On CBS Sports: Play fantasy football 2008 now
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto, News.com
Posted on ZDNet News: Jun 13, 2006 8:37:00 PM

Microsoft has issued patches for 21 flaws in its software, saying all but two of them could let an intruder run malicious code on a compromised computer.

The company sent out a dozen security bulletins on Tuesday as part of its regular monthly patch cycle. Eight of the bulletins are labeled "critical," which is Microsoft's highest risk rating. They cover problems with Windows, Internet Explorer, Word, PowerPoint and Exchange Server.

The number of vulnerabilities mean this is Microsoft's largest clutch of patches to date, security experts said.

"There has never been a Microsoft security update to address 21 issues and never one with 19 potential remote execution flaws," said Amol Sarwate, the manager of the Vulnerability Management Lab at flaw management specialist Qualys.

The most important bulletin, MS06-025, is a fix for routing and remote access vulnerabilities in Windows, said Jonathan Bitle, a senior product manager at Qualys.

"These (vulnerabilities) take advantage of two listening services that run on the host and listen for traffic coming in through ports that are frequently utilized," Bitle said. "While a lot of these (other Microsoft) remote execution flaws require interaction (by the user), this one does not. A user doesn't have to click on a link or open an attachment."

The routing and remote access are deemed critical for systems running Windows 2000, and "important"--the second risk ranking--for Windows XP with Service Pack 1 or 2, and for Windows Server 2003 with Service Pack 1.

Qualys is also suggesting that IT managers should jump on another patch, for an issue in Microsoft Exchange Server running Outlook Web Access (MS06-029), even though Microsoft has tagged it only as important.

"If a user checks their e-mail using Outlook Web Access, all they need to do is just open an e-mail in IE and it will cause the script in their e-mail to be remotely executed," Sarwate said.

Over the next days and weeks, IT administrators should be busy deploying the bundle of patches across their network, experts said.

"There are a couple different vulnerabilities. Some are IE browser problems, some affect the Media Player, ART imaging and JScript," said Chris Andrew, vice president of security technologies at PatchLink. "IT managers will probably have to patch every single desktop."

Four of the critical updates deal with security holes that could allow remote code execution in all versions of Windows. One is a cumulative update for the Internet Explorer component (MS06-021), affecting versions 5.01 and 6 of the Web browser. Another (MS06-024) deals with a problem with Windows Media Player, versions 7.1, 9 and 10. The others cover vulnerabilities in Microsoft Jscript (MS06-023) and ART image rendering (MS06-022).

Another critical Windows bulletin, related to bugs in its graphics rendering engine (MS06-026) affects Windows 98, Windows 98 Second Edition (SE) and Windows Millennium Edition (ME) only.

Two updates affecting Office were also given the highest risk rating. A vulnerability in Word (MS06-027) also hits Microsoft Works. The bulletin for a flaw in PowerPoint (MS06-028) replaces an earlier patch.

Microsoft also issued a fix for an important flaw in Windows' Server Message Block (SMB) component (MS06-030) that could enable attackers to elevate their level of system privileges. The "moderate" bulletins covered an RPC Mutual Authentication (MS06-031) problem and a TCP/IP problem (MS06-032) in Windows.

  • Talkback
  • Most Recent of 123 Talkback(s)
what'd they teach you?
uM0p ap!sdn
You might think you're a cracker but you're cheezy, the stuff that goes on the cracker and I would eat you up! You might be a hacker or a cracker, but that makes you no better than any... (Read the rest)
Posted by: Burnme2 Posted on: 07/22/06 You are currently: Logged In | Log out
Microsoft plugs 21 security holes Loverock Davidson   | 06/13/06
Right, right: two holes open for each one "closed" n michael_t   | 06/13/06
Predictable mikeybrass   | 06/13/06
How dare you use common sense in the talkbacks! No_Ax_to_Grind   | 06/13/06
Life mikeybrass   | 06/13/06
hey, don't diss Scott W   | 06/16/06
To MikeBrass... Spikey_Mike   | 06/13/06
Fix holes mikeybrass   | 06/13/06
Yes they well may... RicD_   | 06/13/06
Macs mikeybrass   | 06/13/06
The code has issues Loverock Davidson   | 06/13/06
Are these cold hard facts loverock , Beyond the Vista, a Snow Leopard is stalking .   | 06/14/06
And for the competent administrators... Spikey_Mike   | 06/13/06
Any mikeybrass   | 06/13/06
WHich is why I use Linux (NT) linux_for_me   | 06/13/06
You must have read it wrong... Loverock Davidson   | 06/13/06
So I guess that means Loverock Davidson   | 06/13/06
The linux jihad has been heard from tswartz   | 06/14/06
No you have that backwards IceTheNet@...   | 06/14/06
You should specify IceTheNet@...   | 06/14/06
Good lord help us all ! Beyond the Vista, a Snow Leopard is stalking .   | 06/14/06
Another one that hates to hear the truth Loverock Davidson   | 06/14/06
I sure did Lovey . Beyond the Vista, a Snow Leopard is stalking .   | 06/14/06
Good Choice I would have done the same IceTheNet@...   | 06/14/06
so in translation..... mypl8s4u2   | 06/14/06
so in translation..... uM0p ap!sdn   | 06/14/06
Good lord help us all ! uM0p ap!sdn   | 06/14/06
Nice Troll IceTheNet@...   | 06/14/06
Is that all you linux fanboys can say? Loverock Davidson   | 06/14/06
Is that all you linux fanboys can say? uM0p ap!sdn   | 06/14/06
Hey, Loverock what about the hundred they haven't fixed RUlistening   | 06/14/06
Mission Impossible: Securing MS windWoes... michael_t   | 06/13/06
You don't use the free firewall? NonZealot   | 06/13/06
NonZealot... Spikey_Mike   | 06/13/06
Are you FUDding us? NonZealot   | 06/13/06
Stupid ZDNet links! NonZealot   | 06/13/06
Non-clickable version of above link wolf_z   | 06/14/06
Published Friday 26th October 2001 19:26 GMT uM0p ap!sdn   | 06/14/06
Malware can't disable my firewall!! NonZealot   | 06/14/06
A REAL system SHOULD NOT NEED a firewall michael_t   | 06/13/06
Fairyland mikeybrass   | 06/13/06
Good: If you feel "safe" because you slapped on a "firewall" michael_t   | 06/13/06
OMG THANKS FOR THE LAUGH!!!! NonZealot   | 06/13/06
I am glad to see you can use your PC again! Did you pay the ransom michael_t   | 06/13/06
Hmm, don't know about your personal firewall but mine can't be tricked uM0p ap!sdn   | 06/14/06
Chances mikeybrass   | 06/13/06
Keep dreaming michael_t   | 06/14/06
You meant to say IceTheNet@...   | 06/14/06
HW FWs are good for as you said to monitor for and filter out "strange" michael_t   | 06/14/06
Uh oh, better back up that statement! NonZealot   | 06/14/06
I think he was saying false security IceTheNet@...   | 06/14/06
False security NonZealot   | 06/14/06
It's OK: I will talk with a more soothing voice and at a slower michael_t   | 06/14/06
Try to keep up NonZealot   | 06/14/06
you are too ignorant :-( michael_t   | 06/15/06
Ignoring a far bigger truth Chad_z   | 06/14/06
Wow, a post from you worth responding to! NonZealot   | 06/14/06
Yahooo!!!!!!!!!!!!!! IceTheNet@...   | 06/14/06
Ignoring a far bigger truth ... uM0p ap!sdn   | 06/14/06
Wow, you must be popular!!! NonZealot   | 06/14/06
And are you preparing for Junior High this Summer? michael_t   | 06/15/06
how hard do you think it is to get logon information. IceTheNet@...   | 06/14/06
Answered in another post NonZealot   | 06/14/06
don't use M$ (NT) uM0p ap!sdn   | 06/14/06
Because it runs apps that businesses make money on tswartz   | 06/14/06
what can I do with Vista but not with XP? michael_t   | 06/14/06
Not to mention the EU IceTheNet@...   | 06/14/06
With UNIX/linuxs/*BSD I know exactly michael_t   | 06/14/06
because mypl8s4u2   | 06/14/06
Why only pick on Microsoft? Leria   | 06/14/06
It is simple michael_t   | 06/15/06
Got Spellcheck? Stellar Winds   | 06/15/06
Do you? Can you spell check my postings? thanks michael_t   | 06/15/06
Why only pick on Microsoft? Bite Me_Ax_Moron   | 06/15/06
So, what are YOU gonna do for us? Stellar Winds   | 06/15/06
Good job, stay on the scum hackers! No_Ax_to_Grind   | 06/13/06
Our fairy queen mother No_Ax_to_Grind says she........... Can you hear me   | 06/13/06
Nothing new here, we have had crooks for a long time here. The village DonnieBoy   | 06/13/06
please.. Spicoli the Cannoli   | 06/13/06
Have to agree with you there Leria   | 06/14/06
I don't agree uM0p ap!sdn   | 06/14/06
they teach crap Scott W   | 06/16/06
what'd they teach you? Burnme2   | 07/22/06
what'd they teach you? Burnme2   | 07/22/06
No_Ax_to_Grind uM0p ap!sdn   | 06/14/06
Axe 2 grind w/ uM0p ap!sdn Burnme2   | 07/22/06
The water and the glass Southern.Pride   | 06/13/06
if you follow shraven   | 06/14/06
It's just a business proposition... techboy_z   | 06/13/06
Does it matter Boot_Agnostic   | 06/13/06
Does it matter uM0p ap!sdn   | 06/14/06
Pass kray_z   | 06/13/06
THIS IS THE YEAR!!!! NonZealot   | 06/13/06
Na................ uM0p ap!sdn   | 06/14/06
That's the year michael_t   | 06/15/06
Then the little hacker nerds tswartz   | 06/14/06
Uhmm hate to burst your bubble kido IceTheNet@...   | 06/14/06
Hey, Windows is NOT that restricted Leria   | 06/14/06
right, only its users are .. n michael_t   | 06/15/06
Then the little hacker nerds.......... uM0p ap!sdn   | 06/14/06
povided IceTheNet@...   | 06/14/06
After the b-slapping from WGA, I passed too... msolgeek   | 06/14/06
hits and tips mypl8s4u2   | 06/14/06
Would you rather Roger Ramjet   | 06/14/06
would you rather..... mypl8s4u2   | 06/14/06
and opens 100 more IceTheNet@...   | 06/14/06
I agree mypl8s4u2   | 06/14/06
right chucke69   | 06/28/06
Make it irrelevant to you:Broken Record Time TripleII   | 06/14/06
Holes plugged mypl8s4u2   | 06/14/06
why so many stomfi@...   | 06/14/06
And You don't think it is a target TripleII   | 06/14/06
Doh, hit reply to story instead of message TripleII   | 06/14/06
Has anyone noticed???? mypl8s4u2   | 06/14/06
My update had only 11 not 21 RUlistening   | 06/14/06
Problem isn't Microsoft wiser2odayz   | 06/14/06
MS harmed 21 zdnet posters Boot_Agnostic   | 06/15/06
Nice but.. sir_cheats_a_lot   | 06/15/06
YOU build a better OS! Stellar Winds   | 06/15/06
YOU build a better OS! thats any Nix Bite Me_Ax_Moron   | 06/15/06
Promote nix Boot_Agnostic   | 06/22/06
oh please! get off the high horse... sir_cheats_a_lot   | 06/19/06
Club Shepherd yyyy cincy2hot4u@...   | 06/21/06

What do you think?

advertisement
advertisement