1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Microsoft Security Bulletins for April 2008

Discussion in 'General Malware And Security' started by Donna Buenaventura, Apr 8, 2008.

  1. Note: There may be latency issues due to replication, if the page does not
    display keep refreshing or try later.

    MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code
    Execution (950183)

    MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code
    Execution (949032)

    MS08-020 - Vulnerability in DNS Client Could Allow Spoofing (945553)

    MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution (948590)

    MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could
    Allow Remote Code Execution (944338)

    MS08-023 - Security Update of ActiveX Kill Bits (948881)

    MS08-024 - Cumulative Security Update for Internet Explorer (947864)

    MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of
    Privilege (941693)


    For information about non-security releases on Windows Update and Microsoft
    update, please see:



    The monthly security bulletin webcast is scheduled tomorrow, April 9, 2008
    at 11 a.m., PST:


    Please scan your system using Microsoft Baseline Security Analyzer for
    missing security updates as well as common security misconfigurations:


    Customers in the U.S. and Canada can receive technical support from
    Microsoft Product Support Services at 1-866-PCSAFETY.
    International customers can receive support from their local Microsoft
    subsidiaries

    There is no charge for support that is associated with security updates.

    Security Bulletin Summary:


    Microsoft Security Response Center Blog:

    Microsoft Security Vulnerability Research and Defense Blog:

    For other Microsoft security tools and resources, visit


    Regards,

    Donna Buenaventura
    Calendar of Updates:
     
  2. MSRC's blog entry at



    "Donna Buenaventura" <dbuenaventura@mvps.org> wrote in message
    news:4AFE2E5D-07FA-4873-AE6E-F544F10150EC@microsoft.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Note: There may be latency issues due to replication, if the page does not
    > display keep refreshing or try later.
    >
    > MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code
    > Execution (950183)
    >

    > MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code
    > Execution (949032)
    >

    > MS08-020 - Vulnerability in DNS Client Could Allow Spoofing (945553)
    >

    > MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution
    > (948590)
    >

    > MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could
    > Allow Remote Code Execution (944338)
    >

    > MS08-023 - Security Update of ActiveX Kill Bits (948881)
    >

    > MS08-024 - Cumulative Security Update for Internet Explorer (947864)
    >

    > MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of
    > Privilege (941693)
    >

    >
    > For information about non-security releases on Windows Update and
    > Microsoft update, please see:
    >

    >

    >
    > The monthly security bulletin webcast is scheduled tomorrow, April 9, 2008
    > at 11 a.m., PST:
    >

    >
    > Please scan your system using Microsoft Baseline Security Analyzer for
    > missing security updates as well as common security misconfigurations:
    >

    >
    > Customers in the U.S. and Canada can receive technical support from
    > Microsoft Product Support Services at 1-866-PCSAFETY.
    > International customers can receive support from their local Microsoft
    > subsidiaries

    > There is no charge for support that is associated with security updates.
    >
    > Security Bulletin Summary:
    >

    >

    > Microsoft Security Response Center Blog:

    > Microsoft Security Vulnerability Research and Defense Blog:
    >

    > For other Microsoft security tools and resources, visit
    >

    >
    > Regards,
    >
    > Donna Buenaventura
    > Calendar of Updates:
    <!--colorc--><!--/colorc-->
     
  3. Request: Please eliminate any unnecessary/inappropriate crossposting in your
    replies to this thread. Thanks.
    --
    ~PA Bear
     
  4. niks

    niks Guest

    After running windows updates and installing all the updates, including the
    security updates I rebooted my laptop to find I could not connect to the
    internet. After many reboots I rolled back my system. After the roll back I
    could connect to the internet again. I then run windows updates, but this
    time I deselected the security updates. After rebooting I was pleased to see
    I could connect to the internet still.

    I am not happy that the security updates that where there to protect my
    computer protected me a little bit too much by stopping connecting to the
    internet.

    NIK

    "Donna Buenaventura" <dbuenaventura@mvps.org> wrote in message
    news:4AFE2E5D-07FA-4873-AE6E-F544F10150EC@microsoft.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Note: There may be latency issues due to replication, if the page does not
    > display keep refreshing or try later.
    >
    > MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code
    > Execution (950183)
    >
    > MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code
    > Execution (949032)
    >

    > MS08-020 - Vulnerability in DNS Client Could Allow Spoofing (945553)
    >

    > MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution
    > (948590)
    >

    > MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could
    > Allow Remote Code Execution (944338)
    >

    > MS08-023 - Security Update of ActiveX Kill Bits (948881)
    >

    > MS08-024 - Cumulative Security Update for Internet Explorer (947864)
    >

    > MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of
    > Privilege (941693)
    >

    >
    > For information about non-security releases on Windows Update and
    > Microsoft update, please see:
    >

    >

    >
    > The monthly security bulletin webcast is scheduled tomorrow, April 9, 2008
    > at 11 a.m., PST:
    >

    >
    > Please scan your system using Microsoft Baseline Security Analyzer for
    > missing security updates as well as common security misconfigurations:
    >

    >
    > Customers in the U.S. and Canada can receive technical support from
    > Microsoft Product Support Services at 1-866-PCSAFETY.
    > International customers can receive support from their local Microsoft
    > subsidiaries

    > There is no charge for support that is associated with security updates.
    >
    > Security Bulletin Summary:
    >

    >

    > Microsoft Security Response Center Blog:

    > Microsoft Security Vulnerability Research and Defense Blog:
    >

    > For other Microsoft security tools and resources, visit
    >

    >
    > Regards,
    >
    > Donna Buenaventura
    > Calendar of Updates:

    > <!--colorc--><!--/colorc-->
     
  5. Larry

    Larry Guest

    I had a different problem. I use IE to access aol. I can get to the msg.
    bds. ok. But when I try to get to the email I get linked to something called
    AOL>MyMobile (or some nonsense like that). I tried to roll back to before
    the updates. I got some kind of failure msg. So for now I installed the AOL
    s/w. Anyone have any ideas?

    "niks" <niknik1971NOSPAM@btinternet.com> wrote in message
    news:FDC4D813-BBAA-445E-866B-1FBC8C1F1EAD@microsoft.com...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > After running windows updates and installing all the updates, including
    > the security updates I rebooted my laptop to find I could not connect to
    > the internet. After many reboots I rolled back my system. After the roll
    > back I could connect to the internet again. I then run windows updates,
    > but this time I deselected the security updates. After rebooting I was
    > pleased to see I could connect to the internet still.
    >
    > I am not happy that the security updates that where there to protect my
    > computer protected me a little bit too much by stopping connecting to the
    > internet.
    >
    > NIK
    >
    > "Donna Buenaventura" <dbuenaventura@mvps.org> wrote in message
    > news:4AFE2E5D-07FA-4873-AE6E-F544F10150EC@microsoft.com...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Note: There may be latency issues due to replication, if the page does
    >> not display keep refreshing or try later.
    >>
    >> MS08-018 - Vulnerability in Microsoft Project Could Allow Remote Code
    >> Execution (950183)
    >>
    >> MS08-019 - Vulnerabilities in Microsoft Visio Could Allow Remote Code
    >> Execution (949032)
    >>

    >> MS08-020 - Vulnerability in DNS Client Could Allow Spoofing (945553)
    >>

    >> MS08-021 - Vulnerabilities in GDI Could Allow Remote Code Execution
    >> (948590)
    >>

    >> MS08-022 - Vulnerability in VBScript and JScript Scripting Engines Could
    >> Allow Remote Code Execution (944338)
    >>

    >> MS08-023 - Security Update of ActiveX Kill Bits (948881)
    >>

    >> MS08-024 - Cumulative Security Update for Internet Explorer (947864)
    >>

    >> MS08-025 - Vulnerability in Windows Kernel Could Allow Elevation of
    >> Privilege (941693)
    >>

    >>
    >> For information about non-security releases on Windows Update and
    >> Microsoft update, please see:
    >>

    >>

    >>
    >> The monthly security bulletin webcast is scheduled tomorrow, April 9,
    >> 2008 at 11 a.m., PST:
    >>

    >>
    >> Please scan your system using Microsoft Baseline Security Analyzer for
    >> missing security updates as well as common security misconfigurations:
    >>

    >>
    >> Customers in the U.S. and Canada can receive technical support from
    >> Microsoft Product Support Services at 1-866-PCSAFETY.
    >> International customers can receive support from their local Microsoft
    >> subsidiaries

    >> There is no charge for support that is associated with security updates.
    >>
    >> Security Bulletin Summary:
    >>

    >>

    >> Microsoft Security Response Center Blog:

    >> Microsoft Security Vulnerability Research and Defense Blog:
    >>

    >> For other Microsoft security tools and resources, visit
    >>

    >>
    >> Regards,
    >>
    >> Donna Buenaventura
    >> Calendar of Updates:

    >><!--colorc--><!--/colorc-->
    > <!--colorc--><!--/colorc-->
     
  6. Larry

    Larry Guest

    Ok, but where do you suggest I post it under? I thought this was an
    appropriate group to post it under.

    "PA Bear [MS MVP]" <PABearMVP@gmail.com> wrote in message
    news:eRD5l$cmIHA.484@TK2MSFTNGP06.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > [Crossposting to Office Update and XP Security_Admin newsgroups
    > eliminated]
    >
    > Please begin a new thread in an appropriate newsgroup about your problem,
    > Larry.
    > --
    > ~Robear Dyer (PA Bear)
    > MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
    > AumHa VSOP & Admin
    > DTS-L

    >
    > Larry wrote:<!--coloro:green--><span style="color:green <!--/coloro-->
    >> I had a different problem. I use IE to access aol. I can get to the msg.
    >> bds. ok. But when I try to get to the email I get linked to something
    >> called
    >> MyMobile (or some nonsense like that). I tried to roll back to before
    >> the updates. I got some kind of failure msg. So for now I installed the
    >> AOL
    >> s/w. Anyone have any ideas?<!--colorc--><!--/colorc-->
    > <snip> <!--colorc--><!--/colorc-->
     
  7. I'd say begin a new thread Vista Security and/or IE General, Larry. In your
    post, clearly state your Windows version (e.g., Vista SP1), which updates
    were installed, and any error messages in their entirety.

    Or you can...

    Start a free Windows Update support incident request:


    Support for Windows Update:


    For home users, no-charge support is available by calling 1-866-PCSAFETY in
    the United States and in Canada or by contacting your local Microsoft
    subsidiary. There is no-charge for support calls that are associated with
    security updates.

    If your problem relates to a Cumulative Security Update for IE (e.g.,
    KB947864), call the above number and ask to be transferred to the Consumer
    IE7 queue (which is 47830).

    For more information about how to contact your local Microsoft subsidiary
    for security update support issues, visit the International Support Web
    site:


    For enterprise customers, support for security updates is available through
    your usual support contacts.
    --
    IE-specific newsgroup:


    ~Robear Dyer (PA Bear)
    MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002

    Larry wrote:<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Ok, but where do you suggest I post it under? I thought this was an
    > appropriate group to post it under.
    >
    > "PA Bear [MS MVP]" <PABearMVP@gmail.com> wrote in message
    > news:eRD5l$cmIHA.484@TK2MSFTNGP06.phx.gbl...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> [Crossposting to Office Update and XP Security_Admin newsgroups
    >> eliminated]
    >>
    >> Please begin a new thread in an appropriate newsgroup about your problem,
    >> Larry.
    >> --
    >> Larry wrote:<!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> I had a different problem. I use IE to access aol. I can get to the msg.
    >>> bds. ok. But when I try to get to the email I get linked to something
    >>> called
    >>> MyMobile (or some nonsense like that). I tried to roll back to before
    >>> the updates. I got some kind of failure msg. So for now I installed the
    >>> AOL
    >>> s/w. Anyone have any ideas?<!--colorc--><!--/colorc-->
    >> <snip> <!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
     

Share This Page