Microsoft finally released the patch for the very public Word 2000/2002/2003 vulnerability I began blogging about several weeks ago. (https://www.ultimatewindowssecurity.com/blog) Until now your only real protection has been comprehensive and up-to-date anti-malware coverage. I recommend deploying this update to all systems with a vulnerable version of Word installed as soon as possible since this is a very public vulnerability already being exploited in the wild.
In addition Microsoft released 11 other security bulletins covering a wide range of vulnerabilities. One bulletin (MS06-021) covers 8 different vulnerabilities in Internet Explorer on all versions of Windows and I recommend installing it on all computers used to access the web. 2 bulletins deal with vulnerabilities in image file formats (ART and WMF) which you should like wise patch on workstations. Out of the 12, only about 4 bulletins deserve particular consideration for servers which I’ve highlighted in the new table beginning with this issue of Patch Tuesday Observer. Let me know if it’s helpful.
| Bulletin | Exploit Types /Technologies Affected | System Types Affected | Exploit details public? / Being exploited? | Comprehensive, practical workaround available? | MS severity rating | Products Affected | Notes | Randy's recommendation |
MS06-025
911280 | Arbitrary code
/ Windows | Workstations Terminal Servers Servers
| No/No | Yes | Critical | Win2000 XP Server 2003 Server 2000 Small Business Server 2003 Advance Server 2000
| Remote Access Connection Manager service | Patch after full testing or disable service |
MS06-029
912442 | Arbitrary code
/ Exchange | Servers
| No/No | No | Important | Exchange 2000 Exchange 2003
| Exchange 2003 Outlook Web Access | Install ASAP |
MS06-030
914389 | Privilege elevation Denial of service
/ Windows | Workstations Terminal Servers
| No/No | No | Important | Win2000 XP Server 2003 Server 2000 Small Business Server 2003 Advance Server 2000 Small Business Server 2000
| Server Message Block Protocol | Patch after testing |
MS06-021
916281 | Arbitrary code
/ Windows | Workstations Terminal Servers
| Yes/No | No | Critical | Win2000 XP Server 2003 Datacenter Server 2000 Small Business Server 2003 Advance Server 2000 Small Business Server 2000 Internet Explorer Windows Millennium Win98
| Internet Explorer | Patch after full testing |
MS06-028
916768 | Arbitrary code
/ PowerPoint | Workstations Terminal Servers
| No/No | No | Critical | Office 2000 Office 2003 Office 2004 for Mac Office 2002
| PowerPoint all versions | Patch after testing |
MS06-027
917336 | Arbitrary code
/ Office | Workstations Terminal Servers
| Yes/No | No | Critical | Office 2000 Office 2003 Word Viewer Works 2005 Works 2004 Works 2006 Office 2002 Works 2000 Works 2001 Works 2002 Works 2003
| Word 2000/2002/2003 | Patch ASAP after testing |
MS06-023
917344 | Arbitrary code
/ Windows | Workstations Terminal Servers
| No/No | No | Critical | Win2000 XP Server 2003 Small Business Server 2003 Advance Server 2000
| Jscript | Patch after full testing |
MS06-024
917734 | Arbitrary code
/ Windows Media | Workstations Terminal Servers
| No/No | Yes | Critical | XP Server 2003 Small Business Server 2003 Small Business Server 2000
| Windows Media Player | Patch or disable WMP |
MS06-031
917736 | Spoofing
/ Windows | Workstations Terminal Servers Servers
| No/No | No | Moderate | Win2000 Server 2000 Advance Server 2000 Small Business Server 2000
| RPC mutual authentication | Patch after testing in high security environments |
MS06-032
917953 | Arbitrary code
/ Windows | Workstations Terminal Servers Servers
| No/No | No | Important | Win2000 XP Server 2003 Server 2000 Datacenter Server 2000 Advance Server 2000
| TCP/IP source routing | Patch vulnerable systems or ensure source routing is disabled |
MS06-022
918439 | Arbitrary code
/ Windows | Workstations Terminal Servers
| No/No | Yes | Critical | Win2000 XP Server 2003 Datacenter Server 2000 Small Business Server 2003 Advance Server 2000 Small Business Server 2000 Internet Explorer Windows Millennium Win98
| ART image files | Patch after testing or use workaround |
MS06-026
918547 | Arbitrary code
/ Windows | Workstations Terminal Servers
| No/No | No | Critical | Windows Millennium Win98
| WMF image files | Patch after testing |