Microsoft has released an update for Windows that fixes critical flaws in Exchange Server and Adobe's Macromedia Flash Player
Two security holes could be used by hackers to execute code remotely on a user's PC
R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft patches two critical flaws

Exchange Server and Flash player holes plugged

Matt Chapman, vnunet.com 10 May 2006
ADVERTISEMENT

Microsoft has released an update for Windows that fixes critical flaws in Exchange Server and Adobe's Macromedia Flash Player

Both of the security holes could be used by hackers to execute code remotely on a user's PC and take full control.

"An attacker could then install programs, view, change or delete data, or create new accounts with full user rights," said the Microsoft statement accompanying the update.

Monty Ijzerman, senior manager of the Global Threat Group at McAfee's Avert Labs, said: "There are two items of note in this announcement by Microsoft. 

"The vulnerability in Exchange Server poses a serious concern as it does not require any user interaction to be exploited, making the vulnerability a worm candidate."

Ijzerman also said it was "interesting" that Microsoft had issued a patch for vulnerabilities that were previously patched by Adobe.

"This is the first time in recent memory that Microsoft has published a patch for third-party software," he explained.

"In this case, it is probably because the Macromedia patch was not widely deployed and Microsoft's updates will help ensure that its customers are protected."

Tuesday's update also fixes a denial of service vulnerability in Microsoft Distributed Transaction Coordinator (MSDTC).

The problem could be exploited to send a specially crafted network message to an affected system that would stop it responding. Microsoft rated the MSDTC update as 'moderate'.

See also:

Vista's enhanced security could cause some firms to go to the wallDifficult to compete with free bundled offerings from Redmond  10 May 2006
Microsoft dropped something of a bombshell yesterday at the LinuxWorld Conference and ExpoVirtualisation bombshell from Redmond  04 Apr 2006
Website and blog won't give away security flaws  17 Mar 2006
Microsoft has come under fire from the European Commission for failing to meet the obligations laid out in its March 2004 antitrust rulingFailure to disclose complete and accurate interface documentation  12 Mar 2006
Microsoft is emphasising the potential security risks posed by pirated softwarePirated software could hold spyware, vendor cautions  10 Mar 2006

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | National Policing Improvement Agency
The NPIA, National Policing Improvement Agency, works for the police service and directly supports forces to deliver improvements today, and into the future. We're a single national support agency led by the police, for the ... more >
Central London, United Kingdom | MI5 Security Service
Communications Centre Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
London, United Kingdom | Feltham City Learning Centre
ICT Systems Administrator - Feltham City Learning Centre - £23,097 - £24,528 A full time ICT Systems Administrator to work in the Feltham City Learning Centre. This role requires a broad range of ICT skills ... more >
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
More job opportunities