News

Microsoft Issues 'Zero-Day' XML Core Patch, 5 Others

As expected, Microsoft today issued six patches for a variety of security issues, including an XML vulnerability considered to be "zero day."

As expected, Microsoft today issued six patches for a variety of security issues, including an XML vulnerability considered to be "zero day."

According to Microsoft, this flaw (MS06-071), rated critical, could allow remote code to infect a user's machine if they visit a Web site with the attack code. According to an earlier security advisory, those using Windows Server 2003 SP1 with default settings and using Enhanced Security Configuration are not vulnerable.

According to Microsoft's Security Response Center blog, unlike today's other patches, the company was unable to distribute this one through SUS 1.0. "The update is available through all other channels, and Software Update Services customers can obtain this update directly from the Download Center or through WSUS," wrote Mike Reavey. "We are working to make this update available through SUS as quickly as possible and expect to release it with the next SUS 1.0 update."

This month's other patches are available through SUS 1.0, as well as all other distribution channels. They are:

  • MS06-066, Important: Fixes two problems relating to NetWare and Microsoft Client Services.
  • MS06-067, Critical: Described by Microsoft as a "Cumulative Security Update for Internet Explorer," fixes several problems relating to Windows and IE 5.01 and 6.
  • MS06-068, Critical: Relates to a flaw in Microsoft Agent Memory Corruption in various versions of Windows.
  • MS06-069, Critical: Deals with issues with Windows XP and Macromedia Flash Player.
  • MS06-070, Critical: Fixes a Workstation Service Memory Corruption vulnerability found in Windows 2000 SP4 and Windows XP SP2.

The company did not patch another flaw relating to Visual Studio that's also reported to be "zero day," meaning that active code exploiting the flaw has been found.

To view the official announcement regarding this month's release, go here.

About the Author

Becky Nagel serves as vice president of AI for 1105 Media specializing in developing media, events and training for companies around AI and generative AI technology. She also regularly writes and reports on AI news, and is the founding editor of PureAI.com. She's the author of "ChatGPT Prompt 101 Guide for Business Users" and other popular AI resources with a real-world business perspective. She regularly speaks, writes and develops content around AI, generative AI and other business tech. She has a background in Web technology and B2B enterprise technology journalism.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.