On CBSSports.com: Mike Tyson's daughter dies in accident
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Apr 11, 2006 8:19:00 PM

Microsoft on Tuesday released a "critical" Internet Explorer update that fixes 10 vulnerabilities in the Web browser, including a high-profile bug that is already being used in cyberattacks.

The Redmond, Wash., software giant sent out the IE megafix as part of its monthly Patch Tuesday cycle of bulletins. In addition, Microsoft delivered two bulletins for "critical" Windows flaws, one for an "important" vulnerability in Outlook Express and one for a "moderate" bug in a component of FrontPage and SharePoint.

"This patch release is a big one with lots of aftershocks," said Jonathan Bitle, a product manager at security company Qualys. "Three of the five updates, the IE and Windows updates, are especially critical as they take advantage of inexperienced users...Although a worm epidemic is unlikely, users can be easily enticed to visit malicious Web pages."

Eight of the 10 vulnerabilities repaired by the IE update could be abused to gain complete control over a Windows computer running vulnerable versions of the Web browser. In all instances, an attacker would have to create a malicious Web site and trick people into visiting that site to hook into a PC, Microsoft said in its Security Bulletin MS06-013.

Microsoft rates its browser update "critical" for IE 5 and IE 6, the most-used versions of the popular software. IE is vulnerable on all current versions of the Windows operating system--Windows 2000, Windows XP and Windows Server 2003--as well as on the older Windows 98 and Windows Millennium Edition, the company said.

"An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system," Microsoft said in its alert. "We recommend that customers apply the update immediately." Windows users who have automatic updates enabled for the operating system will have the fixes delivered to them.

Microsoft had been under pressure to rush the IE patch out before Tuesday because miscreants were already exploiting one of the flaws. Third parties had even provided temporary fixes for this "CreateTextRange" bug, which experts said was being used by malicious Web sites to try to drop code such as spyware on vulnerable PCs.

According to Microsoft's bulletin, three of the 10 vulnerabilities fixed by the update had been publicly disclosed. Only the CreateTextRange flaw was being exploited in attacks, the software maker said.

But Symantec has information that three of the flaws were already being exploited in attacks prior to Microsoft's patch release. More attacks are likely to follow, Oliver Friedrichs, a director at Symantec Security Response, said in a statement. "According to the latest Symantec Internet Security Threat Report, the average time between the release of a security patch and the development of an exploit is six days," he said.

Holes in Windows
In a double-whammy for Windows users, all versions of the operating system vulnerable to the IE problems are also affected by two other "critical" flaws, Microsoft said. These holes could also allow an intruder to commandeer a PC. One is related to a specific ActiveX control, a kind of Web program, (MS06-014), and the other deals with a bug in Windows Explorer (MS06-015).

In these cases also, an intruder would have to build a special Web page to take advantage of the security hole. Some of the vulnerabilities in Windows and IE could also be exploited using an HTML e-mail, which essentially is a Web page sent in an e-mail message.

Users of Outlook Express face an additional security risk, in that the e-mail application is flawed in the way it handles Windows Address Book files. Opening a specially crafted WAB file can result in execution of malicious code, giving an attacker control of the Windows PC, Microsoft said in Security Bulletin MS06-016.

The Windows bugs as well as the Outlook Express flaw were reported privately to Microsoft and have not been used in any attacks, the company said.

The last of the five security alerts issued by Microsoft, MS06-017, affects the lowest number of users and is deemed a "moderate" risk. The cross-site scripting flaw in FrontPage Web site building software and SharePoint collaboration software could lead to a system compromise, the company said.

Eolas tweaks
The IE update, in addition to security fixes, makes a change to the way IE handles ActiveX controls. These tweaks are a response to a long-running patent dispute between Microsoft and Eolas Technologies, a start-up backed by the University of California. The changes can affect how certain sites display in the browser.

People who need more time to adjust to the ActiveX changes can download a special patch that will disable them for two months. This "compatibility patch" is specifically designed for businesses that may have homegrown applications that use ActiveX, Microsoft has said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 156 Talkback(s)
Shill!
I think that you are Loverrock! (Read the rest)
Posted by: Reverend MacFellow Posted on: 05/05/06 You are currently: a Guest | | Terms of Use
Oh, the irony  baggins_z | 04/11/06
'Critical' megapatch sews up 10 holes in IE  Loverock Davidson | 04/11/06
Huh?  yyuko@... | 04/11/06
Huh?  Loverock Davidson | 04/11/06
DON'T EVEN BOTHER  lampdeveloper | 04/12/06
RE: Huh?  richdave | 04/11/06
Please forgive LoverBoy because he  djc1309@... | 04/17/06
When you GET A CLUE!!!..come back and tell me NT  mdsmedia | 04/11/06
In that case I never had to leave (NT)  Loverock Davidson | 04/11/06
RE: In that case I never had to leave (NT)  richdave | 04/11/06
Here we go again  Shelendrea | 04/11/06
Thank you, Shel!  Tony Agudo | 04/11/06
Could you be any more wrong?  Loverock Davidson | 04/11/06
The problem is these were reported ages ago  maldain | 04/11/06
best spin ever!  Scott W | 04/12/06
On time was too late...  jasonp@... | 04/12/06
NASA isn't a wise choice..  viking2007@... | 04/12/06
YOU put a sock in it...  viking2007@... | 04/12/06
Message has been deleted.  Can you hear me | 04/11/06
Bwahahaha!!  Spicoli's Avenger | 04/11/06
You are so sad and pathetic.  Sxooter_z | 04/11/06
That old fool (LoverFUD) is retired and has nothing better to do .  Can you hear me | 04/11/06
Are you sure  viking2007@... | 04/12/06
Another with a reading comprehension problem  Loverock Davidson | 04/11/06
RE: Another with a reading comprehension problem  richdave | 04/11/06
Yeah, what did you mean?  Sxooter_z | 04/11/06
loving M$  oregonnerd13 | 04/11/06
The true identity of loverock is now known  sykandtyed | 04/11/06
The true identity of loverock (AKA loveFUD Flamerson) is now known  DangDaCommonCentz | 04/12/06
Pres. Bush's press secretary wink  sykandtyed | 04/12/06
your linux reference  Scott W | 04/12/06
Another MORON ALERT From Loverock  Microshillslayer | 04/12/06
yippee 10 more patches to download  zmud | 04/12/06
Too little, too late.  Mr. Roboto | 04/11/06
HA HA Funny  ibabadur1 | 04/11/06
Links please!  NonZealot | 04/12/06
Here's the difference  Chad_z | 04/11/06
Yeah, but vista takes it to the next level  george_ou | 04/11/06
It's about time...  woot! | 04/11/06
Yeah they're late, but they're making it even better  george_ou | 04/11/06
George, stop drinking the kool aid!  Sxooter_z | 04/11/06
RE: George, stop drinking the kool aid!  richdave | 04/11/06
brief comments  oregonnerd13 | 04/11/06
Do you know anything about Windows?  NonZealot | 04/12/06
Yes I do!  Linux User 147560 | 04/12/06
Shill!  Reverend MacFellow | 05/05/06
Yeah but Vista is not here yet!!  mdsmedia | 04/11/06
I have used the beta,  JoeMama_z | 04/11/06
I have no doubt...  mdsmedia | 04/11/06
neither?  JoeMama_z | 04/11/06
Ahh...But Vista is still a year away  WiredGuy | 04/11/06
Vista. Pff  notcomingback | 04/11/06
here is what is innovative.....  JoeMama_z | 04/11/06
No but...  Cardinal_Bill | 04/11/06
Security?  viking2007@... | 04/12/06
George, Vista will take it to the next level........  Can you hear me | 04/11/06
Wow! That's impressive  Sxooter_z | 04/11/06
George...  Cardinal_Bill | 04/11/06
George???  axe's worst nightmare | 04/13/06
Yeah, but vista takes it to the next level...  handydan918 | 04/11/06
already possible on linux  Scott W | 04/12/06
Again... Plain and simple "Theories"  ju1ce | 04/12/06
So we're supposed to forget about the last 10 years?  Chad_z | 04/12/06
come on be honest....  JoeMama_z | 04/11/06
Obviously not a unix user  Sxooter_z | 04/11/06
obviously you cant read...  JoeMama_z | 04/11/06
Show me.  Sxooter_z | 04/11/06
kernel 2.6.16  Sxooter_z | 04/11/06
Who cares?  JoeMama_z | 04/11/06
Who cares?  Sxooter_z | 04/11/06
Argued like a true fan boy.....  JoeMama_z | 04/11/06
to jomommy  IceTheNet@... | 04/11/06
Fanboy? Pot, meet Kettle.  Sxooter_z | 04/12/06
to quote you...  Sxooter_z | 04/12/06
Talk about noise..  viking2007@... | 04/12/06
Hmmm, interesting bug reports however  maldain | 04/11/06
wrong a right @ the same time....  JoeMama_z | 04/11/06
You should actually learn about linux before talking  IceTheNet@... | 04/11/06
Speaking of stupid...  viking2007@... | 04/12/06
stupid users  Scott W | 04/12/06
Local vs remote exploit  barsteward | 04/12/06
The concept you're looking for  Yagotta B. Kidding | 04/11/06
depends on your definition of single point of failure is....  JoeMama_z | 04/11/06
clutching at straws Sam?  mdsmedia | 04/11/06
not particularly....  JoeMama_z | 04/11/06
I'm still not sure how you get your 2...  mdsmedia | 04/11/06
my bad ..."know" not "no". nt  mdsmedia | 04/11/06
just so you understand  IceTheNet@... | 04/11/06
the answer is yes  Scott W | 04/12/06
yes, yes it is much harder  Sxooter_z | 04/12/06
Patch  chris.gordon | 04/11/06
Vista, next level...  Media Whore | 04/11/06
name of the game?  viking2007@... | 04/12/06
Survey...  Sxooter_z | 04/11/06
ONLY 14,758,921,346,065,321,987,456,555,001 more Bugs left to fix  realitycheck101 | 04/11/06
PPL who use the term MICROSUCKS are an embarrassment to the computing world  Code Poet | 04/11/06
Sorry About Your Luck with MICROSUCKS Not  IceTheNet@... | 04/11/06
Huh?  Code Poet | 04/12/06
MICROSUCKSMICROSUCKSMICROSUCKSMICROSUCKS  Microshillslayer | 04/12/06
You have issues....  Code Poet | 04/12/06
But what will the new round of patches destroy ?  josephrot | 04/11/06
Windows XP SP1 user  IceTheNet@... | 04/11/06
Software Giants, Patch Giants,  michael_t | 04/11/06
Please enjoy your bordom  Code Poet | 04/11/06
Super Mega Patch released "Privately" get it here:  IceTheNet@... | 04/11/06
MS vs raid  bombardj1 | 04/11/06
JUST WONDERING...  lampdeveloper | 04/12/06
Wait... not for the updates, just to consider what's been said.  jharshey | 04/12/06
Wow...  viking2007@... | 04/12/06
Yawn!  tslocum7 | 04/12/06
more hacks more hardware sales  galv9506 | 04/12/06
Thats 44 updates after service pack 2  zmud | 04/12/06
Please wusses  ilikeit | 04/12/06
Move along folkes, nothing to see here #############  SouthernPride | 04/12/06
Would you like some cheese with that whine?  B.O.F.H. | 04/12/06
No cheese needed!  SouthernPride | 04/12/06
What you talking about Willis?  Rick_K | 04/12/06
Active X  SouthernPride | 04/12/06
good old sun java LOL  bombardj1 | 04/12/06
Sun Java  SouthernPride | 04/12/06
eh?  barsteward | 04/12/06
RE  SouthernPride | 04/12/06
not a hitch  golowenow | 04/13/06
Is there a middle ground?  xilord@... | 04/12/06
Middle Ground  SouthernPride | 04/12/06
No, it wouldn't  Sxooter_z | 04/12/06
Good luck  viking2007@... | 04/12/06
Middle ground  xilord@... | 04/12/06
2nd example of proving  barsteward | 04/12/06
My point provent  SouthernPride | 04/12/06
InDeed there is middle ground  benrob | 04/12/06
YES!!!!  viking2007@... | 04/12/06
George...Maybe you can help....  DeeAitch | 04/12/06
I can help...  benrob | 04/12/06
Hey benrob...  DeeAitch | 04/12/06
Precisely my point...  benrob | 04/12/06
Precisely Your Point?  DeeAitch | 04/12/06
Gotcha!  DeeAitch | 04/12/06
Oh Sure...  viking2007@... | 04/12/06
Sorry  DeeAitch | 04/15/06
Likely Problem with 4/11 Microsoft Security Patches  unravlr | 04/12/06
Thank god - I'm not insane  goddessjuliette | 04/12/06
Well, it's not the first time...  Tony Agudo | 04/12/06
Likely solution  Joed_M | 04/15/06
Megapatch sews up buy another computer!  Robert Himes | 04/12/06
Updates Lock Windows Explorer  randys@... | 04/12/06
Just a minute here...  marbing@... | 04/12/06
Problems..none...  benrob | 04/13/06
"Folders" Explore panel broken in Win Explorer  evano | 04/12/06
Likely solution  Joed_M | 04/15/06
Megapatch, was he a Transformer  Boot_Agnostic | 04/13/06
Annoying!  Arnie Vios | 04/13/06
How can they "fix" it before it's created?  marymo | 04/13/06
Unfortunately ...  Arnie Vios | 04/13/06
Geek, when you sour the code after a long day's double agenting  Boot_Agnostic | 04/14/06
Microsoft Finally Confirms Some Conflicts!!  unravlr | 04/18/06

What do you think?

Meet Doc