Microsoft Patches Windows, Exchange - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Microsoft Patches Windows, Exchange

In the usual array of Tuesday patches was one for a third-party product, Adobe's Flash Player.

Microsoft on Tuesday released three security bulletins that patched a quintet of vulnerabilities sprinkled among Windows, the Exchange e-mail server, and -- for the first time analysts could recall -- a third-party product.

Two of the three bulletins were tagged as "critical," including MS06-019, which patches a flaw in Exchange Server, and MS06-020, which involved the third-party product, Adobe's Flash Player.

"This [the Flash flaw] is the one that will be most disruptive to the most users," said Chris Andrew, vice president of security technologies at patch and vulnerability management developer PatchLink.

Windows XP SP1, Windows XP SP2, Windows 98, and Windows Millennium are bundled with a vulnerable version of Flash, said Microsoft in its alert, and users should update their copies immediately.

According to Microsoft, the Flash Player can be exploited by attackers armed with specially-crafted .swf (Flash animation files) using one of two different bugs. Either vulnerability can be used by hackers, most likely via silent drive-by downloads off malicious Web sites, to hijack PCs. In Microsoft's Internet Explorer, which is typically where Flash animations are rendered, Flash is an ActiveX control.

"Third party vulnerabilities, when those third-party products are bundled with Windows, must be patched just as if they were Windows bugs," explained PatchLink's Andrew.

Last month, Adobe had warned users of the bugs, and told them to update Flash. For its part, Microsoft issued a security advisory at the same time recommending that users upgrade. Tuesday's bulletin formalizes the advice by pushing updates to Windows XP users via Windows Update, Microsoft Update, and other mechanisms from the Redmond, Wash.-based developer. However, Windows 98 and Millennium users were told in the bulletin to head to Adobe's Web site to update Flash themselves.

E-mail Flaw

The critical MS06-019 bulletin patches a flaw in Exchange Server 2000's and Exchange Server 2003's calendaring function. The vulnerability could let attackers grab control of mail server systems. End-user clients -- desktops running the Outlook e-mailer, for instance -- are not affected.

"This is the most serious of the three," argued Mike Murray, director of research at vulnerability management vendor nCircle, taking a different tack than Andrew. "Exchange is pretty widely adopted. The mitigating factor is that they're usually behind a firewall."

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
1 of 2
Comment  | 
Print  | 
More Insights
The State of Cloud Computing - Fall 2020
The State of Cloud Computing - Fall 2020
Download this report to compare how cloud usage and spending patterns have changed in 2020, and how respondents think they'll evolve over the next two years.
Why 2021 May Turn Out to be a Great Year for Tech Startups
John Edwards, Technology Journalist & Author,  2/24/2021
How GIS Data Can Help Fix Vaccine Distribution
Jessica Davis, Senior Editor, Enterprise Apps,  2/17/2021
11 Ways DevOps Is Evolving
Lisa Morgan, Freelance Writer,  2/18/2021
Register for InformationWeek Newsletters
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you.
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll