ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Tackling Microsoft's August patches: Part 2

John McCormick

Published: 22 Aug 2006 13:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

…and leaving Outlook's default setting to open HTML emails in the Restricted Sites security zone would block the remote code execution threat.

Well, that sums up this month's critical security bulletins. Now, let's look at the three bulletins rated as important threats.

MS06-045
Microsoft Security Bulletin MS06-045, "Vulnerability in Windows Explorer Could Allow Remote Code Execution", fixes the Folder GUID Code Execution Vulnerability (CVE-2006-3281). While this is a publicly disclosed threat, there had been no reports of active exploits at the time of publishing.

This update affects Windows 2000 SP4, all versions of Windows XP, and all versions of Windows Server 2003. It's an important threat for all affected versions.

Firewall best practices would likely block an attack on this vector. By default, many programs open HTML emails in the Restricted Sites security zone. A workaround is to disable the Web Client service.

MS06-049
Microsoft Security Bulletin MS06-049, "Vulnerability in Windows Kernel Could Result in Elevation of Privilege", addresses the Windows 2000 Kernel Elevation of Privilege vulnerability (CVE-2006-3444). While this is a publicly disclosed threat, there had been no reports of active exploits at the time of publishing.

As the name implies, this important-rated threat is only an elevation of privilege threat, and it only affects Windows 2000. Valid log-on credentials are required to conduct an attack on this vector.

Microsoft reports no workarounds. This security bulletin replaces MS05-055.

MS06-050
Microsoft Security Bulletin MS06-050, "Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution", addresses two vulnerabilities: Hyperlink Object Buffer Overflow Vulnerability (CVE-2006-3086) and Hyperlink Object Function Vulnerability (CVE-2006-3438). While one of these is a publicly disclosed threat, no reports of active exploits had surfaced for either vulnerability at the time of publishing.

This update affects Windows 2000 SP4, all versions of Windows XP, and all versions of Windows Server 2003. It's an important threat for all affected versions. This security bulletin replaces MS05-015.

Final word
Well, that's definitely a lot of security patches for August. Looking on the bright side, many of them won't be of too much concern for a lot of managers.

In my experience, while Windows 2000 still sees heavy use in government, most corporate users have moved on, which eliminates some of the threats entirely. Using best practices will block some others, and there have been no reports of active exploits for any of the ones in this article.

John McCormick is a security consultant and well-known author in the field of IT, with more than 17,000 published articles. He has written the IT Locksmith column for TechRepublic for more than four years.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
173 out of 345 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.