Yet another Critical fix is available from Microsoft TechNet. I was tipped off to the existence of this one yesterday when attending the SANS security webcase which by the way was excellent. They showed you the tools to check/hack a web application complete with a walkthrough of how they had pentested a bank site and with no clever tricks managed to view users credit card numbers, bank information, log on AS the user and change the users passwords…..quite scary stuff! Needless to say the bank was anonymous!