Newsletter:

Skip Navigation LinksHome > News > Security > Microsoft delivers four security fixes

Microsoft delivers four security fixes

By Shaun Nichols
15 May 2008 07:35AM
Tags: microsoft | delivers | four | security | fixes

Microsoft has issued four security patches in its latest monthly update..

The May edition of Patch Tuesday features patches for three issues rated 'critical' and a fourth rated 'moderate'.

All three critical fixes address issues which could allow an attacker to remotely execute code on a target system, while the fourth plugs a denial-of-service flaw.

Among the fixes is a patch for a vulnerability in the Jet Database Engine used by Windows. An attacker could remotely take control of a system by exploiting the flaw in Windows 2000, XP Service Pack 2 and Windows Server 2003.

Windows Vista, XP Service Pack 3 and Windows Server 2008 are not affected by the flaw.

The most dangerous of the vulnerabilities is the Jet Database flaw, according to security firm Symantec.

"This is a relatively light month with four bulletins that cover a total of six vulnerabilities," wrote Symantec researcher Robert Keith.

"The vulnerability affecting Jet Database Engine is the only update of the bunch. Evidence of this issue being exploited in the wild has been detected."

The second critical fix is for a pair of remote code executions in Word. The fix addresses the flaws in Office 2000, XP, 2003 and 2007. The update also addresses a flaw in Office for Mac 2004 and 2008.

The third critical bulletin addresses a remote code execution flaw in Microsoft Publisher that affects Office 2000, XP, 2003 and Office 2007.

The fourth bulletin, given Microsoft's second-highest security rating of 'moderate', fixes a pair of flaws in Microsoft's Malware Protection Engine that could allow a denial-of-service attack.

The Malware Protection Engine is used by eight Microsoft security products, including Windows Live OneCare, Antigen, Windows Defender and Forefront Security.

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
NetIQ's Secure Configuration Manager (SCM) is a combination of client server and web-based components to help...
Star Rating
Secure Bytes Secure Auditor is actually a suite comprised of several different pieces designed to audit...
Star Rating
For this review, I decided to combine these products into a single group of their own. Please keep in mind...
Star Rating
The netVigilance SecureScout EagleBox SP 2.0 is a highly comprehensive vulnerability management product.
Star Rating
The StillSecure VAM appliance is serious vulnerability management in a single device.


TopTopics
(5628) -  microsoft
(3282) -  telstra
(2911) -  network
(2806) -  google
(2711) -  ibm
(2377) -  internet
(2363) -  iphone
(2143) -  intel
(1882) -  optus
(1515) -  broadband
(1408) -  security
(1324) -  business
(1322) -  australia
(1085) -  digital
(1024) -  windows