Breaking News

EnGenius Announces Affordable ECW520 Access Point KIOXIA Announces Industry’s First 245.76 TB NVMe SSD Built for the Demands of Generative AI Environments DeepCool Releases GENOME III, a Flagship Full-Tower Case for Extreme Cooling and Intelligent Monitoring CORSAIR Launches VENGEANCE 7000 AIR Series Gaming PC, Built with FRAME 4000D Case Elgato Brings 4K60 Game Capture to the Masses

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft offers patches for seven 'critical' flaws

Microsoft offers patches for seven 'critical' flaws

Enterprise & IT Nov 14,2006 0

Microsoft Corp. today released six security bulletins detailing patches for nine separate flaws across several of its products as part of its monthly updates for November. Seven of the flaws were rated "critical" by the company, while the other two were rated "important."

The most dangerous of the vulnerabilities in this month's batch is a flaw in Microsoft's Workstation Service memory, according to security vendor Symantec Corp. The flaw is remotely executable and allows attackers to potentially take complete control of compromised systems to create new user accounts, install programs and view, modify or delete data.

"A successful exploitation of this vulnerability could result in a complete system compromise," Symantec said in its advisory. "This issue can be exploited by remote anonymous attackers on Windows 2000, Windows XP and possibly Windows Server 2003 systems." Symantec added that a wide variety of component technologies and services are affected by this issue.

A remotely exploitable flaw in Microsoft XML Core Services poses another critical threat to enterprises because it has already been publicly disclosed, said Michael Sutton, security evangelist at Web application security firm SPI Dynamics Inc.

As with the Workstation Service flaw, attackers who successfully exploit this vulnerability could take complete administrative control of systems, Microsoft said in its advisory. Enterprises need to make patching this flaw a top priority because public exploits have already started becoming available, Sutton said.

Also important from an enterprise standpoint is the cumulative update Microsoft issued today to fix three separate remotely exploitable vulnerabilities in Internet Explorer, Sutton said. Two of the flaws addressed in the bulletin -- both involving DirectAnimation ActiveX controls -- have already been publicly disclosed, and exploit code for them has begun circulating, he said. November's security update is smaller than others this year in terms of the overall number of patches announced, according to Mark Allen, data manager at Shavlik Technologies LLC. "But the percentage that are critical and remotely exploitable is still pretty high," he noted. Patches for those are definitely worth deploying as quickly as possible, he said.

All of the flaws addressed by the current set of fixes -- except for the one in Workstation Service -- can be exploited over the Internet, though they require users to either go to malicious Web sites or click on malicious e-mails, Allen said.

The Workstation Service flaw, on the other hand, only requires an attacker to send a specially crafted packet to the network to be exploited, he said. "The potential for exploiting this one is pretty high," he added.

Tags: Microsoft
Previous Post
Samsung Powers up 2.5" HDD Line with 160GB
Next Post
Intel Ignites Quad-Core Era

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

EnGenius Announces Affordable ECW520 Access Point
Enterprise & IT

EnGenius Announces Affordable ECW520 Access Point

KIOXIA Announces Industry’s First 245.76 TB NVMe SSD Built for the Demands of Generative AI Environments
Enterprise & IT

KIOXIA Announces Industry’s First 245.76 TB NVMe SSD Built for the Demands of Generative AI Environments

DeepCool Releases GENOME III, a Flagship Full-Tower Case for Extreme Cooling and Intelligent Monitoring
Cooling Systems

DeepCool Releases GENOME III, a Flagship Full-Tower Case for Extreme Cooling and Intelligent Monitoring

CORSAIR Launches VENGEANCE 7000 AIR Series Gaming PC, Built with FRAME 4000D Case
Cooling Systems

CORSAIR Launches VENGEANCE 7000 AIR Series Gaming PC, Built with FRAME 4000D Case

Elgato Brings 4K60 Game Capture to the Masses
Consumer Electronics

Elgato Brings 4K60 Game Capture to the Masses

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed