RPC Request Remote Overflow |
| 49061 | Microsoft Windows Ancillary Function Driver (afd.sys) Local Privilege Escalation |
| 49060 | Microsoft Windows Message Queuing Service RPC Request Handling Remote Code Ex... |
| 49059 | Microsoft IIS IPP Service Unspecified Remote Overflow |
| 49058 | Microsoft Windows Active Directory LDAP(S) Request Handling Remote Overflow |
| 49057 | Microsoft Windows SMB File Name Handling Remote Underflow |
| 49056 | Microsoft Windows Kernel Memory Corruption Local Privilege Escalation |
| 49055 | Microsoft Windows Kernel New Window Creation Process Arbitrary Code Execution |
| 49054 | Microsoft Windows Kernel Double-free Unspecified Local Privilege Escalation |
| 49053 | Microsoft Windows Virtual Address Descriptors (VAD) Local Privilege Escalation |
| 49052 | Microsoft Office CDO Protocol (cdo:) Content-Disposition: Attachment Header XSS |
| 46630 | Microsoft IE location Window Object Handling XSS |
Metasploit Database
| id | Description |
|---|---|
| 2008-10-14 | Microsoft Host Integration Server 2006 Command Execution Vulnerability |

TA08-288A
(Critical)
(High)
(Medium)











