Microsoft Posts Critical Windows Bulletin

A new Microsoft security bulletin includes patches for three Windows flaws, two of them critical problems that can permit attackers to take control of a system over the Internet.

All three flaws that are addressed in bulletin MS05-053 arise from the way Windows renders graphics from Windows Metafile (WMF), Enhanced Metafile (EMF) or both of the image formats. The bulletin posted Tuesday.

The first flaw, involving an unchecked buffer in the rendering of WMF and EMF, is critical for Windows 2000, Windows XP even with Service Pack 2 and Windows Server 2003 even with Service Pack 1.

The second flaw, stemming from an unchecked buffer in WMF rendering, is also critical for Windows 2000, Windows XP SP1 and the gold code version of Windows Server 2003. Windows XP SP2 and Windows Server 2003 SP1 are unaffected by the flaw.

An unchecked buffer in EMF rendering is the source of the third flaw. It is moderate for Windows 2000, Windows XP SP1 and Windows Server 2003. Again, Windows XP SP2 and Windows Server 2003 SP1 are unaffected.

Neither of the critical flaws had been publicly disclosed. The moderate flaw had been disclosed but Microsoft has not received any reports of exploit code being developed for it.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.


  • The 2022 Microsoft Product Roadmap

    Microsoft has a lot in the docket for 2022, including new products like SQL Server 2022, Exchange Subscription Edition and Visual Studio 2022 for Mac.

  • Report: IT Budgets To Increase Despite Slowdown in Hiring

    A newly published annual report found that 51 percent of IT departments are planning to increase their IT spending next year, even in the face of a possible recession.

  • Microsoft Bolsters 'Employee Experience' with Latest Viva Apps

    Microsoft's Viva suite is getting new apps and enhancements, according to an announcement made on Thursday.

  • Microsoft Releases Windows 11 Version 22H2

    The latest version of Windows 11, known as "version 22H2," officially has been released.