Skip to navigation
Latest News

Slew of critical security alerts announced by Microsoft

By Steve Malone

Posted on 13 Oct 2004 at 09:55

Anyone who hoped that Windows XP Service Pack 2 would bring an end to the monthly blizzard of security patches is going to be disappointed. This month, Microsoft has issued a whole slew of 'critical' and 'important' patches to its software.

All in all the bulletin is reporting seven 'critical' problems found with its software and three 'important' vulnerabilities. The good news for customers who have installed Service Pack 2, is that the vulnerabilities revealed should - with one exception - already be covered by SP2.

Included amongst the round of vulnerabilities Microsoft has uncovered, are a remote code execution vulnerability, two elevation of privilege vulnerabilities, and a denial of service vulnerability. The company says that in the most severe case remote code could be executed on an targeted system. The vulnerabilities that have been discovered have been found in the Window management system, the DOS virtual machine, Graphics Rendering Engine, and the Windows Kernel. The vulnerabilities have been declared critical for Windows NT, Windows 2000, XP and Server 2003. Earlier versions of Windows are less affected.

Users have also been warned that a weakness has been found in the way that Windows uncompresses .zip files which may also allow a hacker to take control of the computer.

An Excel vulnerability - including Excel for the Mac - exists which allows an attacker can complete control of the computer if the rightful user has full administrative privileges. The attacker would be able to install software, view, change, or delete data or create new accounts with full privileges.

Elsewhere Microsoft says that a vulnerability exists in the Windows SMTP component and Exchange Server Routing Engine component that could allow remote code execution on an affected system. Similarly, a problem with the Windows NNTP Component could allow remote code execution on an affected system.

Microsoft is also warning that it has found a number of weaknesses in versions of Internet Explorer 5 and above.

Afftected users should go to the Microsoft website to obtain the latest patches.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.