Home > Security News > Microsoft issues Windows, MSN Messenger updates
Security News:
EMAIL THIS

Microsoft issues Windows, MSN Messenger updates

By Robert Westervelt, News Editor
11 Sep 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

In a relatively light monthly bulletin release, Microsoft, Tuesday, issued an update to Windows 2000 that patches a critical flaw that could allow an attacker to gain remote access to a system.

Microsoft said a flaw in the way Microsoft Agent – the pesky paper clip that pops up in Microsoft Word – handles certain specially crafted URLs within Windows 2000, leaves the operating system vulnerable to attack. In its MS07-051 update, Microsoft said the vulnerability affects Microsoft Windows 2000 Service Pack 4.

"I refer to this as the return of Clippy," said Eric Schultze, chief security architect at Shavlik Technologies LLC, in Roseville, Minn. "If I visit a malicious Web site the exploit code can try to call Clippy and pass bad data to crash him and as a result, pass remote code onto a system."

Microsoft pulled back an update that would have plugged an elevation of privilege flaw affecting Windows SharePoint Services 3.0 on Windows Server 2003 and Office SharePoint Server 2007. Schultz said the flaw likely didn't pass a second or third round of testing. Instead, Schultze advised administrators to use the relatively light month to prepare for daylight saving time (DST) issues when clocks "fall back" in October.

Hardware purchased after the round of updates that address the DST issue could be at risk of having DST issues, Schultze said. Microsoft has released an updated DST patch to address the issue.

"Any computer purchased and installed since March doesn't have a patch on it," he said.

In addition to the Windows 2000 patch, the software giant issued three other security bulletins dealing with a remote code execution flaw in MSN Messenger and Windows Live Messenger, a code execution flaw in some installs of Visual Studio, and an elevation of privilege vulnerability in Windows Services for Unix 3.0. The updates were rated "important."

An MS07-054 update to MSN Messenger patches a flaw that could allow an attacker to conduct code execution remotely. In order for an attacker to pull off the exploit, a user must accept a video chat invitation.

The MS07-052 update addresses a code execution vulnerability existing on some systems when a custom version Crystal Reports is installed with some versions of Visual Studio. The vulnerability could allow remote code execution if a user opens a specially crafted RPT file.

MS07-053 addresses an elevation of privilege vulnerability in Windows Services for UNIX 3.0, Windows Services for UNIX 3.5, and Subsystem for UNIX-based Applications within Windows. The components are part of Windows Server 2003 and Windows Vista but are not installed by default.

Microsoft said no version of Windows is vulnerable to the MS07-052, the Crystal Reports for Visual Studio bulletin, and MS07-053, the Services for UNIX bulletin. But Microsoft said the updates should be applied if the Subsystem for UNIX-based Applications was enabled or if the Windows Services for UNIX 3.0 or 3.5 was installed.



Tags: Security Patch ManagementWindows Security: Alerts, Updates and Best PracticesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Patch Management
Squad: Tokenization, Phishing and the Feds
Should management processes change based on a patch release schedule?
Should Windows Mobile updates come from Microsoft?
Adobe updates ColdFusion, JRun, Flex
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
How to manage patches for Adobe
When is it suitable to remove Java updates?

Windows Security: Alerts, Updates and Best Practices
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending
Attackers target Microsoft IIS; new SMB flaw discovered
Microsoft repairs Windows media, TCP/IP vulnerabilities
Microsoft five critical updates won't include IIS

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
attack vector  (SearchSecurity.com)
back door  (SearchSecurity.com)
ethical worm  (SearchSecurity.com)
Patch Tuesday  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts