=====================================================================
                                  CERT-Renater

                       Note d'Information No. 2005/VULN020
_____________________________________________________________________

DATE                      : 12/01/2005

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Windows 2000, Windows XP, Windows Server 2003,
                                  Windows 98, Windows 98 SE, Me.

======================================================================

MS05-001
Title:  Vulnerability in HTML Help Could Allow Code Execution
(890175)

Affected Software:
  - Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000
Service Pack 4
  - Microsoft Windows XP Service Pack 1 and Microsoft Windows XP
Service Pack 2
  - Microsoft Windows XP 64-Bit Edition Service Pack 1
  - Microsoft Windows XP 64-Bit Edition Version 2003
  - Microsoft Windows Server 2003
  - Microsoft Windows Server 2003 64-Bit Edition
  - Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE),
and Microsoft Windows Millennium Edition (Me)

Affected Components:
  - Internet Explorer 6.0 Service Pack 1 when installed on Microsoft
Windows NT Server 4.0 Service Pack 6a or Microsoft Windows NT Server
4.0 Terminal Server Edition Service Pack 6

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Restart required: In some cases, this update does not require a
restart. The installer stops the required services, applies the
update, and then restarts the services. However, if the required
services cannot be stopped for any reason, or if required files are
in use, this update will require a restart. If this occurs, a message
appears that advises you to restart.

Update can be uninstalled: Yes

More information on this vulnerability is available at:
http://www.microsoft.com/technet/security/bulletin/MS05-001.mspx

======================================================================

         =========================================================
         Les serveurs de référence du CERT-Renater
         http://www.urec.fr/securite
         http://www.cru.fr/securite
         http://www.renater.fr
         =========================================================
         + CERT-RENATER          | tel : 01-53-94-20-44          +
         + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
         + 75013 Paris           | email: certsvp@renater.fr     +
         =========================================================







