Microsoft's Security Bulletins for December report the release of one vulnerability patch rated "critical" and five rated "important". In addition, a Microsoft Knowledge Base Article [KB886185] has been released describing a "critical" vulnerability in Microsoft Windows Firewall in Windows XP Service Pack 2 (SP2).
Microsoft Security Bulletin MS04-040 - [KB889293] reports the release of a cumulative security update for Internet Explorer, a critical patch against serious vulnerabilities that could allow for remote code execution on an affected system. If the user is logged in as administrator an attacker could gain complete control of an infected system. An attacker could host a website with malicious code embedded in its pages that would infect systems when loaded in Internet Explorer. However, an attacker would have to coax users to visit the site but would have no way of forcing visits.
The following software is affected by this vulnerability:
Microsoft has also released a Knowledge Base Article [KB886185] that describes a "critical" patch against a significant vulnerability in Microsoft Windows Firewall in Windows XP Service Pack 2 (SP2). According to Microsoft's website users may discover that their computers "can be accessed by anyone on the Internet" when they are connected to the Internet via a dial-up connection.
The following operating systems are affected by this vulnerability:
The release of five other patches are also announced in this months Microsoft Security Bulletins. These patches have all been rated "important" by Microsoft:
Users are advised to patch their systems against these vulnerabilities immediately. Patches can be downloaded via links posted within the appropriate Security Bulletin or by visiting Windows Update.