Info

You are currently browsing the QBS PC Help Blog weblog archives for the day 10/10/2007.

Calendar
October 2007
M T W T F S S
« Sep   Nov »
1234567
891011121314
15161718192021
22232425262728
293031  
Categories

Archive for 10/10/2007

Microsoft patches nine flaws in update

The regular monthly ‘Patch Tuesday’ bulletin fixes nine security flaws, four of which have been rated as critical and affecting versions of Word, Internet Explorer, Outlook Express, and the Kodak Image Viewer.

Two fixes, rated as “important”, cover Windows SharePoint and the remote procedure call (RPC). However, a further update for the Windows 2000 and Server 2003 flaw was pulled because of what Microsoft termed “quality control issues”.

The critical flaw found in Word is causing particular concern as it has already been the subject of attack. Using a specially-crafted Word document, the flaw could be exploited for remote code execution, and has already been abused in the past, according to analysts.

The IE patch, meanwhile, is a cumulative update and covers a memory corruption in Internet Explorer that could lead to remote code execution, and also multiple address bar spoofing vulnerabilities. The spoofing flaw is of particular concern with regards to phishing attacks.

The vulnerability in Windows 2000’s Kodak Image Viewer could allow hackers to take control of a user’s PC, through the opening of an infected image. Although Microsoft says this flaw isn’t being actively exploited, experts disagree and recommend that the patch be installed as quickly as possible.

Source: Yahoo News


AddThis Social Bookmark Button

Return to the main QBS site

|