Wednesday, December 17, 2008

Microsoft Patch - Out of Band - Important

This alert is to provide you with an overview of the new security bulletin released (out of band) on Wednesday, December 17, 2008. Microsoft released security update MS08-078 to address a new vulnerability allowing remote code execution in affected versions of Internet Explorer. MS08-078 has a maximum severity rating of Critical for all versions of Internet Explorer. This security update was released outside of the usual monthly security bulletin release cycle in an effort to protect customers. We request that you take action immediately by first assessing and preparing your own systems and networks and applying the security update, then reaching out to your customers to assist them in securing their systems and networks by applying the update.

Details about this security update are below, but here are your key resources:

· The full bulletin for MS08-078 is available at http://www.microsoft.com/technet/security/bulletin/MS08-078.mspx.
· Attend the webcast hosted by Microsoft to address questions about this bulletin:
Wednesday, December 17, 2008 at 1pm PT or Thursday, December 18, 2008 at 11am PT
· We recommend that Microsoft partners use the Microsoft TechNet Security TechCenter as a source of security information: http://technet.microsoft.com/security

Executive Summary
This security update resolves a publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The security update addresses the vulnerability by modifying the way Internet Explorer validates data binding parameters and handles the error resulting in the exploitable condition.

This security update also addresses the vulnerability first described in Microsoft Security Advisory 961051.

Recommendations
Microsoft recommends that partners first assess their own systems and networks and apply this security update, then reach out and follow up with their customers to assist them in securing their systems and networks to help ensure that their computers are protected from attempted criminal attacks..

New Security Bulletin Technical Details

Identifier
MS08-078
Severity Rating
This security update is rated Critical for Internet Explorer 5.01, Internet Explorer 6, Internet Explorer 6 SP1, and Internet Explorer 7.
Impact of Vulnerability
Remote Code Execution
Detection
Microsoft Baseline Security Analyzer can detect whether your computer system requires this update.
Affected Software
Internet Explorer 5.01 (Windows 2000), Internet Explorer 6 (Windows 2000), Internet Explorer 6 SP1 (Windows XP and Windows Server 2003), and Internet Explorer 7 (Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008). For information about Internet Explorer 8 (Beta) please see the FAQ section of the bulletin.
Restart Requirement
The update will require a restart only if the required files are being used. If this occurs, a message appears that advises you to restart.
Removal Information
· For Windows 2000, Windows XP, Windows Server 2003: Use Add or Remove Programs tool in Control Panel or the Spuninst.exe utility
· For Windows Vista and Windows Server 2008: WUSA.exe does not support uninstall of updates. To uninstall an update installed by WUSA, click Control Panel, and then click Security. Under Windows Update, click View installed updates and select from the list of updates.
Bulletins Replaced by This Update
None.
Full Details:
http://www.microsoft.com/technet/security/bulletin/MS08-078.mspx

No comments: