Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Patch Watch>Goodbye old friends, hello Office patches

Goodbye old friends, hello Office patches

Tweet

Susan bradley By Susan Bradley

This month, we say a fond farewell to MS support for Windows XP SP1, pay tribute to Ray Noorda, and get ready for IE 7.

We also find that the servers at Microsoft Update have taken a page out of Woody Leonhard’s "you should wait to patch" handbook and decided to make you do just that.


Microsoft support ends for XP SP1

Before I begin my normal patch analysis, let me just remind you that this month marks the end of support for our dear old friend XP Service Pack 1 (SP1). Only XP SP2 will be patched in the future.

I’d like to also take a moment to pay tribute a gentleman who converted my business from “sneaker net.” That’s when we used to share files around the office by placing them on floppy diskettes. Ray Noorda, who made Novell into a powerhouse back then, passed away recently, as reported by VnuNet. While Novell isn’t the networking player it used to be, we all should pay homage to the man who did more to start us on the road of networking than anyone else — yes, even more than Bill Gates has done. For many of us, it was Novell that first awakened us to the power of networking.

MS06-057 (923191)
One IE zero-day threat patched, one not

I was expecting to tell you about two critical IE patches, MS06-057 (923191) and another related IE/ActiveX patch. But we ended up getting only one of the issues patched.

The patch we didn’t get was for the DirectAnimation Path ActiveX flaw, which was disclosed by Microsoft in security advisory 925444. What we did get was a patch for the so-called WebView hole. Both problems involve ActiveX issues on Internet Explorer.

For workstations, I strongly recommend that you apply MS06-057 extremely quickly. This vulnerability is being used on Web sites in the wild. The recommended mitigation techniques — setting “kill bits” — can cause visual issues on certain Windows Explorer pages.

For the DirectAnimation ActiveX issue, until it’s patched, consider a GPO kill-bits mitigation technique discussed in Dr. Jesper Johansson’s blog. At the present time I recommend this mitigation be deployed as soon as you can and I’ve seen no major issues at this time. Also see Chris Mosby’s comments, above.

MS06-058 (924163)
Death by PowerPoint revisited

Another patch dealing with a vulnerability that we’ve seen some targeted attacks with is MS06-058 (924163). A paranoid network administrator could try to work around this hole by blocking PowerPoint files from being received via e-mail. But there is still the risk of PowerPoint files being opened up on the Web.

If you and your users have the ability to surf the Web, open up or download any files, it would be wise for you to deploy MS06-058 quickly.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Microsoft monthly patches
  2. Two patches you should jump on
  3. Don’t ignore two critical, reissued patches
  4. Microsoft skips some critical IE patches
  5. April showers bring April patches
= Paid content

All Windows Secrets articles posted on 2006-10-12:

  • Top Story MS OneCare halts flow of antivirus info
  • Hot Tips You’ll love IE 7′s tabs or hate ‘em
  • Perimeter Scan Is Vista locking out security competitors?
  • Over the Horizon Microsoft skips some critical IE patches
  • Patch Watch Goodbye old friends, hello Office patches
  •  Show all articles on a single page
Susan Bradley

About Susan Bradley

Susan Bradley is a Small Business Server and Security MVP, a title awarded by Microsoft to independent experts who do not work for the company. She's also a partner in a California CPA firm.
View all posts by Susan Bradley →
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb