NEWS PC users already suffering under a wave of virus attacks this week have been warned by Microsoft of three critical security flaws in Internet Explorer and Windows that could lead them open to attack. Microsoft released a cumulative patch for Explorer that fixes several vulnerabilities previously disclosed by the company, and it re-released an advisory for Microsoft's SQL Server software, warning that a flaw in it that actually affects most Windows users. Stephen Toulouse, security program manager for Microsoft's security response centre, said users who don't patch their systems could leave the computers open to attack through a fake web page or an HTML email that contains the specific exploit code. "The Internet Explorer bulletin is rated as 'critical' across all platforms except Windows 2003," he said. A critical rating is the highest grade that Microsoft assigns to its alerts. The flaws were rated 'moderate' - the second-lowest grade - for Windows 2003, the latest version of the operating system. On Wednesday, anti-virus firm Symantec said the MSBlast worm, which takes advantage of a month-old vulnerability in Microsoft's operating system, had infected almost 700,000 computers. A variant of the worm, MSBlast.D or Nachi, has infected more than 525,000 computers since it began to spread on Monday. Although critical, the latest vulnerabilities are far less likely to become fodder for a worm writer because a victim would have to go to an attacker-owned web page to be attacked. The Explorer vulnerabilities involve the fact that the software doesn't check the type of an object returned from a web server and because a flaw exists in the browser's cross-domain security model, Microsoft stated in its advisory. The other critical vulnerability affects all supported versions of Windows and was originally thought to be a vulnerability in Microsoft's SQL Server but is, in fact, a flaw in the omnipresent Microsoft data access component (MDAC). Windows 2003 doesn't have the vulnerable software installed by default, but a user could have downloaded the programs and so could be vulnerable. Toulouse pointed out one silver lining in the latest vulnerabilities - the flaws affected Windows 2003 to a lesser degree. "I think it is an observable bit of progress for Trustworthy Computing. The default settings of the operating system are more secure," he said. Robert Lemos writes for CNET News.com
Microsoft warns of three new 'critical' security flaws
Just what users need in a week deluged with virus attacks…
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




