|
|
Microsoft Security Bulletin |
Microsoft Security Bulletin MS06-004
|
Cumulative Security Update for Internet Explorer (910620) Severity: Critical
WMF Image Parsing Memory Corruption Vulnerability - CVE-2006-0020 A remote code execution vulnerability exists in Internet Explorer because of the way that it handles Windows Metafile (WMF) images. An attacker could exploit the vulnerability by constructing a specially crafted WMF image that could potentially allow remote code execution if a user visited a malicious Web site, opened or previewed an e-mail message, or opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
|
 |
 |
Vulnerability in PowerPoint 2000 Could Allow Information Disclosure (889167) Severity: Important
PowerPoint Temporary Internet Files Information Disclosure Vulnerability - CVE-2006-0004 An Information Disclosure vulnerability exists in PowerPoint. An attacker who successfully exploited this vulnerability could remotely attempt to access objects in the Temporary Internet Files Folder (TIFF) explicitly by name. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce useful information that could be used to try to further compromise the affected system.
|
 |
 |
Vulnerability in Microsoft Distributed Transaction Coordinator Could Allow Denial of Service (913580) Severity: Important
A denial of service vulnerability exists that could allow an attacker to send a specially crafted network message to an affected system. An attacker could cause the Microsoft Distributed Transaction Coordinator (MSDTC) to stop responding. |
Vulnerability in Microsoft Exchange Could Allow Remote Code Execution (916803) Severity: Important
Vulnerabilities exist in Microsoft Exchange that could allow remote code execution.
|
Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (913433) Severity: Important
Vulnerabilities exist in Macromedia Flash Player from Adobe that could allow remote code execution. |
|