• On BNET: 24 killer apps for a flash drive

February 8, 2005 3:07 PM PST

Microsoft releases 'critical' patches

Related Stories

Microsoft: SP2 shimmy's not a flaw

February 1, 2005

Patching up problems

January 28, 2005

Expert: Flaw still dogs Windows patch

January 24, 2005
Microsoft on Tuesday released a higher-than-usual number of monthly updates, more than half of which were given the software company's highest rating of "critical."

The software giant announced a dozen updates, eight of which were given its highest severity rating. Microsoft's Office XP, Internet Explorer 6 and an image file component of the Windows operating system for Media Player and MSN Messenger were among the updates dubbed critical.

"This is their second-largest bulletin release since they started doing these monthly updates, except for the 24 bulletins they released last year," said Vincent Gullotto, vice president of the antivirus emergency response team for security specialist McAfee. "But it's common to see this kind of ratio of critical bulletins."

Among the patches is a significant cumulative fix to resolve some of the underlying vulnerabilities of IE that have already been made public. Microsoft said those flaws have not yet been widely exploited.

"There is public exploit code out there for some of the IE vulnerabilities we are patching, but we have not heard of any widespread attacks," said Stephen Toulouse, a Microsoft security program manager.

The update for IE is designed to address vulnerabilities such as an attacker taking control of a system and installing programs; changing, deleting or viewing data; or creating new accounts with full user rights.

IE 6 with Service Pack 1 running on systems featuring Windows XP, with or without Service Pack 1, or Windows 2000 with Service Pack 4 or 3, are affected by this vulnerability.

The scheduled updates come as Microsoft announced plans to acquire security software developer Sybari Software and as it enters its fourth year of its Trustworthy Computing initiative to make its applications more reliable.

The latest flaws add to the many security headaches for businesses. One analyst urged consumers to automatically patch their systems to avoid such exploits but said that for businesses, it's not so easy.

"If I was John Doe consumer, I would have my auto-update turned on so it automatically installs the Microsoft updates," said Mark Nicolett, a Gartner analyst. "But for a corporation, it's not quite so simple. You have to do some level of quality control testing to make sure you're not affecting some of the applications you need to run for business."

See more CNET content tagged:
bulletin, service pack, Microsoft Internet Explorer 6, vulnerability, patch management

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right