This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS Security Bulletin Summary for June, 2005

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.microsoft.com/technet/security/…n/ms05-jun.mspx

Critical (3)

Cumulative Security Update for Internet Explorer (883939) - MS05-025
- http://www.microsoft.com/technet/security/…n/MS05-025.mspx

Vulnerability in HTML Help Could Allow Remote Code Execution (896358) - MS05-026
- http://www.microsoft.com/technet/security/…n/MS05-026.mspx

Vulnerability in SMB Could Allow Remote Code Execution (896422) - MS05-027
- http://www.microsoft.com/technet/security/…n/MS05-027.mspx

Important (4)

Vulnerability in Web Client Service May Allow Remote Code Execution (896426) - MS05-028
- http://www.microsoft.com/technet/security/…n/MS05-028.mspx

Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029
- http://www.microsoft.com/technet/security/…n/MS05-029.mspx

Cumulative Security Update for Outlook Express (897715) - MS05-030
- http://www.microsoft.com/technet/security/…n/MS05-030.mspx

Vulnerability in Microsoft Windows Interactive Training Could Allow Remote Code Execution (898458) - MS05-031
- http://www.microsoft.com/technet/security/…n/MS05-031.mspx

Moderate (3)

Vulnerability in Microsoft Agent Could Allow Spoofing (890046) - MS05-032
- http://www.microsoft.com/technet/security/…n/MS05-032.mspx

Vulnerability in Telnet Client Could Allow Information Disclosure (896428) - MS05-033
- http://www.microsoft.com/technet/security/…n/MS05-033.mspx

Cumulative Security Update for ISA Server 2000 (899753) - MS05-034
- http://www.microsoft.com/technet/security/…n/MS05-034.mspx

——————————————————————-

Effective June 06, 2005; Available only to users of W2K, WinXP, and W2K3.
Patches for Windows, the Office suite, Exchange, and SQL Server.
>>> http://update.microsoft.com/microsoftupdate/v6/default.aspx

The rest of us need to use the usual site:
>>> http://v4.windowsupdate.microsoft.com/default.asp

======================================================

- http://isc.sans.org/diary.php?date=2005-06-14

Updated June 14th 2005 21:09 UTC
"Thanks to the other Handlers for their assistance in compiling this summary. All-in-all not a terrible list. -025 will probably lead to another round of e-mail worms with images in them which should be easy to filter (this should only impact end-user machines as one hopes you don't surf the web or check e-mail from your servers). -026 requires either the exploitation of a assumed good site, or tricking people to go to a malicious website; expect it to be used in the spyware/adware coming to a pop-up near you. For -027, that traffic should be filtered at your gateway anyway but may have some worm potential. I really hope you aren't running telnet (-033). -031 is the only real pain of the bunch where you'll have to search for orun32.exe to see if you have Interactive Training installed. It may or may not be in Add/Remove Programs…

Bulletin Severity Impact

MS05-025 Critical Remote Code Execution (replaces MS05-020) End-user machines only
MS05-026 Critical Remote Code Execution (replaces MS03-044, MS04-023, MS05-001)
MS05-027 Critical Remote Code Execution (replaces MS02-070, MS03-024)
MS05-028 Important Remote Code Execution
MS05-029 Important Remote Code Execution
MS05-030 Important Remote Code Execution
MS05-031 Important Remote Code Execution
MS05-032 Moderate Spoofing
MS05-033 Moderate Information Disclosure
MS05-034 Moderate Elevation of Privilege …"

(For more detailed analysis, use the ISC DIary URL above.)


//////////////////////////////////////////////////////////////////

More… <_<

Re-Released Bulletins:

SQL Server Installation Process May Leave Passwords on System (Q263968) - MS02-035 Critical
- http://www.microsoft.com/technet/security/…n/ms02-035.mspx

ASP.NET Path Validation Vulnerability (887219) - MS05-004 Important
- http://www.microsoft.com/technet/security/…n/ms05-004.mspx

Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks (895179) - MS05-029 Important
- http://www.microsoft.com/technet/security/…n/ms05-029.mspx

:ph34r: :ph34r:
Additional "Re-release":

Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial of Service (893066) - MS05-019 Critical
- http://www.microsoft.com/technet/security/…n/MS05-019.mspx
• V2.0 (June 14, 2005): Microsoft updated this bulletin today to advise customers that a revised version of the security update is available. We recommend installing this revised security update even if you have installed the previous version. The revised security update will be available through Windows Update, Software Update Services (SUS), and will be recommended by the Microsoft Baseline Security Analyzer (MBSA).

:ph34r: