Seven Patches Coming From MicrosoftMicrosoft expects to release seven security patches with four "Critical" and three "Important" bulletins as part of its upcoming Patch Tuesday release.
The critical patches affect Windows Server Service Packs for 2000 and 2003 versions as well as Internet Explorer, versions 5 through 7 and Outlook Express for Windows 2000, 2003 and Windows XP. The common thread of the four "critical" patches is their remote code execution (RCE) implications, a risk consideration that has been pretty consistent over the last few patch release announcements. Microsoft suggests using Baseline Security Analyzer to flesh out any potential bugs or problems.
Meanwhile, the three "important" issues are more varied in nature, with two bulletins affecting almost all Windows OS and server versions, including multiple service pack releases of Windows 2000 and 2003, XP and Vista. A third patch is related to Windows SharePoint Services.
The first important bulletin, given its breadth in affecting every Windows OS program, bears watching. That bulletin pertains to the prospect of denial of service attacks, which are attempts to make IT resources unavailable, locking users out of programs and applications.
The second important item deals with spoofs, also known in techie world as "masquerade ball" attacks, where a hacker as a user or malicious program passes his/itself off as another user/program using erroneous data and gaining unwarranted Read and/or Write access. This would affect all OSes except XP and Vista.
The last important patch affects all versions of SharePoint services and remedies concerns over potential elevation of privilege attacks, where malicious users can change profile settings, usurp access configurations and gain greater entry into the system than intended.
Continue At Source
Send via e-mail | Submit to Digg | Add to Live Favorites
http://feeds.feedburner.com/~r/binkdotnu/~3/165399747/seven-patches-coming-from-microsoft.aspx