14 Dec 2005
Microsoft has released its last batch of scheduled software bug fixes for the year, including one rated 'critical' and one rated 'important'.
The 'critical' patch fixes four vulnerabilities in Internet Explorer, some of which are already being exploited with Trojan malware.
Users had been expecting a patch earlier, since one of the vulnerabilities was reported to the company in June.
The 'important' patch fixes a flaw in the Windows kernel that could allow any code executed on a Windows NT 4.0 or Windows 2000 system to elevate itself to the highest possible local privilege level.
This means that, once the flaw is exploited, the attacker could obtain full admin rights to the PC, even if the user does not have such rights.
Microsoft also announced a change to the way it emails customers designed to thwart attempts by virus writers to send emails masquerading as security updates.
"Starting in 2006, Microsoft will begin signing all security communications sent in email using industry standard Secure Multipurpose Internet Mail Extensions [S/MIME]," the company said in a statement.
"This change will allow for easier customer verification that email coming from Microsoft regarding security is actually coming from Microsoft.
"S/MIME is supported by default on Outlook Express, Microsoft Outlook, and many third-party email programs."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
X2 PMO lead, Investment Banking, London up to £495 per...
SEO analyst - Retail E-commerce - c35-55k - Hertfordshire...
ICT Technician Leicester £10,000 per annum...
Oracle Performance Tuning, Oracle, Tuning, Engineering...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Microsoft embraces Firefox...
It appears that Microsoft have finally succumed to Open Source community pressure. I have had Firefox set as my default browser fro a long time, and after installing the said patch and restarting, any address typed into IE's Address bar now spawns Firefox to display the page. IE itself goes nowhere. Its as though the Address bar has become another 'Run...' box. Its not limited to FF, either. As an experiment, I set Opera to default, and now IE spawns Opera for me! Its great - Microsoft have provided me with a patch that stops me accidentally using IE for surfing!
Posted by: Simon Berriman 14 Dec 2005