Microsoft posts April 2009 security updates

Nice and regular-like... As part of Microsoft’s commitment to deliver security updates on a predictable and consistent monthly schedule, Microsoft released eight security bulletins today, which addressed 23 vulnerabilities in Windows, Microsoft Office, Internet Explorer and Microsoft Internet Security and Acceleration Server. Microsoft’s April Bulletin Release MS09-009 (Maximum severity of Critical): This update resolves a newly discovered, privately reported and a publicly disclosed vulnerability in Microsoft Excel. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index. MS09-010 (Maximum severity of Critical): This update resolves two publicly disclosed vulnerabilities and two privately reported vulnerabilities in Microsoft WordPad and Microsoft Office Text Converters.  This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index. MS09-011 (Maximum severity of Critical): This update resolves a newly discovered and privately reported vulnerability in Microsoft DirectX. This update received a 2 – Inconsistent Exploit Code Likely rating from Microsoft’s Exploitability Index. MS09-012 (Maximum severity of Important): This update resolves four publicly disclosed vulnerabilities in Microsoft Windows. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index. MS09-013 (Maximum severity of Critical): This update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft Windows HTTP Services (WinHTTP). This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index. MS09-014 (Maximum severity of Critical): This update resolves four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploit

Paul Thurrott

April 14, 2009

2 Min Read
ITPro Today logo

Nice and regular-like...

As part of Microsoft’s commitment to deliver security updates on a predictable and consistent monthly schedule, Microsoft released eight security bulletins today, which addressed 23 vulnerabilities in Windows, Microsoft Office, Internet Explorer and Microsoft Internet Security and Acceleration Server.

Microsoft’s April Bulletin Release

  • MS09-009 (Maximum severity of Critical): This update resolves a newly discovered, privately reported and a publicly disclosed vulnerability in Microsoft Excel. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-010 (Maximum severity of Critical): This update resolves two publicly disclosed vulnerabilities and two privately reported vulnerabilities in Microsoft WordPad and Microsoft Office Text Converters.  This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-011 (Maximum severity of Critical): This update resolves a newly discovered and privately reported vulnerability in Microsoft DirectX. This update received a 2 – Inconsistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-012 (Maximum severity of Important): This update resolves four publicly disclosed vulnerabilities in Microsoft Windows. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-013 (Maximum severity of Critical): This update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft Windows HTTP Services (WinHTTP). This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-014 (Maximum severity of Critical): This update resolves four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. This update received a 1 – Consistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-015 (Maximum severity of Moderate): This update resolves one publicly disclosed vulnerability in the Windows SearchPath function. This update received a 2 – Inconsistent Exploit Code Likely rating from Microsoft’s Exploitability Index.

  • MS09-016 (Maximum severity of Important): This update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Internet Security and Acceleration (ISA) Server and Microsoft Forefront Threat Management Gateway (TMG), Medium Business Edition (MBE). This update received a 3 – Functioning Exploit Code Unlikely rating from Microsoft’s Exploitability Index.

Comprehensive bulletin information is also available at Microsoft’s Security Update Archive. Also, Microsoft recommends that all customers sign up for Microsoft Update and enable its Automatic Updates functionality. This will enable customers to receive all updates available this month and help make their systems more secure.

Read more about:

Microsoft

About the Author(s)

Paul Thurrott

Paul Thurrott is senior technical analyst for Windows IT Pro. He writes the SuperSite for Windows, a weekly editorial for Windows IT Pro UPDATE, and a daily Windows news and information newsletter called WinInfo Daily UPDATE.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like