Home > Bila neagra, Etc, News, Tech, Windows > kb950760 – vulnerability for the Microsoft Speech API

kb950760 – vulnerability for the Microsoft Speech API

Microsoft Security Bulletin MS08-032 – Moderate – Cumulative Security Update of ActiveX Kill Bits (kb950760)

This security update resolves a publicly reported vulnerability for the Microsoft Speech API. The vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer & has the Speech Recognition feature in Windows enabled. Users whose accounts are configured to have fewer user rights on the system could be more less impacted than users who operate with administrative user rights. This update also includes a kill bit for software produced by BackWeb.

The security update is rated Moderate for Microsoft Windows 2000 Service Pack 4; all supported editions of Windows XP; & all editions of the original release version of Windows Vista. However, the kill bit deployment also includes Windows Vista Service Pack 1.

For all other supported versions of Windows, this security update is rated Low. For more information, see the subsection, Affected and Non-Affected Software, in this section. The security update addresses the vulnerability by setting a kill bit so the vulnerable controls do not run in Internet Explorer.

Recommendation: Microsoft recommends that customers consider applying the security update.
Known Issues: No known issues.

microsoft.com – Published: June 10, 2008

  1. No comments yet.
  1. No trackbacks yet.
GoCache - ByREV-Cache v1.0 - live served in : 0.177709 sec (gzip)