X

Microsoft fixes 18 vulnerabilities with seven updates

Microsoft fixes 18 vulnerabilities with seven updates

Robert Vamosi Former Editor
As CNET's former resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security.
Robert Vamosi
2 min read
Microsoft has released its July 2006 security bulletin, which includes seven updates: five are listed by Microsoft as critical and two are important. Three of the critical updates this month are specific to Microsoft Office, including one specific to Excel, and one that includes Mac versions of Office. Users of Windows 98 and Windows Me will notice that Microsft is no longer offering technical support for these two operating systems. To keep your Windows 98 and Me systems secure, see our latest roundup of compatible third-party security applications. All Microsoft security patches for Windows and Office software are available via Microsoft Update or via the individual bulletins detailed below.

MS06-033: Important

Entitled "Vulnerability in ASP.NET Could Allow Information Disclosure (917283)," this advisory affects Windows 2000 SP4, Windows XP, and Windows Server 2003; it also affects the .NET framework 2.0. Exploitation could lead to information disclosure.

MS06-034: Important

Entitled "Vulnerability in Microsoft Internet Information Services using Active Server Pages Could Allow Remote Code Execution (917537)," this advisory affects Windows 2000 SP4, Windows XP Professional, and Windows Server 2003; it does not affect Windows XP Home. Exploitation could lead to remote code execution on a compromised PC.

MS06-035: Critical

Entitled "Vulnerability in Server Service Could Allow Remote Code Execution (917159)," this advisory affects Windows 2000 SP4, Windows XP, and Windows Server 2003. Exploitation could lead to remote code execution on a compromised PC.

MS06-036: Critical

Entitled "Vulnerability in DHCP Client Service Could Allow Remote Code Execution (914388)," this advisory affects Windows 2000 SP4, Windows XP, and Windows Server 2003. Exploitation could lead to remote code execution on a compromised PC.

MS06-037: Critical

Entitled "Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)," this advisory affects Excel 2000, Excel 2002, and Excel 2003, plus the Excel 2003 Viewer. Exploitation could lead to remote code execution on a compromised PC.

MS06-038: Critical

Entitled "Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (917284)," this advisory affects Office 2000, Office XP, and Office 2003 as well as Office v.x for Mac and Office 2004 for Mac. Exploitation could lead to remote code execution on a compromised PC.

MS06-039: Critical

Entitled "Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (915384)," this advisory affects Office 2000, Office XP, and Office 2003. Exploitation could lead to remote code execution on a compromised PC.