March 11, 2008
Microsoft Security Bulletin: March 2008 Security Bulletin
Advisory Overview
March 11, 2008 - Qualys® Vulnerability R&D Lab has released new vulnerability checks in QualysGuard® to protect organizations against the 4 new vulnerabilities present in Microsoft Windows that were announced today. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their QualysGuard subscription.

Listen to Podcast
Vulnerability Details
Microsoft has released 4 security patches to fix newly discovered flaws in Microsoft Windows.

Qualys has released the following checks for these new vulnerabilities:
Microsoft Excel Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 110074
VENDOR REFERENCE: MS08-014, 949029
CVE REFERENCE: CVE-2008-0111, CVE-2008-0112, CVE-2008-0114, CVE-2008-0115, CVE-2008-0116, CVE-2008-0117, CVE-2008-0081
CVSS SCORES: Base 9.3/ Temporal 6.9
THREAT: Microsoft Excel is prone to multiple remote code execution vulnerabilities. The security update addresses the following issues.
  • A remote code execution vulnerability exists in the way Excel processes data validation records when loading Excel files into memory
  • A remote code execution vulnerability exists in the way Excel handles data when importing files into Excel.
  • A remote code execution vulnerability exists in the way Excel handles Style record data when opening Excel files.
  • A remote code execution vulnerability exists in the way Excel handles malformed formulas.
  • A remote code execution vulnerability exists in the way Excel handles rich text values when loading application data into memory.
  • A remote code execution vulnerability exists in the way Excel handles conditional formatting values.
  • A remote code execution vulnerability exists in the way Excel handles macros when opening specially crafted Excel files.
IMPACT: An attacker who successfully exploits this vulnerability could run arbitrary code on the affected system as the logged on user.
SOLUTION: Refer to Microsoft Security Bulletin MS08-014 for further details and patches.

Microsoft has rated the most severe of these issues as Critical.

Microsoft Outlook Remote Code Execution Vulnerability
SEVERITY: Critical Critical-4 4
QUALYS ID: 110076
VENDOR REFERENCE: MS08-015, 949031
CVE REFERENCE: CVE-2008-0110
CVSS SCORES: Base 9.3/ Temporal 7.3
THREAT: Microsoft update MS07-003 resolves several newly discovered vulnerabilities in Microsoft Outlook.

The following specific issue was reported:
  • A remote code execution when Outlook is passed a specially crafted mailto URI.
IMPACT: As a result, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS08-015 for further details on these vulnerabilities and patch instructions.

Microsoft has rated this issue as Critical.

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
SEVERITY: Critical Critical-4 4
QUALYS ID: 110073
VENDOR REFERENCE: MS08-016, 949030
CVE REFERENCE: CVE-2008-0113, CVE-2008-0118
CVSS SCORES: Base 5.1/ Temporal 3.8
THREAT: A remote code execution vulnerability exists in the way Microsoft Office handles specially crafted Excel files. Another remote code execution vulnerability exists in the way Microsoft Office processes malformed Office files.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Refer to Microsoft Security Bulletin MS08-016 to address this issue.

Microsoft has rated this issue as Critical.

Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 110075
VENDOR REFERENCE: MS08-017, 949103
CVE REFERENCE: CVE-2007-1201,CVE-2006-4695
CVSS SCORES: Base 6.3/ Temporal 4.9
THREAT: This critical update resolves two privately reported vulnerabilities in Microsoft Office Web Components which can be exploited using a specially crafted web page.
IMPACT: An attacker who successfully exploited this vulnerability could take complete control of an affected system by installing programs; viewing modifying data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
SOLUTION: Refer to Microsoft Security Bulletin MS08-017 for further details on these vulnerabilities and patch instructions.

Microsoft has rated this issue as Critical.

This new vulnerability check is included in Qualys vulnerability signatures v1.19.87-4. Each QualysGuard account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the QualysGuard HOME menu, select the Account Info tab.

SELECTIVE SCAN INSTRUCTIONS USING QUALYSGUARD:

To perform a selective vulnerability scan, configure a scan profile to use the following options:

  1. Ensure access to TCP ports 135 and 139 are available.
  2. Enable Windows Authentication (specify Authentication Records).
  3. Enable the following Qualys IDs:
    • 110074
    • 110076
    • 110073
    • 110075
  4. If you would like the scan to return the Windows Hostname, also include QID 82044 and ensure access to UDP port 137 is available.
  5. If you would like to be notified if QualysGuard is unable to logon to a host (if Authentication fails), also include QID 105015.

In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Matrix Report, available from the QualysGuard HOME page.


Technical Support
For more information, customers may contact Qualys Technical Support directly at support@qualys.com or by telephone toll free at:
US: 1 866.801.6161 | EMEA: 33 1 44.17.00.41 | UK: +44 1753 872102
About QualysGuard
QualysGuard is an on-demand security audit service delivered over the web that enables organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues. By continuously and proactively monitoring all network access points, QualysGuard dramatically reduces security managers' time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

Access for QualysGuard customers: https://qualysguard.qualys.com

Free trial of QualysGuard service: http://www.qualys.com/solutions/free/trials