News

Microsoft Releases 5 Security Bulletins

Microsoft on Tuesday released five security bulletins as promised. All five addressed vulnerabilities that could allow an attacker to take complete control of an affected system. Three of the bulletins were rated critical, and one addressed a high-profile, zero-day exploit in Internet Explorer.

The most anticipated of the bulletins is MS06-013, a cumulative update for Internet Explorer. That critical bulletin addressed a flaw that Microsoft named the "DHTML Method Call Memory Corruption Vulnerability." Code taking advantage of the flaw popped up all over the Web weeks in advance of Microsoft's patch. Microsoft considered, but rejected, releasing the patch before today's regular monthly patching event. The flaw is rated critical for Internet Explorer 5.0 Service Pack 4, IE 6.0 SP1 (except on Windows Server 2003) and IE for Windows XP SP2.

But that fix is only one of 10 new vulnerabilities that are fixed in the cumulative IE patch -- and eight of the fixes are for critical problems. Meanwhile, the patch also includes a non-security update to ActiveX resulting from Eolas Technologies' patent dispute with Microsoft.

The other two critical bulletins address a vulnerability in the Microsoft Data Access Components (MDAC) Function (MS06-014) and a vulnerability in Windows Explorer (MS06-015).

A cumulative update bulletin for Outlook Express (MS06-016) fixes a problem rated "important" on the Microsoft threat scale; while a cross-site scripting flaw in Microsoft FrontPage Server Extensions prompted a bulletin (MS06-017) with a "moderate" severity rating.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.

  • An image of planes flying around a globe

    2025 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Notebook

    Microsoft Centers AI, Security and Partner Dogfooding at MCAPS

    Microsoft's second annual MCAPS for Partners event took place Tuesday, delivering a volley of updates and directives for its partners for fiscal 2026.

  • Microsoft Layoffs: AI Is the Obvious Elephant in the Room

    As Microsoft doubles down on an $80 billion bet on AI this fiscal year, its workforce reductions are drawing scrutiny over whether AI's ascent is quietly reshaping its human capital strategy, even as official messaging avoids drawing a direct line.