RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities

Microsoft has released advance notification that on February 9, 2010, the vendor will be releasing 13 security bulletins covering 26 vulnerabilities.

The vendor has rated five of the bulletins 'Critical', seven 'Important', and one 'Moderate'.

Eleven of the bulletins affect Windows; one affects Office.

The following individual records exist to better document these issues:

38108 Microsoft PowerPoint Viewer TextCharsAtom Record Stack Overflow Remote Code Execution Vulnerability
38107 Microsoft PowerPoint Viewer TextBytesAtom Record Stack Overflow Remote Code Execution Vulnerability
38104 Microsoft PowerPoint 'OEPlaceholderAtom' Record Corrupt Memory Remote Code Execution Vulnerability
38103 Microsoft PowerPoint 'OEPlaceholderAtom' Record Invalid Index Remote Code Execution Vulnerability
38099 Microsoft PowerPoint File Path Handling Remote Code Execution Vulnerability
38101 Microsoft PowerPoint 'LinkedSlideAtom' Heap Overflow Remote Code Execution Vulnerability
38112 Microsoft DirectX DirectShow AVI File Parsing Remote Code Execution Vulnerability
37884 Microsoft Internet Explorer URI Validation Remote Code Execution Vulnerability
38113 Microsoft Hyper-V Local Denial of Service Vulnerability
38110 Microsoft Windows Kerberos 'Ticket-Granting-Ticket' Remote Denial of Service Vulnerability
38073 Microsoft Office 'OfficeArtSpgr' Container Pointer Overwrite Remote Code Execution Vulnerability
38045 Microsoft Data Analyzer 'max3activex.dll' ActiveX Control Remote Code Execution Vulnerability
38049 Microsoft Windows SMB Pathname Remote Buffer Overflow Vulnerability
38051 Microsoft Windows SMB Null Pointer Remote Denial of Service Vulnerability
38085 Microsoft Windows SMB NTLM Authentication Unauthorized Access Vulnerability
38054 Microsoft Windows SMB Memory Corruption Remote Denial of Service Vulnerability
38093 Microsoft Windows SMB Client Pool Corruption Remote Code Execution Vulnerability
38100 Microsoft Windows SMB Client Race Condition Remote Code Execution Vulnerability
37864 Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
38044 Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
38061 Microsoft Windows ICMPv6 Router Advertisement Remote Code Execution Vulnerability
38064 Microsoft Windows TCP/IP Selective Acknowledgement Remote Denial of Service Vulnerability
38063 Microsoft Windows ICMPv6 Route Information Remote Code Execution Vulnerability
38062 Microsoft Windows Header MDL Fragmentation Remote Code Execution Vulnerability
38098 Microsoft Windows Client/Server Run-time Subsystem Local Privilege Escalation Vulnerability
38042 Microsoft Paint JPEG Image Processing Integer Overflow Vulnerability


 

Privacy Statement
Copyright 2010, SecurityFocus