Bravo to Microsoft for shipping the WMF patch early, rather than waiting an additional five days to ship on their regularly scheduled Patch Tuesday. Many security experts were very concerned about this flaw.
Users of Windows 2000, XP and 2003 should update immediately. Users of previous versions of Windows should stop using IE until Microsoft ships a patch.
The actual MS06-001 Security Bulletin is a bit confusing. It lists “Maximum Severity Rating: Critical” but in the FAQ seems to indicate that they are not shipping a version for Win9x/ME:
“Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME) — Review the FAQ section of this bulletin for details about these operating systems….”
In the FAQ… “How does the extended support for Windows 98, Windows 98 Second Edition, and Windows Millennium Edition affect the release of security updates for these operating systems?”
“For these versions of Windows, Microsoft will only release security updates for critical security issues.
”
Okay, I’m confused. Critical or not? Supported or not?