May 9, 2006

Start Your Patching Engines - May Patch Roundup

sw-0019As we previously mentioned, there’s two Windows Patches and One for Exchange. Let’s start with the Windows:

MS06-018 - Moderate

  • Denial of Service Vulnerability in Distributed Transaction Coordinator
  • 2 Vulnerabilities fixed with one patch
  • Remotely Exploitable
  • Affected: XP SP1&2, 2000, 2003
  • Non-Affected: 2003 SP1, 98, ME

MS06-020 - Critical

  • Vulnerabilities in Flash Player Could Allow Remote Code Execution
  • Announced by MS because they bundled Flash player since Windows 98.
  • 2 Vulnerabilities in one patch
  • Exploitable by visiting a malicious website, or (rarely) by opening an email.
  • Definitely Affected: XP SP1&2, 98, ME
  • Maybe Affected: Anything else you installed Flash on.

The Exchange one is the most tricky and scary:

MS06-019 - Critical

  • Vulnerability in Exchange Could Allow Remote Code Execution
  • Exploited by sending a malicious cal or iCal message through and Exchange server.
  • Breaks Blackberry Enterprise Server and Goodlink functionality (via SANS ISC) But it’s fixable.
  • No workarounds.
  • Affected: Exchange Server 2000, Server 2003 SP1&2

Have fun with this one.

Official Patch Summary [Microsoft]

Share It: del.icio.us:Start Your Patching Engines - May Patch Roundup digg:Start Your Patching Engines - May Patch Roundup reddit:Start Your Patching Engines - May Patch Roundup Y!:Start Your Patching Engines - May Patch Roundup
Read More: Vulnerabilities, Windows
Related: MS06-040 Monday Roundup
 12 Microsoft Patches Next Week
 Symantec Won’t, Will Whine About Microsoft
 0-Day Word Vulnerability Roundup

Post a Comment...

(required)

(required)
(will not be published)

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>