Critical holes newly fixed for Internet Explorer and Windows

Analysis
Apr 23, 20082 mins

Microsoft has re-issued two patches. One patch, originally issued during the April Patch Tuesday, is rated critical and affects all recent version of Internet Explorer. The vulnerability is known as the “data stream handling memory corruption vulnerability.” It could enable remote code execution because of the way that IE processes data streams. If a user visits a Web page that exploits the vulnerability, it could allow the attacker to gain the same user rights as the logged-in user.

The second patch, also rated critical, patches vulnerabilities the .NET Framework that could allow remote code execution. This affects most versions of Windows including most flavors of Windows Server and XP and all flavors of Vista. The patch fixes the .Net PE loader and the .Net JIT compiler flaws both of which could allow an attacker to gain control of a system with the same permissions as the logged on user. It also includes a fix for the “information disclosure” hole in ASP.NET, a vulnerability known as the “null byte termination hole.” Microsoft says that this could allow an attacker to bypass the security features of an ASP.NET Web site to download the contents of any Web site. This is an update of a patch originally issued July 10, 2007.

More Microsoft Subnet security-related posts

Microsoft CAPTCHA easy to thwart

Only XP SP3 safe from hacker Windows exploit of a bug patched on Tuesday

Eight patches for today’s Patch Tuesday, affecting all Windows

Microsoft buys Komoku, maker of rootkit detection products

Podcast: Microsoft security? Experts applaud it

Plus, check out these Microsoft Subnet blog posts:

New Microsoft virtualization tool coming soon Exchange and SharePoint to be revamped for multitenant versions Low-cost PCs and a lightbulb goes off in Redmond Microsoft attempts to appease its channel while moving forward with servicesMicrosoft’s Salesforce.com “killer” offers killer pricing XP SP3 available to volume license holdersMore info on Office Genuine Advantage notificationAll Microsoft Subnet blog posts

Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)