Microsoft has released four Security Bulletins on September 9, covering eight separate vulnerabilities. The bulletins addressed errors in Microsoft Windows, Microsoft Office, Microsoft Internet Explorer, the .NET Framework, Microsoft SQL Server, and Microsoft Visual Studio software.
Exploit code has been released for a recently disclosed DNS Cache Poisoning Vulnerability, CVE-2008-1447, which affects several vendors. Administrators are urged to patch as soon as possible.
- Critical
- Systems worldwide are targeted by a worm.
- New malware that potentially can cause damage has been reported and has spread globally.
- Severe
- An unpatched or recently patched vulnerability can be exploited by a worm, and systems worldwide are at risk to be targeted by a particular worm. No worm activity has been identified.
- A high incidence of new malware that potentially can cause damage has been reported.
- Elevated
- An unpatched or recently patched vulnerability is present on many systems worldwide but requires user interaction to be exploited.
- An existing vulnerability becomes more serious because new exploit code has been published.
- There is new malware activity, but it is not widespread.
- Low
- There is no direct threat to systems that have been patched.
- No new significant malware activity has been reported.