Critical Flaws found in MS Java

  • Who should read this bulletin: All customers using Microsoft® Windows®.
  • Impact of vulnerability: Three vulnerabilities, the most serious of which could enable an attacker to gain complete control over a user’s system.
  • Maximum Severity Rating: Critical
  • Recommendation: Customers should apply the patch immediately.

Nice!

There are a few major issues that could allow malicious web pages or HTML email (with applets) to compromise any machine using certain versions of the Microsoft JVM. Which versions is a bit sketchy, the advisory states "Microsoft tested VM builds 5.0.3167 and later to assess whether they are affected by these vulnerabilities." So that appears to mean any version up to and including that one are affected. Just UNINSTALL the Microsoft JVM stuff and install a Sun JVM.

For more see the linked advisory.   Microsoft JVM Advisory