This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS Security Bulletin Summary for May, 2005

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.microsoft.com/technet/security/…n/ms05-may.mspx
Issued: May 10, 2005
Version Number: 1.0

Important (1)
Microsoft Security Bulletin MS05-024
- http://www.microsoft.com/technet/security/…n/MS05-024.mspx
Vulnerability in Web View Could Allow Remote Code Execution (894320)
…Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Important
Recommendation: Customers should apply the update at the earliest opportunity…
Affected Software:
• Windows 2000 SP 3 and Windows 2000 SP4
• Windows 98, Windows 98SE, and Windows ME – Review the FAQ section of this bulletin for details about these operating systems…"


(That's all, folks.)

:huh:
FYI…

ISC analysis (after a -very- short meeting):
- http://isc.sans.org/diary.php?date=2005-05-10
Updated May 10th 2005 18:03 UTC
"…According the advisory, there is a problem in the way Windows Explorer "handles certain HTML characters in preview fields". A typical attack scenario is on the workaround section: "In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability." "…an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site. After they click the link, they would be prompted to perform an action. An attack could only occur after they performed these actions…Our good reader Juha-Matti wrote that this Microsoft patch will fix the flaw, published only five months ago, at http://www.greymagic.com/security/advisories/gm015-ie/ , discovered by Grey Magic Software with a Bugtraq ID 13248. Good Work!"

:huh: