News

Microsoft Puts Out 2 Security Bulletins

Microsoft issued new security bulletins warning users of moderate threats due to vulnerabilities in Internet Explorer and Microsoft Outlook 2002.

The Internet Explorer vulnerability affects versions 5.5 and 6.0 but not 5.01. It is addressed in a cumulative patch for Internet Explorer that can be found at http://www.microsoft.com/technet/security/bulletin/MS02-068.asp.

The new vulnerability involves a flaw in IE's cross-domain security model that arises from IE's incomplete security checks when certain object caching techniques are used on Web pages. The flaw could result in information disclosure.

The flaw in Microsoft's flagship e-mail client exists in the way Outlook 2002 processes e-mail header information. To execute this denial of service attack, an attacker would need to send a specially malformed e-mail to the Outlook 2002 user. The message would cause Outlook 2002 to fail and the e-mail client application would continue to fail until the message is removed from the server. The message removal could be done at the server level by an administrator or by the client using another e-mail client, such as Outlook Web Access or Outlook Express.

The patch for the Outlook 2002 vulnerability can be found at http://www.microsoft.com/technet/security/bulletin/MS02-067.asp.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft 365 Business To Get Azure Active Directory Premium P1 Perks

    Subscribers to Microsoft 365 Business (which is being renamed this month to "Microsoft 365 Business Premium") will be getting Azure Active Directory Premium P1 licensing at no additional cost.

  • How To Use .CSV Files with PowerShell, Part 1

    When it comes to bulk administration, few things are handier than .CSV files. In this two-part series, Brien demos his top techniques for working with .CSV files in PowerShell. First up: How to create a .CSV file.

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

  • Basic Authentication Extended to 2H 2021 for Exchange Online Users

    Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.