Fixes in for Windows, Microsoft e-mail flaws

By Joris Evers, CNET News.com
11 January 2006 08:53 AM
Tags: windows, flaw, patch, tuesday, wmf, bug, exchange, microsoft
Microsoft on Tuesday released fixes for two critical security flaws, one in Windows and another in the Outlook e-mail client and Exchange mail server.

Both vulnerabilities could allow an attacker to gain complete control over vulnerable PC or server running the Microsoft software, the company said in two security bulletins, released as part of its monthly patching cycle.

The Windows problem lies in the way the software processes Web fonts and affects all current versions of the operating system. A vulnerable Windows system could be compromised if the user opened an e-mail or visited a Web site containing a malicious font, Microsoft said in security bulletin MS06-002.

Outlook and Exchange are flawed in the way the applications decode certain e-mail messages, Microsoft said in security bulletin MS06-003. An attacker could craft a malicious e-mail message, and vulnerable systems would be compromised when the message is processed by Exchange or viewed by the Outlook user.

Both vulnerabilities were reported privately to Microsoft, which has not reported any current cyberattacks that use the flaws as a conduit. Patches to repair the bugs are available via the online bulletins, and the company urges people to install those as soon as possible.

Broken Windows
Tuesday is Microsoft's first official Patch Tuesday of 2006. However, the company broke its monthly patching program last week to deliver a fix for another serious flaw in Windows. That bug, related to the way the operating system renders Windows Metafile images, is being used in exploits, experts have said.

On Monday, two new Windows image problems were reported on a popular e-mail list. Microsoft acknowledged those issues, but said they are performance problems, not security vulnerabilities.

The new Exchange and Outlook vulnerability affects all current versions of the software except Exchange 2003 with Service Pack 1 or Service Pack 2, Microsoft said. The issue is specific to the processing of mail that uses the Transport Neutral Encapsulation Format protocol, used in sending messages in Rich Text Format. For temporary protection, Exchange users could block TNEF, Microsoft suggested.

The Windows problem was discovered and reported by eEye Digital Security, and the Exchange and Outlook flaw found by Next Generation Security Software.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured