Microsoft Posts Critical Windows Bulletin

A new Microsoft security bulletin includes patches for three Windows flaws, two of them critical problems that can permit attackers to take control of a system over the Internet.

All three flaws that are addressed in bulletin MS05-053 arise from the way Windows renders graphics from Windows Metafile (WMF), Enhanced Metafile (EMF) or both of the image formats. The bulletin posted Tuesday.

The first flaw, involving an unchecked buffer in the rendering of WMF and EMF, is critical for Windows 2000, Windows XP even with Service Pack 2 and Windows Server 2003 even with Service Pack 1.

The second flaw, stemming from an unchecked buffer in WMF rendering, is also critical for Windows 2000, Windows XP SP1 and the gold code version of Windows Server 2003. Windows XP SP2 and Windows Server 2003 SP1 are unaffected by the flaw.

An unchecked buffer in EMF rendering is the source of the third flaw. It is moderate for Windows 2000, Windows XP SP1 and Windows Server 2003. Again, Windows XP SP2 and Windows Server 2003 SP1 are unaffected.

Neither of the critical flaws had been publicly disclosed. The moderate flaw had been disclosed but Microsoft has not received any reports of exploit code being developed for it.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • Microsoft Ups Its Windows 10 App Compatibility Assurances

    Microsoft gave assurances this week that organizations adopting Windows 10 likely won't face application compatibility issues.

  • SharePoint Online Users To Get 'Modern' UI Push in April

    Microsoft plans to alter some of the tenant-level blocking capabilities that may have been set up by organizations and deliver its so-called "modern" user interface (UI) to Lists and Libraries for SharePoint Online users, starting in April.

  • How To Use PowerShell Splatting

    Despite its weird name, splatting can be a really handy technique if you create a lot of PowerShell scripts.

  • New Microsoft Customer Agreement for Buying Azure Services To Start in March

    Microsoft will have a new approach for organizations buying Azure services called the "Microsoft Customer Agreement," which will be available for some customers starting as early as this March.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.