|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
New patches for dangerous IE, MDAC flaws By John McCormick, 0 September 03, 2003 URL: http://www.zdnet.com.au/insight/soa/New-patches-for-dangerous-IE-MDAC-flaws/0,139023731,120278099,00.htm
Several new and revised Microsoft security bulletins highlight this week's report because the vulnerabilities are rated Critical. MS03-032, a cumulative patch for Internet Explorer, also addresses some newly discovered vulnerabilities. MS03-032 includes patches for two vulnerabilities that can be exploited if users either visit a malicious Web site or open a specially crafted HTML e-mail. The other bulletin, MS03-033, relates to a collection of database access components called Microsoft Data Access Components (MDAC), which is found in many systems, either as shipped or as an upgrade. Details The other new threat addressed by MS03-032 is a failure to correctly determine object types. This vulnerability can be exploited if a user merely visits a malicious Web site or opens an HTML e-mail. MDAC is a set of database connection tools found in most Microsoft applications. The patch provided with MS03-033 supersedes the one released last year (MS02-040), which originally blamed the problem on the Microsoft SQL Server OpenRowSet command. An attacker sending a malformed UDP packet to an unpatched system could gain complete control over the targeted system. Causing a bit of confusion, the e-mail bulletin for this revision mistakenly listed the original release date as July 31, 2003, instead of the actual July 31, 2002, date. Applicability
The MDAC vulnerability affects:
Microsoft Data Access Components 2.8, installed by Windows Server 2003, is not affected. MDAC is installed by default with Windows Me, 2000, and XP, but it is often also installed on Windows NT 4 systems (as part of the Windows NT 4 Option Pack) or by Microsoft Access or SQL Server. Some components are even installed with Internet Explorer. Because MDAC code is also available as a stand-alone component, it may be found in virtually any Windows system, even older Windows 98 systems. Risk level—critical Fix Final word
TechRepublic is the online community and information resource for all IT professionals, from support staff to executives. We offer in-depth technical articles written for IT professionals by IT professionals. In addition to articles on everything from Windows to e-mail to firewalls, we offer IT industry analysis, downloads, management tips, discussion forums, and e-newsletters.
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |