Home
Resources
Training
About Us
eStore
<a href="http://www.isdecisions.com/en/software/userlock/?xtor=SEC-230"><img src="http://www.isdecisions.com/images/pubs/Randy/userlock.gif" alt="UserLock" border="0" /></a>

>

resources > bulletins > MS06-068

 

 

 

 

 

 

 

Latest Blog: WinReporter 4.0 Makes It Easy to Assess Attack Surface

 

Microsoft Security Bulletin MS06-068 - Vulnerability in Microsoft Agent Could Allow Remote Code Execution (920213)

MS Agent is a services that developers can use to add interactive personalities in the form of animated characters to the UI of their applications.  The vulnerability lies in the MS Agent ActiveX control being invoked with bad data from malicious web or email content.  You can either set the kill bits on the associated controls using my handy and free KillBits administrative template or deploy the patch after testing.  I recommend testing since the vulnerability is not public or actively being exploited in attacks.
Vista isn’t vulnerable due to changes in MsAgent.

Get this valuable commentary each month as soon as Microsoft releases security updates!

Free log parser scripts, a clear explanation of Microsoft's latest security bulletin, helpful security tips, how-to's and more.

Email address:

 

Newsletter archive
Your e-mail address will be held strictly confidential and you can unsubscribe at any time.


Upcoming Webinars by Randy Franklin Smith


Additional Links

A
D
V