Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
8,064 Members
165,822 Posts
41 Users Online

Please welcome our newest member, freeza!

Affiliates
Go Back AdminFusion » The Break Room » Off Topic » Microsoft Patches Two Critical Flaws
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 01-13-2006, 10:58 AM   #1

shellspeare's Avatar

Title: Forum Enthusiast

Points: 16,350, Level: 38Points: 16,350, Level: 38Points: 16,350, Level: 38
Level up: 39%, 100 Points neededLevel up: 39%, 100 Points neededLevel up: 39%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2005

Posts: 2,521

Location: England

shellspeare is on a distinguished road
Send a message via MSN to shellspeare  
 
Arrow Microsoft Patches Two Critical Flaws

Microsoft Patches Two Critical Flaws
source: http://www.pcworld.com/news/article/...124336,00.asp#

Software giant issues fixes for Windows, Outlook, and Exchange.

Robert McMillan, IDG News Service
Wednesday, January 11, 2006
Microsoft has released patches for two critical security flaws in its software products. The patches fix a problem in the Windows operating system, as well as a bug in the Outlook and Exchange messaging software, all of which could theoretically be exploited by attackers to seize control of an unpatched computer.

The Windows bug relates to the way the OS processes embedded Web fonts, which are used by Web page authors to ensure that their pages are displayed exactly as intended. By tricking a user into visiting a Web page with a specially formed embedded Web font, an attacker could, in theory, "take complete control of an affected system," Microsoft warned on its Web site.

The second vulnerability relates to the TNEF (Transport Neutral Encapsulation Format) encoding format used by Outlook and Exchange. In theory, attackers could send specially crafted e-mail messages to unpatched Exchange servers or Outlook clients that could then be used to seize control of the systems running the messaging software.


Not as Serious
Because hackers have not yet published code that shows how to exploit these bugs, the two vulnerabilities are not considered as dangerous as the Windows WMF (Windows Metafile Format) flaw that Microsoft patched late last week. But the flaws are critical, and security experts suggest that it may only be a matter of time before they are exploited.

The Web fonts bug seems like it will be the easier of the two for attackers to exploit, said Alain Sergile, technical product manager for Internet Security Systems' X-Force research team. But because the TNEF bug can affect server software as well as the client, it is particularly noteworthy, he said. "We deem this one very critical and very serious because of the criticality of Exchange within organizations," he said.

Microsoft rates the Web fonts bug as critical for Windows 98, 2000, and XP users. The TNEF flaw is rated critical for Outlook 2000, 2002, and 2003, as well as Exchange Server 5.0 and 5.5 and Exchange 2000 server. This latter flaw also affects users running the Office Multilingual User Interface Packs.
__________________
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Releases Three Windows Patches shellspeare Off Topic 0 04-12-2006 12:36 PM
Microsoft Warns Against Outside Fixes shellspeare Off Topic 0 04-03-2006 01:17 PM
Microsoft Seeks Online Partner shellspeare Off Topic 5 12-25-2005 03:46 PM
Microsoft plans a critical patch on Tuesday shellspeare Off Topic 1 12-09-2005 11:15 AM
Microsoft Announce.. shellspeare Off Topic 0 11-13-2005 01:58 PM

AdminFusion

All times are GMT +1. The time now is 08:55 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72