RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
BID:39313
Info
RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 39313 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 08 2010 12:00AM |
| Updated: | Apr 13 2010 07:53PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition SP3 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP3 Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP3 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Gold 0 Microsoft Windows XP Embedded Update Rollup 1.0 Microsoft Windows XP Embedded SP2 Feature Pack 2007 0 Microsoft Windows XP Embedded SP3 Microsoft Windows XP Embedded SP2 Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Ultimate 64-bit edition 0 Microsoft Windows Vista Home Premium 64-bit edition SP2 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition 0 Microsoft Windows Vista Home Basic 64-bit edition SP2 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition 0 Microsoft Windows Vista Enterprise 64-bit edition SP2 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition 0 Microsoft Windows Vista December CTP Microsoft Windows Vista Business 64-bit edition SP2 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition 0 Microsoft Windows Vista Ultimate SP2 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista Ultimate Microsoft Windows Vista SP2 Beta Microsoft Windows Vista SP2 Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise SP2 Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Enterprise Microsoft Windows Vista Business SP2 Microsoft Windows Vista Business SP1 Microsoft Windows Vista Business Microsoft Windows Vista beta 2 Microsoft Windows Vista Beta 1 Microsoft Windows Vista Beta Microsoft Windows Vista 0 Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition Release Candidate Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 R2 Datacenter 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition Release Candidate Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition Release Candidate Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2008 SP2 Beta Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Beta 1 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Terminal Services 0 Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Platform SDK Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2003 R2 Platfom SDK Microsoft Windows Server 2008 R2 Microsoft Windows 7 XP Mode 0 Microsoft Windows 7 Ultimate 0 Microsoft Windows 7 Starter 0 Microsoft Windows 7 Professional 0 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for Itanium-based Systems 0 Microsoft Windows 7 for 32-bit Systems 0 Microsoft Windows 7 RC Microsoft Windows 7 beta Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Windows 7 Microsoft Visio 2007 SP2 Microsoft Visio 2007 SP1 Microsoft Visio 2007 0 Microsoft Visio 2003 Standard Microsoft Visio 2003 Professional Microsoft Visio 2003 SP3 Microsoft Visio 2003 SP2 Microsoft Visio 2003 SP1 Microsoft Visio 2003 Microsoft Publisher 2007 SP2 Microsoft Publisher 2007 SP1 Microsoft Publisher 2007 0 Microsoft Publisher 2003 SP3 Microsoft Publisher 2003 SP2 Microsoft Publisher 2003 Microsoft Publisher 2002 SP3 Microsoft Publisher 2002 Microsoft Exchange Server 2010 x64 0 Microsoft Exchange Server 2007 x64 SP2 Microsoft Exchange Server 2007 x64 SP1 Microsoft Exchange Server 2007 x64 0 Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 Microsoft Exchange Server 2000 SP3 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on April 13, 2010, the vendor will be releasing 11 security bulletins covering 25 vulnerabilities.
The bulletins and their affected components are as follows:
Five rated Critical affecting Windows
Five rated Important affecting Windows, Office, and Exchange
One rated Moderate affecting Windows
The following individual records exist to better document these issues:
39328 Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
39332 Microsoft Windows Cabinet File Viewer Cabview Validation Remote Code Execution Vulnerability
36989 Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
39312 Microsoft Windows SMB Client Memory Allocation Remote Code Execution Vulnerability
39339 Microsoft Windows SMB Client Transaction Response Remote Code Execution Vulnerability
39336 Microsoft Windows SMB Client Response Parsing Remote Code Execution Vulnerability
39340 Microsoft Windows SMB Client Message Size Remote Code Execution Vulnerability
39297 Microsoft Windows Kernel NULL Pointer Local Denial Of Service Vulnerability
39309 Microsoft Windows Kernel Symbolic Link Local Denial Of Service Vulnerability
39323 Microsoft Windows Kernel Registry Key Symbolic Link Local Privilege Escalation Vulnerability
39324 Microsoft Windows Kernel Symbolic Link Creation Local Privilege Escalation Vulnerability
39318 Microsoft Windows Kernel Invalid Registry Key Local Denial Of Service Vulnerability
39319 Microsoft Windows Kernel Virtual Path Local Denial Of Service Vulnerability
39320 Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
39322 Microsoft Windows Kernel Exception Handling Local Denial Of Service Vulnerability
38463 Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
39347 Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
39308 Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
39381 Microsoft Windows SMTP Server Memory Allocation Information Disclosure Vulnerability
39356 Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
39303 Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability
39351 Microsoft Windows Media Player ActiveX Control Remote Code Execution Vulnerability
39300 Microsoft Visio Attribute Validation Memory Corruption Remote Code Execution Vulnerability
39302 Microsoft Visio Index Calculation Memory Corruption Remote Code Execution Vulnerability
39352 Microsoft Windows ISATAP Component IPv6 Address Spoofing Vulnerability
Microsoft has released advance notification that on April 13, 2010, the vendor will be releasing 11 security bulletins covering 25 vulnerabilities.
The bulletins and their affected components are as follows:
Five rated Critical affecting Windows
Five rated Important affecting Windows, Office, and Exchange
One rated Moderate affecting Windows
The following individual records exist to better document these issues:
39328 Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
39332 Microsoft Windows Cabinet File Viewer Cabview Validation Remote Code Execution Vulnerability
36989 Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
39312 Microsoft Windows SMB Client Memory Allocation Remote Code Execution Vulnerability
39339 Microsoft Windows SMB Client Transaction Response Remote Code Execution Vulnerability
39336 Microsoft Windows SMB Client Response Parsing Remote Code Execution Vulnerability
39340 Microsoft Windows SMB Client Message Size Remote Code Execution Vulnerability
39297 Microsoft Windows Kernel NULL Pointer Local Denial Of Service Vulnerability
39309 Microsoft Windows Kernel Symbolic Link Local Denial Of Service Vulnerability
39323 Microsoft Windows Kernel Registry Key Symbolic Link Local Privilege Escalation Vulnerability
39324 Microsoft Windows Kernel Symbolic Link Creation Local Privilege Escalation Vulnerability
39318 Microsoft Windows Kernel Invalid Registry Key Local Denial Of Service Vulnerability
39319 Microsoft Windows Kernel Virtual Path Local Denial Of Service Vulnerability
39320 Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
39322 Microsoft Windows Kernel Exception Handling Local Denial Of Service Vulnerability
38463 Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
39347 Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
39308 Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
39381 Microsoft Windows SMTP Server Memory Allocation Information Disclosure Vulnerability
39356 Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
39303 Microsoft Windows MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability
39351 Microsoft Windows Media Player ActiveX Control Remote Code Execution Vulnerability
39300 Microsoft Visio Attribute Validation Memory Corruption Remote Code Execution Vulnerability
39302 Microsoft Visio Index Calculation Memory Corruption Remote Code Execution Vulnerability
39352 Microsoft Windows ISATAP Component IPv6 Address Spoofing Vulnerability
Exploit / POC
RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on April 13, 2010.
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on April 13, 2010.
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
References:
References:
- April 2010 Bulletin Release Advance Notification (Microsoft)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin Advance Notification for April 2010 (Microsoft)