May 8, 2007 1:47 PM PDT
Microsoft releases 'critical' updates for new programs
- Related Stories
-
Microsoft to patch zero-day DNS flaw
May 3, 2007 -
Attack code raises Windows DNS zero-day risk
April 16, 2007 -
Cybercrooks exploiting new Windows DNS flaw
April 12, 2007 -
Cursor flaw gives Vista security a black eye
April 4, 2007
The company published seven security bulletins as part of its monthly patch cycle. All are tagged "critical," its highest rating. Critical vulnerabilities typically allow an attacker to gain full control of an affected system with very little, if any, action by the user.
Most of the vulnerabilities addressed by Tuesday's fixes can only be exploited after someone visits a rigged Web site or opens a malicious file, attack approaches that are increasingly popular among cybercrooks.
Microsoft's
Exchange is flawed in a way that could allow a system running the e-mail server software to be fully compromised without any special user action. There are four vulnerabilities in Exchange, including Exchange 2007, addressed by Microsoft's
The fact that several of the newly reported vulnerabilities critically affect Internet Explorer 7, Office 2007 and Exchange 2007,
"Microsoft 2007 software, including Exchange and Office, continues to come up vulnerable, demonstrating that the security development lifecycle is not infallible," Sarwate said. Last month's Microsoft patches included a fix for a
Another vulnerability that may affect many users lies in "Capicom," a component to add cryptography to applications. It is flawed in the way it handles specific data, a bug that could let an attacker commandeer a computer running the component, Microsoft said in bulletin
Among Microsoft's updates are fixes for a trio of zero-day vulnerabilities. This includes
The remaining zero-day vulnerabilities for which fixes are now available are in Internet Explorer and Word, Microsoft said. The Word flaw had also been used in cyberattacks, it said.
Microsoft's fixes will be made available to Windows users via the Automatic Updates feature and are also available for download from Microsoft Update and Windows Update.
See more CNET content tagged:
Microsoft Exchange Server 2007,
vulnerability,
fix,
Microsoft Update,
Microsoft Office 2007

Example: Micro$loth security.
"The fact that several of the newly reported vulnerabilities
critically affect Internet Explorer 7, Office 2007 and Exchange
2007, hurts Microsoft's security message, said Amol Sarwate,
manager of the vulnerability research lab at Qualys. Microsoft
has marketed these programs as secure, citing its security
development process."
Maybe we better read over those claims again, did they actually
claim their newest junk offerings were "secure" (a rediculously
stupid claim all by itself - there is no such thing as "secure
software"!), or "the most secure version to date". M$'s security
record is so bad at this point that if they could release
something that only had a thousand major security holes it
could be called a major improvement!
But hey, if you're still drinking Bill's Kool-Aid, you're probably to
high to realize you're being taken for a ride. In that case, enjoy
your slavery!
Microsoft released SEVEN (7) critital security patches during their regular monthly update.
If they had all been discovered the day before... nothing really needs to be read into it at all.
But we all know that several of these zero-day flaws have been out for quite some time.
But rather than act like a security concious company and offer patches for critical flaws within 24 hours... they wait long past the non-critical 72 hour mark and release critical patches on thier Patch Tuesday... only once a month!!!
They ARE NOT serious about security.
Otherwise they would have released patches within 24 hours!!!
Walt
Let's hope they have a fix soon!!
BoB...