Hi Folks,

Nice to meet you all again through DC blogs.  Here is an quick update on the “December Patch Tuesday”.  The following patches were tested and updated in the Patch DB of Desktop Central around 9.00 AM EST.  Here is an quick snap shot of it.

Desktop Central supported patches according to Vulnerability updates by Microsoft.

Bulletin ID Vulnerability Title CVE ID Exploitability Index Assessment
MS09-069 Local Security Authority Subsystem Service Resource Exhaustion Vulnerability CVE-2009-3675 3 – Functioning exploit code unlikely
MS09-070 Single Sign On Spoofing in ADFS Vulnerability CVE-2009-2508 3 – Functioning exploit code unlikely
*MS09-070 Remote Code Execution in ADFS Vulnerability CVE-2009-2509 1 – Consistent exploit code likely
MS09-071 Internet Authentication Service Memory Corruption Vulnerability CVE-2009-2505 2 – Inconsistent exploit code likely
MS09-071 MS-CHAP Authentication Bypass Vulnerability CVE-2009-3677 3 – Functioning exploit code unlikely
MS09-072 ATL COM Initialization Vulnerability CVE-2009-2493 None 
MS09-072 Uninitialized Memory Corruption Vulnerability CVE-2009-3671 1 – Consistent exploit code likely
MS09-072 HTML Object Memory Corruption Vulnerability CVE-2009-3672 1 – Consistent exploit code likely
MS09-072 Uninitialized Memory Corruption Vulnerability CVE-2009-3673 1 – Consistent exploit code likely
MS09-072 Uninitialized Memory Corruption Vulnerability CVE-2009-3674 1 – Consistent exploit code likely
< small>MS09-073 WordPad and Office Text converter Memory Corruption Vulnerability CVE-2009-2506 2 – Inconsistent exploit code likely

* – Windows Server 2003 R2, Windows Server 2003 R2 x64 yet to be supported

The affected Operating Systems and Applications list supported by Desktop Central

  • Microsoft Windows 2000 Service Pack 4, 
  • Windows XP Service Pack 2
  • Windows XP Service Pack 3, 
  • Windows XP Professional x64 Edition Service Pack 2, 
  • Windows Server 2003 Service Pack 2, 
  • Windows Server 2003 x64 Edition Service Pack 2,
  • Windows Vista
  • Windows Vista Service Pack 1, 
  • Windows Vista Service Pack 2, 
  • Windows Vista x64 Edition
  • Windows Vista x64 Edition Service Pack 1, 
  • Windows Vista x64 Edition Service Pack 2, 
  • Windows Server 2008 for 32-bit Systems,
  • Windows Server 2008 for 32-bit Systems Service Pack 2, 
  • Windows Server 2008 for x64-based Systems
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Internet Explorer 5.01 Service Pack 4
  • Internet Explorer 6 Service Pack 1
  • Internet Explorer 6
  • Internet Explorer 7
  • Internet Explorer 8
  • Microsoft Office Word 2002 Service Pack 3
  • Microsoft Office Word 2003 Service Pack 3

Support Non-Security Patches

  • Microsoft Malicious Software Removal Tool updates
  • Microsoft Outlook Email junk filter – Office 2003, 2007

For any assistance on patching feel free to contact desktopcentral-support@manageengine.com

Happy Patching. 

cheers,
Romanus