Qualys Vulnerability R&D Lab has released new vulnerability checks in the Enterprise TruRisk Platform to protect organizations against 10 vulnerabilities that were fixed in 7 bulletins announced today by Microsoft. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their Qualys subscription. Visit Qualys Security Blog to prioritize remediation.
Non-Qualys customers can audit their network for these and other vulnerabilities by signing up for a Qualys Free Trial, or by trying Qualys Community Edition.
Microsoft has released 7 security bulletins to fix newly discovered flaws in their software. Qualys has released the following checks for these new vulnerabilities:
A remote code execution vulnerability exists in the Bluetooth stack because the Bluetooth stack does not correctly handle a large number of service description requests.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
December 2008 Updates are Available (including for XPe SP3 and Standard) (KB951376)
August 2008 Security Updates Are Now Available (KB951376)
July 2008 Windows XP Embedded Security Updates Now Available (KB951376)
June 2008 Security Updates are Now Available (KB951376)
Windows XP Service Pack 2 and Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=980bb421-950f-4825-8039-44cc961a47b8
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=81ab56ca-933f-4974-a393-290a54c30a78
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=6524debe-be50-44d1-8543-af0bfaf086ad
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=6adee8b9-3455-4f3b-8bdd-2585c8ff83b8
Refer to Micrsoft Security Bulletin MS08-030 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
June 2008 Security Updates are Now Available (KB950759)
Microsoft Windows 2000 Service Pack 4 (Microsoft Internet Explorer 5.01 Service Pack 4):
http://www.microsoft.com/downloads/details.aspx?FamilyId=88990B23-D37F-4D02-A5A3-2EE389ADE53C
Microsoft Windows 2000 Service Pack 4 (Microsoft Internet Explorer 6 Service Pack 1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=4C47CF8A-8100-4D43-855A-F225A3492B19
Windows XP Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=CC325017-3A48-4475-90E4-0C79A002FCE3
Windows XP Service Pack 3 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=CC325017-3A48-4475-90E4-0C79A002FCE3
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=C8783CFE-9DA5-4842-AB3A-1E2BE4FAFC47
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=286AADA6-A358-41F1-B81A-8DE39B9F908A
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=6604569A-3DB0-47E7-BD30-7DFBA8145386
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (Microsoft Internet Explorer 6):
http://www.microsoft.com/downloads/details.aspx?FamilyId=0262BEB8-1EB5-4C2D-A50A-0C6C6E0C1F61
Windows XP Service Pack 2 and Windows XP Service Pack 3 (Windows Internet Explorer 7):
http://www.microsoft.com/downloads/details.aspx?FamilyId=FBC31BDE-0BF5-490C-96A8-071310D9464A
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (Windows Internet Explorer 7):
http://www.microsoft.com/downloads/details.aspx?FamilyId=19C0CCDC-95C9-4151-96B6-4F49B594EBE0
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-031.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
June 2008 Security Updates are Now Available (KB950760)
Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=CEDFD988-232C-4CBA-AC65-BEB54B8946E0
Windows XP Service Pack 2 :
http://www.microsoft.com/downloads/details.aspx?FamilyId=2D8957C2-E473-4DCA-8D68-19FDAEA36E26
Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2D8957C2-E473-4DCA-8D68-19FDAEA36E26
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=62874096-7D17-4116-9795-4756E2FB6DAE
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=DADEAD99-09CB-4F2B-850D-E98A627CB9F8
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=84F9B533-B0CB-46D1-B4A8-5C9469ABBD22
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=AC35CE19-D761-4529-9F55-1E1B5B2447AD
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4AF6575E-B061-45A6-B3D8-ECB32D76B2D3
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=67576ACB-9CB6-4C76-9A72-DC5E5556B658
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=8A507FBA-8C93-4952-91E4-98E9E7AFFBD2
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=1A11499D-A008-407F-9084-A5189FA27015
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59B1689C-E723-4D87-973E-4BEAC107A6F7
Refer to Micrsoft Security Bulletin MS08-032 for further details.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
June 2008 Security Updates are Now Available (KB951698)
Microsoft Windows 2000 Service Pack 4 (DirectX 7.0):
http://www.microsoft.com/downloads/details.aspx?FamilyId=65640123-a9e4-455c-a51a-9df28bd2d412
Microsoft Windows 2000 Service Pack 4 (DirectX 8.1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=c6a28d45-13cf-48c4-8f89-3417d552e90b
Microsoft Windows 2000 Service Pack 4 (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=4dc47e04-5e95-4636-a814-3f912d961461
Windows XP Service Pack 2 and Windows XP Service Pack 3 (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=7aaa6427-1e22-4566-960c-836a3b9e5f36
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=5e8e7e9d-828d-442c-acac-8d91e80dfb36
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2274ecb2-2802-47e2-84fd-6621fcb17758
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=5ba63bb7-ed6d-4c59-88b3-456eda07e190
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (DirectX 9.0, DirectX 9.0a, DirectX 9.0b, or DirectX 9.0c):
http://www.microsoft.com/downloads/details.aspx?FamilyId=be71c002-2f64-49e9-9f4b-ba99c4f3caf6
Windows Vista (DirectX 10.0):
http://www.microsoft.com/downloads/details.aspx?FamilyId=4d4b305b-57f8-448d-92fa-3dcdd1f42ed7
Windows Vista Service Pack 1 (DirectX 10.0):
http://www.microsoft.com/downloads/details.aspx?FamilyId=4d4b305b-57f8-448d-92fa-3dcdd1f42ed7
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-033.
Microsoft Windows 2000 Server Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?familyid=aa8aa79f-c2cc-440c-9e5c-089143e6f814
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=08fc90d5-23aa-4327-8aef-16bc5170769d
Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/details.aspx?familyid=71675ae8-d60a-4834-b358-2d8e761e62fc
Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=71675ae8-d60a-4834-b358-2d8e761e62fc
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=87affdc9-d9fe-413c-af30-f3d3b671ec72
Refer to Micrsoft Security Bulletin MS08-034 for further details.
Microsoft Windows 2000 Server Service Pack 4 (Active Directory):
http://www.microsoft.com/downloads/details.aspx?FamilyID=53438880-9ea9-4975-9b85-2a1d3d232793
Windows XP Professional Service Pack 2 (ADAM):
http://www.microsoft.com/downloads/details.aspx?FamilyID=7d6aec31-cfb4-470c-983e-78c6a3ebabfe
Windows XP Professional Service Pack 3 (ADAM):
http://www.microsoft.com/downloads/details.aspx?FamilyID=7d6aec31-cfb4-470c-983e-78c6a3ebabfe
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 (ADAM):
http://www.microsoft.com/downloads/details.aspx?FamilyID=ef2e0b48-1bde-4ccc-8f40-2918c2568b2b
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (Active Directory):
http://www.microsoft.com/downloads/details.aspx?FamilyID=a4aed117-3c76-4d80-b50e-8e07e2ef2f7d
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 (ADAM):
http://www.microsoft.com/downloads/details.aspx?FamilyID=0a983ffb-4f5a-4b78-9bf5-813dcc5df8d3
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (Active Directory):
http://www.microsoft.com/downloads/details.aspx?FamilyID=8298a6e4-d3e2-48ea-ac29-aa4dc5a8ec77
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 (ADAM):
http://www.microsoft.com/downloads/details.aspx?FamilyID=334252db-4a7a-4161-bb71-2a20c0b5bd93
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems (Active Directory):
http://www.microsoft.com/downloads/details.aspx?FamilyID=f6bf4b85-b91d-4378-a356-cd11f12cbbfd
Windows Server 2008 for 32-bit Systems (Active Directory):
http://www.microsoft.com/downloads/details.aspx?FamilyID=2981156e-2e2f-469e-91be-da127d50f3fc
Windows Server 2008 for 32-bit Systems (AD LDS):
http://www.microsoft.com/downloads/details.aspx?FamilyID=2981156e-2e2f-469e-91be-da127d50f3fc
For a complete list of patch download links, please refer to Micrsoft Security Bulletin MS08-035.
Windows XP Embedded Systems:- For additional information regarding security updates for embedded systems, refer to the following MSDN blog(s):
June 2008 Security Updates are Now Available (KB950762)
Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=36b14a81-5979-4e38-9ba3-ed83dfc17adf
Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=36b14a81-5979-4e38-9ba3-ed83dfc17adf
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9e9d24ee-8183-428c-8067-168a8d85eaa1
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=1e8e2faf-009f-403b-a5fe-a47cf014db3a
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=78bf92d8-63c4-4596-8425-8fcfea7f5582
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=5b7e94fa-22ed-4f7c-b452-647b2e620113
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=ef2d2a4b-4831-41be-b5d0-8df5b01fd205
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=0839fcf4-85ca-445e-896b-f634b10b6700
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=0466a6e7-fdca-4647-af62-449e5f20d1e4
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=304898e6-21a7-476f-b9ed-7ac0d88a91e2
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=8907783b-e3fe-40b2-9fc8-4937e7d58b7e
Refer to Micrsoft Security Bulletin MS08-036 for further details.
These new vulnerability checks are included in Qualys vulnerability signature 1.19.158-4. Each Qualys account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the Qualys Help menu, select the About tab.
To perform a selective vulnerability scan, configure a scan profile to use the following options:
In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Analysis Report, available from the Qualys Vulnerability Management Reports tab.
Platforms and Platform Identification
For more information, customers may contact Qualys Technical Support.
The Enterprise TruRisk Platform and its integrated suite of security and compliance applications provides organizations of all sizes with a global view of their security and compliance solutions, while drastically reducing their total cost of ownership. Qualys solutions include: continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, malware detection and SECURE Seal for security testing of web sites.