Oklahoma State University: The STATE's University
Visit the OSU Home Page
Home
Report an Incident
Services
Search

News
FAQs
Policies and Guidelines
Secure Coding
Hardening Guides
IT Announcements

IT Information Security Office
301 Whitehurst
Oklahoma State University
Stillwater, OK 74075
Phone: (405) 744-4357
Email: abuse [at] okstate.edu
WebD.jpg
Welcome to the IT Information Security Office

The IT Information Security Office (ISO) was established to secure the data systems and computers of Oklahoma State University.

Image
The ISO strives to protect students, faculty, and employees by protecting University information, helping to write and use secure applications, and detecting and preventing potential threats.

 
Microsoft's Security Bulletin

Microsoft's RSS feed of the new security releases and patch updates. These are hot out of the Microsoft factory. Click on the link to learn more about the vulnerability or just to download the patch.

  • MS08-040 ? Important: Vulnerabilities in Microsoft SQL Server Could Allow Elevation of Privilege (941203)
    Bulletin Severity Rating:Important - This security update resolves four privately disclosed vulnerabilities. The more serious of the vulnerabilities could allow an attacker to run code and to take complete control of an affected system. An authenticated attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.
  • MS08-039 ? Important: Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747)
    Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in Outlook Web Access (OWA) for Microsoft Exchange Server. An attacker who successfully exploited these vulnerabilities could gain access to an individual OWA client?s session data, allowing elevation of privilege. The attacker could then perform any action the user could perform from within the individual client?s OWA session.
  • MS08-038 ? Important: Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582)
    Bulletin Severity Rating:Important - This security update resolves a publicly reported vulnerability in Windows Explorer that could allow remote code execution when a specially crafted saved-search file is opened and saved. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • MS08-037 ? Important: Vulnerabilities in DNS Could Allow Spoofing (953230)
    Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in the Windows Domain Name System (DNS) that could allow spoofing. These vulnerabilities exist in both the DNS client and DNS server and could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker?s own systems.
  • MS08-036 ? Important: Vulnerabilities in Pragmatic General Multicast (PGM) Could Allow Denial of Service (950762)
    Bulletin Severity Rating:Important - This security update resolves two privately reported vulnerabilities in the Pragmatic General Multicast (PGM) protocol that could allow a denial of service if malformed PGM packets are received by an affected system. An attacker who successfully exploited this vulnerability could cause a user?s system to become non-responsive and to require a restart to restore functionality. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.
  • MS08-035 ? Important: Vulnerability in Active Directory Could Allow Denial of Service (953235)
    Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in implementations of Active Directory on Microsoft Windows 2000 Server, Windows Server 2003, and Windows Server 2008; Active Directory Application Mode (ADAM) when installed on Windows XP Professional and Windows Server 2003; and Active Directory Lightweight Directory Service (AD LDS) when installed on Windows Server 2008. The vulnerability could be exploited to allow an attacker to cause a denial of service condition. On Windows XP Professional, Windows Server 2003, and Windows Server 2008, an attacker must have valid logon credentials to exploit this vulnerability. An attacker who successfully exploited this vulnerability could cause the system to stop responding or automatically restart.
  • MS08-034 ? Important: Vulnerability in WINS Could Allow Elevation of Privilege (948745)
    Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS) that could allow elevation of privilege. A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
  • MS08-033 ? Critical: Vulnerabilities in DirectX Could Allow Remote Code Execution (951698)
    Bulletin Severity Rating:Critical - This security update resolves two privately reported vulnerabilities in Microsoft DirectX that could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited either of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • MS08-032 - Moderate: Cumulative Security Update of ActiveX Kill Bits (950760)
    Bulletin Severity Rating:Moderate - This security update resolves a publicly reported vulnerability for the Microsoft Speech API. The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer and has the Speech Recognition feature in Windows enabled. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. This update also includes a kill bit for software produced by BackWeb.
  • MS08-031 - Critical: Cumulative Security Update for Internet Explorer (950759)
    Bulletin Severity Rating:Critical - This security update resolves one privately reported and one publicly disclosed vulnerability. The privately reported vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The publicly disclosed vulnerability could allow information disclosure if a user viewed a specially crafted Web page using Internet Explorer.
 
Oklahoma State University - Stillwater | Stillwater, OK 74078 | 405.744.5000
Copyright © 2006 Oklahoma State University | All rights reserved