Microsoft
Microsoft has fixed 'critical' vulnerabilities in Excel 2000, Windows Server 2000 and .Net

Microsoft fixes 11 flaws in latest update

Five 'critical', five 'important', one 'moderate'

Written by Shaun Nichols in California

Microsoft has plugged 11 security vulnerabilities as part of its July Patch Tuesday release. 

Five of the vulnerabilities carry a severity rating of 'critical', five are labelled 'important' and one is labelled 'moderate'.

The 'critical' vulnerabilities affect Excel 2000, Windows Server 2000 and versions 1.0, 1.1 and 2.0 of the .Net framework. An attacker could use each vulnerability to remotely execute malicious code on a target system.

A remote code execution vulnerability was also found in Office Publisher 2007. An attacker could use a specially crafted '.pub' file to take control of the target system with the privileges of the current user.

The vulnerability is classified as 'important' rather than 'critical' because the attacker would have to convince the user to manually launch the malicious file.

None of the 'critical' vulnerabilities affects Windows Vista, but the 'moderate' vulnerability lies within the firewall security software in the 32-bit and 64-bit versions of Vista.

If exploited, an attacker could access the network interface and view sensitive user information.

Oliver Friedrichs, director of emerging technologies at Symantec Security Response, warned that, while the firewall vulnerability is not severe, it is still significant. 

The flaw indicates that Vista's new networking components, or network stack, are not bullet-proof.

"A network stack can take decades of heavy scrutiny in order to become battle hardened," Friedrichs said in an emailed statement.

"As an operating system's first line of defence, its quality is directly related to its ability to withstand attack."

Users can download the monthly update through Windows Update or from Microsoft's TechNet website. 

Microsoft bundles its patches in security bulletins, each covering one application or software component. July's security update contained six bulletins.

Tags:

Further reading

Microsoft Software Assurance 'overpriced'

Quarter of subscribers planning to axe contracts   More...

Microsoft to patch six flaws on Tuesday

'Critical' vulnerabilities in Excel, .Net and Windows Server   More...

Microsoft facing $1.15bn Xbox 360 repair bill

Redmond reports significant increases in repair requests   More...

Microsoft fights to prevent GPLv3 contamination

Redmond unilaterally slashes terms for its SuSE Linux coupons   More...

Related articles

Microsoft to patch six flaws on Tuesday

'Critical' vulnerabilities in Excel, .Net and Windows Server   More...

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities   More...

Microsoft issues 15 security updates

IE takes centre stage in June patch release   More...

Adobe fixes Flash and Photoshop flaws

Publicly available exploit code leaves millions at risk   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement