Microsoft has released 12 security bulletins that cover a total of 21 security holes in Windows, Exchange and Office
Eight of Microsoft's security bulletins cover issues rated 'critical'
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft plugs 21 software holes

Internet Explorer leads the way with eight security vulnerabilities

Tom Sanders in California, vnunet.com 14 Jun 2006
ADVERTISEMENT

Microsoft has released 12 security bulletins that cover a total of 21 security holes in Windows, Exchange and Office.

Eight of the bulletins cover issues rated 'critical', indicating that an attacker could exploit the flaws to take control of a system without the user's knowledge, but that there are mitigating factors.

Most of the repaired security holes are found in the Internet Explorer browser, which received patches for eight vulnerabilities.

Four of the vulnerabilities could allow attackers to take control of a system through a specially crafted website.

In two cases the application could display a spoofed internet address, which could be exploited by phishing websites to steal confidential information such as user names and passwords for financial websites.

Microsoft's Routing and Remote Access Service is suffering from a flaw that could compromise a system's security.

Attackers could exploit the hole by directly attacking affected systems without users having to visit a specially crafted website or open an email attachment.

But the flawed service is turned off by default, limiting the number of computers that are vulnerable to such an attack.

Microsoft also repaired yet another vulnerability in the way that Windows handles WMF images, as well as the ART image format.

The two vulnerabilities could allow attackers to take control of a system by placing a specially crafted image on a website or sending it as an email attachment.

Microsoft was forced to rush out a patch earlier this year for another WMF flaw after attackers started to successfully exploit an unpatched vulnerability.

The same attack method could be used to exploit a vulnerability in Microsoft's Jscript, a technology similar to JavaScript.

The remaining critical vulnerabilities affect the way that Windows Media Player handles PNG images, which again could allow attackers to take control of a system.

Microsoft finally plugged two critical security holes in Word and PowerPoint. Attackers in both cases could use a specially crafted document to take control of a user's system.

Users can download and install the updates through Windows Update or Microsoft Update services.

Additional details on the critical security bulletins, as well as the three updates rated 'important' and the one 'moderate', are available from the Microsoft TechNet website.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
South West, Darlington, United Kingdom | University College Falmouth
  Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
  The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
Colindale (C1905), United Kingdom | NHS Blood and Transplant
 Operations Engineer, £28,313 - £37,326 pa plus High Cost Area Supplement, Colindale (C1905) About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute 1.6 ... more >
London, United Kingdom | Shell
 Site Systems Integration Manager, London, United Kingdom Shell Downstream encompasses all the activities necessary to transform crude oil into petroleum products and petrochemicals, and deliver them around the world.   Our Downstream businesses refine, supply, ... more >
More job opportunities