Home | Patch Tuesday: June 13, 2006Patch Tuesday: June 13, 2006The eEye Digital Security Research Team is dedicated to finding and educating the public about new and existing security vulnerabilities. Below is a list of resources to help you understand the scope of the vulnerabilities behind this month's patches and how to make informed decisions about best ways to proceed with patch installation.
Patch Tuesday Email BulletinImmediately following each Patch Tuesday's releases from Microsoft, eEye provides an email bulletin detailing the specifics of each patch's underlying vulnerability, along with information to help administrators plan for patch deployment. The email is available to subscribers of eEye's "Alert" mailing list only. Subscribers also receive timely bulletins when important network security events are unfolding, such as worms and zero-day exploits.
Free Webinar: Vulnerability Experts ForumAs a service to the network security community, eEye's Research Team - headed by Marc Maiffret, eEye's co-founder and Chief Hacking Officer - conducts a Vulnerability Expert Forum web seminar during the second week of every month. To accommodate our customers and partners worldwide, eEye hosts two sessions. These Vulnerability Expert Forums enable participants to stay current on the potential risks and remediation requirements, such as those announced today, by exploring the effect that high-risk vulnerabilities and exploits have on network environments and infrastructures. To register for this month's Vulnerability Expert Forums, visit:
http://www.eeye.com/events.
Trial DownloadsEach of eEye's vulnerability management products is designed to help you better prepare your network for remediation activities resulting from Patch Tuesday.
- Retina® Network Security Scanner
Retina proactively identifies known vulnerabilities, allowing security teams to remediate them before they are exploited.
- Blink® Endpoint Vulnerability Prevention
For organizations where patching isn't an immediate option, Blink offers host-based intrusion prevention for total protection of systems, without the need for patching.
- Iris® Network Traffic Analyzer
Iris captures network traffic and allows for the sessions to be played back in its native format, allowing security admins to identify and track certains types of traffic associated with today's flaws.
Retina AuditseEye's Retina Network Security Scanner has been updated to verify if this month's Microsoft patches are installed. Retina version 5.4.21 is available to customers via Auto-Update, and has been updated with the following audits:
MS06-021: Cumulative Security Update for Internet Explorer (916281)
[4905] Microsoft IE Cumulative Security Update - Windows 2000 SP4 IE5
[4906] Microsoft IE Cumulative Security Update - Windows XP SP2 IE6
[4907] Microsoft IE Cumulative Security Update - Windows 2000/XP IE6
[4908] Microsoft IE Cumulative Security Update - Windows 2003 IE6
MS06-022: Vulnerability in ART Image Rendering Could Allow Remote Code Execution (918439)
[4909] Microsoft Windows ART Image Remote Code Execution - Windows 2003
[4910] Microsoft Windows ART Image Remote Code Execution - Windows XP SP2
[4911] Microsoft Windows ART Image Remote Code Execution - IE6
[4912] Microsoft Windows ART Image Remote Code Execution - IE5.01
MS06-023: Vulnerability in Microsoft JScript Could Allow Remote Code Execution (917344)
[4913] Microsoft JScript Remote Code Execution - 2003
[4914] Microsoft JScript Remote Code Execution - Windows XP
[4915] Microsoft JScript Remote Code Execution - Windows 2000
MS06-024: Vulnerability in Windows Media Player Could Allow Remote Code Execution (917734)
[4916] Microsoft Windows Media Player PNG Image Remote Code Execution - Windows 2003
[4917] Microsoft Windows Media Player PNG Image Remote Code Execution Windows XP
[4918] Microsoft Windows Media Player PNG Image Remote Code Execution - Windows 2000
MS06-025: Vulnerability in Routing and Remote Access Could Allow Remote Code Execution (911280)
[4920] Microsoft Routing And Remote Access Service Remote Code Execution - Windows 2000
[4921] Microsoft Routing And Remote Access Service Remote Code Execution - Windows XP
[4922] Microsoft Routing And Remote Access Service Remote Code Execution - Windows 2003
MS06-026: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (918547)
[4923] Microsoft Graphics Rendering Engine Remote Code Execution
MS06-027: Vulnerability in Microsoft Word Could Allow Remote Code Execution (917336)
[4924] Microsoft Word Could Allow Remote Code Execution - Office 2000
[4925] Microsoft Word Could Allow Remote Code Execution - Office XP
[4926] Microsoft Word Could Allow Remote Code Execution - Office 2003
MS06-028: Vulnerability in Microsoft PowerPoint Could Allow Remote Code Execution (916768)
[4927] Microsoft PowerPoint Could Allow Remote Code Execution - Mac OS X
[4928] Microsoft PowerPoint Could Allow Remote Code Execution - Office 2000
[4929] Microsoft PowerPoint Could Allow Remote Code Execution - Office XP
[4930] Microsoft PowerPoint Could Allow Remote Code Execution - Office 2003
MS06-029: Vulnerability in Microsoft Exchange Server Running Outlook Web Access Could Allow Script Injection (912442)
[4931] Exchange Running OWA Could Allow Script Injection
MS06-030: Vulnerability in Server Message Block Could Allow Elevation of Privilege (914389)
[4932] SMB Could Allow Elevation of Privilege - Windows 2000
[4933] SMB Could Allow Elevation of Privilege - Windows XP
[4934] SMB Could Allow Elevation of Privilege - Windows 2003
MS06-031: Vulnerability in RPC Mutual Authentication Could Allow Spoofing (917736)
[4935] RPC Mutual Authentication Could Allow Spoofing
MS06-032: Vulnerability in TCP/IP Could Allow Remote Code Execution (917953)
[4936] TCP/IP Could Allow Remote Code Execution - Windows 2000
[4937] TCP/IP Could Allow Remote Code Execution - Windows XP
[4938] TCP/IP Could Allow Remote Code Execution - Windows 2003