Microsoft Plugs Critical Vista Hole



Microsoft Plugs Critical Vista Hole

The vulnerability that has been bothering Windows Vista since Christmas has been patched recently. The new problem involves the way that the OS's Client/Server Run-time Subsystem (CSRSS) handles error messages, and it affects Windows 2000 SP4 and Windows XP too.

Before an assault could succeed one has to perform certain unspecified actions on a malicious Web site not like the previous cursor problem.
You should have Automatic Updates enabled for the fix to be already installed. Otherwise, make sure to get hold of it at Microsoft TechNet.windows vista

In addition, Microsoft has fixed a critical weakness in its Agent technology in Windows 2000 SP4 and Windows XP SP2. The flaw can be exploited through Internet Explorer 6 if you visit a Web page with a poisoned link or banner ad. While the Agent is normally supposed to run little animated helpers (like the infamous Clippy), a malicious site need not display one prior to delivering an attack. Instead, the bad code could lurk inside a seemingly harmless link.
Vista is unaffected by this hole, as is Internet Explorer 7. You can get the patch via Automatic Updates or download it from Microsoft TechNet.
Adobe's PhotoShop CS2 and CS3 contain critical flaws that can give an attacker control over your PC if you use either program to open bitmap images that have been rigged, according to security firm Secunia and the French Security Incident Response Team.

Microsoft patched a Windows Vista bug that can corrupt an iPod when you use the 'Safely Remove Hardware' feature or disconnect the iPod using Windows Explorer. Though Microsoft provided no details on just how a player is affected by the bug, the company's notice says that you'll have to use iTunes to restore all the music on your iPod if it happens.
Yahoo Messenger has a faulty ActiveX control that leaves you open to attack via IE if you view a poisoned Web page. IE 7 and Windows Vista mitigate but don't remove the threat. Any 8.x version installed before March 13, 2007, is at risk; download the most recent YM version.

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • TwitThis
  • Reddit
  • del.icio.us
  • StumbleUpon
  • Mixx

Comments

(required)

(will not be published/required)

(required)