Skip to navigation
Latest News

Microsoft patches IE in August security update

By Alun Williams

Posted on 10 Aug 2005 at 11:23

Microsoft has issued six bulletins as part of its monthly security update. Three are rated as Critical, one as Important and two as Moderate, with the much-patched IE once again receiving attention.

Beginning wit the critical updates, bulletin MS05-038 patches a flaw in IE that could allow a remote attacker to execute code on affected systems. It includes a memory corruption vulnerability that involves JPEG image rendering. Most versions of Windows are affected, but see the bulletin for precise version information.

Bulletin MS05-039 again involves a vulnerability that could allow remote code execution and the local elevation of user privileges. The flaw exists in Plug and Play functionality, potentially enabling an attacker to install programs and view, change, or delete data.

The third Critical bulletin - MS05-043 - involves a vulnerability in the Print Spooler service that could allow remote code execution.

Bulletin MS05-040 has a rating of Important and addresses a vulnerability in the Telephony Application Programming Interface (TAPI) service which, again, could allow remote code execution.

Bulletins MS05-041 and MS05-042 are rated as Moderate and could be used as part of Denial of Service (DoS) attacks. The first involves a vulnerability in the Remote Desktop Protocol (RDP), which could allow an attacker to cause a system to stop responding, and the second involves vulnerabilities in the Kerberos system that could lead to unauthorised information disclosure as well as DoS attacks.

Microsoft is also re-releasing two security bulletins. MS05-023 is rated as Critical and involves Microsoft Word (it has been determined that the vulnerability originally addressed also affects Microsoft Word 2003 Viewer). Bulletin MS05-032 is rated as moderate and involves a Microsoft Agent vulnerability (revised updates are available for 64-bit versions of Windows).

As always, users are recommended to update their software with the latest patches.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.