Welcome | Sign In
TechNewsWorld.com
Exploits & Vulnerabilities

Microsoft Preps 3 Critical Fixes for Patch Tuesday Release

Print Version
E-Mail Article
Reprints
Microsoft Preps 3 Critical Fixes for Patch Tuesday Release

Though Microsoft's June Patch Tuesday release is relatively small, with only seven fixes in all, three of them are rated "critical." Users who fail to install the updates could be leaving their systems vulnerable to remote hijacking.


Microsoft (Nasdaq: MSFT) plans to issue seven security updates -- three of which are rated "critical" -- in its monthly Patch Tuesday release next week.

Several of the patches deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with preventing remote code execution (RCE). Attackers could potentially take advantage of vulnerabilities by remotely running malicious code and gaining access to an unsuspecting user's computer.

The listed fixes are designed to correct a variety of problems with Internet Explorer that affect Windows 2000, Windows XP, Windows Vista and Windows Server 2003.

Critical Patches

One critical fix focuses on the way Bluetooth, a wireless protocol utilizing short-range communications technology, works with various Windows components and the Windows XP, Server 2003 and Vista operating systems.

Another critical fix pertains to every version of Internet Explorer from IE 5.01 through IE 7. Several operating systems are affected: Windows 2000, XP, Windows Server 2003, Vista and Windows Server 2008.

Also among the critical fixes is one that deals with DirectX, a collection of application programming interfaces designed for handling multimedia tasks such as game programming. This update affects Windows 2000, Vista, and Windows Server 2003 and 2008.

Important and Moderate Fixes

In addition to the three critical patches, Microsoft is rolling out three patches rated "important" and one rated "moderate."

One of the important patches affects all versions of Windows Server 2003 and includes a fix for Windows Internet Name Service (WINS), which acts as a central mapping of host names to network addresses. This update prevents hackers from intruding and gaining unauthorized administrative privileges.

Another important patch affects Active Directory settings in Windows XP, Windows Server 2003 and some versions of Windows Server 2008. The main purpose of Active Directory is to provide central authentication and authorization services for Windows-based computers. It also permits administrators to assign policies, utilize software, and apply critical updates to an organization. This fix prevents hackers from locking authorized users out of their systems through denial-of-service exploits.

The third important patch deals with file transfers.

The moderate patch involves the "kill bit" function, which is a method that users can employ to shut off ActiveX controls in IE.

Besides the seven patches, Microsoft is releasing an update of its Windows Malicious Software Removal Tool on Tuesday. The update will be distributed via Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

Microsoft will provide more specific information when it officially posts the bulletins on Tuesday, company spokesperson Allison Hammer told TechNewsWorld.


Print Version E-Mail Article Reprints More by Lisa Klink


More by Lisa Klink

Los Angeles Mad as Hell at Time Warner
June 05, 2008
Los Angeles City Attorney Rocky Delgadillo is on the warpath against Time Warner Cable. After it absorbed Adelphia and took over as cable provider for the city, a civil lawsuit alleges, TWC engaged in illegal practices that left customers helpless -- and paying through the nose for services that ranged from shoddy to nonexistent.
Hong Kong Tops McAfee's Riskiest Web Domains Chart
June 04, 2008
In an effort to illuminate the Web's darkest, most dangerous back alleys, security firm McAfee has released a report warning consumers to steer clear of sites with domain name extensions that are havens for scammers. Hong Kong's .hk domain topped the list of undesirables, but the group responsible for registering .hk sites claims it has already improved safety practices there.
Wikia Search Invites Users to Stir the Pot
June 03, 2008
Wikia has a different idea of how a search engine should operate: Humans should be involved. Toward that end, it has retooled its fledgling open source Wikia Search tool to allow users to collaborate on refining results.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network