Windows Vista KB958690 

 

KB958690

 

by Marc Liron - Microsoft MVP


 

A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.

What is KB958690?

A vulnerability in the Windows Kernel that could allow remote code execution.

Executive Summary

This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system.

This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.

In particular for Windows Vista Service Pack 1 users:

Windows Vista Business
Windows Vista Enterprise
Windows Vista Home Basic
Windows Vista Home Premium
Windows Vista Starter
Windows Vista Ultimate
Windows Vista Enterprise 64-bit Edition
Windows Vista Home Basic 64-bit Edition
Windows Vista Home Premium 64-bit Edition
Windows Vista Ultimate 64-bit Edition
Windows Vista Business 64-bit Edition

The security update addresses the vulnerabilities by validating input passed from user mode through the kernel component of GDI, correcting the way that the kernel validates handles, and changing the way that the Windows kernel handles specially crafted invalid pointers.

Recommendation

The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294781.

For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.


The main difference with a service is that they load into memory at boot time and start running whether or not anyone logs into the computer.


-------------------------------------------------------------------------------------------------------------

 

I hope you got something useful out of visiting this website today!

Make sure you sign up for the FREE Newsletter and checkout the Main Index for a growing list of articles you are going to find informative!

Kind Regards

Marc Liron

Marc Liron - Microsoft MVP
http://www.marcliron.com

 

Try Now:






Grab the ENTIRE 4 Part Guide:

Windows Services Guide - $9.97


--------------------

 

Protect your files with Carbonite Online Backup

--------------------