Microsoft's software has 11 bugs. Five of them are marked as "critical"Â, the other five "important"Â and one "moderate"Â. The bugs are in Internet Explorer, Windows Media Player and the Visual Studio 2005. The last minute added patch is for Windows Media Format.
Four bugs of those 11 are in Internet Explorer versions 5.01 and 6.0. Two "critical"Â patches are to fix these bugs which concern scripting problems: scripting error-handling bug, and the scripts which is to Dynamic HTML. Both of these issues are dangerous for web browser users and make users open for web attackers.
Internet Explorer contains more two bugs marked as "important" and "moderate". Both of these bugs can result in unintended disclosure of the files in "Temporary Internet Files"Â folder. The newer version of Internet Explorer 7 is completely patched and is available for Windows XP users.
Third "critical"Â bug is in ActiveX control which is used by Visual Studio 2005. This bug was found only a month ago.
Two more "critical"Â patches are for Windows Media Player. Player users may open malformed .asx files created by hackers, and infect client side computers. This is why Oliver Friedrichs, the director of Symantec's security response group, advises to update Windows Media Players as soon as possible..
Three "important"Â patches concern Outlook Express and Windows itself.
The rest "important"Â patch is for Simple Network Management Protocol, This bug was marked as "important"Â, because the SNMP is not being installed by default. But Gunter Ollmann, the director of IBM's Internet Security Systems X-Force threat research team, says that this patch must be marked as ""Âcritical.
"It may not be a default installed service, but SNMP is widely deployed in enterprises," says Ollmann. "It's pretty much the de facto protocol for monitoring server integrity. This is a critical patch."
All Microsoft patches are available Windows' Automatic Update. These updates ate also available at any Microsoft's service centers.
By Ruzan Harutyunyan for HULIQ
Posted December 13th, 2006 by ruzik_tuzik