New Microsoft OSes Hit by Patch Tuesday Shrapnel

執筆者
Ryan Naraine
Ryan Naraine
Published: Apr 8, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Two of Microsoft’s newest operating systems-Windows Vista and Windows Server 2008-are vulnerable to serious remote code execution attacks, according to a warning from the software giant.

The “critical” warning comes April 8 as part of Microsoft’s April batch of Patch Tuesday updates, which include eight security bulletins covering at least 10 documented software vulnerabilities.

The biggest eye-opener is the “high-risk” severity of the patches that apply to Windows Vista and Windows Server 2008, the two operating systems touted by Microsoft as its most secure ever.

One of the bulletins-MS08-021-is rated “critical” across the board for all supported versions of Windows, from Windows 2000 through Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

The bulletin provides cover for at least two known flaws that could allow malicious hackers remote access to “take complete control of an affected system” if a user opens a specially crafted EMF or WMF image file.

According to Microsoft’s documentation, both vulnerabilities were found in the way the Windows GDI (graphics device interface) handles integer calculations and filename parameters in EMF and WMF files. The Windows GDI allows applications to use graphics and formatted text on both the video display and the printer.

Windows Vista and Windows Server 2008 are also affected by another batch of bugs affecting the company’s flagship IE (Internet Explorer) browser. The company slapped a high-priority tag on both MS08-023 and MS08-024, which address flaws in ActiveX controls and a remote code execution flaw in IE’s handling of data streams.

One of the IE updates includes a kill bit for a known bug in an Active X control in the Yahoo Music Jukebox product.

A fourth “critical” bulletin-MS08-022-was also released to provide a fix for a remote code execution vulnerability in the way that the VBScript and JScript scripting engines decode script in Web pages.

“This vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running specially crafted script,” Microsoft warned.

This VBScript and Jscript bug affects Windows 2000, Windows XP and Windows Server 2003 systems.

Advertisement

This month’s updates also include a fix for a “critical” code execution hole in Microsoft Project, the enterprise-facing project management program. This bug, which allows a hacker to rig Project files to take “complete control” of affected systems, was reported to Microsoft by the Republic of Korea’s National Cyber Security Center.

The company also shipped separate patches for two “important” vulnerabilities in Microsoft Office Visio, a DNS spoofing attack flaw affecting Windows 2000 through Windows Vista computers, and a kernel vulnerability that could allow remote code execution attacks on all versions of Windows.

Just hours after Microsoft released its updates, Immunity, a private penetration testing company, released exploit code for the Windows kernel vulnerability.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。