News

Cumulative Patch Ships for 3 Critical IE Flaws

More than a month after the Download.Ject vulnerability began exploiting a flaw in Internet Explorer, Microsoft fixed the underlying critical security vulnerability with a cumulative security patch over the weekend. The software giant urged customers to apply the update immediately.

Microsoft released security bulletin MS04-025 Friday evening and updated it on Sunday. The cumulative bulletin includes fixes for three vulnerabilities that are all public and are each critical on some version of IE.

Microsoft's patch is unusual in two respects that underscore its severity. It is only the third time since the company instituted a monthly patch cycle that it has released a bulletin outside of that schedule. One of the other times was last month, when the company released a workaround in advance of the actual patch for the flaw permitting Download.Ject. The other unusual aspect of the patch is that it includes fixes for Windows NT Workstation 4.0 Service Pack 6a and Windows 2000 Service Pack 2. Support for both of those platforms has been officially discontinued.

All three flaws can allow an attacker to take complete control of a user's computer over the Internet.

The one exploited by Download.Ject is called a navigation method cross-domain vulnerability. It is critical for IE 6 SP1 on any platform other than Windows Server 2003, IE 6 and IE 5.5 SP2. A flaw called the malformed BMP file buffer overrun is critical for IE 5.01 with service packs 2 through 4, IE 5.5 SP2 and IE 6. The third flaw, malformed GIF file double free vulnerability, is critical for all supported versions of Internet Explorer, including those running under Enhanced Security Configuration in Windows Server 2003.

The Download.Ject attack emerged in June. The attackers compromised Windows 2000 Web servers using versions of IIS 5.0 that hadn't been patched for an earlier vulnerability. Code appended to those compromised sites was used to compromise the flaw in IE that Microsoft hadn't yet patched.

View Microsoft's security bulletin:
www.microsoft.com/technet/security/bulletin/ms04-025.mspx.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Report: Cost, Sustainability Drive DaaS Adoption Beyond Remote Work

    Gartner's 2025 Magic Quadrant for Desktop as a Service reveals that while secure remote access remains a key driver of DaaS adoption, a growing number of deployments now focus on broader efficiency goals.

  • Windows 365 Reserve, Microsoft's Cloud PC Rental Service, Hits Preview

    Microsoft has launched a limited public preview of its new "Windows 365 Reserve" service, which lets organizations rent cloud PC instances in the event their Windows devices are stolen, lost or damaged.

  • Hands-On AI Skills Now Outshine Certs in Salary Stakes

    For AI-related roles, employers are prioritizing verifiable, hands-on abilities over framed certificates -- and they're paying a premium for it.

  • Roadblocks in Enterprise AI: Data and Skills Shortfalls Could Cost Millions

    Businesses risk losing up to $87 million a year if they fail to catch up with AI innovation, according to the Couchbase FY 2026 CIO AI Survey released this month.