Blog powered by TypePad

« 2 Microsoft Patches Planned | Main | ‘Tis the Season…For Holiday Viruses »

December 14, 2005

Microsoft Fixes Critical IE Flaw

As expected, one of the two patches that Microsoft released yesterday fixes the recent publicly disclosed vulnerability in how IE handles JavaScript “Window()” function calls.  On November 21st an exploit was released targeting this flaw. 

The cumulative patch for IE, MS05-054, also includes previous fixes for the web browser.  The patch fixes a hole in IE’s COM (Component Object Model) that could allow remote code to run on some versions of IE, and fixes for moderately serious vulnerabilities in IE’s File Download Dialog box and HTTPS proxy.

It is highly suggested that you apply this patch as soon as possible as attacks have been reported on this flaw.

The other security bulletin, MS05-055, is rated as important and fixes a hole in the Windows core processing kernel on Windows 2000 machines running SP4.  This vulnerability could allow a user with few security privileges to take control of the Windows 2000 machine once successfully logged in.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834520ea169e200d83523849153ef

Listed below are links to weblogs that reference Microsoft Fixes Critical IE Flaw:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment