News

Microsoft Fix Roundup: Server Flurry Slows Down

Security administrators had to be on their feet in early May to keep up with all the fixes to Microsoft Corp.'s server products. The last few weeks saw a big slowdown in major server fixes, although some newly discovered client vulnerabilities affect the enterprise.

Early in May, Microsoft released a fix for an IIS 5 vulnerability that could let an attacker take over a server, a fix for a domain controller vulnerability and Windows 2000 Service Pack 2.

Microsoft's three most recent security vulnerabilities hit the Windows Media Player, Word and Internet Explorer. Microsoft recommended customers immediately install the fixes for the Media Player and Word vulnerabilities as both allow attackers to execute code on a target system. Customers using IE only needed to consider the patch, in Microsoft's estimation.

The Media Player vulnerability affects version 6.4 and 7. Customers running Windows Media Player 6.4 were instructed to install the patch, while customers running version 7 were told to upgrade to version 7.1.

Through a buffer overrun, an attacker is able to execute any code on the machine. Mitigating factors are that the attacker must draw a user to a Web page or cause the user to open an HTML attachment. The attacker also must know the operating system being used.

The Word vulnerability allows an attacker to run macros without warning the user. The vulnerability relies on the way versions of Word prior to Word 2002 open Rich Text Format (RTF) documents.

The vulnerability affecting IE 5.01 and 5.5 allows spoofing of trusted Web sites.

"When IE is configured to perform certain types of checking on digital certificates provided by Web servers, it no longer performs other expected checks," Microsoft's bulletin explains. "This could potentially enable an attacker's Web site to masquerade as a trusted site."

The patch rolls in fixes for three other related vulnerabilities, including one that allows an attacker to spoof another site by making it appear that content on the attacker's site is coming from the other site.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • How To Use .CSV Files with PowerShell, Part 1

    When it comes to bulk administration, few things are handier than .CSV files. In this two-part series, Brien demos his top techniques for working with .CSV files in PowerShell. First up: How to create a .CSV file.

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

  • Basic Authentication Extended to 2H 2021 for Exchange Online Users

    Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

  • Microsoft Offers Endpoint Configuration Manager Advice for Keeping Remote Clients Patched

    Microsoft this week offered advice for organizations using Microsoft Endpoint Configuration Manager with remote Windows systems that need to get patched, and it also announced Update 2002.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.