Network World

research center:

Security

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Microsoft releases seven software patches

By Shelley Solheim, IDG News Service, 02/14/06

Microsoft released seven software patches on Tuesday, including fixes for critical security flaws in Internet Explorer and Windows Media Player.

Advertisement:

Of the two critical patches released Tuesday, update MS06-004 provides a fix for a vulnerability in the way IE handles Windows Metafile (WMF) images, used by some CADs (computer-aided designs). The flaw could allow an attacker to construct a WMF image that could allow remote code execution if a user viewed a malicious Web site, e-mail or e-mail attachment. If successful, an attacker could take control of an affected system. The update is critical for users of Internet Explorer 5.01 Service Pack 4 running on Microsoft Windows 2000 Service Pack 4, said the bulletin.

This WMF-related vulnerability is not as severe as the WMF flaw Microsoft patched last month because it affects such a narrow scope of users, said Michael Sutton, director of VeriSign's iDefense Labs unit in Reston, Va.

"We're not aware of any public exploit code for it at this time," he said.

The other critical update, MS06-005, is for a vulnerability in the way Windows Media Player processes bitmap (.bmp) files. An attacker could exploit this flaw by creating a malicious .bmp file that could allow remote code execution if a user viewed a malicious Web site or e-mail message. This vulnerability could also allow an attacker to take control of an affected system. The update is deemed critical for users of Windows XP SP1 and SP2 and Windows Server 2003, Windows 98/SE/ME and Windows 2000 SP4.

The Windows Media Player flaw poses more of a ripe target for attackers, Sutton said. "Even though Windows Media Player is not something generally used to render images, it has the capability of doing that. It's not difficult to create a Web page that uses Windows Media Player to display an image instead of the default application. I think it's a ripe target for exploitation if we see public exploit code for it," Sutton said.

The patches this week reflected an overall trend in client-side vulnerabilities, said Sutton.

But researchers said this latest round of vulnerability patches isn't that ominous.

"These are seven of the most boring patches I've ever seen," said Russ Cooper, senior information security analyst at Cybertrust and editor of the NTBugtraq mailing list. "I think they were being nice to us on Valentine's Day so no one would be bogged down applying seven bulletins tonight so they can get home with flowers and chocolates."


The IDG News Service is a Network World affiliate.

Network World's Hot seat with John Gallant. Five minutes. Unscripted. Unexpected.

Interview: Keeping insider information inside
PortAuthority's appliance-based approach to data protection helps keep company secrets from getting out. PortAuthority President and CEO Pete Foley explains how it all works on this week's Network World Hot Seat.Watch it now

All Hot Seat videos

TOP STORIES | MOST DUGG STORIES

  1. Nokia's new N97 vs. the iPhone
  2. 10 Microsoft research projects
  3. Hard to get justice in MySpace case
  4. Smartphone smackdown: Storm vs. iPhone
  5. Apple removes antivirus support page
  6. Verizon trounces competition
  7. Cisco sued over allegedly monopolistic SMARTnet
  8. Cool Yule Tools: 2008 Holiday Gift Guide
  9. Google Earth used by terrorists in India attacks
  10. 10 kitchen gadgets for the geek gourmet

  11. MOST-WATCHED VIDEO:
    EU gets telecom reform on track

Newsletters
Sign up for one of NWW's Network Security newsletters.

Security in Practice
Virus and Bug Patch Alert
Security Strategies
Security News Alert
VPNs
Messaging
View all newsletters

Email Address:
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Vendor Solutions

White Papers

IT Search: Recapture Control Over Your IT Infrastructure.
- Splunk

Software Assurance Protection: Bridging the Gap in Application Security for Open Source
- Palamida

Protecting Data on Laptops: Why Encryption Isn't Enough
- Absolute Software

More...

Special Report

The Evolution of Network Security - Check Point Software
Organizations are facing up to the fact that their perimeter network defenses no longer afford the protection they once did. But the good news is a slew of new technologies are available to help companies stay out in front of the bad guys


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles