
“Of the eight vulnerabilities, only one is rated “Critical”—a remote code-execution vulnerability affecting the Windows kernel. This is a fairly serious issue, because a successful exploit will result in a complete compromise of the affected computer. The remaining issues, all rated “Important”, affect the Windows kernel, SChannel, and Windows WINS and DNS servers,” revealed Symantec’s Robert Keith.
The March 2009 Security Release ISO Image contains no less than four bulletins, namely MS09-006, MS09-008, MS09-007, and MS08-052. Microsoft has also included MS08-052 with this release of the ISO image, because it revised the contents on March 10. Of course, MS09-006, considered Critical because it can allow an attacker to perform remote code execution in the eventuality of a successful exploit, should be at the top of every patch priority list.
“A remote code-execution vulnerability affects the GDI component of the Windows kernel when handling malformed EMF or WMF files. Remote attackers can exploit this issue by tricking a victim into viewing a specially crafted image; this can occur simply by visiting a malicious web page or viewing a specially crafted email. Successful exploits will result in the execution of arbitrary attacker-supplied code with SYSTEM-level privileges,” Keith added.
March 2009 Security Release ISO Image is available for download here.