Microsoft Patch Tuesday 2010-04-13

MS10-019
Title Vulnerabilities in Windows Authenticode Verification
Replaces
Affected Authenticode
KB KB981210
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0486 2
2010-0487 2
MS10-020
Title Vulnerabilities in SMB Client
Replaces MS10-006
Affected SMB Client
KB KB980232
Known Exploits Yes
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0269 3
2010-0270 2
2010-0476 2
2010-0477 3
2009-3676 3
MS10-021
Title Privilege Elevation Vulnerabilities in Windows Kernel
Replaces MS10-015
Affected Windows Kernel
KB KB979683
Known Exploits No
Microsoft Rating Important
ISC Client Rating Important
ISC Server Rating Important
CVE Exploitability
2010-0234 0
2010-0235 0
2010-0236 1
2010-0237 1
2010-0238 0
2010-0481 0
2010-0482 0
2010-0810 0
MS10-022
Title Vulnerability in VBScript Engine
Replaces
Affected VBScript
KB KB981169
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Patch now
ISC Server Rating Patch now
CVE Exploitability
2010-0483 1
MS10-023
Title Vulnerability in Microsoft Office Publisher
Replaces MS80-27, MS90-30
Affected Publisher
KB KB981160
Known Exploits No
Microsoft Rating Important
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0479 1
MS10-024
Title DoS Vulnerability in Microsoft Exchange and SMTP Service
Replaces
Affected Exchange, SMTP Service
KB KB981832
Known Exploits Yes
Microsoft Rating Important
ISC Client Rating N/A
ISC Server Rating N/A
CVE Exploitability
2010-0024 3
2010-0025 0
MS10-025
Title Vulnerability in Micorsoft Windows Media Services
Replaces
Affected Windows Meida Services
KB KB980858
Known Exploits No
Microsoft Rating Critical
ISC Client Rating N/A
ISC Server Rating N/A
CVE Exploitability
2010-0478 1
MS10-026
Title Vulnerability in Microsoft MPEG Layer 3 Codec
Replaces
Affected MPEG Layer 3 Codec
KB KB977816
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0480 1
MS10-027
Title Vulnerability in Windows Media Player
Replaces MS70-47
Affected Windows Media Player
KB KB979402
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0268 1
MS10-028
Title Vulnerabilities in Microsoft Visio
Replaces MS90-05, MS90-62
Affected Windows Media Player
KB KB980094
Known Exploits No
Microsoft Rating Critical
ISC Client Rating Critical
ISC Server Rating Critical
CVE Exploitability
2010-0254 1
2010-0256 2
MS10-029
Title ISATAP Spoofing Vulnerability
Replaces
Affected ISATAP
KB KB978338
Known Exploits No
Microsoft Rating Moderate
ISC Client Rating N/A
ISC Server Rating N/A
CVE Exploitability
2010-0812 0
We will update issues on this page for about a week or so as they evolve. We appreciate your updates!
US based customers can call Microsoft for free patch related support on 1-866-PCSAFETY
(*): ISC rating
  • We use 4 levels:
    • PATCH NOW: Typically used where we see immediate danger of exploitation. Typical environments will want to deploy these patches ASAP. Workarounds are typically not accepted by users or are not possible. This rating is often used when typical deployments make it vulnerable and exploits are being used or easy to obtain or make.
    • Critical: Anything that needs little to become "interesting" for the dark side. Best approach is to test and deploy ASAP. Workarounds can give more time to test.
    • Important: Things where more testing and other measures can help.
    • Less Urgent: practices for servers such as not using outlook, MSIE, word etc. to do traditional office or leisure work.
    • The rating is not a risk analysis as such. It is a rating of importance of the vulnerability and the perceived or even predicted threatatches.