Home · Compatibility Lists · Support Forums · FAQ · News Archive · Articles · Submit News/Upcoming News
NT Compatible
advertisement


Critical Product Vulnerability - July 2004 Microsoft Security Bulletin Release
Posted by Philipp on: 2004-07-13 14:56:02 [ Print | Permalink ]

Today 13 July 2004, Microsoft is releasing 7 security updates for newly discovered vulnerabilities in Microsoft Windows.

- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Moderate, MS04-018
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Important, MS04-019
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Important, MS04-020
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Important, MS04-021
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Critical, MS04-022
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Critical, MS04-023
- One Microsoft Security Bulletin affecting Microsoft Windows with a maximum severity of Important, MS04-024


Summaries for these new bulletins may be found at the following page:
- http://www.microsoft.com/technet/security/bulletin/ms04-jul.mspx

Customers are advised to review the information in the bulletins, test and deploy the updates immediately in their environments, if applicable.

Microsoft will host a webcast tomorrow to address customer questions on these bulletins. For more information on this webcast please see below:
- Information about Microsoft's July Security Bulletins
- Wednesday, July 14, 2004 10:00 AM - Wednesday, July 14, 2004 11:00 AM
(GMT-08:00) Pacific Time (US & Canada)
- http://go.microsoft.com/fwlink/?LinkId=30865

- The on-demand version of the webcast will be available 24 hours after the live webcast at:
- http://go.microsoft.com/fwlink/?LinkId=30865




MS04-018

Title: Cumulative Security Update for Outlook Express (823353)

Affected Software:
- Microsoft Windows NT Workstation 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack
6
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP and Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1
- Microsoft Windows XP 64-Bit Edition Version 2003
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 64-Bit Edition
- Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) - Review the FAQ section of this bulletin for details about these operating systems.

Affected Components:
- Microsoft Outlook Express 5.5 Service Pack 2
- Microsoft Outlook Express 6
- Microsoft Outlook Express 6 Service Pack 1
- Microsoft Outlook Express 6 Service Pack 1 (64 bit Edition)
- Microsoft Outlook Express 6 on Windows Server 2003
- Microsoft Outlook Express 6 on Windows Server 2003 (64 bit edition)

Impact of Vulnerability: Denial of Service

Maximum Severity Rating: Moderate

Restart required: In some cases, this update does not require a restart. The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-018.mspx




MS04-019

Title: Vulnerability in Utility Manager Could Allow Code Execution
(842526)

Affected Software:
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4

Impact of Vulnerability: Local Elevation of Privilege

Maximum Severity Rating: Important

Restart required: In some cases, this update does not require a restart. The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-019.mspx




MS04-020

Title: Vulnerability in POSIX Could Allow Code Execution (841872)

Affected Software:
- Microsoft Windows NT Workstation 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4

Impact of Vulnerability: Local Elevation of Privilege

Maximum Severity Rating: Important

Restart required: In some cases, this update does not require a restart.
The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-020.mspx




MS04-021

Title: Security Update for IIS 4.0 (841373)

Affected Software:
- Microsoft Windows NT Workstation 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Service Pack 6a

Affected Components:
- Microsoft Internet Information Server (IIS) 4.0

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Important

Restart required: Yes

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-021.mspx




MS04-022

Title: Vulnerability in Task Scheduler Could Allow Code Execution
(841873)

Affected Software:
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP and Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1

Affected Components:
- Internet Explorer 6 when installed on Windows NT 4.0 SP6a (Workstation, Server, or Terminal Server Edition)

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Restart required: In some cases, this update does not require a restart.
The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-022.mspx




MS04-023

Title: Vulnerability in HTML Help Could Allow Code Execution (840315)

Affected Software:
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP and Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1
- Microsoft Windows XP 64-Bit Edition Version 2003
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 64-Bit Edition
- Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME) - Review the FAQ section of this bulletin for details about these operating systems.

Affected Components:
- Internet Explorer 6.0 Service Pack 1 when installed on Windows NT 4.0 SP6a (Workstation, Server, or Terminal Server Edition)

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Restart required: In some cases, this update does not require a restart.
The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx




MS04-024

Title: Vulnerability in Windows Shell Could Allow Remote Code Execution
(839645)

Affected Software:
- Microsoft Windows NT(r) Workstation 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack
6
- Microsoft Windows NT(r) Workstation 4.0 Service Pack 6a with Active Desktop
- Microsoft Windows NT Server 4.0 Service Pack 6a with Active Desktop
- Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack
6 with Active Desktop
- Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP and Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1
- Microsoft Windows XP 64-Bit Edition Version 2003
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 64-Bit Edition
- Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME) - Review the FAQ section of this bulletin for details about these operating systems.

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Important

Restart required: In some cases, this update does not require a restart. The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx

Digg it! Slashdot Del.icio.us Technorati Fark it! Binklist Furl Newsvine Windows Live Netscape Google Bookmarks Reddit! LinkaGoGo Tailrank Wink Dzone Simpy Spurl Yahoo! MyWeb NetVouz RawSugar Smarking Scuttle Magnolia BlogMarks Nowpublic FeedMeLinks Wists Onlywire Connotia Shadows Co.mments
News Source: Email

Related Stories RSS


Related Threads RSS

- [CentOS-announce] CESA-2009:1601 Critical CentOS 5 x86_64 kdelibs Update (11/28/2009 12:49 am)
- [CentOS-announce] CESA-2009:1601 Critical CentOS 5 i386 kdelibs Update (11/28/2009 12:49 am)
- [RHSA-2009:1601-01] Critical: kdelibs security update (11/25/2009 01:14 am)
- [RHSA-2009:1582-01] Critical: java-1.6.0-ibm security update (11/12/2009 07:35 pm)
- [RHSA-2009:1571-01] Critical: java-1.5.0-sun security update (11/10/2009 09:07 pm)
- [RHSA-2009:1560-01] Critical: java-1.6.0-sun security update (11/09/2009 05:49 pm)
- [RHSA-2009:1530-01] Critical: firefox security update (10/28/2009 01:14 am)
- [RHSA-2009:1531-01] Critical: seamonkey security update (10/28/2009 01:14 am)
- [RHSA-2009:1499-01] Critical: acroread security update (10/14/2009 07:00 pm)
- Toy Kite Software releases iSamurai: Critical Strike for the iPhone (10/13/2009 11:21 am)
- News Item: Open Source Changing Face of Content Management Market Says Report from Basex; Choosing the Right Platform is More Critical than Ever (09/30/2009 07:28 pm)
- [CentOS-announce] CESA-2009:1430 Critical CentOS 5 x86_64 firefox Update (09/15/2009 10:28 pm)
- [CentOS-announce] CESA-2009:1430 Critical CentOS 5 i386 firefox Update (09/15/2009 10:21 pm)
- [RHSA-2009:1430-01] Critical: firefox security update (09/10/2009 02:07 am)
- [RHSA-2009:1431-01] Critical: seamonkey security update (09/10/2009 02:07 am)
- [RHSA-2009:1432-01] Critical: seamonkey security update (09/10/2009 02:07 am)
- [RHSA-2009:1236-01] Critical: java-1.5.0-ibm security update (08/28/2009 11:28 am)
- [CentOS-announce] CESA-2009:1218 Critical CentOS 5 x86_64 pidgin Update (08/18/2009 09:56 pm)
- [CentOS-announce] CESA-2009:1218 Critical CentOS 5 i386 pidgin Update (08/18/2009 09:49 pm)
- [RHSA-2009:1218-01] Critical: pidgin security update (08/18/2009 08:56 pm)

Post New Comment


All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2009 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Website powered by Esselbach Storyteller CMS System