On The Insider: Mamma Mia NYC Premier
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Apr 11, 2006 8:19:00 PM

Microsoft on Tuesday released a "critical" Internet Explorer update that fixes 10 vulnerabilities in the Web browser, including a high-profile bug that is already being used in cyberattacks.

The Redmond, Wash., software giant sent out the IE megafix as part of its monthly Patch Tuesday cycle of bulletins. In addition, Microsoft delivered two bulletins for "critical" Windows flaws, one for an "important" vulnerability in Outlook Express and one for a "moderate" bug in a component of FrontPage and SharePoint.

"This patch release is a big one with lots of aftershocks," said Jonathan Bitle, a product manager at security company Qualys. "Three of the five updates, the IE and Windows updates, are especially critical as they take advantage of inexperienced users...Although a worm epidemic is unlikely, users can be easily enticed to visit malicious Web pages."

Eight of the 10 vulnerabilities repaired by the IE update could be abused to gain complete control over a Windows computer running vulnerable versions of the Web browser. In all instances, an attacker would have to create a malicious Web site and trick people into visiting that site to hook into a PC, Microsoft said in its Security Bulletin MS06-013.

Microsoft rates its browser update "critical" for IE 5 and IE 6, the most-used versions of the popular software. IE is vulnerable on all current versions of the Windows operating system--Windows 2000, Windows XP and Windows Server 2003--as well as on the older Windows 98 and Windows Millennium Edition, the company said.

"An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system," Microsoft said in its alert. "We recommend that customers apply the update immediately." Windows users who have automatic updates enabled for the operating system will have the fixes delivered to them.

Microsoft had been under pressure to rush the IE patch out before Tuesday because miscreants were already exploiting one of the flaws. Third parties had even provided temporary fixes for this "CreateTextRange" bug, which experts said was being used by malicious Web sites to try to drop code such as spyware on vulnerable PCs.

According to Microsoft's bulletin, three of the 10 vulnerabilities fixed by the update had been publicly disclosed. Only the CreateTextRange flaw was being exploited in attacks, the software maker said.

But Symantec has information that three of the flaws were already being exploited in attacks prior to Microsoft's patch release. More attacks are likely to follow, Oliver Friedrichs, a director at Symantec Security Response, said in a statement. "According to the latest Symantec Internet Security Threat Report, the average time between the release of a security patch and the development of an exploit is six days," he said.

Holes in Windows
In a double-whammy for Windows users, all versions of the operating system vulnerable to the IE problems are also affected by two other "critical" flaws, Microsoft said. These holes could also allow an intruder to commandeer a PC. One is related to a specific ActiveX control, a kind of Web program, (MS06-014), and the other deals with a bug in Windows Explorer (MS06-015).

In these cases also, an intruder would have to build a special Web page to take advantage of the security hole. Some of the vulnerabilities in Windows and IE could also be exploited using an HTML e-mail, which essentially is a Web page sent in an e-mail message.

Users of Outlook Express face an additional security risk, in that the e-mail application is flawed in the way it handles Windows Address Book files. Opening a specially crafted WAB file can result in execution of malicious code, giving an attacker control of the Windows PC, Microsoft said in Security Bulletin MS06-016.

The Windows bugs as well as the Outlook Express flaw were reported privately to Microsoft and have not been used in any attacks, the company said.

The last of the five security alerts issued by Microsoft, MS06-017, affects the lowest number of users and is deemed a "moderate" risk. The cross-site scripting flaw in FrontPage Web site building software and SharePoint collaboration software could lead to a system compromise, the company said.

Eolas tweaks
The IE update, in addition to security fixes, makes a change to the way IE handles ActiveX controls. These tweaks are a response to a long-running patent dispute between Microsoft and Eolas Technologies, a start-up backed by the University of California. The changes can affect how certain sites display in the browser.

People who need more time to adjust to the ActiveX changes can download a special patch that will disable them for two months. This "compatibility patch" is specifically designed for businesses that may have homegrown applications that use ActiveX, Microsoft has said.

  • Talkback
  • Most Recent of 156 Talkback(s)
Shill!
I think that you are Loverrock! (Read the rest)
Posted by: Reverend MacFellow Posted on: 05/05/06 You are currently: Logged In | Log out
Oh, the irony baggins_z   | 04/11/06
'Critical' megapatch sews up 10 holes in IE Loverock Davidson   | 04/11/06
Huh? yyuko@...   | 04/11/06
Huh? Loverock Davidson   | 04/11/06
DON'T EVEN BOTHER lampdeveloper   | 04/12/06
RE: Huh? richdave   | 04/11/06
Please forgive LoverBoy because he djc1309@...   | 04/17/06
When you GET A CLUE!!!..come back and tell me NT mdsmedia   | 04/11/06
In that case I never had to leave (NT) Loverock Davidson   | 04/11/06
RE: In that case I never had to leave (NT) richdave   | 04/11/06
Here we go again Shelendrea   | 04/11/06
Thank you, Shel! Tony Agudo   | 04/11/06
Could you be any more wrong? Loverock Davidson   | 04/11/06
The problem is these were reported ages ago maldain   | 04/11/06
best spin ever! Scott W   | 04/12/06
On time was too late... jasonp@...   | 04/12/06
NASA isn't a wise choice.. viking2007@...   | 04/12/06
YOU put a sock in it... viking2007@...   | 04/12/06
Message has been deleted. Can you hear me   | 04/11/06
Bwahahaha!! Spicoli's Avenger   | 04/11/06
You are so sad and pathetic. Sxooter_z   | 04/11/06
That old fool (LoverFUD) is retired and has nothing better to do . Can you hear me   | 04/11/06
Are you sure viking2007@...   | 04/12/06
Another with a reading comprehension problem Loverock Davidson   | 04/11/06
RE: Another with a reading comprehension problem richdave   | 04/11/06
Yeah, what did you mean? Sxooter_z   | 04/11/06
loving M$ oregonnerd13   | 04/11/06
The true identity of loverock is now known RUlistening   | 04/11/06
The true identity of loverock (AKA loveFUD Flamerson) is now known DangDaCommonCentz   | 04/12/06
Pres. Bush's press secretary ;) RUlistening   | 04/12/06
your linux reference Scott W   | 04/12/06
Another MORON ALERT From Loverock Microshillslayer   | 04/12/06
yippee 10 more patches to download zmud   | 04/12/06
Too little, too late. Mr. Roboto   | 04/11/06
HA HA Funny ibabadur1   | 04/11/06
Links please! NonZealot   | 04/12/06
Here's the difference Chad_z   | 04/11/06
Yeah, but vista takes it to the next level george_ou   | 04/11/06
It's about time... woot!   | 04/11/06
Yeah they're late, but they're making it even better george_ou   | 04/11/06
George, stop drinking the kool aid! Sxooter_z   | 04/11/06
RE: George, stop drinking the kool aid! richdave   | 04/11/06
brief comments oregonnerd13   | 04/11/06
Do you know anything about Windows? NonZealot   | 04/12/06
Yes I do! Linux User 147560   | 04/12/06
Shill! Reverend MacFellow   | 05/05/06
Yeah but Vista is not here yet!! mdsmedia   | 04/11/06
I have used the beta, JoeMama_z   | 04/11/06
I have no doubt... mdsmedia   | 04/11/06
neither? JoeMama_z   | 04/11/06
Ahh...But Vista is still a year away WiredGuy   | 04/11/06
Vista. Pff notcomingback   | 04/11/06
here is what is innovative..... JoeMama_z   | 04/11/06
No but... Cardinal_Bill   | 04/11/06
Security? viking2007@...   | 04/12/06
George, Vista will take it to the next level........ Can you hear me   | 04/11/06
Wow! That's impressive Sxooter_z   | 04/11/06
George... Cardinal_Bill   | 04/11/06
George??? axe's worst nightmare   | 04/13/06
Yeah, but vista takes it to the next level... handydan918   | 04/11/06
already possible on linux Scott W   | 04/12/06
Again... Plain and simple "Theories" ju1ce   | 04/12/06
So we're supposed to forget about the last 10 years? Chad_z   | 04/12/06
come on be honest.... JoeMama_z   | 04/11/06
Obviously not a unix user Sxooter_z   | 04/11/06
obviously you cant read... JoeMama_z   | 04/11/06
Show me. Sxooter_z   | 04/11/06
kernel 2.6.16 Sxooter_z   | 04/11/06
Who cares? JoeMama_z   | 04/11/06
Who cares? Sxooter_z   | 04/11/06
Argued like a true fan boy..... JoeMama_z   | 04/11/06
to jomommy IceTheNet@...   | 04/11/06
Fanboy? Pot, meet Kettle. Sxooter_z   | 04/12/06
to quote you... Sxooter_z   | 04/12/06
Talk about noise.. viking2007@...   | 04/12/06
Hmmm, interesting bug reports however maldain   | 04/11/06
wrong a right @ the same time.... JoeMama_z   | 04/11/06
You should actually learn about linux before talking IceTheNet@...   | 04/11/06
Speaking of stupid... viking2007@...   | 04/12/06
stupid users Scott W   | 04/12/06
Local vs remote exploit barsteward   | 04/12/06
The concept you're looking for Yagotta B. Kidding   | 04/11/06
depends on your definition of single point of failure is.... JoeMama_z   | 04/11/06
clutching at straws Sam? mdsmedia   | 04/11/06
not particularly.... JoeMama_z   | 04/11/06
I'm still not sure how you get your 2... mdsmedia   | 04/11/06
my bad ..."know" not "no". nt mdsmedia   | 04/11/06
just so you understand IceTheNet@...   | 04/11/06
the answer is yes Scott W   | 04/12/06
yes, yes it is much harder Sxooter_z   | 04/12/06
Patch chris.gordon   | 04/11/06
Vista, next level... Media Whore   | 04/11/06
name of the game? viking2007@...   | 04/12/06
Survey... Sxooter_z   | 04/11/06
ONLY 14,758,921,346,065,321,987,456,555,001 more Bugs left to fix realitycheck101   | 04/11/06
PPL who use the term MICROSUCKS are an embarrassment to the computing world Code Poet   | 04/11/06
Sorry About Your Luck with MICROSUCKS Not IceTheNet@...   | 04/11/06
Huh? Code Poet   | 04/12/06
MICROSUCKSMICROSUCKSMICROSUCKSMICROSUCKS Microshillslayer   | 04/12/06
You have issues.... Code Poet   | 04/12/06
But what will the new round of patches destroy ? josephrot   | 04/11/06
Windows XP SP1 user IceTheNet@...   | 04/11/06
Software Giants, Patch Giants, michael_t   | 04/11/06
Please enjoy your bordom Code Poet   | 04/11/06
Super Mega Patch released "Privately" get it here: IceTheNet@...   | 04/11/06
MS vs raid bombardj1   | 04/11/06
JUST WONDERING... lampdeveloper   | 04/12/06
Wait... not for the updates, just to consider what's been said. jharshey   | 04/12/06
Wow... viking2007@...   | 04/12/06
Yawn! tslocum7   | 04/12/06
more hacks more hardware sales galv9506   | 04/12/06
Thats 44 updates after service pack 2 zmud   | 04/12/06
Please wusses ilikeit   | 04/12/06
Move along folkes, nothing to see here ############# SouthernPride   | 04/12/06
Would you like some cheese with that whine? B.O.F.H.   | 04/12/06
No cheese needed! SouthernPride   | 04/12/06
What you talking about Willis? Rick_K   | 04/12/06
Active X SouthernPride   | 04/12/06
good old sun java LOL bombardj1   | 04/12/06
Sun Java SouthernPride   | 04/12/06
eh? barsteward   | 04/12/06
RE SouthernPride   | 04/12/06
not a hitch golowenow   | 04/13/06
Is there a middle ground? xilord@...   | 04/12/06
Middle Ground SouthernPride   | 04/12/06
No, it wouldn't Sxooter_z   | 04/12/06
Good luck viking2007@...   | 04/12/06
Middle ground xilord@...   | 04/12/06
2nd example of proving barsteward   | 04/12/06
My point provent SouthernPride   | 04/12/06
InDeed there is middle ground benrob   | 04/12/06
YES!!!! viking2007@...   | 04/12/06
George...Maybe you can help.... DeeAitch   | 04/12/06
I can help... benrob   | 04/12/06
Hey benrob... DeeAitch   | 04/12/06
Precisely my point... benrob   | 04/12/06
Precisely Your Point? DeeAitch   | 04/12/06
Gotcha! DeeAitch   | 04/12/06
Oh Sure... viking2007@...   | 04/12/06
Sorry DeeAitch   | 04/15/06
Likely Problem with 4/11 Microsoft Security Patches unravlr   | 04/12/06
Thank god - I'm not insane goddessjuliette   | 04/12/06
Well, it's not the first time... Tony Agudo   | 04/12/06
Likely solution Joed_M   | 04/15/06
Megapatch sews up buy another computer! Robert Himes   | 04/12/06
Updates Lock Windows Explorer randys@...   | 04/12/06
Just a minute here... marbing@...   | 04/12/06
Problems..none... benrob   | 04/13/06
"Folders" Explore panel broken in Win Explorer evano   | 04/12/06
Likely solution Joed_M   | 04/15/06
Megapatch, was he a Transformer Boot_Agnostic   | 04/13/06
Annoying! Arnie Vios   | 04/13/06
How can they "fix" it before it's created? marymo   | 04/13/06
Unfortunately ... Arnie Vios   | 04/13/06
Geek, when you sour the code after a long day's double agenting Boot_Agnostic   | 04/14/06
Microsoft Finally Confirms Some Conflicts!! unravlr   | 04/18/06

What do you think?

advertisement
advertisement

The Green Enterprise