July's Security Bulletin From Microsoft Fixes 'Critical' Flaws
The holes affect various Microsoft operating system versions and apps ranging from Internet Explorer 6 SP1 to Windows Server 2003 Gold.
Microsoft on Tuesday released seven bulletins for security problems in Microsoft software that it assessed as "moderate" or "critical." Critical is the software maker's highest security rank. The designation often means the flaw can be exploited by remote attackers and could even be a target for a Sasser-style worm.
The flaws affect various Microsoft operating system versions and apps ranging from Internet Explorer 6 Service Pack 1 to Windows Server 2003 Gold.
Microsoft Security Bulletin MS04-023 addresses critical vulnerabilities within HTML Help. According to the bulletin, an attacker who exploited the most serious of these vulnerabilities could take complete control over an unpatched system. "We recommend that customers apply the update immediately," the bulletin warns.
Another patch that's part of bulletin MS04-022 addresses an unchecked buffer, or buffer overflow, error found within Microsoft Task Scheduler. According to Microsoft, it's possible for an attacker to gain complete control over a vulnerable system, including the ability to delete data and create new user accounts with full-access privileges.
More information about the vulnerabilities published today is available here.
Microsoft plans a Webcast Wednesday afternoon designed to help customers deploy July's security patches.
This month's scheduled patches came the same day the company revised its release date for a new patch-management tool, Windows Update Services. Windows Update Services, or WUS, is now due the first half of next year.
In an E-mailed response to questions regarding the delay, a Microsoft spokeswoman said that incorporating user feedback from WUS beta users is part of the delay. Also, Microsoft is developing a new automatic-update agent in Windows XP Service Pack 2 next month.
Building A Mobile Business MindsetAmong 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps – and it's past time for those with no plans to get cracking.