On mySimon: KitchenAid Professional Stand Mixer
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: May 3, 2007 8:00:00 PM

Microsoft on Tuesday plans to release seven security bulletins, including a fix for a zero-day flaw in Windows that is already being used in cyberattacks.

The bulletins, part of Microsoft's monthly patch cycle, are slated to provide fixes for an undisclosed number of security vulnerabilities in Windows, Office, Exchange and BizTalk, Microsoft said on its Web site Thursday. The issue affecting BizTalk also relates to "Capicom," a developer component to add cryptography to applications.

Each of the four product families is scheduled to get at least one "critical" update, Microsoft's highest severity rating, the company said. Microsoft plans to release two bulletins related to issues in Windows and three related to Office, with one remaining for both Exchange and BizTalk, it said.

Security issues tagged as critical typically could allow an attacker to gain full control of an affected system with very little, if any, action by the user.

Microsoft's updates will include a patch for a vulnerability in the Windows domain name system, or DNS. The security vulnerability affects Windows 2000 Server and Windows Server 2003. Microsoft warned of the problem last month and has said it was being used in "limited" attacks.

Some of the planned Office patches will likely deal with vulnerabilities in the software that have been disclosed and have been waiting for fixes.

Microsoft gave no further information on the upcoming alerts, other than to state that some of the fixes may require restarting the computer or server.

Last month, Microsoft released six security bulletins. Shortly after it released the fixes, several new Office zero-day bugs and the Windows DNS bug hit. Some security watchers have come to call this phenomenon "zero-day Wednesday."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 10 Talkback(s)
Drat, They Did It Again
The May 8th update rips the "preferred browser" choice from whatever your favorite may have been, and hands it to Internet Explorer. Again.

(now that it's patched, it *must* be your favorite, right?)
sigh...... (Read the rest)
Posted by: astro_z Posted on: 05/08/07 You are currently: a Guest | | Terms of Use
Microsoft to patch zero-day DNS flaw  Loverock Davidson | 05/03/07
Agreed  ITguy5678 | 05/07/07
Any given home user  epcraig | 05/07/07
Right, but home users aren't affected  SecurityGeek_z | 05/07/07
Firewalling DNS  gotitright | 05/07/07
'gotitright' doesn't... have it right...  SecurityGeek_z | 05/07/07
Not so fast...  SecurityGeek_z | 05/07/07
Loverock, you are an idiot...  SecurityGeek_z | 05/07/07
Agree w/ Everything Except  rkuhn040172@... | 05/07/07
Drat, They Did It Again  astro_z | 05/08/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here