News

Cumulative Patch Ships for 3 Critical IE Flaws

More than a month after the Download.Ject vulnerability began exploiting a flaw in Internet Explorer, Microsoft fixed the underlying critical security vulnerability with a cumulative security patch over the weekend. The software giant urged customers to apply the update immediately.

Microsoft released security bulletin MS04-025 Friday evening and updated it on Sunday. The cumulative bulletin includes fixes for three vulnerabilities that are all public and are each critical on some version of IE.

Microsoft's patch is unusual in two respects that underscore its severity. It is only the third time since the company instituted a monthly patch cycle that it has released a bulletin outside of that schedule. One of the other times was last month, when the company released a workaround in advance of the actual patch for the flaw permitting Download.Ject. The other unusual aspect of the patch is that it includes fixes for Windows NT Workstation 4.0 Service Pack 6a and Windows 2000 Service Pack 2. Support for both of those platforms has been officially discontinued.

All three flaws can allow an attacker to take complete control of a user's computer over the Internet.

The one exploited by Download.Ject is called a navigation method cross-domain vulnerability. It is critical for IE 6 SP1 on any platform other than Windows Server 2003, IE 6 and IE 5.5 SP2. A flaw called the malformed BMP file buffer overrun is critical for IE 5.01 with service packs 2 through 4, IE 5.5 SP2 and IE 6. The third flaw, malformed GIF file double free vulnerability, is critical for all supported versions of Internet Explorer, including those running under Enhanced Security Configuration in Windows Server 2003.

The Download.Ject attack emerged in June. The attackers compromised Windows 2000 Web servers using versions of IIS 5.0 that hadn't been patched for an earlier vulnerability. Code appended to those compromised sites was used to compromise the flaw in IE that Microsoft hadn't yet patched.

View Microsoft's security bulletin:
www.microsoft.com/technet/security/bulletin/ms04-025.mspx.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Previews Microsoft Teams for Linux

    Microsoft on Tuesday announced a "limited preview" release of Microsoft Teams for certain Linux desktop operating systems.

  • Hyper-V Architecture: Some Clarifications

    Brien answers two thought-provoking reader questions. First, do Hyper-V VMs have direct hardware access? And second, how is it possible to monitor VM resource consumption from the host operating system?

  • Old Stone Wall Graphic

    Microsoft Addressing 36 Vulnerabilities in December Security Patch Release

    Microsoft on Tuesday delivered its December bundle of security patches, which affect Windows, Internet Explorer, Office, Skype for Business, SQL Server and Visual Studio.

  • Microsoft Nudging Out Classic SharePoint Blogs

    So-called "classic" blogs used by SharePoint Online subscribers are on their way toward "retirement," according to Dec. 4 Microsoft Message Center post.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.