Microsoft
Fixes for XML Core Services and Internet Explorer 6

Microsoft plugs seven 'critical' security holes

Internet Explorer and XML Core Services flaws already being exploited

Written by Tom Sanders in California

Microsoft has released a security update that repairs nine software vulnerabilities, seven of which are rated 'critical'. 

The patch includes a fix for a flaw in the XMLHTTP 4.0 ActiveX Control component of the XML Core Service. Microsoft issued a security bulletin about the vulnerability and warned that attackers are actively exploiting the flaw.

The update also repairs three critical vulnerabilities in Internet Explorer 6, all of which are rated 'critical'.

Two of the flaws affect the DirectAnimation ActiveX Controls, which attackers could exploit by luring a user to a specially crafted website.

An attacker could install spyware or other malware on a system without any user interaction. Microsoft warned that the flaw is being actively exploited.

The third Internet Explorer 6 flaw could also allow for remote code execution if attackers succeed in luring users to a specially crafted website.

The vulnerability is caused by a design flaw in the way that the browser interprets HTML code with certain layout combinations. Microsoft claimed that it is not aware of any exploits.

The Sans Internet Storm Center rated the XML Core Services and Internet Explorer updates as the most urgent.

The remaining updates affect Microsoft Agent, Adobe's Flash player and the Workstation Service, all of which could allow an attacker to take control of a system. Microsoft said that it is not aware of any active exploits.

Users can update their systems through the auto update feature or by downloading the patches from the Microsoft Update website. 

The remaining two patches affect Novell's Netware technology and received severity ratings of 'moderate' and 'low'.

Tags:

reader comments

related articles

 

Microsoft issues 'critical' security alert

Attack targets server component in Windows and Windows Server 24 Oct 2008

Microsoft rolls out monthly patch

Two fixes released for November 12 Nov 2008

Microsoft warns of new Word attacks

Remote code flaw being exploited 10 Jul 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Soca unitAnalysis

EU police in the dock over data sharing

Poor integration and lax practices are jeopardising EU efforts to fight international crime 20 Nov 2008

Advertisement

Primary Navigation