• December 2008

    by  • December 2, 2008 • 2008

    To view a summary of the December 2008 bulletins, visit Microsoft Security Bulletin Summary for December, 2008. Click the links below to view the individual Microsoft Security Bulletins and to download any patches that might be required for your system. You can also visit Windows Update to automatically determine what patches or updates your system needs.

    1. MS08-070

    Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution
    Criticality: Critical

    2. MS08-071

    Vulnerabilities in GDI Could Allow Remote Code Execution
    Criticality: Critical

    3. MS08-072

    Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution
    Criticality: Critical

    4. MS08-073

    Cumulative Security Update for Internet Explorer
    Criticality: Critical

    5. MS08-074

    Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution
    Criticality: Critical

    6. MS08-075

    Vulnerabilities in Windows Search Could Allow Remote Code Execution
    Criticality: Critical

    7. MS08-076

    Vulnerabilities in Windows Media Components Could Allow Remote Code Execution
    Criticality: Important

    8. MS08-077

    Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege
    Criticality: Important

    About

    Tony has driven security policies and technologies for antivirus and incident response for Fortune 500 companies, and he has been network administrator and technical support for smaller companies. He has written for a variety of other Web sites and publications, including BizTech Magazine, PC World, SearchSecurity.com, WindowsNetworking.com, Smart Computing magazine, and Information Security magazine. Tony is a CISSP (Certified Information Systems Security Professional) and ISSAP (Information Systems Security Architecture Professional). He is Microsoft Certified as an MCSE (Microsoft Certified Systems Engineer) and MCSA (Microsoft Certified Systems Administrator) in Windows 2000 and an MCP (Microsoft Certified Professional) in Windows NT. Tony has been recognized by Microsoft as an MVP (Most Valuable Professional) in Windows security since 2006. In addition to his Web site and magazine contributions, Tony was also tech editor of PCI Compliance (ISBN: 1597491659 ) and author of Essential Computer Security: Everyone’s Guide to E-mail, Internet, and Wireless Security (ISBN: 1597491144), coauthor of Hacker’s Challenge 3 (ISBN: 0072263040) and a contributing author to Winternals: Defragmentation, Recovery, and Administration Field Guide (ISBN: 1597490792), Combating Spyware in the Enterprise (ISBN: 1597490644) Syngress Force 2006 Emerging Threat Analysis: From Mischief to Malicious (ISBN: 1597490563), Botnets: The Killer Web Applications (ISBN: 1597491357), and AVIEN Malware Defense Guide for the Enterprise (ISBN: 1597491640).

    http://www.tonybradley.com