R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft update brings critical patches

Five applications plugged as part of April's Patch Tuesday

Tom Sanders in California, vnunet.com 12 Apr 2006
ADVERTISEMENT

Microsoft, as part of its monthly patch release for April, has released a security update to address vulnerabilities in Windows and Office.

The software vendor rated updates for Internet Explorer, Windows Explorer and the Microsoft Data Access Components (MDAC) Function as "critical" because they could allow an attacker to execute arbitrary code on a user's system.

The MDAC vulnerability exists as part of Microsoft's ActiveX technology. An attacker could use the security hole through a specially crafted website to take over control of a system without any user interaction, Microsoft said in a security bulletin on its website.

Attackers could exploit the flaw in Windows Explorer again by persuading users to visit a specially crafted website. Microsoft warned that the site could force the system to connect to a remote file server, which could then cause Windows Explorer to fail in a way that allows an attacker to execute code. 

The Internet Explorer patch addresses a total of ten vulnerabilities with severity ratings ranging from critical to moderate. As expected, the update includes a fix for a previously disclosed vulnerability in the createTextRange call which is actively being exploited. It also repairs two other vulnerabilities that were disclosed earlier this month.

April's patch furthermore delivers a fix for Outlook Express. A vulnerability in the email and personal information client could allow attackers to take over control of a system. Because the bug requires user interaction to be exploited, it received a severity rating of "important".

The fifth patch addresses a vulnerability in Front Page that could allow for a cross site scripting attack.

See also:

Software vendor accidentally discloses details about database flaw  12 Apr 2006
Microsoft plans to publicly release an update to its ActiveX technologyDevelopers urged to test applications to prevent outages  31 Mar 2006
The malware opens a backdoor on the system and attempts to lower the security settingsZero day attack hits the web  24 Mar 2006
Critical flaw in Sendmail's could give hackers full access to affected networksPatch immediately or get hacked, warns security expert  23 Mar 2006
Spikesource aims to improve application support  17 Mar 2006

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 397874 IP Network Administrator Location - Reading Job Description: There is a requirement for an IP network administrator to join the Infrastructure Services operational support team to manage the movement of network resources, ... more >
Telford, Shropshire, United Kingdom | EDS
EDS are currently looking to recruit a PMO Support Analyst to join our Project Management Defence team in Telford, Shropshire. Summary: Within DII Service Management. To perform the PMO function for SM Service Introduction. This ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >
London, Haringey, United Kingdom | Haringey Council
PMO Support Officer - Haringey, London - £32,289 - £37,542 pa   Experienced project support officer required by the internal IT services organisation of a London borough council to work within its Programme Management Office ... more >
More job opportunities