SHARE
Facebook X Pinterest WhatsApp

Two Critical Fixes Top MS List for IE, Outlook Express Bugs

Microsoft issued seven security bulletins Tuesday, two of them designated “critical,” for various versions of Windows and associated products. The company recommends that all Windows users apply the critical updates immediately. One of the critical bulletins, MS04-023, titled “Vulnerability in HTML Help Could Allow Code Execution,” addresses vulnerabilities in the Windows HTML Help system that […]

Written By
thumbnail Larry Seltzer
Larry Seltzer
Jul 13, 2004
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft issued seven security bulletins Tuesday, two of them designated “critical,” for various versions of Windows and associated products. The company recommends that all Windows users apply the critical updates immediately.

One of the critical bulletins, MS04-023, titled “Vulnerability in HTML Help Could Allow Code Execution,” addresses vulnerabilities in the Windows HTML Help system that were reported previously.

An attacker could execute code on the affected system and take complete control if that user’s privileges were sufficient, according to the bulletin. Updates are available for Windows NT4, Windows 2000, Windows XP and Windows Server 2003. No patch is available yet for Windows 9x, although the bulletin says one will be available later through Windows Update.

The other critical vulnerability, MS04-022, or “Vulnerability in Task Scheduler Could Allow Code Execution,” also allows remote code execution. The affected component, which has an unchecked buffer, is installed in many recent versions of Windows, but not in Windows Server 2003.

Four bulletins are deemed “important,” and Microsoft recommends that users install the updates “at the earliest opportunity.”

Finally, MS04-018, termed a “moderate” problem, is a cumulative update for Outlook Express. The attack allows a denial of service by an attacker who uses a specially malformed e-mail header. A message with such a header could cause Outlook Express to fail.

Check out eWEEK.com’s Security Center athttp://security.eweek.com for security news, views and analysis.


Be sure to add our eWEEK.com security news feed to your RSS newsreader or My Yahoo page:  

Recommended for you...

Manny Rivelo on Evolving Channel & How MSPs Can Get Ahead
Victoria Durgin
Aug 20, 2025
Databricks Raises at $100B+ Valuation on AI Momentum
Allison Francis
Aug 20, 2025
Keepit Achieves SOC 2 Type 1 & Canadian Ingram Micro Deal
Jordan Smith
Aug 20, 2025
AI Customer Service Fails to Satisfy Consumer Needs: Verizon
Franklin Okeke
Aug 19, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.