﻿<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xhtml="http://www.w3.org/1999/xhtml">
	<channel xmlns:mssec="http://schemas.microsoft.com/security/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" >
		<copyright>Copyright Microsoft Corporation 2005</copyright>
		<description>Microsoft Security Bulletins</description>
		<link>http://www.microsoft.com/technet/security/current.aspx</link>
		<title>Microsoft Security Bulletins</title>
		<language>en-us</language>
		<image>
			<link>http://www.microsoft.com/technet/security/current.aspx</link>
			<title>Microsoft Security Bulletins</title>
			<url>http://technet.microsoft.com/library/toolbar/3.0/images/banners/TechNetB_masthead_ltr.gif</url>
			<height>42</height>
			<width>225</width>
		</image>
		<cf:listinfo>
			<cf:group ns="http://schemas.microsoft.com/security/" element="rating" 
               label="Security Rating"  />
            <cf:sort ns="" element="PubDate" label="Release Date" data-type="date" />
            <cf:group ns="http://schemas.microsoft.com/security/" element="affects" label="Affected Component" />
		</cf:listinfo>
		<lastBuildDate>Wed, 11 Jan 2006 19:14:12 GMT</lastBuildDate>
		<item>
			<title>MS06-003: Vulnerability in TNEF Decoding in Microsoft Outlook and Microsoft Exchange Could Allow Remote Code Execution (902412)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability that could allow an attacker to run arbitrary code on the system. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. On vulnerable versions of Outlook, Office Language Interface Packs, Office MultiLanguage Packs or Office Multilingual User Interface Packs, if a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. On vulnerable versions of Exchange, an attacker who successfully exploited this vulnerability could take complete control of an affected system. This vulnerability could be exploited automatically without user interaction. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx?pubDate=2006-01-10</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx</guid>
			<pubDate>Tue, 10 Jan 2006 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>Outlook</mssec:affects>
			<mssec:affects>Exchange</mssec:affects>
		</item>
		<item>
			<title>MS06-002: Vulnerability in Embedded Web Fonts Could Allow Remote Code Execution (908519)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. An attacker who successfully exploited this vulnerability could take control of an affected system. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx?pubDate=2006-01-10</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx</guid>
			<pubDate>Tue, 10 Jan 2006 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>IE</mssec:affects>
		</item>
		<item>
			<title>MS06-001: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (912919)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, public vulnerability. The vulnerability is documented in the "Vulnerability Details" section of this bulletin. Note This vulnerability is currently being exploited and was previously discussed by Microsoft in Microsoft Security Advisory 912840. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx?pubDate=2006-01-05</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx</guid>
			<pubDate>Thu, 05 Jan 2006 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>GDI+</mssec:affects>
		</item>
		<item>
			<title>MS05-055: Vulnerability in Windows Kernel Could Allow Elevation of Privilege (908523)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. A vulnerability exists in the way that asynchronous procedure calls are processed within the kernel. This vulnerability could allow a logged on user to take complete control of the system</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-055.mspx?pubDate=2005-12-13</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-055.mspx</guid>
			<pubDate>Tue, 13 Dec 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>Kernel</mssec:affects>
		</item>
		<item>
			<title>MS05-054: Cumulative Security Update for Internet Explorer (905915)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves several newly-discovered, publicly and privately reported vulnerabilities. Each vulnerability is documented in its own Vulnerability Details section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx?pubDate=2005-12-13</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx</guid>
			<pubDate>Tue, 13 Dec 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>IE</mssec:affects>			
		</item>
		<item>
			<title>MS05-053: Vulnerabilities in Graphics Rendering Engine Could Allow Code Execution (896424)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves several newly-discovered, privately reported and public vulnerabilities. Each vulnerability is documented in this bulletin in its own Vulnerability Details section of this bulletin. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-053.mspx?pubDate=2005-11-08</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-053.mspx</guid>
			<pubDate>Tue, 08 Nov 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>GDI+</mssec:affects>			
		</item>
		<item>
			<title>MS05-052: Cumulative Security Update for Internet Explorer (896688)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered public vulnerability and other privately-reported variations of the same vulnerability. The Microsoft DDS Library Shape Control (Msdds.dll) and other COM objects could, when instantiated in Internet Explorer, allow an attacker to take complete control of an affected system. Because these COM objects were not designed to be instantiated in Internet Explorer, this update sets the kill bit for the affected Class Identifiers (CLSID) in these COM objects. The vulnerability is documented in the Vulnerability Details section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-052.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-052.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>IE</mssec:affects>			
		</item>
		<item>
			<title>MS05-051: Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution (902400)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves several newly-discovered, privately-reported vulnerabilities. Each vulnerability is documented in this bulletin in its own Vulnerability Details section of this bulletin. An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that Windows 2000 and Windows XP Service Pack 1 customers apply the update immediately. We recommend that customers using other operating system versions apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-051.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-051.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>MSDTC</mssec:affects>			
			<mssec:affects>COM+</mssec:affects>
		</item>
		<item>
			<title>MS05-050: Vulnerability in DirectShow Could Allow Remote Code Execution (904706)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. The vulnerability is documented in the "Vulnerability Details" section of this bulletin.  If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.  We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-050.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-050.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>DirectShow</mssec:affects>
		</item>
		<item>
			<title>MS05-049: Vulnerabilities in Windows Shell Could Allow Remote Code Execution (900725)</title>
			<description>Bulletin Severity Rating:Important - This update resolves several newly-discovered, privately reported vulnerabilities in the Windows Shell. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. However, user interaction is required to exploit this vulnerability.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>Shell</mssec:affects>
		</item>
		<item>
			<title>MS05-048: Vulnerability in the Microsoft Collaboration Data Objects Could Allow Remote Code Execution (907245)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability that could allow an attacker to run arbitrary code on the system. The vulnerability is documented in the Vulnerability Details section of this bulletin. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-048.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-048.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>CDO</mssec:affects>			
		</item>
		<item>
			<title>MS05-047: Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege (905749)</title>
			<description>Bulletin Severity Rating:Important - This update resolves a newly-discovered, privately-reported vulnerability. A remote code execution vulnerability exists in Plug and Play (PnP) that could allow an authenticated attacker who successfully exploited this vulnerability to take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The vulnerability is documented in the Vulnerability Details section of this bulletin. We recommend that customers apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Important</mssec:rating>
			<mssec:affects>PnP</mssec:affects>
		</item>
		<item>
			<title>MS05-046: Vulnerability in the Netware Client Could Allow Remote Code Execution (899589)</title>
			<description>Bulletin Severity Rating:Important - This update resolves a newly-discovered, privately-reported vulnerability. A remote code execution vulnerability exists in the Client Service for NetWare (CSNW). By default, CSNW is not installed on any affected operating system version. Only customers who manually installed CSNW could be vulnerable to this issue. The vulnerability is documented in the Vulnerability Details section of this bulletin. This service is also called Gateway Service for NetWare on Windows 2000 Server. An attacker who successfully exploited this vulnerability could remotely take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-046.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-046.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Important</mssec:rating>
			<mssec:affects>Netware</mssec:affects>
		</item>
		<item>
			<title>MS05-045: Vulnerability in Network Connection Manager Could Allow Denial of Service (905414)</title>
			<description>Bulletin Severity Rating:Moderate - This update resolves a newly-discovered, public vulnerability. A vulnerability in Network Connection Manager could allow a denial of service on the affected platforms against the Network Connection Manager. The vulnerability is documented in the Vulnerability Details section of this bulletin. An attacker who successfully exploited this vulnerability could cause the component responsible for managing network and remote access connections to stop responding. If the affected component is stopped due to an attack, it will automatically restart when new requests are received. We recommend that customers consider applying the security update.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-045.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-045.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Moderate</mssec:rating>
			<mssec:affects>CM</mssec:affects>
		</item>
		<item>
			<title>MS05-044: Vulnerability in the Windows FTP Client Could Allow File Transfer Location Tampering (905495)</title>
			<description>Bulletin Severity Rating:Moderate - This update resolves a newly-discovered, public vulnerability. A vulnerability exists in the Windows FTP client because of the way it validates file names. This vulnerability could allow an attacker to tamper with the file transfer location on the client during an FTP file transfer session.We recommend that customers consider applying the security update.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-044.mspx?pubDate=2005-10-11</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-044.mspx</guid>
			<pubDate>Tue, 11 Oct 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Moderate</mssec:rating>
			<mssec:affects>FTP Client</mssec:affects>
		</item>
		<item>
			<title>MS05-043: Vulnerability in the Print Spooler Service Could Allow Remote Code Execution (896423)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. A vulnerability exists in the Print Spooler service that could allow remote code execution. The vulnerability is documented in the "Vulnerability Details" section of this bulletin. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-043.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-043.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>Print Spooler</mssec:affects>
		</item>
		<item>
			<title>MS05-042: Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587)</title>
			<description>Bulletin Severity Rating:Moderate - This update resolves two newly-discovered vulnerabilities, a privately reported vulnerability and a publicly reported vulnerability. Each vulnerability is documented in this bulletin in its own “Vulnerability Details” section of this bulletin. An attacker who successfully exploited the most severe of these vulnerabilities could cause the service responsible for authenticating users in an Active Directory domain to stop responding. We recommend that customers consider applying the security update.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-042.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-042.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Moderate</mssec:rating>
			<mssec:affects>Kerberos</mssec:affects>
		</item>
		<item>
			<title>MS05-041: Vulnerability in Remote Desktop Protocol Could Allow Denial of Service (899591)</title>
			<description>Bulletin Severity Rating:Moderate - This update resolves a newly-discovered, privately-reported vulnerability. A vulnerability in the Remote Desktop Protocol (RDP) exists that could allow an attacker to cause a system to stop responding. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. We recommend that customers consider applying the security update.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-041.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-041.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Moderate</mssec:rating>
			<mssec:affects>RDP</mssec:affects>
		</item>
		<item>
			<title>MS05-040: Vulnerability in Windows Telephony Service Could Allow Remote Code Execution (893756)</title>
			<description>Bulletin Severity Rating:Important - This update resolves a newly-discovered, privately-reported vulnerability. A vulnerability exits in the Telephony Application Programming Interface (TAPI) service that could allow remote code execution. The vulnerability is documented in the "Vulnerability Details" section of this bulletin. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-040.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-040.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Important</mssec:rating>
			<mssec:affects>Telephony</mssec:affects>
		</item>
		<item>
			<title>MS05-039: Vulnerability in Plug and Play Could Allow Remote Code Execution and Elevation of Privilege (899588)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. A remote code execution vulnerability exists in Plug and Play (PnP) that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-039.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-039.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>PnP</mssec:affects>
		</item>
		<item>
			<title>MS05-038: Cumulative Security Update for Internet Explorer (896727)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves several newly-discovered, publicly and privately reported vulnerabilities. Each vulnerability is documented in this bulletin in its own "Vulnerability Details" section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx?pubDate=2005-08-09</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx</guid>
			<pubDate>Tue, 09 Aug 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>IE</mssec:affects>
		</item>
		<item>
			<title>MS05-037: Vulnerability in JView Profiler Could Allow Remote Code Execution (903235)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, public vulnerability. A COM object, the JView Profiler (Javaprxy.dll), when instantiated in Internet Explorer, contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system. Since the JView Profiler COM object was not designed to be accessed through Internet Explorer, this update sets the kill bit for the JView Profiler (Javaprxy.dll) COM object. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-037.mspx?pubDate=2005-07-12</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-037.mspx</guid>
			<pubDate>Tue, 12 Jul 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>JView</mssec:affects>
		</item>
		<item>
			<title>MS05-036: Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution (901214)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. A remote code execution vulnerability exists in the Microsoft Color Management Module because of the way that it handles ICC profile format tag validation. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-036.mspx?pubDate=2005-07-12</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-036.mspx</guid>
			<pubDate>Tue, 12 Jul 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>CMM</mssec:affects>
		</item>
		<item>
			<title>MS05-035: Vulnerability in Microsoft Word Could Allow Remote Code Execution (903672)</title>
			<description>Bulletin Severity Rating:Critical - This update resolves a newly-discovered, privately-reported vulnerability. The vulnerability is documented in the “Vulnerability Details” section of this bulletin. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update at the earliest opportunity.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-035.mspx?pubDate=2005-07-12</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-035.mspx</guid>
			<pubDate>Tue, 12 Jul 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Critical</mssec:rating>
			<mssec:affects>Word</mssec:affects>
		</item>
		<item>
			<title>MS05-034: Cumulative Security Update for ISA Server 2000 (899753)</title>
			<description>Bulletin Severity Rating:Moderate - This update resolves several newly-discovered, privately reported vulnerabilities. Each vulnerability is documented in this bulletin in its own “Vulnerability Details” section of this bulletin. We recommend that customers consider applying the security update.</description>
			<link>http://www.microsoft.com/technet/security/bulletin/ms05-034.mspx?pubDate=2005-06-14</link>
			<guid isPermaLink="false">http://www.microsoft.com/technet/security/bulletin/ms05-034.mspx</guid>
			<pubDate>Tue, 14 Jun 2005 08:00:00 GMT</pubDate>
			<mssec:rating>Moderate</mssec:rating>
			<mssec:affects>ISA Server</mssec:affects>
		</item>
	</channel>
</rss>