Site Statistics
 
Threads: 3,718
Posts: 16,702
Members: 2,844
Users Online: 10
Newest Member: Boydaysop


Go Back   PC101 > PC Software > PC Security

PC Security Stop Spyware, Hackers and Identity thieves. Info re: Viruses, trojans, removal, etc...

Reply
 
LinkBack Thread Tools Display Modes
Old 06-13-2006, 07:04 PM   #1
OulZac
Senior Member
 
OulZac's Avatar
 
Join Date: Apr 2006
Location: Wilbur
Posts: 346
Rep Power: 3 OulZac is on a distinguished road
Microsoft plugs 21 security holes

Just so everyone knows:

By Dawn Kawamoto
Staff Writer, CNET News.com
Published: June 13, 2006, 1:37 PM PDT


Microsoft has issued patches for 21 flaws in its software, saying all but two of them could let an intruder run malicious code on a compromised computer.

The company sent out a dozen security bulletins on Tuesday as part of its regular monthly patch cycle. Eight of the bulletins are labeled "critical," which is Microsoft's highest risk rating. They cover problems with Windows, Internet Explorer, Word, PowerPoint and Exchange Server.

The number of vulnerabilities mean this is Microsoft's largest clutch of patches to date, security experts said.

"There has never been a Microsoft security update to address 21 issues and never one with 19 potential remote execution flaws," said Amol Sarwate, the manager of the Vulnerability Management Lab at flaw management specialist Qualys.

The most important bulletin, MS06-025, is a fix for routing and remote access vulnerabilities in Windows, said Jonathan Bitle, a senior product manager at Qualys.

"These (vulnerabilities) take advantage of two listening services that run on the host and listen for traffic coming in through ports that are frequently utilized," Bitle said. "While a lot of these (other Microsoft) remote execution flaws require interaction (by the user), this one does not. A user doesn't have to click on a link or open an attachment."

The routing and remote access are deemed critical for systems running Windows 2000, and "important"--the second risk ranking--for Windows XP with Service Pack 1 or 2, and for Windows Server 2003 with Service Pack 1.

Qualys is also suggesting that IT managers should jump on another patch, for an issue in Microsoft Exchange Server running Outlook Web Access (MS06-029), even though Microsoft has tagged it only as important.

"If a user checks their e-mail using Outlook Web Access, all they need to do is just open an e-mail in IE and it will cause the script in their e-mail to be remotely executed," Sarwate said.

Over the next days and weeks, IT administrators should be busy deploying the bundle of patches across their network, experts said.

"There are a couple different vulnerabilities. Some are IE browser problems, some affect the Media Player, ART imaging and JScript," said Chris Andrew, vice president of security technologies at PatchLink. "IT managers will probably have to patch every single desktop."

Four of the critical updates deal with security holes that could allow remote code execution in all versions of Windows. One is a cumulative update for the Internet Explorer component (MS06-021), affecting versions 5.01 and 6 of the Web browser. Another (MS06-024) deals with a problem with Windows Media Player, versions 7.1, 9 and 10. The others cover vulnerabilities in Microsoft Jscript (MS06-023) and ART image rendering (MS06-022)

Another critical Windows bulletin, related to bugs in its graphics rendering engine (MS06-026) affects Windows 98, Windows 98 Second Edition (SE) and Windows Millennium Edition (ME) only.

Two updates affecting Office were also given the highest risk rating. A vulnerability in Word (MS06-027) also hits Microsoft Works. The bulletin for a flaw in PowerPoint (MS06-028) replaces an earlier patch.

Microsoft also issued a fix for an important flaw in Windows' Server Message Block (SMB) component (MS06-030) that could enable attackers to elevate their level of system privileges. The "moderate" bulletins covered an RPC Mutual Authentication (MS06-031) problem and a TCP/IP problem (MS06-032) in Windows.
__________________
In the beginning, the Universe was created. This made a lot of people angry, and has been widely regarded as a bad idea.

IPreport.info - Showing people there IP for no apparent reason!
OulZac is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-13-2006, 11:04 PM   #2
Ronin
Junior Member
 
Ronin's Avatar
 
Join Date: May 2006
Posts: 17
Rep Power: 0 Ronin is on a distinguished road
I just got this update notification this morning I believe. I dont think it was a fix for 21 holes though, I only saw around 10 updates.

I wonder if these updates will cause anymore holes to show up?
Ronin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-18-2006, 08:27 PM   #3
McDaddy
Senior Member
 
McDaddy's Avatar
 
Join Date: Nov 2005
Location: Texas
Posts: 179
Rep Power: 3 McDaddy is on a distinguished road
a hole for a hole

there will alwase be holes, they will never be compleetly fixed or eliminated. just as soon as old ones are fixed, someone new will find 2 new ones.
McDaddy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-08-2006, 01:22 AM   #4
Vibrumzut
Junior Member
 
Join Date: Aug 2006
Location: USA
Posts: 1
Rep Power: 0 Vibrumzut is on a distinguished road
Too early...
Vibrumzut is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-08-2006, 01:29 AM   #5
Lyte
Forum Staff
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,035
Rep Power: 6 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Too early? Please explain.
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-08-2006, 01:18 PM   #6
OulZac
Senior Member
 
OulZac's Avatar
 
Join Date: Apr 2006
Location: Wilbur
Posts: 346
Rep Power: 3 OulZac is on a distinguished road
Quote:
Originally Posted by Vibrumzut
Too early...
its not late, no, its early
__________________
In the beginning, the Universe was created. This made a lot of people angry, and has been widely regarded as a bad idea.

IPreport.info - Showing people there IP for no apparent reason!
OulZac is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft to kick off 2007 with 8 security patches Lyte PC Security 0 01-04-2007 06:35 PM
Microsoft Dares Security Experts to Find Holes in Windows Vista Will.Spencer Windows Vista, XP, 2000, 98, etc... 3 08-09-2006 09:07 PM
Microsoft confirms Office 12 will be Office 2007 aleeonline Graphic/Utility/Business Software 3 05-16-2006 12:37 AM
Microsoft releases Office 12 beta 1 to testers aleeonline Graphic/Utility/Business Software 0 04-17-2006 02:25 PM
"Why Windows Vista Won't Suck" Lyte News, events, alerts and more! 1 03-12-2006 02:35 PM



Flex Development


Our partners:



All times are GMT -5. The time now is 10:12 PM.

Powered by vBulletin Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
Design by vBSkinworks

Copyright © PC101 and PC101.com Computer Forum. All rights reserved.