On mySimon: Rite-Lite Super Bright LED Puck Lights
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Jan 11, 2005 11:21:00 PM

Microsoft on Tuesday released two critical patches for its Windows operating system, but a patch for the underlying security problems with Internet Explorer 6 is not yet ready for prime time.

As part of its monthly update release, the company issued three patches--one rated important and two critical. That announcement reflects a more active month than December, when the software giant issued no critical patches for the period.

"Even though we did not rate any patches critical in December, the two we have in January are not indicative of a year more of this type of situation," said Stephen Toulouse, a Microsoft security program manager.

One critical patch is designed to resolve the security issues surrounding the HTML Help ActiveX control in Windows. Security experts had warned Microsoft about this problem and were pushing the vendor to take quick action, given that an exploit for the vulnerability existed.

The patch addresses the potential problem of attackers taking complete control over an affected system, such as placing and executing programs like spyware and pornography dialers without the users' knowledge.

The second critical patch addresses vulnerabilities in systems from Windows NT servers to Windows XP involving the cursor and icon format handling. Attackers could exploit the vulnerabilities by creating a specially crafted Web page that would have malware.

"These first two patches address vulnerabilities that have proven exploits, and the third has the potential (for an exploit)," said Jimmy Kuo, a McAfee research fellow.

Microsoft also issued a third patch for Windows indexing service, with the threat level rated as important but not critical. That's because the indexing component is turned off by default, making it more difficult for an attacker to access index contents in Windows Media, for example, Toulouse said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 17 Talkback(s)
Spyware
I agree completely, these Spyware programs are great for security but for the consumer, we are not tech support . Since some of these programs have been installed in our computer and others, PROBLEMS,... (Read the rest)
Posted by: PMHMOM02 Posted on: 01/13/05 You are currently: a Guest | | Terms of Use
Nice to see MS announced something today too  tic swayback | 01/11/05
Well, if you want to reverse their fortunes  FilledOut | 01/11/05
Heart monitor?  Roger Ramjet | 01/12/05
It would seem that they are not alone.  ShadeTree | 01/13/05
Like anyone would trust IE  Suicida| | 01/11/05
Please fix the drive-by Spyware Installs!  BitTwiddler | 01/12/05
Its EASY to stop  Roger Ramjet | 01/12/05
Spyware  PMHMOM02 | 01/13/05
Firefox/ IE Analogy  itanalyst | 01/12/05
Hey I saw that guy!  Roger Ramjet | 01/12/05
what kind of car?  linuxoverwindows | 01/12/05
Airbag musta rattled my brain.....  Dave F_z | 01/12/05
ROFLMAO!  Suicida| | 01/12/05
Remarkable Craftsmanship  michael-t | 01/12/05
10.0, great job!  NonZealot | 01/12/05
Good one  rapson | 01/12/05
It's called "Integration"  George Jay | 01/12/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More