Updated: July 11, 2020 (February 20, 2006)

  Analyst Report

Feb. 2006 Security Updates

My Atlas / Analyst Reports

755 wordsTime to read: 4 min
Michael Cherry by
Michael Cherry

Michael analyzed and wrote about Microsoft's operating systems, including the Windows client OS, as well as compliance and governance. Michael... more

Two new critical and five new important patches were released on the Feb. 2006 “Patch Tuesday.” Among the more noteworthy patches are one for a second Windows Metafile (WMF) vulnerability and a patch for a Windows Media Player plug-in that is used by non-Microsoft software. Microsoft also updated its Malicious Software Removal Tool and advised customers that later this year Windows 98 and Windows XP SP1 will no longer qualify for public security updates.

Critical Patches

The first critical patch for Feb. 2006 involves the way in which Internet Explorer (IE) handles WMF images, but it is separate from the WMF vulnerabilities addressed in the previously issued MS05-053 and MS06-001 bulletins. When IE 5.01 SP4 on Windows 2000 SP4 displays a Web page that contains a specially crafted WMF image, system memory may be corrupted in such a way that an attacker could take complete control of the affected system.

The other critical patch fixes a buffer overflow in the Windows Media Player, a feature of the Windows OS that plays audio and video. The affected Windows Media Player code processes bitmap files and, if exploited, could allow an attacker to take complete control of the affected system.

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now