Windows gets big security update


Recommended Posts

One of the biggest security updates for more than a year is being released by Microsoft to fix 12 software flaws.

Nine of the updates apply to the Windows operating system and one is deemed critical, a rating reserved for the most serious security problems.

At least one of the loopholes being patched is already being actively exploited by malicious hackers.

Windows users are being urged to download the patches as soon as they become available on Tuesday 13 June.

Support shift

Microsoft issues its security patches on the second Tuesday of every month and June's update will be the biggest for more than a year.

This is because Microsoft is not only tackling security problems but also the fallout of a legal case that the software giant lost.

Microsoft gives advance notice of what is in its security patches to help companies plan how best to install the software and limit the impact on day-to-day business.

While most of the updates apply to Windows, two are for the Office suite of products and one for the Exchange e-mail server software.

One of the security problems being tackled in Office was found in Microsoft's Word software and the virus created to exploit it has been dubbed Backdoor.Ginwui. The virus and loophole were first discovered in mid-May.

The virus travels in an e-mail bearing a Word document that purports to summarise the results of a US-Asia summit.

Legal woes

Another of the updates has come about as a result of a courtroom clash between Microsoft and Eolas over technology in the Internet Explorer browser. The lawsuit ended with a $521m (?283m) judgement against Microsoft.

Microsoft had to re-engineer Internet Explorer to stop a technology known as ActiveX automatically starting when users visit some websites.

Before now, users could choose to apply this change to their browser, but this update makes it mandatory.

At the same time as information about the update was being released, Microsoft mentioned that it will not be able to patch Windows 98 and ME against a loophole discovered in April 2006.

Fixing this bug in the ageing software would require a major re-write of the Windows Explorer program used in these old copies of the operating system.

Microsoft is not prepared to undertake this work, given that all support for Windows 98 and ME ends on 11 July 2006.

On its security blog Microsoft wrote: "We strongly recommend that those of you who are still running these older versions of Windows upgrade to a newer, more secure version, such as Windows XP SP2, as soon as possible."

Source:

http://news.bbc.co.uk/1/hi/technology/5071656.stm

Link to comment
https://www.neowin.net/forum/topic/469655-windows-gets-big-security-update/
Share on other sites

Thanks for the info.

Btw: it would be intresting to know how Vista (B2) handles these flaws - as it got public before these fixes. I really like to hear a statement, like "Vista doesn't need these fixes, because of the rewritten network parts: it defends you from these flaws out of the box". :p But i have a feeling it won't happen... :rolleyes:

High-priority updates

Microsoft Windows XP

Windows Malicious Software Removal Tool - June 2006 (KB890830)

Security Update for Windows XP (KB914389)

Security Update for Windows XP (KB918439)

Security Update for Windows XP (KB911280)

Security Update for Windows XP (KB917953)

Microsoft Office 2002/XP

Security Update for Word 2002 (KB917335)

Security Update for PowerPoint 2002 (KB916519)

Download size: 7.3 MB , less than 1 minute

Microsoft has released a security update for Microsoft PowerPoint 2002. This update resolves a security issue that could allow arbitrary code to run when you open a malicious presentation. Details...

(dunno why thats showing up,I'm not even using Powerpoint 2002,I'll save myself 7.3MB by not installing it,thus making my total download 8.5MB instead of 15.8MB)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Adobe Acrobat Reader DC 2026.001.21651 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The consumer ESU is ending in 4 months. LTSC isn't now, never has been, and never will be for consumer use, it is for OT usage - plant machinery, medical devices, manufacturing equipment etc. LTSC requires a Microsoft EA. You can't legally obtain LTSC to run on your PC at home.
    • Hmm actually looks decently interesting!  
    • Being on GitHub doesn't make something safe. Like any unofficial scripts to do x or y this caters to people with just enough knowledge to be dangerous. If you want to do what this does, and you actually know what you're doing then write your own script (or maybe just add the reg keys yourself) if you don't have the ability to read and understand what a script is doing, and especially don't run it with elevated privileges. Or in this case just use an MSA, sign up the normal route, and stop trying to push water up hill
  • Recent Achievements

    • Week One Done
      JKR earned a badge
      Week One Done
    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      489
    2. 2
      PsYcHoKiLLa
      271
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      64
  • Tell a friend

    Love Neowin? Tell a friend!