Windows Vista KB958690
KB958690
A security issue has been identified that could allow an unauthenticated
remote attacker to compromise your system and gain control over it. You can help
protect your system by installing this update from Microsoft. After you install
this update, you may have to restart your system.
What is KB958690?
|
|
A vulnerability in the Windows Kernel that could allow
remote code execution.
Executive Summary
This security update resolves several privately reported
vulnerabilities in the Windows kernel. The most serious
vulnerability could allow remote code execution if a user viewed a
specially crafted EMF or WMF image file from an affected system.
This security update is rated Critical for all supported editions of
Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows
Vista, and Windows Server 2008.
In particular for Windows Vista Service Pack 1 users:
Windows Vista Business
Windows Vista Enterprise
Windows Vista Home Basic
Windows Vista Home Premium
Windows Vista Starter
Windows Vista Ultimate
Windows Vista Enterprise 64-bit Edition
Windows Vista Home Basic 64-bit Edition
Windows Vista Home Premium 64-bit Edition
Windows Vista Ultimate 64-bit Edition
Windows Vista Business 64-bit Edition
The security update addresses the vulnerabilities by validating
input passed from user mode through the kernel component of GDI,
correcting the way that the kernel validates handles, and changing
the way that the Windows kernel handles specially crafted invalid
pointers.
Recommendation
The majority of customers have automatic updating enabled and will
not need to take any action because this security update will be
downloaded and installed automatically. Customers who have not
enabled automatic updating need to check for updates and install
this update manually. For information about specific configuration
options in automatic updating, see
Microsoft Knowledge Base Article 294781.
For administrators and enterprise installations, or end users who
want to install this security update manually, Microsoft recommends
that customers apply the update immediately using update management
software, or by checking for updates using the
Microsoft Update service.
The main difference with a service is that they load into memory at
boot time and start running whether or not anyone logs into the
computer.
-------------------------------------------------------------------------------------------------------------
I hope you got something useful out of visiting this website today!
Make sure you sign up for the FREE Newsletter and checkout the Main Index for a growing list of articles you are going to find informative!
Kind Regards

Marc Liron - Microsoft MVP
http://www.marcliron.com
Try Now:

Grab the ENTIRE 4 Part Guide:
Windows Services Guide - $9.97
--------------------
--------------------
