网站首页  |   业界社区  |  电信社区  |  技术社区   |  极客社区  |  游戏社区  |  生活社区   |   科技博客  |   同事录
TechWeb-业界社区


标题: 微软三月安全公告发布
游客
未注册









发表于 08-3-12 09:11
微软三月安全公告发布

微软已经发布了三月安全公告,本月的公告数量并不多,仅仅4个,但是危险性却是非常的大,其中还包括Microsoft Excel的0day漏洞,利用该漏洞的攻击代码和恶意软件均已在网上开始传播.
此外,其它三个补丁的风险评级无一例外都是“危急”等级,希望大家注意对自己的系统进行修补工作.

查看:Microsoft Security Bulletin Summary for March 2008

Bulletin Identifier         Microsoft Security Bulletin MS08-014

Bulletin Title
       

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029)

Executive Summary
       

This security update resolves several privately reported and publicly reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating
       

Critical

Impact of Vulnerability
       

Remote Code Execution

Detection
       

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will not require a restart.

Affected Software
       

Microsoft Office. For more information, see the Affected Software and Download Locations section.


Bulletin Identifier         Microsoft Security Bulletin MS08-015

Bulletin Title
       

Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (949031)

Executive Summary
       

This security update resolves a privately reported vulnerability in Microsoft Office Outlook. The vulnerability could allow remote code execution if Outlook is passed a specially crafted mailto URI. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This vulnerability is not exploitable by simply viewing an e-mail through the Outlook preview pane.

Maximum Severity Rating
       

Critical

Impact of Vulnerability
       

Remote Code Execution

Detection
       

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will not require a restart.

Affected Software
       

Microsoft Office. For more information, see the Affected Software and Download Locations section.


Bulletin Identifier         Microsoft Security Bulletin MS08-016

Bulletin Title
       

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (949030)

Executive Summary
       

This security update resolves two privately reported vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a malformed Office file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating
       

Critical

Impact of Vulnerability
       

Remote Code Execution

Detection
       

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update will not require a restart.

Affected Software
       

Microsoft Office. For more information, see the Affected Software and Download Locations section.


Bulletin Identifier         Microsoft Security Bulletin MS08-017

Bulletin Title
       

Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (933103)

Executive Summary
       

This critical update resolves two privately reported vulnerabilities in Microsoft Office Web Components. These vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Maximum Severity Rating
       

Critical

Impact of Vulnerability
       

Remote Code Execution

Detection
       

Microsoft Baseline Security Analyzer can detect whether your computer system requires this update. The update may require a restart.

Affected Software
       

Microsoft Office Web Components. For more information, see the Affected Software and Download Locations section.

引用 回复 顶部
查看积分策略说明快速回复主题
选项 标题 Smilies
禁用 URL 识别
禁用 Smilies
禁用 Discuz!代码
使用个人签名
接收新回复邮件通知
内容





当前时区 GMT+8, 现在时间是 08-10-16 03:51
京ICP证060517号

本论坛支付平台由支付宝提供
携手打造安全诚信的交易社区 Powered by Discuz! 5.5.0 © 2001-2008 Comsenz Inc.
清除 Cookies - 联系我们 - TechWeb.com.cn - Archiver - WAP