J-Security Center

Title: RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities

Severity: CRITICAL

Description:

Microsoft has released advance notification that the vendor will be releasing four security bulletins on February 10, 2009. The highest severity rating for these issues is 'Critical'.

These issues affect:

- Internet Explorer
- Exchange
- SQL Server
- Office

Successfully exploiting these issues may allow remote or local attackers to compromise affected computers.

NOTE: The following individual records have been created to document these issues:

33627 Microsoft Internet Explorer Uninitialized Memory Remote Code Execution Vulnerability
33628 Microsoft Internet Explorer CSS Memory Corruption Remote Code Execution Vulnerability
33134 Microsoft Exchange Server TNEF Decoding Remote Command Execution Vulnerability
33136 Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
32710 Microsoft SQL Server 'sp_replwritetovarbin' Remote Memory Corruption Vulnerability
33659 Microsoft Visio Object Validation Remote Code Execution Vulnerability
33660 Microsoft Visio Object Copy Memory Corruption Remote Code Execution Vulnerability
33661 Microsoft Visio Memory Corruption Remote Code Execution Vulnerability

Affected Products:

  • Akiva WebBoard 6.1.0
  • Microsoft Access 2000
  • Microsoft Application Center 2000
  • Microsoft BizTalk Server 2000 Developer Edition
  • Microsoft BizTalk Server 2000 Enterprise Edition
  • Microsoft BizTalk Server 2000 Standard Edition
  • Microsoft BizTalk Server 2002 Developer Edition
  • Microsoft BizTalk Server 2002 Enterprise Edition
  • Microsoft Exchange Server 2000
  • Microsoft Exchange Server 2000 SP1
  • Microsoft Exchange Server 2000 SP2
  • Microsoft Exchange Server 2000 SP3
  • Microsoft Exchange Server 2003
  • Microsoft Exchange Server 2003 SP1
  • Microsoft Exchange Server 2003 SP1
  • Microsoft Exchange Server 2003 SP2
  • Microsoft Exchange Server 2007
  • Microsoft Exchange Server 2007 SP 1
  • Microsoft Internet Explorer 7.0
  • Microsoft Internet Explorer 7.0 beta1
  • Microsoft Internet Explorer 7.0 beta2
  • Microsoft Internet Explorer 7.0 beta3
  • Microsoft Internet Explorer 7.0.5730.11
  • Microsoft Office 2000
  • Microsoft Project Central Server
  • Microsoft SQL Server 2000
  • Microsoft SQL Server 2000 Desktop Engine
  • Microsoft SQL Server 2000 Desktop Engine
  • Microsoft SQL Server 2000 Desktop Engine SP1
  • Microsoft SQL Server 2000 Desktop Engine SP2
  • Microsoft SQL Server 2000 Desktop Engine SP3
  • Microsoft SQL Server 2000 Desktop Engine SP4
  • Microsoft SQL Server 2000 Itanium Edition
  • Microsoft SQL Server 2000 Itanium Edition SP1
  • Microsoft SQL Server 2000 Itanium Edition SP2
  • Microsoft SQL Server 2000 Itanium Edition SP3
  • Microsoft SQL Server 2000 Itanium Edition SP4
  • Microsoft SQL Server 2000 SP1
  • Microsoft SQL Server 2000 SP2
  • Microsoft SQL Server 2000 SP3
  • Microsoft SQL Server 2000 SP3a
  • Microsoft SQL Server 2000 SP4
  • Microsoft SQL Server 2005
  • Microsoft SQL Server 2005 Express Edition
  • Microsoft SQL Server 2005 Express Edition SP1
  • Microsoft SQL Server 2005 Express Edition SP2
  • Microsoft SQL Server 2005 Express Edition with Advanced Serv SP1
  • Microsoft SQL Server 2005 Express Edition with Advanced Serv SP2
  • Microsoft SQL Server 2005 Itanium Edition
  • Microsoft SQL Server 2005 Itanium Edition SP1
  • Microsoft SQL Server 2005 Itanium Edition SP2
  • Microsoft SQL Server 2005 Itanium Edition SP3
  • Microsoft SQL Server 2005 SP1
  • Microsoft SQL Server 2005 SP2
  • Microsoft SQL Server 2005 SP3
  • Microsoft SQL Server 2005 Yukon
  • Microsoft SQL Server 2005 x64 Edition SP1
  • Microsoft SQL Server 2005 x64 Edition SP2
  • Microsoft SQL Server 2005 x64 Edition SP3
  • Microsoft SharePoint Team Services from Microsoft
  • Microsoft Visio 2000 Enterprise Edition
  • Microsoft Visio 2002
  • Microsoft Visio 2002 Professional SP2
  • Microsoft Visio 2002 SP1
  • Microsoft Visio 2002 SP2
  • Microsoft Visio 2002 SP3
  • Microsoft Visio 2002 Standard SP2
  • Microsoft Visio 2003
  • Microsoft Visio 2003 SP1
  • Microsoft Visio 2003 Professional
  • Microsoft Visio 2003 SP2
  • Microsoft Visio 2003 SP3
  • Microsoft Visio 2003 Standard
  • Microsoft Visio 2007
  • Microsoft Visio 2007 SP1
  • Microsoft Visio 2007 SP3
  • Microsoft Visio Enterprise Network Tools
  • Microsoft Visual FoxPro 6.0
  • Microsoft Visual Studio .NET Academic Edition
  • Microsoft Visual Studio .NET Enterprise Architect Edition
  • Microsoft Visual Studio .NET Enterprise Developer Edition
  • Microsoft Visual Studio .NET Professional Edition
  • Microsoft Visual Studio 6.0
  • Microsoft Windows Internal Database (WYukon)
  • Microsoft Windows Internal Database (WYukon) SP1
  • Microsoft Windows Internal Database (WYukon) SP2
  • Microsoft Windows Internal Database (WYukon) x64
  • Microsoft Windows Internal Database (WYukon) x64 SP1
  • Microsoft Windows Internal Database (WYukon) x64 SP2
  • Microsoft Windows Vista
  • Microsoft Windows Vista Business
  • Microsoft Windows Vista Enterprise
  • Microsoft Windows Vista Home Basic
  • Microsoft Windows Vista Home Premium
  • Microsoft Windows Vista Ultimate
  • SmartMax Software MailMax 5.0.0
  • Veritas Software Backup Exec 9.0.0
  • Veritas Software Backup Exec for Windows Servers 9.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.