About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Ten security patches
Ten security patches
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Microsoft issues patches for 21 software flaws

'Critical' vulnerabilities could allow attackers to gain complete control

Iain Thomson, vnunet.com 13 Oct 2004
ADVERTISEMENT

Microsoft has released 10 security patches for 21 weaknesses, in the company's largest security bulletin of the year.

The seven 'critical' and three 'important' patches variously affect versions of Windows, Internet Explorer, Windows Server 2003 and Excel.

All the critical flaws allow attackers to gain complete control over infected systems, turning them into 'zombie' machines to send out spam.

In one instance, a malicious programmer could instruct a computer to use all its available memory, forcing users to restart.

Microsoft has also re-released last month's patch for the vulnerability in its JPEG handling software.

"This is going to take a little time to patch properly but the results will be beneficial," said Professor Neil Barrett of Cranfield University's computer science department.

"As part of the monthly schedule, enterprises will be ready to install and update the IT infrastructure."

Microsoft said that all the critical updates in this month's release are already included in Windows XP Service Pack 2.

Customers running XP SP2 who have enabled Automatic Updates will automatically receive the sole update that applies.

Those users with Windows XP SP2 are unaffected by any of the critical patches but will have to do some repair work. Patch 38 is only rated as important for SP2 users, while for the rest it is critical.

"There's no great reason for the amount [of patches]," said Simon Conant, Microsoft's security programme manager. "To reduce the impact of any class of problem is the purpose of Service Pack 2."

See also:

Serious security vulnerabilitiesMillions at risk from 'silent and remote' attacks, claims security firm  11 Nov 2004
Trustworthy ComputingTrustworthy Computing programme lives on  04 Nov 2004
Service Pack 2 migration fearsStudy claims half of IT managers expect migration 'issues'  03 Nov 2004
Istanbul collaboration clientIstanbul client designed to integrate IM, voice and video  20 Oct 2004
Sans InstitutePatching could reduce viruses, spam and cyber-exortion, says Sans Institute  11 Oct 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | VOSA
Management Information Analyst - Up to £30,231 plus benefits - South West This is an excellent opportunity for an experienced Business Analyst or an ambitious Information Analyst to influence a national organisation and contribute to ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Middle Tier solution Designer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
London, United Kingdom | BP
Project Manager - £ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. ... more >
United Kingdom | ESRC
Web/Project Manager - £33,118 to £35,694 + Benefits Cutting-edge research is our business. You'll give us the cutting-edge web technologies to match. The Economic and Social Research Council is the UK's leading research agency for ... more >
More job opportunities
ADVERTISEMENT