On MovieTome: New writers on 'Uncharted' the movie
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: May 9, 2006 7:54:00 PM

Microsoft on Tuesday released three security updates, two of which address critical flaws in its Exchange e-mail server and third-party software in Windows.

Critical vulnerabilities in Microsoft Exchange Calendar and Adobe's Macromedia Flash Player in Windows can lead to a remote execution of code on a user's system, according to Microsoft's security bulletins.

The software giant also issued a "moderate" update for flaws in Windows, according to the software giant's bulletin. A malicious attacker could launch a denial-of-service attack by sending a specially crafted network message through the system to exploit the flaw.

The critical Microsoft Exchange flaws affect Microsoft Exchange Server 2000 with Post-Service Pack (SP) 3, Microsoft Exchange 2000 Enterprise Server, and Microsoft Exchange Server 2003 with SP 1 or SP 2.

"An attacker could exploit the vulnerability by constructing a specially crafted message that could potentially allow remote code execution when an Exchange Server processes an e-mail with certain...properties," according to Microsoft's bulletin.

Security firm Symantec said the Microsoft Exchange flaw is the most serious of the three.

"Because the majority of Exchange servers are configured to receive e-mails from anonymous users, this vulnerability has the potential to manifest itself in the form of a worm if machines are not properly patched," Oliver Friedrichs, Symantec Security Response director, said in a statement.

Microsoft also issued a Windows update for what it described as critical flaws in Adobe's Macromedia Flash Player 5 and 6. An attacker could exploit these vulnerabilities in the Flash Player by constructing a malicious Flash animation file. Users visiting a Web site containing the specially crafted file may find their computer system taken over.

The Flash Player flaws affect Windows XP Home Edition, with SP 1 or SP 2; XP Professional; Windows 98 with Gold service pack or SP1; Windows 98 SE with Gold service pack; and Windows ME with Gold service pack.

Microsoft on Tuesday released three security updates, two of which address critical flaws in its Exchange e-mail server and third-party software in Windows.

Critical vulnerabilities in Microsoft Exchange Calendar and Adobe's Macromedia Flash Player in Windows can lead to a remote execution of code on a user's system, according to Microsoft's security bulletins.

The software giant also issued a "moderate" update for flaws in Windows, according to the software giant's bulletin. A malicious attacker could launch a denial-of-service attack by sending a specially crafted network message through the system to exploit the flaw.

The critical Microsoft Exchange flaws affect Microsoft Exchange Server 2000 with Post-Service Pack (SP) 3, Microsoft Exchange 2000 Enterprise Server, and Microsoft Exchange Server 2003 with SP 1 or SP 2.

"An attacker could exploit the vulnerability by constructing a specially crafted message that could potentially allow remote code execution when an Exchange Server processes an e-mail with certain...properties," according to Microsoft's bulletin.

Security firm Symantec said the Microsoft Exchange flaw is the most serious of the three.

"Because the majority of Exchange servers are configured to receive e-mails from anonymous users, this vulnerability has the potential to manifest itself in the form of a worm if machines are not properly patched," Oliver Friedrichs, Symantec Security Response director, said in a statement.

Microsoft also issued a Windows update for what it described as critical flaws in Adobe's Macromedia Flash Player 5 and 6. An attacker could exploit these vulnerabilities in the Flash Player by constructing a malicious Flash animation file. Users visiting a Web site containing the specially crafted file may find their computer system taken over.

The Flash Player flaws affect Windows XP Home Edition, with SP 1 or SP 2; XP Professional; Windows 98 with Gold service pack or SP1; Windows 98 SE with Gold service pack; and Windows ME with Gold service pack.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 30 Talkback(s)
Thats Kewl .
You don't even have to compile the source on Mandriva Linux , just run the updater and install . That's RPM for ya , (Red Hat Package) Lovey wouldn't know anything about Linux , so whatever he states about Linux is just plain old FUD like himself .... (Read the rest)
Posted by: I'm Ye, the MS SHILL . Posted on: 06/08/06 You are currently: a Guest | | Terms of Use
SOS, DD...  realitycheck101 | 05/09/06
Microsoft patches Windows and Exchange flaws  Loverock Davidson | 05/09/06
..... " no compiling the source"....  Reverend MacFellow | 05/09/06
I'm right  Loverock Davidson | 05/09/06
What a laugh  Shelendrea | 05/09/06
You are a liar.  Linux User 147560 | 05/09/06
not to nitpick, but....  toadlife | 05/09/06
Sure, but...  JDThompson | 05/10/06
Actually...  Justin James | 05/10/06
My God you are pathetic  itanalyst | 05/09/06
compile what source?  B.O.F.H. | 05/09/06
Thats Kewl .  I'm Ye, the MS SHILL . | 06/08/06
You can appreciate  georgep_z | 05/09/06
Downtime?  Michael Kelly | 05/09/06
Yes  Loverock Davidson | 05/09/06
When do I do routine maintenance?  Michael Kelly | 05/10/06
I never said that  Loverock Davidson | 05/10/06
Oh I know that  Michael Kelly | 05/10/06
Yep  tslocum7 | 05/10/06
And your use  Loverock Davidson | 05/10/06
My response might be slow  NonZealot | 05/10/06
I am a day late and a patch short  nucrash | 05/10/06
Patch to fix patches with the last patch that was patched will be patched  itanalyst | 05/09/06
no it won't  Shelendrea | 05/09/06
You sure?  tslocum7 | 05/10/06
Oh, you mean the one for the obsolete third party software  Confused by religion | 05/10/06
Perhaps because I didn't put a =-)  Shelendrea | 05/10/06
micro-soft vs mega-patch  michael_t | 05/09/06
Mega-mega patches to patch mega patches!  Reverend MacFellow | 05/10/06
Microsoft releases pates to fix flaws...  Snippy Clippit | 05/10/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here