The legit Patch Tuesday Security Bulletin is available

Analysis
Jun 12, 20072 mins

June Patch Tuesday has commenced. Microsoft has made available six patches, four of them rated critical. One critical fixes a vulnerability in the Secure Channel (Schannel) security package in Windows. Specifically Microsoft says:

“This vulnerability could allow remote code execution if a user viewed a specially crafted Web page using an Internet Web browser or used an application that makes use of SSL/TLS. However, attempts to exploit this vulnerability would most likely result in the Internet Web browser or application exiting. The system would not be able to connect to Web sites or resources using SSL or TLS until a restart of the system …”

The second critical fix deals with Internet Explorer: From Microsoft:

“This critical security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability. All but one of these vulnerabilities could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. One vulnerability could allow spoofing, and also involves a specially crafted Web page …”

The third fix is for Outlook Express/Windows Mail. Microsoft says:

“This critical security update resolves two privately reported and two publicly disclosed vulnerabilities. One of these vulnerabilities could allow remote code execution if a user viewed a specially crafted e-mail using Windows Mail in Windows Vista. The other vulnerabilities could allow information disclosure if a user visits a specially crafted Web page using Internet Explorer …”

The fourth critical fix is for a vulnerability in a Win32 API. According to Microsoft:

“This vulnerability could allow remote code execution or elevation of privilege if the affected API is used locally by a specially crafted application. Therefore, applications that use this component of the Win32 API could be used as a vector for this vulnerability …”

Click here for more info and to download patches.