13 August 2008

Security advisory

In its security bulletin summary for August 2008 Microsoft has published six updates for new critical vulnerabilities in its operating systems / applications, as well as five important.

Critical is Microsoft’s highest vulnerability rating.

A summary describing briefly the vulnerabilities is available from Microsoft’s Security Bulletin Summary for August 2008.
From this page you will also find links to more detailed information in Microsoft's Security Bulletins MS08-041, MS08-043-046 and MS08-051.

The critical updates address the following issues:

  • One privately reported vulnerability in the Microsoft Image Color Management (ICM) system.
  • Five privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer.
  • One privately reported vulnerability in the ActiveX control for the Snapshot Viewer for Microsoft Access.
  • Four privately reported vulnerabilities in Microsoft Excel.
  • Three privately reported vulnerabilities in Microsoft Office PowerPoint and Microsoft Office PowerPoint Viewer.
  • Five privately reported vulnerabilities in Microsoft Office Filters.

The vulnerabilities in Internet Explorer (MS08-045) are probably the most serious as one of these is publicly disclosed.

Updates that fixes the vulnerabilities are available from Windows automatic update mechanism for systems that support this. Alternatively, one may download updates from http://windowsupdate.microsoft.com.  

Norman advices all affected users to download the security updates as soon as possible, to be protected from potential exploits.