Microsoft has released their December security bulletins. This release covers 8 bulletins (MS08-070 - MS08-077), 6 of which are rated critical. Vulnerable components include Visual Basic (ActiveX Controls), GDI, Microsoft Word, Internet Explorer, Microsoft Excel, Windows Search, Windows Media Components, and SharePoint. All updates, with the exception of MS08-077 (SharePoint) carry a potential impact of Remote Code Execution.
- Critical
- Systems worldwide are targeted by a worm.
- New malware that potentially can cause damage has been reported and has spread globally.
- Severe
- An unpatched or recently patched vulnerability can be exploited by a worm, and systems worldwide are at risk to be targeted by a particular worm. No worm activity has been identified.
- A high incidence of new malware that potentially can cause damage has been reported.
- Elevated
- An unpatched or recently patched vulnerability is present on many systems worldwide but requires user interaction to be exploited.
- An existing vulnerability becomes more serious because new exploit code has been published.
- There is new malware activity, but it is not widespread.
- Low
- There is no direct threat to systems that have been patched.
- No new significant malware activity has been reported.