ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Microsoft releases critical patches for XP

Dawn Kawamoto CNET News.com

Published: 12 Jan 2005 08:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Tuesday released two critical patches for its Windows operating system, but a patch for underlying security problems in Internet Explorer 6 is not yet ready for prime time.

As part of its monthly update release, the company issued three patches -- one rated important and two critical. That announcement reflects a more active month than December, when the software giant issued no critical patches for the period.

"Even though we did not rate any patches critical in December, the two we have in January are not indicative of a year more of this type of situation," said Stephen Toulouse, a Microsoft security programme manager.

One critical patch is designed to resolve the security issues surrounding the HTML Help ActiveX control in Windows. Security experts had warned Microsoft about this problem and were pushing the vendor to take quick action, given that an exploit for the vulnerability existed.

The patch addresses the potential problem of attackers taking complete control over an affected system, such as placing and executing programs like spyware and pornography diallers without the users' knowledge.

The second critical patch addresses vulnerabilities in systems from Windows NT servers to Windows XP involving the cursor and icon format handling. Attackers could exploit the vulnerabilities by creating a specially crafted Web page that would have malware.

"These first two patches address vulnerabilities that have proven exploits, and the third has the potential [for an exploit]," said Jimmy Kuo, a McAfee research fellow.

Microsoft also issued a third patch for Windows indexing service, with the threat level rated as important but not critical. That's because the indexing component is turned off by default, making it more difficult for an attacker to access index contents in Windows Media, for example, Toulouse said.

The patches are available from Microsoft's Web site or through its Windows Update service.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 100 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Support Analyst - 2nd line - Windows XP - ITIL - 175-200/day

Windows XP / Blackberry / ITIL / Excel / Poweerpoint / Asset Mgmt. Urgent requirement - 2nd line support role. The client are a global asset ...

DESKTOP SPECIALIST- Financial Traders- London City (40-45k)

Additional knowledge of energy trading applications, application packaging and imaging, and security patch management would be useful as well as ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.