http://www.informationweek.com/story/showArticle.jhtml?articleID=15305930Microsoft on Wednesday issued two security bulletins that fix seven security flaws, five of which the software maker ranked as critical, its most severe rating. It's the first round of security bulletins issued under Microsoft's new policy of releasing patches on a monthly schedule whenever possible.
snip
Microsoft disclosed five Windows vulnerabilities, four of which are ranked critical and would allow the execution of remote code.
snip
Here's a listing of the vulnerabilities announced Wednesday. More information is available at www.microsoft.com/security:
• MS03-047: Vulnerability in Exchange Server 5.5 Outlook Web Access could allow cross-site scripting attack (828489)
• MS03-046: Vulnerability in Exchange Server could allow arbitrary code execution (822363)
• MS03-045: Buffer overrun in the ListBox and in the ComboBox Control could allow code execution (824141)
• MS03-044: Buffer overrun in Windows Help and Support Center could lead to system compromise (825119)
• MS03-043: Buffer overrun in Messenger Service could allow code execution (828035)
• MS03-042: Buffer overflow in Windows Troubleshooter ActiveX Control could allow code execution (826232)
• MS03-041: Vulnerability in Authenticode Verification could allow remote code execution (823182)