Computing in the real world
SEARCH FOR: IN:
Guest  Level 00    Register Log in

News 

[PSUs]
Wednesday 11th January 2006
Three security flaws covered by Microsoft 10:17AM, Wednesday 11th January 2006
This month's crop of vulnerabilities in Microsoft's security update includes three 'critical' issues. The announcement includes the .wmf vulnerability which came to light over the holiday period.

The .wmf flaw came to light when the problem - and accompanying source code - began to appear just after Christmas. Initially, Microsoft planned to release the patch alongside the regular update on the first Tuesday of January. However, the furore caused by Microsoft's apparent complacency led many IT managers to use an unofficial patch. Sensing a PR disaster if an exploit became widespread Redmond eventually announced it had completed testing 'ahead of schedule' and released the code.

Elsewhere, Microsoft is providing patches for two other vulnerabilities.

The first relates to the behaviour of embedded web fonts in Microsoft Windows. According
 
 
ADVERTISEMENT
to Microsoft, a remote code execution vulnerability exists in Windows due to the way that it manages malformed embedded Web fonts. Because of this weakness, an attacker could exploit the vulnerability by constructing a malicious embedded Web font that would allow remote code execution.

To trigger an attack a user would either have to visit a malicious Web site or open a specially crafted e-mail message. Anyone who successfully exploited this vulnerability could take complete control of an affected system.

The other issue is with Outlook and Exchange. Microsoft says there is a problem with the Transport Neutral Encapsulation Format (TNEF) MIME attachment because of the way it is decoded by Microsoft Outlook and Microsoft Exchange Server.

Once again, a specially built TNEF message could allow a hacker to take control of a machine when a user opens or previews a malicious e-mail message or when the Microsoft Exchange Server Information Store processes the message.

Subscribers to Microsoft's Update services should receive the patches automatically. Further details are available at the Microsoft Technet Security pages.

Submit to: Digg  |  Slashdot  |  Del.icio.us  |  Technorati

Related News


Buy Direct From 3
Buy direct from the official online 3 store for exclusive deals including line rental discounts, clearance offers, 3G datacards, pay as you go phones and more.

Buy Direct From 3
Buy direct from the official online 3 store for exclusive deals including line rental discounts, clearance offers, 3G datacards, pay as you go phones and more.
www.3-mobile-phones.co.uk
Compare Broadband
Broadband?
Compare 50+ packages
Enter your postcode below:
Powered by:
Top 10 Broadband
Bookstore Top 5

Columns

Prolog:

There are lots of ways to save money, says Tim Danton, but it's the little things that count. › See full Opinion