Microsoft has released updates to address a vulnerability in Microsoft Windows. Microsoft has also published an Advisory about multiple vulnerabilities in Adobe Flash Player 6 that is included with Windows XP.
Install updates
The updates to address the Windows font vulnerability are available on the Microsoft Update site (requires Internet Explorer). We recommend enabling Automatic Updates.
Upgrade or Remove Adobe Flash Player 6
To address the Flash Player 6 vulnerabilitites, upgrade to a current version or remove Flash Player using the uninstaller.
Microsoft Security Bulletin MS10-001 describes a vulnerability in the Embedded Open Type (EOT) font engine in Windows. Microsoft Security Advisory (979267) notes multiple vulnerabilities in Adobe Flash Player 6 (formerly Macromedia Flash Player) that is included with Windows XP. The Advisory recommends that Windows XP users upgrade or remove Flash Player
These vulnerabilities may allow an attacker to gain control of your computer or cause it to crash.
- Microsoft Security Bulletin Summary for January 2010 - <http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx>
- CVE-2010-0018 - <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018>
- Vulnerabilities in Adobe Flash Player 6 Provided in Windows XP Could Allow Remote Code Execution - <http://www.microsoft.com/technet/security/advisory/979267.mspx>
- Vulnerability Note VU#204889 - <http://www.kb.cert.org/vuls/id/204889>
- Adobe Flash Player - <http://get.adobe.com/flashplayer/>
- How to uninstall the Adobe Flash Player plug-in and ActiveX control - <http://kb2.adobe.com/cps/141/tn_14157.html>
Feedback can be directed to US-CERT.
Produced 2010 by US-CERT, a government organization. Terms of use
January 12, 2010: Initial release