Qualys Vulnerability R&D Lab has released new vulnerability checks in the Enterprise TruRisk Platform to protect organizations against 26 vulnerabilities that were fixed in 11 bulletins announced today by Microsoft. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their Qualys subscription. Visit Qualys Security Blog to prioritize remediation.
Non-Qualys customers can audit their network for these and other vulnerabilities by signing up for a Qualys Free Trial, or by trying Qualys Community Edition.
Microsoft has released 11 security bulletins to fix newly discovered flaws in their software. Qualys has released the following checks for these new vulnerabilities:
Affected products:
Snapshot Viewer for Microsoft Access
Microsoft Office Access 2000
Microsoft Office Access 2002
Microsoft Office Access 2003
Note: The vulnerability is currently being actively exploited.
Snapshot Viewer for Microsoft Access:
http://www.microsoft.com/download/details.aspx?FamilyId=7C22BB32-7CE3-4FF2-8366-BA2EB5135833
Microsoft Office 2000 Service Pack 3 (Microsoft Office Access 2000 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?familyid=54e4031d-298f-480c-88d5-0ad3b2b62ba9
Microsoft Office XP Service Pack 3 (Microsoft Office Access 2002 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?familyid=34b655f8-1922-4246-94ca-ed381c3e3b13
Microsoft Office 2003 Service Pack 2 and Microsoft Office 2003 Service Pack 3 (Microsoft Office Access 2003 Service Pack 2 and Microsoft Office Access 2003 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?familyid=fd698517-a504-427d-9e5f-fde8f102142c
Refer to Micrsoft Security Bulletin MS08-041 for further details.
Previously this was a Zero Day.
Microsoft Office XP Service Pack 3 (Microsoft Word 2002 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=c7146dfc-e1be-4d13-877b-1d9bcacc4a64
Microsoft Office 2003 Service Pack 2 (Microsoft Word 2003 Service Pack 2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=13a37b76-9fec-426f-8176-3c95f934efe0
Microsoft Office 2003 Service Pack 3 (Microsoft Word 2003 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=13a37b76-9fec-426f-8176-3c95f934efe0
Refer to Micrsoft Security Bulletin MS08-042 for further details.
- Excel Credential Caching Vulnerability (CVE-2008-3003)
- Excel Indexing Validation Vulnerability (CVE-2008-3004)
- Excel Index Array Vulnerability (CVE-2008-3005)
- Excel Record Parsing Vulnerability (CVE-2008-3006)
Microsoft Office 2000 Service Pack 3 (Excel 2000 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=4bf8688e-e5b9-4e53-a1a1-8cf1acfdb80b
Microsoft Office XP Service Pack 3 (Excel 2002 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=9BBF7550-F5C4-4B9B-BD86-1E7BE6C42EB5
Microsoft Office 2003 Service Pack 2 (Excel 2003 Service Pack 2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3-4952-8ada-0de5a50973f0
Microsoft Office 2003 Service Pack 3 (Excel 2003 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3-4952-8ada-0de5a50973f0
2007 Microsoft Office System (Excel 2007):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2753e8d6-e156-49ef-af2d-4c521c808ffd
2007 Microsoft Office System Service Pack 1 (Excel 2007 Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2753e8d6-e156-49ef-af2d-4c521c808ffd
Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7ed9e75-15f2-4950-98b3-93023ba0f4c1
Microsoft Office Excel Viewer 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7ed9e75-15f2-4950-98b3-93023ba0f4c1
Microsoft Office Excel Viewer:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b574d906-7f09-49b0-80bf-e84dee8c4583
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7afdae9b-9c74-4af7-9844-0e54221ea3b9
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7afdae9b-9c74-4af7-9844-0e54221ea3b9
Microsoft Office SharePoint Server 2007:
http://www.microsoft.com/downloads/details.aspx?FamilyId=a7731749-b026-4765-808a-e151b990f0e1
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-043.
1) A remote code execution vulnerability exists in the way that a Microsoft Office filter handles a malformed graphics image. (CVE-2008-3019)
2) A remote code execution vulnerability exists in the way that Microsoft Office handles a PICT-format image file. (CVE-2008-3018 and CVE-2008-3021)
3) A remote code execution vulnerability exists in the way that Microsoft Office handles a BMP format image file. (CVE-2008-3020)
4) A remote code execution vulnerability exists in the way that Microsoft Office handles a WordPerfect Graphics (WPG) format image file. (CVE-2008-3460)
Microsoft Office 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=3ab323ec-9f92-453c-b7c7-9a95a9efcaea
Microsoft Office XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=bf566ce6-23da-45e5-9c2b-c47331d30e79
Microsoft Office 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=e0df2f6e-1102-461d-829f-5f3e2d7eb4b3
Microsoft Office Project 2002 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=bf566ce6-23da-45e5-9c2b-c47331d30e79
Microsoft Office Converter Pack:
http://www.microsoft.com/downloads/details.aspx?familyid=199b08c7-6d79-4930-8f0c-31034629c485
Microsoft Works 8:
http://www.microsoft.com/downloads/details.aspx?familyid=458985C3-9C6F-4049-81CD-0D0389C81F11
Refer to Micrsoft Security Bulletin MS08-044 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB953838)
August 2008 Security Updates Are Now Available (KB953838)
Microsoft Windows 2000 Service Pack 4 (Microsoft Internet Explorer 5.01 Service Pack 4):
http://www.microsoft.com/downloads/details.aspx?familyid=1557B93B-ECBA-4F42-B89D-DB0EE067D65B
Microsoft Windows 2000 Service Pack 4 (Microsoft Internet Explorer 6 Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?familyid=AA780735-5928-4C46-89A4-63A814954796
Windows XP Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=69AF2F30-138E-4B15-AB8D-4FCE44CC0BC2
Windows XP Service Pack 3 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=69AF2F30-138E-4B15-AB8D-4FCE44CC0BC2
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=4780B89E-9735-4D3F-8DEF-34E7337FF604
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=0617A5DD-DCE9-4DE0-B0A0-CE38EFE13524
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=32A63F52-9FE6-48E3-BB4E-7D4DDA5E0A90
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?familyid=1855997E-A3BE-46B1-A0BC-BB55EB0045FE
Windows XP Service Pack 2 and Windows XP Service Pack 3 (Windows Internet Explorer 7):
http://www.microsoft.com/downloads/details.aspx?familyid=8E2125C7-52CB-4052-82A3-2D3C6A953752
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Windows Internet Explorer 7):
http://www.microsoft.com/downloads/details.aspx?familyid=39B41E4B-3237-409D-A818-AB0517C5E7CF
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-045.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB952954)
August 2008 Security Updates Are Now Available (KB952954)
Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?familyid=db455d17-435f-46d7-b2dd-5babb5a1eeb3
Windows XP Service Pack 2 and Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=d313f42c-f43f-48ea-82ef-3bc33077c7fa
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=3150c6b8-f50b-4b84-a7ce-c8daf77c080c
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=828d8fdc-8534-4621-85a5-08aec255496f
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=0a13776f-d543-41df-b904-d51e368c81cc
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=9566493f-4260-4072-947a-527887d2cd63
Refer to Micrsoft Security Bulletin MS08-046 for further details.
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=3f21a8a2-9861-4fef-9d1e-caf5f7822c1a
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=aa04a754-fbfb-42a7-89d2-14373e3f4742
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=c3363df6-39dc-4910-9ce5-66553155378e
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=39dd1722-412b-469d-a475-b6513764838c
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=e9c6cd46-30ad-46ee-9c8b-d0b446e660c4
Refer to Micrsoft Security Bulletin MS08-047 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB951066)
August 2008 Security Updates Are Now Available (KB951066)
Microsoft Windows 2000 Service Pack 4 (Microsoft Outlook Express 5.5 Service Pack 2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=6257bfae-35f0-4c0e-b960-bca7aa6f86f7
Microsoft Windows 2000 Service Pack 4 (Microsoft Outlook Express 6 Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=dab178f7-c282-41f4-acb1-a86e6aa4c91b
Windows XP Service Pack 2 and Windows XP Service Pack 3 (Microsoft Outlook Express 6 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=91469f2f-461c-4a67-8738-d42520427f6b
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Microsoft Outlook Express 6 ):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2220aece-79d2-426f-90ec-24a17470567a
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Microsoft Outlook Express 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=30f2244a-f6fd-4fc1-a871-abf6958cb660
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Microsoft Outlook Express 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3287f006-cbb2-4c6d-820c-32833e08035a
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (Microsoft Outlook Express 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=c8570e40-355b-4a9b-933d-53ae021cbda5
Windows Vista and Windows Vista Service Pack 1 (Windows Mail):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3851bcf8-f971-4d38-b27f-97396854aac0
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 (Windows Mail):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3bf7eb8a-b347-4661-be2d-682adc713769
Windows Server 2008 for 32-bit Systems (Windows Mail):
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc3c4b63-acd3-4469-8d47-e0562d99ee65
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-048.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB950974)
August 2008 Security Updates Are Now Available (KB950974)
Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=1b2ad648-7dc9-407a-99f6-f39922746027
Windows XP Service Pack 2 and Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=01a34aa4-a456-4efc-a93a-c3c682b0181c
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=246b2686-e330-47a2-b4d4-68f218ad4021
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=92a3d08f-c117-4b24-bc78-2b913d270df6
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyID=6bfbb6d8-5106-4adf-83cb-35ffc6e8eaf8
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyID=45356565-697f-41b3-9879-3edd11dbcb7e
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=6418c78f-f008-4028-beb1-5a5ea8e797a1
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=e03ccfb0-3ea3-4c59-adcf-9882d7086013
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=0640f95e-1eee-4dd1-b4dd-2b82b7e984b9
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=51a93538-5e94-4f81-a6e0-d497a7b4899d
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=390da130-749d-4890-aad7-be91e15b32bb
Refer to Micrsoft Security Bulletin MS08-049 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB946648)
August 2008 Security Updates Are Now Available (KB946648)
Windows XP Service Pack 2 and Windows XP Service Pack 3 (Windows Messenger 4.7):
http://www.microsoft.com/downloads/details.aspx?FamilyID=8f588f7e-c4ed-42a0-b157-54b1eda60474
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Windows Messenger 4.7):
http://www.microsoft.com/downloads/details.aspx?FamilyID=a5fc5457-832f-4ee8-be60-4cc8518d1c10
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Windows Messenger 4.7):
http://www.microsoft.com/downloads/details.aspx?FamilyID=302315a8-ccb2-47c2-9104-b8e1d1f49aa0
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Windows Messenger 4.7):
http://www.microsoft.com/downloads/details.aspx?FamilyID=be94d138-7d7b-489e-baa6-e214950be6b9
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (Windows Messenger 4.7):
http://www.microsoft.com/downloads/details.aspx?FamilyID=e4b72618-536b-4a21-bd91-d91be9ca24e5
Microsoft Windows 2000 Service Pack 4 (Windows Messenger 5.1):
http://www.microsoft.com/downloads/details.aspx?FamilyID=A8D9EB73-5F8C-4B9A-940F-9157A3B3D774
Windows XP Service Pack 2 and Windows XP Service Pack 3 (Windows Messenger 5.1):
http://www.microsoft.com/downloads/details.aspx?FamilyID=A8D9EB73-5F8C-4B9A-940F-9157A3B3D774
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Windows Messenger 5.1):
http://www.microsoft.com/downloads/details.aspx?FamilyID=A8D9EB73-5F8C-4B9A-940F-9157A3B3D774
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Windows Messenger 5.1):
http://www.microsoft.com/downloads/details.aspx?FamilyID=A8D9EB73-5F8C-4B9A-940F-9157A3B3D774
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Windows Messenger 5.1):
http://www.microsoft.com/downloads/details.aspx?FamilyID=A8D9EB73-5F8C-4B9A-940F-9157A3B3D774
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-050.
The security update addresses the following issues:
- Memory Allocation Vulnerability (CVE-2008-0120)
- Memory Calculation Vulnerability (CVE-2008-0121)
- Parsing Overflow Vulnerability (CVE-2008-1455)
Microsoft Office 2000 Service Pack 3 (Microsoft Office PowerPoint 2000 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=e7c044d8-778a-4985-b25b-4f7f6e4abadd
Microsoft Office XP Service Pack 3 (Microsoft Office PowerPoint 2002 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=f8921074-7985-4d42-ac2b-d2f3b1d466ba
Microsoft Office 2003 Service Pack 2 (Microsoft Office PowerPoint 2003 Service Pack 2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=7a7c21f0-5e0e-4dee-9710-1ce3d565913f
Microsoft Office 2003 Service Pack 3 (Microsoft Office PowerPoint 2003 Service Pack 3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=7a7c21f0-5e0e-4dee-9710-1ce3d565913f
2007 Microsoft Office System (Microsoft Office PowerPoint 2007):
http://www.microsoft.com/downloads/details.aspx?FamilyId=55fd618a-e9c5-4f1e-b9a5-b2e47ec98ef1
2007 Microsoft Office System Service Pack 1 (Microsoft Office PowerPoint 2007 Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=55fd618a-e9c5-4f1e-b9a5-b2e47ec98ef1
Microsoft Office PowerPoint Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=911c8872-dec8-4b8e-9708-93dcabd3e036
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/details.aspx?familyid=84ce5d58-0010-4945-bce9-67a41f898f2f
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=84ce5d58-0010-4945-bce9-67a41f898f2f
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EBD3AF0C-3F62-4D18-BF45-881655683BD5
Refer to Micrsoft Security Bulletin MS08-051 for further details.
These new vulnerability checks are included in Qualys vulnerability signature 1.20.12-3. Each Qualys account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the Qualys Help menu, select the About tab.
To perform a selective vulnerability scan, configure a scan profile to use the following options:
In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Analysis Report, available from the Qualys Vulnerability Management Reports tab.
Platforms and Platform Identification
For more information, customers may contact Qualys Technical Support.
The Enterprise TruRisk Platform and its integrated suite of security and compliance applications provides organizations of all sizes with a global view of their security and compliance solutions, while drastically reducing their total cost of ownership. Qualys solutions include: continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, malware detection and SECURE Seal for security testing of web sites.