Advertisement
Promo

Industry watch Toolkit

Microsoft patches 'critical' Outlook, IE bugs

Published: 24 Apr 2003 07:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has warned customers that they should apply updates for both Internet Explorer and Outlook Express to fix critical security vulnerabilities that could let attackers run programs on a victim's PC.

"The No. 1 thing that we want people to walk away with is to install the updates so their machine is protected," said Stephen Toulouse, security program manager for Microsoft's security response centre.

Last year, Microsoft began to release advisories midweek due to customer comments indicating such a policy makes it more likely that patches can be applied quickly. Both advisories can be found on the company's Web site.

Internet Explorer 5.01, 5.5 and 6.0 all have four flaws, the worst of which could allow an attacker to take control of a person's computer if a victim were to follow links to a Web site or read an HTML (Hypertext Markup Language) email created by an attacker.

A so-called buffer overflow vulnerability, which an attacker can exploit by sending more input to a program than the application expects, could allow the owner of a Web site to run code on the person's computer. Buffer overflows are an old type of vulnerability that still crop up frequently in programs. The flaw occurs in a component of Internet Explorer that delivers Web addresses to the browser from other sources -- for instance, if a person clicked on a URL in an email or a Word document.

Two other vulnerabilities allow an attacker to place code on a Web site that would cause the browser to upload a file from a victim's computer. Another flaw affects how the application handles third-party files such as Adobe Systems' portable document format.

The flaw in Outlook Express is in the way that the application handles the encapsulation of HTML in emails. A software error in the component allows an attacker to run programs on a victim's computer.

Even Windows users who don't read or send email using Microsoft Outlook Express or browse with Internet Explorer should install the update, the advisories stressed.

The advisories are the software giant's 14th and 15th this year. This is the company's second year of trying to secure its many applications under its Trustworthy Computing Initiative.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
52 out of 92 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Discussions

lezlow lezlow

ator

Thursday 17 December 2009, 1:47 PM

2 comments
lezlow lezlow

PLASTEKE

Thursday 17 December 2009, 1:41 PM

1 comment
lezlow lezlow

don,t like to sai

Thursday 17 December 2009, 1:34 PM

1 comment
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters