Microsoft has released an update for Windows that fixes critical flaws in Exchange Server and Adobe's Macromedia Flash Player
Two security holes could be used by hackers to execute code remotely on a user's PC
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft patches two critical flaws

Exchange Server and Flash player holes plugged

Matt Chapman, vnunet.com 10 May 2006
ADVERTISEMENT

Microsoft has released an update for Windows that fixes critical flaws in Exchange Server and Adobe's Macromedia Flash Player

Both of the security holes could be used by hackers to execute code remotely on a user's PC and take full control.

"An attacker could then install programs, view, change or delete data, or create new accounts with full user rights," said the Microsoft statement accompanying the update.

Monty Ijzerman, senior manager of the Global Threat Group at McAfee's Avert Labs, said: "There are two items of note in this announcement by Microsoft. 

"The vulnerability in Exchange Server poses a serious concern as it does not require any user interaction to be exploited, making the vulnerability a worm candidate."

Ijzerman also said it was "interesting" that Microsoft had issued a patch for vulnerabilities that were previously patched by Adobe.

"This is the first time in recent memory that Microsoft has published a patch for third-party software," he explained.

"In this case, it is probably because the Macromedia patch was not widely deployed and Microsoft's updates will help ensure that its customers are protected."

Tuesday's update also fixes a denial of service vulnerability in Microsoft Distributed Transaction Coordinator (MSDTC).

The problem could be exploited to send a specially crafted network message to an affected system that would stop it responding. Microsoft rated the MSDTC update as 'moderate'.

See also:

Vista's enhanced security could cause some firms to go to the wallDifficult to compete with free bundled offerings from Redmond  10 May 2006
Microsoft dropped something of a bombshell yesterday at the LinuxWorld Conference and ExpoVirtualisation bombshell from Redmond  04 Apr 2006
Website and blog won't give away security flaws  17 Mar 2006
Microsoft has come under fire from the European Commission for failing to meet the obligations laid out in its March 2004 antitrust rulingFailure to disclose complete and accurate interface documentation  12 Mar 2006
Microsoft is emphasising the potential security risks posed by pirated softwarePirated software could hold spyware, vendor cautions  10 Mar 2006

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
Hertfordshire, United Kingdom | Tesco.com
Database Operations Team Leader - Hertfordshire Who's behind the world's most successful online retailer?Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under £1 ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Development Team Leader / IT Specialist - Welwyn Garden City Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers ... more >
London, United Kingdom | BP
Business Analyst - £ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. ... more >
More job opportunities