AplusWebMaster
Topic Starter
FYI…
- http://www.microsoft.com/technet/security/…n/ms05-jun.mspx
Critical (3)
Cumulative Security Update for Internet Explorer (883939) - MS05-025
- http://www.microsoft.com/technet/security/…n/MS05-025.mspx
Vulnerability in HTML Help Could Allow Remote Code Execution (896358) - MS05-026
- http://www.microsoft.com/technet/security/…n/MS05-026.mspx
Vulnerability in SMB Could Allow Remote Code Execution (896422) - MS05-027
- http://www.microsoft.com/technet/security/…n/MS05-027.mspx
Important (4)
Vulnerability in Web Client Service May Allow Remote Code Execution (896426) - MS05-028
- http://www.microsoft.com/technet/security/…n/MS05-028.mspx
Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029
- http://www.microsoft.com/technet/security/…n/MS05-029.mspx
Cumulative Security Update for Outlook Express (897715) - MS05-030
- http://www.microsoft.com/technet/security/…n/MS05-030.mspx
Vulnerability in Microsoft Windows Interactive Training Could Allow Remote Code Execution (898458) - MS05-031
- http://www.microsoft.com/technet/security/…n/MS05-031.mspx
Moderate (3)
Vulnerability in Microsoft Agent Could Allow Spoofing (890046) - MS05-032
- http://www.microsoft.com/technet/security/…n/MS05-032.mspx
Vulnerability in Telnet Client Could Allow Information Disclosure (896428) - MS05-033
- http://www.microsoft.com/technet/security/…n/MS05-033.mspx
Cumulative Security Update for ISA Server 2000 (899753) - MS05-034
- http://www.microsoft.com/technet/security/…n/MS05-034.mspx
——————————————————————-
Effective June 06, 2005; Available only to users of W2K, WinXP, and W2K3.
Patches for Windows, the Office suite, Exchange, and SQL Server.
>>> http://update.microsoft.com/microsoftupdate/v6/default.aspx
The rest of us need to use the usual site:
>>> http://v4.windowsupdate.microsoft.com/default.asp
======================================================
- http://isc.sans.org/diary.php?date=2005-06-14
Updated June 14th 2005 21:09 UTC
"Thanks to the other Handlers for their assistance in compiling this summary. All-in-all not a terrible list. -025 will probably lead to another round of e-mail worms with images in them which should be easy to filter (this should only impact end-user machines as one hopes you don't surf the web or check e-mail from your servers). -026 requires either the exploitation of a assumed good site, or tricking people to go to a malicious website; expect it to be used in the spyware/adware coming to a pop-up near you. For -027, that traffic should be filtered at your gateway anyway but may have some worm potential. I really hope you aren't running telnet (-033). -031 is the only real pain of the bunch where you'll have to search for orun32.exe to see if you have Interactive Training installed. It may or may not be in Add/Remove Programs…
Bulletin Severity Impact
MS05-025 Critical Remote Code Execution (replaces MS05-020) End-user machines only
MS05-026 Critical Remote Code Execution (replaces MS03-044, MS04-023, MS05-001)
MS05-027 Critical Remote Code Execution (replaces MS02-070, MS03-024)
MS05-028 Important Remote Code Execution
MS05-029 Important Remote Code Execution
MS05-030 Important Remote Code Execution
MS05-031 Important Remote Code Execution
MS05-032 Moderate Spoofing
MS05-033 Moderate Information Disclosure
MS05-034 Moderate Elevation of Privilege …"
(For more detailed analysis, use the ISC DIary URL above.)
//////////////////////////////////////////////////////////////////
More… <_<
Re-Released Bulletins:
SQL Server Installation Process May Leave Passwords on System (Q263968) - MS02-035 Critical
- http://www.microsoft.com/technet/security/…n/ms02-035.mspx
ASP.NET Path Validation Vulnerability (887219) - MS05-004 Important
- http://www.microsoft.com/technet/security/…n/ms05-004.mspx
Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029 Important
- http://www.microsoft.com/technet/security/…n/ms05-029.mspx

- http://www.microsoft.com/technet/security/…n/ms05-jun.mspx
Critical (3)
Cumulative Security Update for Internet Explorer (883939) - MS05-025
- http://www.microsoft.com/technet/security/…n/MS05-025.mspx
Vulnerability in HTML Help Could Allow Remote Code Execution (896358) - MS05-026
- http://www.microsoft.com/technet/security/…n/MS05-026.mspx
Vulnerability in SMB Could Allow Remote Code Execution (896422) - MS05-027
- http://www.microsoft.com/technet/security/…n/MS05-027.mspx
Important (4)
Vulnerability in Web Client Service May Allow Remote Code Execution (896426) - MS05-028
- http://www.microsoft.com/technet/security/…n/MS05-028.mspx
Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029
- http://www.microsoft.com/technet/security/…n/MS05-029.mspx
Cumulative Security Update for Outlook Express (897715) - MS05-030
- http://www.microsoft.com/technet/security/…n/MS05-030.mspx
Vulnerability in Microsoft Windows Interactive Training Could Allow Remote Code Execution (898458) - MS05-031
- http://www.microsoft.com/technet/security/…n/MS05-031.mspx
Moderate (3)
Vulnerability in Microsoft Agent Could Allow Spoofing (890046) - MS05-032
- http://www.microsoft.com/technet/security/…n/MS05-032.mspx
Vulnerability in Telnet Client Could Allow Information Disclosure (896428) - MS05-033
- http://www.microsoft.com/technet/security/…n/MS05-033.mspx
Cumulative Security Update for ISA Server 2000 (899753) - MS05-034
- http://www.microsoft.com/technet/security/…n/MS05-034.mspx
——————————————————————-
Effective June 06, 2005; Available only to users of W2K, WinXP, and W2K3.
Patches for Windows, the Office suite, Exchange, and SQL Server.
>>> http://update.microsoft.com/microsoftupdate/v6/default.aspx
The rest of us need to use the usual site:
>>> http://v4.windowsupdate.microsoft.com/default.asp
======================================================
- http://isc.sans.org/diary.php?date=2005-06-14
Updated June 14th 2005 21:09 UTC
"Thanks to the other Handlers for their assistance in compiling this summary. All-in-all not a terrible list. -025 will probably lead to another round of e-mail worms with images in them which should be easy to filter (this should only impact end-user machines as one hopes you don't surf the web or check e-mail from your servers). -026 requires either the exploitation of a assumed good site, or tricking people to go to a malicious website; expect it to be used in the spyware/adware coming to a pop-up near you. For -027, that traffic should be filtered at your gateway anyway but may have some worm potential. I really hope you aren't running telnet (-033). -031 is the only real pain of the bunch where you'll have to search for orun32.exe to see if you have Interactive Training installed. It may or may not be in Add/Remove Programs…
Bulletin Severity Impact
MS05-025 Critical Remote Code Execution (replaces MS05-020) End-user machines only
MS05-026 Critical Remote Code Execution (replaces MS03-044, MS04-023, MS05-001)
MS05-027 Critical Remote Code Execution (replaces MS02-070, MS03-024)
MS05-028 Important Remote Code Execution
MS05-029 Important Remote Code Execution
MS05-030 Important Remote Code Execution
MS05-031 Important Remote Code Execution
MS05-032 Moderate Spoofing
MS05-033 Moderate Information Disclosure
MS05-034 Moderate Elevation of Privilege …"
(For more detailed analysis, use the ISC DIary URL above.)
//////////////////////////////////////////////////////////////////
More… <_<
Re-Released Bulletins:
SQL Server Installation Process May Leave Passwords on System (Q263968) - MS02-035 Critical
- http://www.microsoft.com/technet/security/…n/ms02-035.mspx
ASP.NET Path Validation Vulnerability (887219) - MS05-004 Important
- http://www.microsoft.com/technet/security/…n/ms05-004.mspx
Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029 Important
- http://www.microsoft.com/technet/security/…n/ms05-029.mspx