|
Microsoft Security Bulletin MS06-057
Vulnerability in Windows Explorer Could Allow Remote Execution
Update Number: 923191
Severity Rating: Critical
Affected Software:
· Microsoft Windows 2000 Service Pack 4
· Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
· Microsoft Windows XP Professional x64 Edition
· Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
· Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
· Microsoft Windows Server 2003 x64 Edition
This update resolves a newly-discovered, publicly reported vulnerability. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/bulletin/MS06-057.mspx
Microsoft Security Bulletin MS06-058
Vulnerability in Microsoft Powerpoint Could Allow Remote Code Execution
Update Number: 924163
Severity Rating: Critical
Affected Software:
· Microsoft Office 2000 Service Pack 3 -- Microsoft PowerPoint 2000
· Microsoft Office XP Service Pack 3 -- Microsoft PowerPoint 2002
· Microsoft Office 2003 Service Pack 1 or Service Pack 2 -- Microsoft PowerPoint 2003
· Microsoft Office 2004 for Mac -- Microsoft PowerPoint 2004 for Mac
· Microsoft Office v. X for Mac -- Microsoft PowerPoint v. X for Mac
This update addresses several newly discovered, privately reported and public vulnerabilities. When using vulnerable versions of PowerPoint, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/bulletin/MS06-058.mspx
Microsoft Security Bulletin MS06-059
Vulnerability in Microsoft Excel Could Allow Remote Code Execution
Update Number: 924164
Severity Rating: Critical
Affected Software:
· Microsoft Office 2000 Service Pack 3 -- Microsoft Excel 2000
· Microsoft Office XP Service Pack 3 -- Microsoft Excel 2002
· Microsoft Office 2003 Service Pack 1 or Service Pack 2 -- Microsoft Excel 2003
· Microsoft Office 2004 for Mac -- Microsoft Excel 2004 for Mac
· Microsoft Office v. X for Mac -- Microsoft Excel v. X for Mac
· Microsoft Works Suites:
· Microsoft Works Suite 2004
· Microsoft Works Suite 2005
· Microsoft Works Suite 2006
This update addresses several newly discovered, privately reported and public vulnerabilities. When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/Bulletin/MS06-059.mspx
Microsoft Security Bulletin MS06-060
Vulnerability in Microsoft Word Could Allow Remote Code Execution
Update Number: 924554
Severity Rating: Critical
Affected Software:
· Microsoft Office 2000 Service Pack 3 -- Microsoft Word 2000
· Microsoft Office XP Service Pack 3 -- Microsoft Word 2002
· Microsoft Office 2003 Service Pack 1 or Service Pack 2 -- Microsoft Word 2003
· Microsoft Office 2004 for Mac -- Microsoft Word 2004 for Mac
· Microsoft Office v. X for Mac -- Microsoft Word v. X for Mac
· Microsoft Works Suites:
· Microsoft Works Suite 2004
· Microsoft Works Suite 2005
· Microsoft Works Suite 2006
This update addresses several newly discovered, privately reported and public vulnerabilities. When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/Bulletin/MS06-060.mspx
Microsoft Security Bulletin MS06-061
Vulnerability in Microsoft XML Core Services Could Allow Remote Execution
Update Number: 924191
Severity Rating: Critical
Affected Software:
· Microsoft Office 2003 Service Pack 1 or Service Pack 2 with Microsoft XML Core Services 5.0 Service Pack 1
· Microsoft XML Parser 2.6 (all versions) and Microsoft XML Core Services 3.0 (all versions) on the following operating systems
· Microsoft Windows 2000 Service Pack 4
· Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
· Microsoft Windows XP Professional x64 Edition
· Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
· Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
· Microsoft Windows Server 2003 x64 Edition
This update resolves two newly discovered, privately reported vulnerabilities. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/bulletin/MS06-061.mspx
Microsoft Security Bulletin MS06-062
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
Update Number: 922581
Severity Rating: Critical
Affected Software:
· Microsoft Office 2000 Service Pack 3
· Microsoft Office XP Service Pack 3
· Microsoft Office 2003 Service Pack 1 or Service Pack 2
· Microsoft Office 2004 for Mac
· Microsoft Office v. X for Mac
· Microsoft Project 2000 Service Release 1
· Microsoft Project 2002 Service Pack 1
· Microsoft Visio 2002 Service Pack 2
This update addresses several newly discovered, privately reported and public vulnerabilities. When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. More information for this update can be found at:
http://www.microsoft.com/technet/security/bulletin/MS06-062.mspx
|