tricore Guest
|
Posted: Fri Dec 08, 2006 5:11 am Post subject: Microsoft fixes 13 flaws with 6 patches |
|
|
Microsoft has released its November 2006 security bulletin, which includes six updates: five are listed as Critical and one as Important. None of the updates this month are specific to Microsoft Office. Users of Windows 98 and Windows Me will notice that Microsoft no longer offers technical support for these two operating systems, nor will Microsoft continue to provide technical support for users of Windows XP SP1. To keep your Windows 98 and Me systems secure, see our roundup of compatible third-party security applications. To keep your Windows XP SP1 system secure, update to Windows XP SP2 today. All Microsoft security patches for Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.
MS06-066: Important
Entitled "Vulnerabilities in client service for NetWare could allow remote code execution (923980)," this bulletin affects users of Windows 2000, Windows XP (SP1 and SP2), and Windows Server 2003 (SP1 and SP2), but not the x64 editions of each, and it addresses the vulnerabilities detailed in CVE-2006-4688, CVE-2006-4689. Successful exploitation could lead to remote code execution.
MS06-067: Critical
Entitled "Cumulative security update for Internet Explorer (922760)," this bulletin affects users of Windows 2000 (SP4), Windows XP (SP2), and Windows Server 2003 (SP1), running Internet Explorer versions 5.01 through 6.x, and it addresses the vulnerabilities detailed in CVE-2006-4446, CVE-2006-4777, and CVE-2006-4687. Successful exploitation could lead to remote code execution.
MS06-068: Critical
Entitled "Vulnerability in Microsoft Agent could allow remote code execution (920213)," this bulletin affects users of Windows 2000 (SP4), Windows XP (SP2 and x64 editions), and Windows Server 2003 (SP1 and x64 editions), and it addresses the vulnerability detailed in CVE-2006-3445. Successful exploitation could lead to remote code execution.
MS06-069: Critical
Entitled "Vulnerabilities in Macromedia Flash Player from Adobe could allow remote code execution (923789)," this bulletin affects users of Windows XP (SP2 and x64 editions) but not Windows 2000 (SP4) or Windows Server 2003 (SP1 and x64 editions), and it addresses the vulnerabilities detailed in CVE-2006-3311, CVE-2006-3014, CVE-2006-3587, CVE-2006-3588, and CVE-2006-4640. Successful exploitation could lead to remote code execution.
MS06-070: Critical
Entitled "Vulnerability in Workstation Service could allow remote code execution (924270)," this bulletin affects users of Windows 2000 (SP4) and Windows XP (SP2) but not Windows XP (x64) and Windows Server 2003 (SP2 and x64 editions), and it addresses the vulnerability detailed in CVE-2006-4691. Successful exploitation could lead to remote code execution.
MS06-071: Critical
Entitled "Vulnerability in Microsoft XML Core Services could allow remote code execution (928088)," this bulletin affects users of Microsoft XML Core Services 4.0 and Microsoft XML Core Services 6.0, and it addresses the vulnerability detailed in CVE-2006-5745. Successful exploitation could lead to remote code execution. |
|