Go to Home page
  • Home
  • News & Events
  • Products
  • Partners
  • Resources
  • FAQ
  • About Us
  • Blog
  • Contact Us
Online Demos
Online Demos Click to view a demo of AOK software products

Products
Go to Products page
Click here to see module contents & bolt-on options...

Test-It
Test-It™
Identify compatibility issues before testing an app

Fix-It
Fix-It™
Auto-fix compatibility issues before deploying an app

Virtualise-It
Virtualise-It™
Check in seconds which apps can be virtualised

OfficeIE
OfficeIE™
Migration tool for Office 2007 & IE8

QA-It
QA-It™
Fully automate in-house standards & Best Practices

Manage-It
Manage-It™
Identify & fix compatibility issues before deployment

Convert-It
Convert-It™
Automated installed application extraction utility
Latest News
Go to News page
19 August 2010
ChangeBASE AOK launches Microsoft Office 2010 Plug-ins to ensure application compatibility. More...
10 August 2010
Microsoft Patch Tuesday: August 10th, 2010. More...
29 July 2010
ChangeBASE AOK launches VMware ThinApp application compatibility Plug-in. More...
22 July 2010
ChangeBASE announces August product launch to overcome web browser compatibility and rendering problems. More...
20 July 2010
ChangeBASE AOK launches free Windows 7 application compatibility service. More...
13 July 2010
Microsoft Patch Tuesday: July 13th, 2010. More...
22 June 2010
ChangeBASE AOK signs agreement with KiZAN, leading US Microsoft Gold Partner. More...
15 June 2010
Deutsche Telekom selects ChangeBASE AOK for 150,000 PCs. More...
11 June 2010
Join ChangeBASE and PDS in Holland on July 1st at the "App Compat for OS Migration seminar", Click to register. More...
8 June 2010
Microsoft Patch Tuesday: June 8th, 2010. More...


Microsoft Patch TuesdaySep 8th 2009.

Sep 8th 2009.

By: Greg Lambert

Application Compatibility Update


Executive Summary

September 2009 brings a moderate Microsoft Patch Tuesday update from Microsoft with five CRITICAL Security updates. All five Microsoft Security Updates (MS09-45 to MS09-49) will require system reboots and relate to Remote Code Execution. The ChangeBASE team has raised the system reboot ratings for patch MS09-046 and MS09-047 to "Require a Reboot" from "May require a reboot" due to the nature of the files updated and the impact on standard desktop workstation environments.

The expectation from the ChangeBASE team is that the five September Microsoft updates are not likely to cause serious OS level or application compatibility issues. Sample results from the AOK report generator for Microsoft Office 2003 has been included here;





Testing Summary
  • MS09-045 : Marginal Impact (both Package level and dependencies) detected across portfolio.
  • MS09-046 : Marginal Impact (both Package level and dependencies) detected across portfolio.
  • MS09-047 : Marginal Impact (both Package level and dependencies) detected across portfolio.
  • MS09-048 : Marginal Impact (both Package level and dependencies) detected across portfolio.
  • MS09-049 : Marginal Impact (both Package level and dependencies) detected across portfolio.


Patch NameTotal
Issues
Matches
Affected
RebootRatingRAG
Microsoft Security Bulletin MS09-045<1%<1%YESCriticalGreen
Microsoft Security Bulletin MS09-046<1%<1%YESCriticalGreen
Microsoft Security Bulletin MS09-047<1%<1%YESCriticalGreen
Microsoft Security Bulletin MS09-048<1%<1%YESCriticalGreen
Microsoft Security Bulletin MS09-049<1%<1%YESCriticalGreen

Legend:
No IssueNo Issues Detected
FixablePotentially fixable application Impact
SeriousSerious Compatibility Issue

Security Update Detailed Summary
MS09-045Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)
DescriptionThis security update resolves a privately reported vulnerability in the JScript scripting engine that could allow remote code execution if a user opened a specially crafted file or visited a specially crafted Web site and invoked a malformed script. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadJscript.dll
Impact Critical

MS09-046Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)
DescriptionThis security update resolves a privately reported vulnerability in the DHTML Editing Component ActiveX control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadTriedit.dll
Impact Critical

MS09-047Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812)
DescriptionThis security update resolves two privately reported vulnerabilities in Windows Media Format. Either vulnerability could allow remote code execution if a user opened a specially crafted media file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
PayloadWwmvcore.dll
Impact Critical

MS09-048Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723)
DescriptionThis security update resolves several privately reported vulnerabilities in Transmission Control Protocol/Internet Protocol (TCP/IP) processing. The vulnerabilities could allow remote code execution if an attacker sent specially crafted TCP/IP packets over the network to a computer with a listening service. Firewall best practices and standard default firewall configurations can help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.
PayloadTcpip.sys, Tcpip6.sys, W03a3409.dll, Ww03a3409.dll
Impact Critical

MS09-049Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution (970710)
DescriptionThis security update resolves a privately reported vulnerability in Wireless LAN AutoConfig Service. The vulnerability could allow remote code execution if a client or server with a wireless network interface enabled receives specially crafted wireless frames. Systems without a wireless card enabled are not at risk from this vulnerability.
PayloadL2sechc.dll, L2sechc.mof, Gatherwirelessinfo.vbs, Gatherwirelessinfo.xslt, eport.system.wireless.xml, Rules.system.wireless.xml, Wireless diagnostics.xml, Wlan.mof, Wlan.tmf, Wlanapi.dll, Wlanhlp.dll, Wlanmsm.dll, Wlansec.dll, Wlansvc.dll
Impact Critical


*All results are based on an AOK Application Compatibility Lab’s test portfolio of over 1,000 applications.

©2009 ChangeBASE Ltd. All Rights Reserved
Website: ID Graphic Design