Feeds

One, two, three, four MS patches at our door

Monthly fix number two

  • alert
  • submit to reddit

Build a business case: developing custom apps

Microsoft yesterday released a set of four security patches in its second stab at releasing security fixes once a month.

A cumulative patch for Internet Explorer, a fix for a buffer overflow vulnerability in components of Microsoft's FrontPage Server and a patch for a flaw with Workstation Service that could crackers to inject code on vulnerable systems are all deemed critical by Redmond. A fix for a flaw in Microsoft Word and that could allow arbitrary Code to run is given the lower category of "important".

A buffer overflow vulnerability in the Microsoft Workstation service represents the most serious risk. Workstation service is responsible for handling remote connections between computers and network resources such as fileservers or networked printers and is enabled by default on vulnerable platforms (windows 2000 - SP2 and later - and XP).

Security tools vendor ISS warns that "vulnerability is a standard stack overflow, and therefore it may be relatively easy to exploit".

"Exploits written to take advantage of standard stack overflows are generally very robust, and are good candidates for use in the creation of Internet worms," it warns.

According to Network Associates, the vulns covered by the four patches "range in scope from allowing arbitrary code to be run on a users machine (all of them)... to a buffer overrun vulnerability in FrontPage Server Extension and another vulnerability in the SmartHTML Interpreter could lead to denial of service on the server running FrontPage Extension."

All the more reason then to apply Microsoft's security fixes, a summary of which can be found here and here. ®

Related Stories

MS shores up five critical security holes
Ballmer's new MS security fix - same patches, but 'nicer'
Beefed-up firewall, new version of Update for XP SP2
Microsoft shoots the Windows Messenger

Next gen security for virtualised datacentres

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Scale data protection with your virtual environment
To scale at the rate of virtualization growth, data protection solutions need to adopt new capabilities and simplify current features.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?