Patch Tuesday Brings 6 Bulletins, 3 are Critical

Microsoft released six security bulletins on Patch Tuesday, including three bulletins rated "critical." All six bulletins involved Windows, and one of the bulletins also involved Internet Explorer.

Altogether, the six bulletins contained patches for nine security vulnerabilities and four of those vulnerabilities were critical.

The most serious of the bulletins is a cumulative security update for Internet Explorer (MS05-038). The bulletin, which also applies to some versions of Windows, addresses three security flaws. Two of those are critical flaws that allow an attacker to take complete control of a computer over the Internet. The other flaw allows information disclosure.

As a cumulative update for IE, the patch does more than patch the three new flaws. It sets a kill bit for older versions of certain objects that have known security vulnerabilities. Those objects include the Microsoft HTML Help ActiveX control, the Microsoft MSAgent ActiveX control and a SharePoint Portal Services logging ActiveX control. The patch also changes the way IE Favorites behaves to close off a class of vulnerabilities.

Another bulletin patches a critical vulnerability found in Windows Plug and Play that can allow remote code execution and elevation of privilege (MS05-039).

The other bulletin involving a critical flaw is MS05-043 for a vulnerability in the Windows Print Spooler Service that could allow remote code execution.

The other bulletins posted Tuesday addressed an important remote code execution vulnerability in the Windows Telephony Service (MS05-040), a moderate denial-of-service vulnerability in the Remote Desktop Protocol (MS05-041) and a moderate vulnerability in Kerberos that could allow denial of service, information disclosure and spoofing (MS05-042). Bulletin MS05-042 patches two flaws; one is rated low, the other moderate.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • Gears

    Top 10 Microsoft Tips and Analyses of 2018

    Here are the year's most popular explainers and how-to columns -- along with some plain, old "Why did Microsoft do that?" musings thrown in.

  • Sign

    2018 Microsoft Predictions Revisited

    From guessing the fate of Windows 10 S to predicting Microsoft's next big move with Linux, Brien's predictions from a year ago were on the mark more than they weren't.

  • Microsoft Recaps Delivery Optimization Bandwidth Controls for Organizations

    Microsoft expects organizations using its Delivery Optimization peer-to-peer update scheme will optimally see 60 percent to 70 percent improvements in terms of network bandwidth use.

  • Getting a Handle on Hyper-V Virtual NICs

    Hyper-V usually makes it easy to configure virtual network adapters within VMs. That is, until you need to create a VM containing multiple virtual NICs.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.