Known Issues
-
Important Information issued Tuesday, August 8, 2006
Among the twelve security bulletins, MS06-040 was issued to resolve a privately disclosed vulnerability as well as additional issues discovered through internal investigations. There is a remote code execution vulnerability in the Server Service that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. As a result, we are recommending that customers apply the update immediately. The vulnerability affects the following Microsoft Windows software:
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.
The security update for MS06-040, and for the other 11 bulletins, is now available. Summaries for these new bulletins may be found at the following page:
http://www.microsoft.com/technet/security/bulletin/ms06-Aug.mspx. Customers who are using Windows Server Update Services will receive the update automatically. In addition the update is supported by Microsoft Baseline Security Analyzer 2.0, Systems Management Server, and Software Update Services. Customers can also manually download the update from the Microsoft Download Center. They can be found most easily by doing a keyword search for "security_patch."
- Beware of spam emails
Many employees are receiving emails from “service@paypal.com”, who misrepresent themselves as being a part of eBay. Some employees have fallen victim and provided confidential information, including credit card numbers and PIN information. They have subsequently discovered charges against these credit accounts.

