24 October 2008
23 October 2008 Microsoft released an unscheduled update for a privately reported critical vulnerability in Windows Server service.
Critical is Microsoft’s highest vulnerability rating.
More information is available from Microsoft’s Security Bulletin MS08-067.
An update that fixes the vulnerabilities is available from Windows automatic update mechanism for systems that support this. Alternatively, one may download updates from http://windowsupdate.microsoft.com.
It is very rare that Microsoft releases out-of-band security bulletins and patches. This indicates that this vulnerability is seen as very serious by Microsoft.
Norman advices all affected users to download ths security update as soon as possible, to be protected from potential exploits.