Microsoft Windows Knowledge Base Article 944338 update not installed (WinMs08kb944338Update)

Vuln ID: 40059
Risk Level: High risk vulnerability  High WinMs08kb944338Update
Platforms: Microsoft VBScript: 5.1, Microsoft VBScript: 5.6, Microsoft Windows XP: SP2 x64-Professional, Microsoft Windows 2003 Server: SP2, Microsoft Windows 2003 Server: SP2 Itanium, Microsoft Windows 2003 Server: SP2 x64, Microsoft JScript: 5.1, Microsoft JScript: 5.6, Microsoft Windows 2003 Server: SP1 Itanium, Microsoft Windows XP: x64-Professional, Microsoft Windows 2003 Server: SP1, Microsoft Windows XP: SP2, Microsoft Windows 2003 Server: x64, Microsoft Windows 2000: SP4
Description:

Microsoft Windows Knowledge Base Article 944338 update is not installed on the system, which could allow an attacker to exploit the following vulnerability:

The Microsoft Windows VBScript (VBScript.dll) and JScript (JScript.dll) scripting engines could allow a remote attacker to execute arbitrary code on the system, caused by a vulnerability regarding the decoding of scripts within a Web page. By persuading a victim to visit a malicious Web page, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-022. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS08-022
Vulnerability in VBScript and JScript Scripting Engines Could Allow Remote Code Execution (944338)
http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx

IBM Internet Security Systems X-Force Database
Microsoft Windows VBScript and JScript engines code execution
http://xforce.iss.net/xforce/xfdb/40056

ISS X-Force
Microsoft Windows Knowledge Base Article 944338 update not installed
http://www.iss.net/security_center/static/40059.php

CVE CVE-2008-0083
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0083


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures