Web pick: ADrive
Have data, will lose. Well, you will if you don't back it up, so ADrive may help save future headaches. »more
Imagine Cup in Paris
ENN follows two Irish teams as they compete in the Imagine Cup. »more
Cut the paper chase
Save time and get your morning tech news fix with ENN's 'In The Papers' newsletter »more

Microsoft patches nine flaws in update
10-10-2007
by Ciara O'Brien

Microsoft has released six security bulletins for its software, but held back a patch that had been expected for an unnamed flaw in Windows 2000 and Server 2003.

The regular monthly 'Patch Tuesday' bulletin fixes nine security flaws, four of which have been rated as critical and affecting versions of Word, Internet Explorer, Outlook Express, and the Kodak Image Viewer.

Two fixes, rated as "important", cover Windows SharePoint and the remote procedure call (RPC). However, a further update for the Windows 2000 and Server 2003 flaw was pulled because of what Microsoft termed "quality control issues".

The critical flaw found in Word is causing particular concern as it has already been the subject of attack. Using a specially-crafted Word document, the flaw could be exploited for remote code execution, and has already been abused in the past, according to analysts.

The IE patch, meanwhile, is a cumulative update and covers a memory corruption in Internet Explorer that could lead to remote code execution, and also multiple address bar spoofing vulnerabilities. The spoofing flaw is of particular concern with regards to phishing attacks.

The vulnerability in Windows 2000's Kodak Image Viewer could allow hackers to take control of a user's PC, through the opening of an infected image. Although Microsoft says this flaw isn't being actively exploited, experts disagree and recommend that the patch be installed as quickly as possible.

Vista users will need to be mindful of this particular update too -- three of the patches affect users of the new operating system, including the RPC exploit, the IE patch and the security Update for Outlook Express and Windows Mail.

This month's patch bundle compares unfavourably to September when the 'Patch Tuesday' update identified only one critical flaw and included patches for only four flaws in total -- a record for 2007. The biggest batch of 2007 was released in February, when 20 vulnerabilities were fixed in a security bulletin that consisted of 12 patches. Running a close second was August's security update, when 14 flaws were fixed in nine security updates and eight of these security holes were rated as "critical".

Create eAlertPrinter-friendly versionemail a friendRSS feed
ENN Blog
Innovation fund foments ideas
There's no question that people like a challenge. Especially so when there's a cash prize involved. That's why it's genuinely interesting to see what people » Read more
spacer

 Get RSS Feed
Choose one or all of our RSS Newsfeed Channels
» Find out more
Top News
The Government has pledged to tackle the thorny digital divide issue as it promises broadband for all by early 2010. » Read more

Who's who in pr
Full listing of Irish PR firms, including high-tech specialists. » Click here
subscribe
Not a member yet?
Sign up free, click here
To change your ENN Newsletter and alerts preferences here
spacer
opinion
Bringing science back to life
Science courses continue to prove unpopular with students, but some new initiatives are trying to change that trend.
» Read more
Hosted by Telecity
enn corporate
Complete copywriting services
ENN CorporateDo you need skilled writers to put together compelling prose for your company? Why not check out the new-look corporate services site from ENN and see how we can put our skills to your use.»more
events
22 July
Introduction to IT Security for Internal Audit
9:15am, Espion Training Centre
» View more events
» Post your event on ENN
reader survey
Let us know how to make ENN better! Take our reader's survey.