Microsoft Glitches Hamper Critical Fixes
Crucial patches for IE and Office hit snags; a fix for a Norton security hole.
Stuart J. Johnston
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Take the latest cumulative update for Internet Explorer. Two of its corrections sealed significant holes in IE 7 for both Vista and XP, starting with COM objects (precursors to ActiveX controls). Viewing a site with a poisoned COM object could allow an attacker to take control of your system, although you would have to okay an IE 7 dialog box first.
The second flaw exists in an internal IE function, the property method. An attacker could target the flaw with a specially crafted Web page and hit you with a drive-by download.
The same cumulative update addressed four crucial issues with ActiveX and Active Scripting in IE 6 on Windows XP SP2. When you factor in fixes for critical flaws in IE 5.01 and 6 on Windows 2000 SP4, as well as in IE 6 on Windows XP SP1, it's a patch you'll want from Microsoft Support, if you haven't already received it through Automatic Updates.
Broken IE
It's clear these are must-have patches. But a nasty post-patch surprise awaits some Vista users: IE may fail to start. Here's the problem: If you've changed the location of Vista's Temporary Internet Files folder and employ the antiphishing filter, IE might not be able to use that new folder location. The workaround, described at Microsoft Support Article ID 937409, involves moving the folder back to its original location or changing the permissions on its new location.
On top of that, some Windows XP SP2, Windows 2000 SP4, and Windows Server 2003 users had trouble with Windows Update and Microsoft Update: When Windows scanned automatically for updates, or when the user went to the update site, the PC's CPU sometimes bogged down and became unresponsive.
Bad problem, so Microsoft released a patch. But in some PCs, the hotfix not only failed to work, it caused important system tasks to crash. So Redmond released a second patch that supersedes the first and will be distributed via Automatic Updates through the end of June; it's also available at Microsoft Support Article ID 927891 . We'll see if the second hotfix fully cures the problem.
- Page 1 of 2
- Next ยป
PCW Download Guide
CDW Virtualization Center
Related Security Articles
- Online Encyclopedia Lists Internal Network Security Threats A new online encyclopedia lists internal network security threats.
- Judge Dissolves Gag Order Against MIT Students A U.S. District court judge on Tuesday dissolved a gag order against a trio of MIT students who say they found flaws in the...
- Data Security: What the Law Requires of IT IT's legal duty to secure sensitive data is complex and continuously evolving. Here's how to avoid the legal ramifications of a data breach.
- Wells Fargo Access Codes Compromise Personal Data Thieves may have accessed personal data of as many as 7,000 of the bank's customers.
- Internet Fraud Ignored by Authorities, Study Charges Spyware, viruses, and phishing cost consumers $7.1 billion in 2007, but a report says the U.S. fails to prosecute Internet fraud.
Best Prices on Antivirus Software
Anti-Virus 7.0 (Electronic Software Distribution)Price: $29.95
VirusScan Plus 2008 - 3-User (Full Product)Price: $7.24
AntiVirus 2008 (Full Product)Price: $14.95
Internet Security 2008 - 3 Users (Full Product)Price: $19.95
Norton AntiVirus 2008 - 3 UserPrice: $39.49
Anti-Virus 7.0 (Full Product)Price: $21.00
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- Myth of the Million Dollar Database Think only the big boys can afford the best database solutions? Think again. Learn about low cost systems that have proven time and time again to outperform legacy UNIX vendors on a dollar for dollar basis.
- The Future Sales Force - A Consultative Approach This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ in today's evolving market.





"Microsoft Glitches Hamper Critical Fixes" Comments