winxpfix.com

Home

News

Dual Boot

All Win Tips

Search

BootDisk

Software List

Welcome to Windows XP Fix - Microsoft Patch Tuesday: Six Vulnerabilities Fixed In Four Bulletins

Windows XP Fix ~ Microsoft Patch: Six Vulnerabilities Fixed In Four Bulletins

Menu

Home Page!
WinXP Troubleshooting
WinXP Software Review
WinXP Basics
WinXP Update & add-on
WinXP Recycle Bin Tips
WinXP Messenger Popup
Spy Software Reviews
Tweaking WinXP Tips
WinXP Home Edition
WinXP Pro Editione
XP PowerToys & Tips
WinXp BootDisk Tips
Hacking WinXP?
WinXP Support Tools
WinXP Logon Tips
WinXP Starting Errors
Win File Sharing Progs
Windows xp Support Tip
Software Review List

Site Map!

Advertising on this site

Windows Xp Support

Optimizer
Change XP Start Button
WinXpFix XP Tips List!
Tech Support Xp 3part
Dual Boot WinXP
Upgrading to WinXP
XP BootDisk How To
Basics XP 4 beginners
Clean Boot Windows XP
Recycle Bin Tips
WinXP Burning CDs Tips
Messenger Service Popup
Schedule Tasks Xp Tips
Sharing XP PC Tips
General Tech support XP
Uninstalling WinXP Tips

Software Links

Web News Page
Win Vista News
News Index page
News page

Links Page Here!

Links Soon!

 

Free Background Check &
People Search Click Here!


(?)

Add to My Yahoo!



WinFixZone.com ©2001-2008
Comment or Support Tips

 

 

 

Microsoft Patch: Six Vulnerabilities Fixed In Four Bulletins - Today's News!

 

Welcome! - Yes We Still Love Using Windows
Get your Windows News Fix Here! Win Fix Zone.com

 

Microsoft Patch: Six Vulnerabilities Fixed In Four Bulletins

 

It's Patch Tuesday, and as promised, Microsoft issued its May security fix, addressing six vulnerabilities in four bulletins.

Three of the bulletins describe critical vulnerabilities in Microsoft Word, Microsoft Publisher, and Microsoft Jet Database Engine respectively.

The fourth details a moderate vulnerability in Microsoft's Malware Protection Engine, which powers products like Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security.

All the vulnerabilities addressed this month are client-side vulnerabilities.

MS08-026 fixes two privately reported holes in Word that could have been allowed an attacker to take control of a victim's computer using a maliciously crafted Word file.

MS08-027 fixes a privately reported vulnerability in Publisher that, similarly, could have allowed an attacker to subvert a victim's computer using a maliciously crafted Publisher file.

MS08-028 repairs a publicly reported flaw in the Microsoft Jet Database Engine (4.0) in Windows. If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code, mitigated by the user's administrative rights.

MS08-029 resolves two privately reported issues affecting Microsoft Malware Protection Engine that could have allowed a remote attacker to craft a malicious file that, when scanned, could have allowed the attack to conduct a denial of service attack.

In an e-mailed statement, Ben Greenbaum, senior research manager of Symantec Security Response, stressed that the buffer-overflow bug affecting the Jet Database Engine "is especially critical since there is evidence of hackers already exploiting the vulnerability. While Microsoft database (MDB) files are blocked by default in Outlook, the file can be hidden and renamed. Users may be more inclined to open a well-recognized file type than one with the less well known .mdb extension."

Jason Miller, security data team manager at Shavlik Technologies, concurs. "The biggest thing is going to be the Jet vulnerability," he said in a phone interview. "It affects a wide range of operating systems and it's also publicly known. In addition the scenario to exploit this vulnerability can be easily done."

The first way such an attack might be launched would be through a Web site that entices a victim to download a malicious .mdb file, Miller explained. Another way would be by sending someone a malicious file via e-mail. If the recipient of such a file used Outlook 2003 or 2007 with the Preview Pane active, merely previewing the file would be enough to launch the attack.

Miller also noted that Microsoft was patching its security software. "I think that's pretty important," he said. "If you're relying on security software, you want your security software to work."

While Microsoft characterizes the vulnerability in its Malware Protection Engine as moderate in severity, Miller said that the flaw could be exploited to cause Microsoft's malware scanning software to hang, leaving the affected machine unprotected in the event of a second malware salvo.

Source: AP


Windows Support & Fix Zone
By: WinFixZone.com

 


More Fun Videos Here at - VideoChew.com Check it Out!-

New HOT Software Picks!

Spyware Doctor Free Download, is an advanced adware and spyware removal utility.

evidence eliminator Software - Free Download, This program offers complete protection, eliminating tracks you accumulate online and your PC..

WinXpFix RSS News Feed WinXpFix.com news feed info page!



Windows Software Reviews!
winxpfix.com


Email to your friend!
winxpfix.com

:

 

eMail Page To - Be a Friend! E-MAIL This Page Link to a Friend!
Enter recipient's e-mail:

Top

If you have a Pc/Windows Tip or Comment!

 

Copyright © 2001-2008 WinXpFix.com / WinFixZone.com all rights reserved. Privacy Policy. Reproduction without written permission from WinXpFix.com / WinFixZone.com is prohibited. Other company/product names mentioned herein may be trademarks of their respective owners. This site is NOT responsible for any damage that the information on this site may cause to your system. You are responsible for any damage you cause to your system!