Microsoft Patch Tuesday Sees Fixes for Four Security Flaws
Microsoft Inc. released its security update yesterday in what has now commonly become known as Patch Tuesday, the second Tuesday of the month. This patch Tuesday included fixes for four security flaws affecting several of its products, including two flaws affecting recent versions of Windows, and three that have been publicly disclosed. There was only a single critical flaw issued; for a remote code execution vulnerability affecting Windows 2000 SP4. The three other patches were deemed as important, and though there was a fifth patch in the works, it was not ready for release by yesterday.
The one critical patch fixes a problem in the Microsoft Agent software in Windows 2000 SP4 that could allow an attacker to take complete control of an affected system if the user visited a malformed Web site or opened a malicious e-mail. Microsoft says the vulnerability has not been publicly disclosed, nor used as the basis for an attack. Just the same, Windows 2000 SP4 users should apply the patch immediately, as hackers and script kiddies are bound to start using the flaw for attempted exploits in the days and weeks to come.