Windows and Office CRITICAL UPDATE re: Credit Card Security!

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,057
67
91
This one's only a Hot Deal if you happen to buy or sell anything on line.

The headline on News.com reads, Credit card theft feared in Windows flaw. :Q

Get it before it gets you. :)

* * *

Microsoft Security Bulletin MS02-050 -- More info

Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)

Originally posted: September 04, 2002
Updated: September 05, 2002

Summary:

Who should read this bulletin: Customers using Microsoft® Windows®, Office for Mac, Internet Explorer for Mac, or Outlook Express for Mac.

Impact of vulnerability: Identity spoofing.

Maximum Severity Rating: Critical

Recommendation: Administrators should install the patch immediately.

Affected Software:

Microsoft Windows 98
Microsoft Windows 98 Second Edition
Microsoft Windows Me
Microsoft Windows NT® 4.0
Microsoft Windows NT 4.0, Terminal Server Edition
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Office for Mac
Microsoft Internet Explorer for Mac
Microsoft Outlook Express for Mac

Patch availability:

Download locations for this patch:

Microsoft Windows 98/98SE
Windows Me
Windows NT 4.0
Windows NT 4.0 Terminal Server Edition
Windows 2000: (To be released shortly)
Windows XP and Windows XP 64 Bit Edition

Microsoft Office v.X for Mac: (To be released shortly)
Microsoft Office 2001 for Mac: (To be released shortly)
Microsoft Office 98 for the Macintosh (To be released shortly)
Microsoft Internet Explorer for Mac (for OS 8.1 to 9.x) (To be released shortly)
Microsoft Internet Explorer for Mac (for OS X) (To be released shortly)
Microsoft Outlook Express 5.0.5 for Mac (To be released shortly)

Microsoft Office v.X for Mac: (To be released shortly)
Microsoft Office 2001 for Mac: (To be released shortly)
Microsoft Office 98 for the Macintosh (To be released shortly)
Microsoft Internet Explorer for Mac (for OS 8.1 to 9.x) (To be released shortly)
Microsoft Internet Explorer for Mac (for OS X) (To be released shortly)
Microsoft Outlook Express 5.0.5 for Mac (To be released shortly)

---

We locked this topic at the top of several forums to alert our members about this critical update that was not yet posted on Microsoft's Windows Update page. It has now been up for several days. We hope everyone is now aware of it.

Please continue discussion of this topic in our Operating Systems forum.

Thank you,

AnandTech Moderator
 

jonnashville

Senior member
Sep 22, 2001
378
0
0
Mac Severity: Moderate - update to be released soon.

Windows Severity: Circle the wagons... Them be injuns! (ie. Critical)

(Winhosed again!)
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,057
67
91
It's too new to be on Windows Update, yet. I found it when I was reading the article on News.com (see link in my first post). The link to the MS bulletin is in that article.
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,057
67
91
Originally posted by: lotust
i wonder if this is fixed in sp1 for XP.
I doubt it. The date on the bulletin is 9-5-1002, only two days ago. You can check more info link in my post.

Of course, it's a quick d/l, so it can't hurt to just do it.

 

Oakenfold

Diamond Member
Feb 8, 2001
5,740
0
76
Thanks man,
I also would have never known...
That thing isn't even on the win updater yet....:|

Leave it to the AT crowd to be my Sys Admin! :D
 

rochlin

Senior member
Jun 10, 2000
284
0
0
www.bestportlandrentals.com
A couple peculiar things about this update. It was already reported in the media
This Infoworld Article was published on August 30. The article has a less Microsofty perspective and fairly clear explanation.

But MSFT has known about the problem for quite a while - and so has everyone else from this Bugtraq posting on August 5 - more than a month ago!

(The poster did not warn MSFT before publication, which seems like kind of a bad idea to me.)

What is news is the availability of patches (after this whole month has passed) for SOME windows systems. Windows 2000 - certainly the most affected server OS - is unpatched (as of yesterday).