Re: MSIE may download and run progams automatically

From: Richard Welty (rwelty@averillpark.net)
Date: 12/14/01


Date: Fri, 14 Dec 2001 14:37:46 -0500 (EST)
From: Richard Welty <rwelty@averillpark.net>
To: bugtraq@securityfocus.com

On Fri, 14 Dec 2001 16:41:09 +0200 (EET) Jouko Pynnonen <jouko@solutions.fi> wrote:
> The company was informed about the new variation on
> November 27th and started working on a patch to correct the flaw. The
> patch is now out and downloadable on Microsoft's site at
>
> http://www.microsoft.com/technet/security/bulletin/MS01-058.asp

note that this patch does NOT show up if you click on "Windows Update" in
the Start menu; you must go to the above URL to get to the patch.

users who treat Windows Update as their method for verifying the state of
their system may be in for a suprise.

richard

--
Richard Welty
Averill Park Networking          Unix, Linux, IP Network Engineering, Security
rwelty@averillpark.net
518-573-7592



Relevant Pages

  • Re: Bug in IE critical patch?
    ... The patch is important for your security, ... > I may have left Norton running while installing the patch. ... >> Did you "download" the patch via Windows Update? ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: 891711/MS05-002 Updated (fixed) for Win9x
    ... I am still confused as to whether it is better to | just update and overwrite the old patch through Windows Update or is it much | safer and or better to remove the original patch and update to the new one | through Windows Update. ... |> current form, is a more or less a permanent solution, with the update |> still running as a background process? ... security |> update ...
    (microsoft.public.security)
  • [Full-Disclosure] OT but related.
    ... Windows Update doesn't check files, ... "For the rest of you, testing has shown that some patch management ... Update Expert will incorrectly assert ... they will correctly report the patch level. ...
    (Full-Disclosure)
  • RE: Print Current Record Only
    ... >> Microsoft Access Support ... >> to visit Windows Update at ... >> the patch. ...
    (microsoft.public.access.gettingstarted)
  • Re: What happened to my last post
    ... > stopped access to my Access file using ASP.NET. ... > it worked fine for over two years, and suddenly (after a windows update) ... because this is not the right forum to get in touch with Microsoft. ... previously with our SQL Server database access, again after a service patch. ...
    (microsoft.public.win2000.general)