October 2007
M T W T F S S
« Sep   Nov »
1234567
891011121314
15161718192021
22232425262728
293031  
Categories

Microsoft patches four critical security holes

Microsoft issued fixes for four critical security flaws, including holes that could let hackers hijack computers using a Web browser, in a regularly scheduled update Tuesday.

Microsoft said it was patching four Internet Explorer holes with this one update. The flaws were found in several versions of Internet Explorer, including the most recent IE7.

GET FIXES:Security Central for Microsoft

Two of the four holes would have let attackers put fake content into the address bar of a Web browser — a technique used in phishing scams to convince Web surfers that a fake site is actually their bank, for example.

The other two flaws could have let hackers break into Web surfers’ computers using specially crafted Web pages.

Microsoft gave this four-in-one update its most urgent “critical” rating, is meant to prevent hackers from breaking into Web surfers’ computers using specially crafted Web pages.

“There has always been this escalating arms race” between hackers and security professionals, said Ben Greenbaum, a senior manager at Symantec Security Response. “Lately, the stakes are higher. People are losing actual money due to attacker activities.”

The three other critical patches are also meant to keep hackers from breaking into users’ computers to steal information or install malicious software.

One fixes a problem with the Kodak Image Viewer, formerly known as the Wang Image Viewer, used on computers running Windows 2000 or that were upgraded from Windows 2000. Another fixes a flaw in the way newsgroups are handled by Outlook Express and Windows Mail. The third protects users of Microsoft Word 2000 and 2004, and Office for Mac 2004, from malicious Word documents.

The software maker also issued four “important” patches — the second-most-urgent rating — related to Windows, Office and Sharepoint.

Windows users can visit Microsoft’s security website to get the updates, or configure their computers to automatically update each month.

http://www.usatoday.com/tech/news/computersecurity/2007-10-09-microsoft-patches_N.htm

Comments are closed.