Technical Documentation

Security Center

Microsoft Security Bulletins: Prior Updates


July 2005

Microsoft Security Bulletin MS05-035

Vulnerability in Microsoft Word Could Allow Remote Code Execution (903672)

Severity: Critical
Vulnerabilities:
  • Font Parsing Vulnerability in Word - CAN-2005-0564
    A remote code execution vulnerability exists in Word that could allow an attacker who successfully exploited this vulnerable to take complete control of the affected system.

Microsoft Security Bulletin MS05-036

Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution (901214)

Severity: Critical
Vulnerabilities:
  • Color Management Module Vulnerability - CAN-2005-1219
    A remote code execution vulnerability exists in the Microsoft Color Management Module because of the way that it handles ICC profile format tag validation. An attacker could exploit the vulnerability by constructing a malicious image file that could potentially allow remote code execution if a user visited a malicious Web site or viewed a malicious e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft Security Bulletin MS05-037

Vulnerability in JView Profiler Could Allow Remote Code Execution (903235)

Severity: Critical
Vulnerabilities:
  • JView Profiler Vulnerability - CAN-2005-2087
    A remote code execution vulnerability exists in HTML Help that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.