two
Volume 3, Number 10 -- March 15, 2006

Microsoft Patches Security Vulnerabilities in Windows and Office

Published: March 15, 2006

by Alex Woodie

Two patches were issued by Microsoft yesterday to fix security vulnerabilities in its software, including a previously disclosed flaw in Windows XP and Windows Server 2003 that could give an attacker administrative privileges, and a series of flaws in its Office and Works suites that could lead to remote code execution.

Microsoft Security Bulletin MS06-011 fixes an escalation of privilege vulnerability that exists in Windows XP Service Pack 1 (SP1), Windows Server 2003, and Windows Server 2003 for Itanium that could enable a user to take complete control over an affected system.

The vulnerability cannot be exploited over the Internet, Microsoft says, and was given an "important" rating by the vendor for Windows XP SP1, and only a "moderate" rating for Windows Server 2003. The vulnerability--which was discovered by SIA Group, a Spanish security researcher--had previously been disclosed to the public, but Microsoft has received no reports of any attacks exploiting it.

Microsoft Security Bulletin MS06-012, the only other patch issued yesterday, fixes several critical security vulnerabilities in many versions of Microsoft Office and its Works Suite that could allow attackers to gain complete control over affected systems over the Internet.

Microsoft says that, while it's not aware of any attacks taking place that have exploited these previously disclosed vulnerabilities, Office and Works users should immediately apply MS06-012 to shut down six related vulnerabilities. These include the Malformed Range Vulnerability, the Malformed File Format Parsing Vulnerability, the Malformed Description Vulnerability, the Malformed Graphic Vulnerability, the Malformed Record Vulnerability, and the Malformed Routing Slip Vulnerability.



Sponsored By
WOLF COMPUTER CONSULTING

Reliable service and affordable rates for all
of your business computing needs.

                                             * Network Design/Installation/Support
                                             * Network Printing/Digital Print Migration
                                             * Upgrades and Troubleshooting
                                             * Training
                                             * Graphic Design
                                             * Virus Removal
                                             * Consulting

Wolf is a Microsoft Certified Systems Engineer and
Microsoft Certified Systems Administrator.

Contact Wolf
Email: info@wolfconsult.net
Fax: 973-293-0100
Phone: 914-443-5534



Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

MKS:  Meet your compliance goals with iSeries and cross-platform application lifecycle management
OpenLogic:  Install, integrate, test, manage, and learn over 120 open source projects with BlueGlue
COMMON:  Join us at the Spring 2006 conference, March 26-30, in Minneapolis, Minnesota

 


 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement