- BlackBerry Storm vs. the iPhone
- 2008 IT industry graveyard
- Top 10 worst uses for Windows
- Economic crisis means double duty for IT pros
- BlackBerry Storm, RIM's first touchscreen device, rolls in
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Microsoft on Tuesday released a flood of information on new and previously disclosed holes in a wide range of software products, many of them rated "critical" and well-suited to use by malicious hackers or computer virus writers, according to one security expert.
The company published four security bulletins, MS04-011, 012, 013 and 014 containing patches for 20 unique software vulnerabilities. Critical holes were found in the Internet Explorer Web browser, a standard Windows component for managing local system security and authentication, the Microsoft Secure Sockets Layer library (SSL) and Remote Procedure Call (RPC) Runtime Library, which is installed with Windows, Microsoft said.
The software patches touched a wide range of Microsoft's products, from Windows 98 through Windows Server 2003 64-bit edition, as well as a number of versions of the Outlook Express e-mail program.
Among the most critical holes Microsoft warned customers about are:
An attacker who could exploit the PCT hole could take complete control of affected systems, installing programs, viewing, modifying or deleting data or changing user access to the system. Attackers could exploit the flaw by sending a TCP message to a vulnerable system using SSL. The message would have to be designed to cause the buffer overrun and run the attacker's code on the machine, the company said.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment