Vulnerability scan report

  • Hi i am looking for some feedback regarding these below concerns. Our servers have SQL server 2008 R2 -SP2 enterprise edition

    we received these vulnerabilities when we performaned vulnerability scan.

    1.Microsoft Foundation Class Library Remote Code Execution Vulnerability (MS11-025)

    -- So based on my read of the Security Bulletin this is likely for the Microsoft Visual C++ Redistributable Package (since we don’t install Visual Studio on the servers)

    Does this usually get installed when we install SQL server 2008? can some one clarify and would there be any issues if i remove it from Database server?

    2. Microsoft Windows GDI+ Remote Code Execution Vulnerability (MS09-062)

    Is this a known vulnerability and do i need to patch the DB servers when i get this?

    3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    Is this a SQL server vulnerability? Do i need to patch the server?

  • You have to look at which kind of threats these vulnerabilities are! If it is a local one, normally you would have more problems already as the attacker would need to execute code locally on the system.

    😎

  • 3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    -- This security patch is released on Feb 2012 before of the SQL Server 2008 R2 SP2(june 2012). DO i need to still apply this patch on the server. Does the Service packs include the Security patch releases which are released before to SP?

  • muthyala_51 (6/3/2014)


    3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    -- This security patch is released on Feb 2012 before of the SQL Server 2008 R2 SP2(june 2012). DO i need to still apply this patch on the server. Does the Service packs include the Security patch releases which are released before to SP?

    Recommend that you do if it shows up on the scan, some components may not be up to date.

    😎

  • Eirikur Eiriksson (6/3/2014)


    muthyala_51 (6/3/2014)


    3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    -- This security patch is released on Feb 2012 before of the SQL Server 2008 R2 SP2(june 2012). DO i need to still apply this patch on the server. Does the Service packs include the Security patch releases which are released before to SP?

    Recommend that you do if it shows up on the scan, some components may not be up to date.

    😎

    But if i go for applying this patch- the bulletin does not have anything for my SQL version. They have updates only for SQL 2008 R2 RTM only. PLease see below link.

    https://technet.microsoft.com/en-us/library/security/ms11-049.aspx

  • muthyala_51 (6/3/2014)


    Eirikur Eiriksson (6/3/2014)


    muthyala_51 (6/3/2014)


    3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    -- This security patch is released on Feb 2012 before of the SQL Server 2008 R2 SP2(june 2012). DO i need to still apply this patch on the server. Does the Service packs include the Security patch releases which are released before to SP?

    Recommend that you do if it shows up on the scan, some components may not be up to date.

    😎

    But if i go for applying this patch- the bulletin does not have anything for my SQL version. They have updates only for SQL 2008 R2 RTM only. PLease see below link.

    https://technet.microsoft.com/en-us/library/security/ms11-049.aspx

    Those are not SQL Server version specific issues, check out this MSDN article

    😎

  • Eirikur Eiriksson (6/3/2014)


    muthyala_51 (6/3/2014)


    Eirikur Eiriksson (6/3/2014)


    muthyala_51 (6/3/2014)


    3.Microsoft XML Editor Information Disclosure Vulnerability (MS11-049)

    -- This security patch is released on Feb 2012 before of the SQL Server 2008 R2 SP2(june 2012). DO i need to still apply this patch on the server. Does the Service packs include the Security patch releases which are released before to SP?

    Recommend that you do if it shows up on the scan, some components may not be up to date.

    😎

    But if i go for applying this patch- the bulletin does not have anything for my SQL version. They have updates only for SQL 2008 R2 RTM only. PLease see below link.

    https://technet.microsoft.com/en-us/library/security/ms11-049.aspx

    Those are not SQL Server version specific issues, check out this MSDN article

    😎

    I am confused as in the "applies to" section i dont see for SQL server 2008 R2 SP2. WHen you see closely in applies to section i can see for SQL 2005 SP4 and SQL 2008 SP2, SQL 2008 SP1 etc. but not for SQL server 2008 R2 SP2.

  • These are Windows Server vulnerabilities methinks - these and any other MS security hot-fixes should ALWAYS be applied.

    RegardsRudy KomacsarSenior Database Administrator"Ave Caesar! - Morituri te salutamus."

  • Rudyx - the Doctor (6/4/2014)


    These are Windows Server vulnerabilities methinks - these and any other MS security hot-fixes should ALWAYS be applied.

    It is an OS scope threat, as I said before, not SQL Server version specific!

    Cannot assert the scan but if such issues shows up, do fix them.

    😎

Viewing 9 posts - 1 through 8 (of 8 total)

You must be logged in to reply to this topic. Login to reply