Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1214
    posted: 07/17/08
  • NSM Daily Update #1214
    posted: 07/17/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1214
    posted: 07/17/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1201
    posted: 07/17/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 07/17/08
Microsoft Security Bulletins

January 2005


Prior Updates:


lock icon Login to learn more about how Juniper Networks products can protect you from these vulnerabilities. (If you don't already have a login, see Requesting Support.)

January 2005

Microsoft Security Bulletin MS05-001

Vulnerability in HTML Help Could Allow Code Execution

Severity: Critical
Vulnerabilities:
  • HTML Help ActiveX control Cross Domain Vulnerability - CAN-2004-1043
    A cross-domain vulnerability exists in HTML Help ActiveX control that could allow information disclosure or remote code execution on an affected system. An attacker could exploit the vulnerability by constructing a malicious Web page that could potentially allow remote code execution if a user visited that page. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS05-002

Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution

Severity: Critical
Vulnerabilities:
  • Cursor and Icon Format Handling Vulnerability - CAN-2004-1049
    A remote code execution vulnerability exists in the way that cursor, animated cursor, and icon formats are handled. An attacker could try to exploit the vulnerability by constructing a malicious cursor or icon file that could potentially allow remote code execution if a user visited a malicious Web site or viewed a malicious e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS05-003

Vulnerability in the Indexing Service Could Allow Remote Code Execution

Severity: Important
Vulnerabilities:
  • Indexing Service Vulnerability - CAN-2004-0897
    A remote code execution vulnerability exists in the Indexing Service because of the way that it handles query validation. An attacker could exploit the vulnerability by constructing a malicious query that could potentially allow remote code execution on an affected system. An attacker who successfully exploited this vulnerability could take complete control of an affected system. While remote code execution is possible, an attack would most likely result in a denial of service condition.