Microsoft to Issue 7 Security Patches

By Nate Mook | Published July 6, 2006, 2:30 PM

Microsoft plans to release 7 security bulletins as part of its July 11 Patch Tuesday, the company said Thursday. Four of the updates are for Windows, with the most severe being rated as "critical." Three other patches are directed at Office, also with a maximum severity of "critical."

Although Microsoft does not disclose in advance what flaws are to be patched, two vulnerabilities in Excel are likely to be among the fixes. One issue relates to maliciously crafted spreadsheet files that could lead to a full system compromise, while the other relates to hyperlinks in Excel documents.

Two security flaws affecting Internet Explorer were also reported last week, including a cross-site scripting issue where an attacker could view information in an open browser window from another that is visiting a malicious site.

A second more serious flaw involves how HTA applications are handled. A user could be tricked into opening a malicious file, which in turn could execute code. The file would need to be accessed through SMB or WebDAV in order for the issue to be exploited.

Microsoft said last week that it was investigating the issues, but it's not clear if the company has had time to develop and properly test a fix.

Along with the 7 security patches, Microsoft will release one high-priority non-security update that is not for Windows. Per usual, the Redmond company will also deliver an update to its Malicious Software Removal Tool on Tuesday.

Comments

I've downloaded IE 7 Beta and now can not use IExplorer at all. Is is just me and my computer? Using XP Home Edition w/ sp2.
HELP!!!!!!!!!!

Score: 0

|

IE7 Beta is not a new program, it is a new version of an existing program, and thus when you install it, it replaces your old version (IE6) with itself
so you are still using the same product, it is still Internet Explorer, the difference is the version number

if the program wont run at all, try reinstalling it, or uninstalling and then doing a fresh install

Score: 0

|

Hi Ho....Hi Ho....off to patch we go

Score: 0

|

Hey!!!!!!!!!!!!!!!!!!!!!!!!!Don't be talking 'bout my sistah!!!!!!!

Score: 0

|

ANOTHER SWISS CHEESE TUESDAY!

Score: 0

|

I cannot imagine Microsoft without "critical patches". Well, I think there's always something to be made better. Some years ago I had to return to my old computer with Windows 98 SE in it. I keep using it since then. I have improved it in many ways (new motherboard, new hard drive, new processor, firewall, editors, registry cleaners, DVD, TV, Satellite receiver, tweaks, etc.) I never loaded a patch. If you are a Windows 98 SE user, don't worry: It is a really cool system and keeps working perfectly. You may find almost everything you need to improve it up to very high standards in the Internet, no need to buy a new machine.

Score: 0

|

And THAT is the last official day of any patch being released for win9x.

Those of you wanting future patches, and as well previous unofficial patches(by anonymous MS insiders) for the issues MS has stated it will not patch on 9X, check out either mdgx.com under your particular OS, or here: http://www.msfn.org/boar...dex.php?showtopic=46581

Score: 0

|

You won't be able to get future patches at that site because there won't be any future patches. All of those "unofficial service packs" and hot fixes are made by Microsoft. People just bundle them together into packs.

Score: 0

|

The critical one must be a WGA update.

*grin*

Score: 0

|

Oh gosh...

Is that an angry mob I see coming up the road?

lol

Score: 0

|

Grab yer Torch and Pitchforks!

Score: 0

|

and in the morning, I'm make-in WAFFLES.

Score: 0

|

Don't forget the rope!

Score: 0

|

Someone got it. ;)

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET