ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Microsoft patches critical flaws

Joris Evers CNET News.com

Published: 11 Jan 2006 10:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Tuesday released fixes for two "critical" security flaws, one in Windows and another in the Outlook email client and Exchange mail server.

Both vulnerabilities could allow an attacker to gain complete control over vulnerable PCs or servers running the Microsoft software, the company said in two security bulletins, released as part of its monthly patching cycle.

The Windows problem lies in the way the software processes Web fonts and affects all current versions of the operating system. A vulnerable Windows system could be compromised if the user opened an email or visited a Web site containing a malicious font, Microsoft said in security bulletin MS06-002.

Outlook and Exchange are flawed in the way the applications decode certain email messages, Microsoft said in security bulletin MS06-003. An attacker could craft a malicious email message, and vulnerable systems would be compromised when the message is processed by Exchange or viewed by the Outlook user.

Both vulnerabilities were reported privately to Microsoft, which has not discovered any current cyberattacks that use the flaws as a conduit. Patches to repair the bugs are available via the online bulletins, and the company urges people to install those as soon as possible.

Tuesday is Microsoft's first official patch Tuesday of 2006. However, the company broke its monthly patching program last week to deliver a fix for another serious flaw in Windows. That bug, related to the way the operating system renders WMF images, is being used in exploits, experts have said.

On Monday, two new Windows image problems were reported on a popular email list. Microsoft acknowledged those issues, but said they are performance problems, not security vulnerabilities.

The new Exchange and Outlook vulnerability affects all current versions of the software except Exchange 2003 with Service Pack 1 or Service Pack 2, Microsoft said. The issue is specific to the processing of mail that uses the Transport Neutral Encapsulation Format protocol, used in sending messages in Rich Text Format. For temporary protection, Exchange users could block TNEF, Microsoft suggested.

The Windows problem was discovered and reported by eEye Digital Security, and the Exchange and Outlook flaw was found by Next Generation Security Software.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 163 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Operations Support Analyst

We're also truly international in both outlook and opportunity. You will have competence across multiple areas of IT infrastructure with emphasis on ...

2nd line support 3 -9 months LONDON * URGENT*

Exchange 2003 / Outlook Active Directory There will also be a number of bespoke applications that you will be supporting across multiple sectors. Im ...

Messaging support analyst- Investment banking city based

Meeeting/Office Communicator server environment, including transition into full production support troubleshoot and resolve cross platform message ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.