Microsoft Security Bulletins
July 2008
Prior Updates:
2009
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
2008
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
2007
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
2006
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
2005
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
2004
|December
|November
|October
|September
|August
|July
|June
|May
|April
|March
|February
|January
Login to learn more about how Juniper Networks products can protect you from these vulnerabilities. (If you don't already have a login, see Requesting Support.)
July 2008
Microsoft Security Bulletin MS08-037
Vulnerabilities in DNS Could Allow Spoofing (953230)
Severity: ImportantVulnerabilities:
- DNS Insufficient Socket Entropy Vulnerability - CVE-2008-1447
A spoofing vulnerability exists in Windows DNS client and Windows DNS server. This vulnerability could allow a remote attacker to quickly and reliably spoof responses and insert records into the DNS server or client cache, thereby redirecting Internet traffic. Visit the attack detection TechNet article for more information of DNS cache poisoning. - DNS Cache Poisoning Vulnerability - CVE-2008-1454
A cache poisoning vulnerability exists in Windows DNS Server. The vulnerability could allow an unauthenticated attacker to send malicious responses to DNS requests made by vulnerable systems, thereby poisoning the DNS cache and redirecting Internet traffic from legitimate locations.
Microsoft Security Bulletin MS08-038
Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582)
Severity: ImportantVulnerabilities:
- Windows Saved Search Vulnerability - CVE-2008-1435
A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.
Microsoft Security Bulletin MS08-039
Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747)
Severity: ImportantVulnerabilities:
- Outlook Web Access for Exchange Server Data Validation Cross-Site Scripting Vulnerability - CVE-2008-2247
This is a cross-site scripting vulnerability in the affected versions of Outlook Web Access for Exchange Server that could lead to elevation of privilege on individual OWA clients connecting to the Outlook Web Access for Exchange Server. An attacker must convince a user to open a specially crafted e-mail from within an individual OWA client that would run a malicious script. If the malicious script is executed, the script would run in the security context of the userís OWA session and perform any action the user could perform such as reading, sending, and deleting e-mail as the logged on user. - Outlook Web Access for Exchange Server HTML Parsing Cross-Site Scripting Vulnerability - CVE-2008-2248
This is a cross-site scripting vulnerability in the affected versions of Outlook Web Access for Exchange Server that could lead to elevation of privilege on individual OWA clients connecting to the Outlook Web Access for Exchange Server. An attacker must convince a user to open a specially crafted e-mail from within an individual OWA client that would run a malicious script. If the malicious script is executed, the script would run in the security context of the userís OWA session and perform any action the user could perform such as reading, sending, and deleting e-mail as the logged on user
Microsoft Security Bulletin MS08-040
Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)
Severity: ImportantVulnerabilities:
- Memory Page Reuse Vulnerability - CVE-2008-0085
An information disclosure vulnerability exists in the way that SQL Server manages memory page reuse. An attacker with database operator access who successfully exploited this vulnerability could access customer data. - Convert Buffer Overrun - CVE-2008-0086
A vulnerability exists in the convert function in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system. - SQL Server Memory Corruption Vulnerability - CVE-2008-0107
A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system. - SQL Buffer Overrun Vulnerability - CVE-2008-0106
A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.