Home | Patch Tuesday: November 14, 2006

Patch Tuesday: November 14, 2006

The eEye Digital Security Research Team is dedicated to finding and educating the public about new and existing security vulnerabilities. Below is a list of resources to help you understand the scope of the vulnerabilities behind this month's patches and how to make informed decisions about best ways to proceed with patch installation.

Patch Tuesday Email Bulletin
Immediately following each Patch Tuesday's releases from Microsoft, eEye provides an email bulletin detailing the specifics of each patch's underlying vulnerability, along with information to help administrators plan for patch deployment. The email is available to subscribers of eEye's "Alert" mailing list only. Subscribers also receive timely bulletins when important network security events are unfolding, such as worms and zero-day exploits.
Free Webinar: Vulnerability Expert Forum
As a service to the network security community, eEye's Research Team - headed by Marc Maiffret, eEye's co-founder and Chief Hacking Officer - conducts a Vulnerability Expert Forum web seminar during the second week of every month. This Vulnerability Expert Forum enables participants to stay current on the potential risks and remediation requirements, such as those announced Tuesday, by exploring the effect that high-risk vulnerabilities and exploits have on network environments and infrastructures. To register for this month's Vulnerability Expert Forum, visit: Vulnerability Expert Forum.

Trial Downloads
Each of eEye's vulnerability management products is designed to help you better prepare your network for remediation activities resulting from Patch Tuesday.

Retina Audits
eEye's Retina Network Security Scanner has been updated to verify if this month's Microsoft patches are installed. Retina version 5.6 is available to customers via Auto-Update, and has been updated with the following audits:

MS06-066 - Vulnerabilities in Client Service for NetWare Could Allow Remote Code Execution (923980)
[5569] Microsoft Client Services for NetWare Remote Code Execution (923980) - 2000
[5570] Microsoft Client Services for NetWare Remote Code Execution (923980) - XP
[5571] Microsoft Client Services for NetWare Remote Code Execution (923980) - 2003


MS06-067 - Cumulative Security Update for Internet Explorer (922760)
[5563] Microsoft Internet Explorer Cumulative Security Update (922760) - 2000 IE5.01 [5562] Microsoft Internet Explorer Cumulative Security Update (922760) - 2000 IE6
[5574] Microsoft Internet Explorer Cumulative Security Update (922760) - XP/2003 IE6


MS06-068 - Vulnerability in Microsoft Agent Could Allow Remote Code Execution (920213)
[5564] Microsoft Agent ACF File Remote Code Execution (920213) - 2000
[5565] Microsoft Agent ACF File Remote Code Execution (920213) - XP
[5566] Microsoft Agent ACF File Remote Code Execution (920213) - 2003


MS06-069 - Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (923789)
[5475] Adobe Flash Player Multiple Vulnerabilities (Microsoft KB923789)


MS06-070 - Vulnerability in Workstation Service Could Allow Remote Code Execution (924270)
[5567] Microsoft Workstation Service Remote Code Execution (924270) - 2000
[5568] Microsoft Workstation Service Remote Code Execution (924270) - XP


MS06-071 - Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (928088)
[5572] Microsoft XML Core Services Remote Code Execution (928088) - XML 4 core
[5573] Microsoft XML Core Services Remote Code Execution (928088) - XML 6 core