Microsoft security update
Microsoft security update

Microsoft warns of seven Windows flaws

More security vulnerabilities, more patches

Robert Jaques

Microsoft yesterday warned of seven security vulnerabilities, two of which it rated as 'critical'.

The company has issued updates for all seven flaws. These include MS04-022, which addresses a vulnerability in Task Scheduler that could allow code execution.

Advertisement

Microsoft explained that if a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges.

The flaw affects Windows 2000 (Service Pack 2, 3 and 4), XP, and XP 64-bit edition Service Pack 1.

Update MS04-023 addresses the other critical flaw, which centres on vulnerabilities in HTML Help and also could allow malicious hackers to run code on compromised Windows PCs.

The flaw affects the same versions of Windows as MS04-022 but also affects Windows Server 2003 and 64-bit edition.

Of the remaining alerts four are rated as 'important' and one 'moderate'. They include MS04-018, a cumulative security update for Outlook Express; MS04-019, concerning a vulnerability in Utility Manager that could allow code execution; and MS04-020, dealing with a vulnerability in POSIX that could allow code execution.

MS04-021 comprises a security update for IIS 4.0, while MS04-024 addresses a vulnerability in Windows Shell that could allow remote code execution.

Further information, and patches for all seven vulnerabilities, can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Secure computing

Windows XP key to Microsoft's secure computing

Upgrade now if you want security, Redmond tells 2000 and 9x users

Serious IE flaw

Microsoft offers IE flaw workaround

Browser fix 'improves system resiliency' but does not patch the flaw

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation