Vulnerabilities could allow attackers to take complete control
Vulnerabilities could allow attackers to take complete control
R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft patches critical flaws

Users urged to update systems immediately

Iain Thomson, vnunet.com 13 Apr 2005
ADVERTISEMENT

Microsoft has released eight new patches, five of which are rated 'critical' and could allow attackers to take complete control of compromised systems.

The vulnerabilities affect TCP/IP protocols, Internet Explorer, MSN Messenger, Microsoft Word and Microsoft Exchange server system. Microsoft warned of the impending updates on 11 April.

Users are advised to visit the Microsoft security website and update all software up to Windows 98.

Vulnerability management firm Qualys, which discovered the TCP/IP flaw, warned that other vendors will have to address the issue.

"We found the problem last October and notified Microsoft," said Gerhard Eschelbeck, chief technical officer at Qualys.

"The problem is that the standard is not particularly clear in how to deal with this, and different vendors have different solutions. Most of the vendors affected have released patches or will release patches in the coming days."

Cisco stated that it has already released a patch for the problem.

The three remaining patches, which affect Windows, are rated 'important' by Microsoft, and could allow remote control of PCs if used correctly.

The software giant is also re-releasing two security bulletins: MS05-002 for users running Windows 98, 98 Second Edition and Windows ME; and MS05-009 for users running Windows Messenger.

See also:

Hackers place key-logging software onto blog sitesFree and anonymous hacking tools storage  15 Apr 2005
Third of UK businesses 'unprepared and under resourced' to cope with security issuesHacking and viruses top concern for UK's small and medium-sized businesses  15 Apr 2005
Update includes PeopleSoft code  15 Apr 2005
Chris Andrew of patch management specialist PatchLink explains how third parties can help firms guard systems  14 Mar 2005
Standard method of rating security vulnerabilitiesCommon Vulnerability Scoring System allows IT managers to prioritise patches  24 Feb 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
United Kingdom | Nottingham University NHS
Analyst/Developer - Nottingham University NHS - £24,103 - £32,653   An analyst/developer is required within the Systems Development Section of Nottingham University Hospitals ICT Services. The successful applicants will be part of a team whose ... more >
Central London, United Kingdom | MI5 Security Services
Communications Centre Operator - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
More job opportunities