| Microsoft Windows Knowledge Base Article 952044 update not installed (WinMs08kb952044Update) |
|---|
| Vuln ID: | 42109 | |
|---|---|---|
| Risk Level: | Low |
WinMs08kb952044Update |
| Platforms: | Microsoft Windows Live OneCare, Microsoft Forefront Security for SharePoint, Microsoft Standalone System Sweeper located in Diagnostics and Recovery Toolset: 6.0, Microsoft Forefront Security for Exchange Server, Microsoft Forefront Client Security, Microsoft Forefront Edge Server, Microsoft Antigen for SMTP Gateway, Microsoft Antigen for Exchange, Microsoft Windows Defender | |
| Description: | Microsoft Windows Knowledge Base Article 952044 update is not installed on the system, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft Malware Protection Engine is vulnerable to a denial of service, caused by improper validation of input when parsing files. By persuading a victim to scan a specially-crafted file using the Microsoft Malware Protection Engine, a remote attacker could cause the Malware Protection Engine to become unresponsive and eventually restart. An attacker could exploit this vulnerability by hosting the malicious file on a Web site or sending the file as an email attachment. Microsoft Malware Protection Engine is vulnerable to a denial of service, caused by improper validation of certain data structures when parsing files. By persuading a victim to scan a specially-crafted file using the Microsoft Malware Protection Engine, a remote attacker could cause large temporary files to be created and consume all available disk resources. An attacker could exploit this vulnerability by hosting the malicious file on a Web site or sending the file as an email attachment. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-029. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS08-029 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2008-1438 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |