Microsoft security update
Microsoft security update

Microsoft warns of seven Windows flaws

More security vulnerabilities, more patches

Written by Robert Jaques

Microsoft yesterday warned of seven security vulnerabilities, two of which it rated as 'critical'.

The company has issued updates for all seven flaws. These include MS04-022, which addresses a vulnerability in Task Scheduler that could allow code execution.

Advertisement

Microsoft explained that if a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges.

The flaw affects Windows 2000 (Service Pack 2, 3 and 4), XP, and XP 64-bit edition Service Pack 1.

Update MS04-023 addresses the other critical flaw, which centres on vulnerabilities in HTML Help and also could allow malicious hackers to run code on compromised Windows PCs.

The flaw affects the same versions of Windows as MS04-022 but also affects Windows Server 2003 and 64-bit edition.

Of the remaining alerts four are rated as 'important' and one 'moderate'. They include MS04-018, a cumulative security update for Outlook Express; MS04-019, concerning a vulnerability in Utility Manager that could allow code execution; and MS04-020, dealing with a vulnerability in POSIX that could allow code execution.

MS04-021 comprises a security update for IIS 4.0, while MS04-024 addresses a vulnerability in Windows Shell that could allow remote code execution.

Further information, and patches for all seven vulnerabilities, can be found here.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Podcast image

02 Oct 2008

14.35 MBComputing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit More...

Shaun Nichols and Iain Thomson

26 Sep 2008

3.43 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation