Microsoft IE, Outlook, Word Get Critical Bug Fixes
Even users who have removed Outlook Express from their PCs should install this month's critical patch for this software, according to Microsoft's Budd. "The files in question are part of the core operating system, so what we tell people is if the bits in question are on the box then you should apply the security update."
The IE patch is the most critical, agreed Andrew Storms, director of security operations with nCircle Network Security. According to him, an address spoofing flaw that was patched in this update has been known publicly for three months. "The URL spoof has been known since at least July and it's the perfect tool for a phisher," he said via instant message.
As for what Storms would patch after installing the IE update? "Second on my list is pretty much a tie between everything else minus the SharePoint vulnerability," he wrote.
Microsoft



