Microsoft brings April shower of patches

Powered by SC Magazine
 

Microsoft has released its latest monthly security update, addressing 23 security vulnerabilities with eight different bulletins.

Of the eight bulletins, five have been deemed 'critical', the highest of the company's security alert levels. If exploited, each could allow an attacker to remotely execute code on a targeted system.

Among the fixes is a bulletin to address a pair of flaws in Excel, both of which are being actively targeted by cyber criminals to perform attacks in the wild.

Microsoft noted that the 'critical' rating applies only to Office 2000 users, as later versions of the software will notify users before a potential attack file is launched.

Other critical fixes include updates to address flaws in Office, DirectX, Internet Explorer and the Windows HTTP Services component.

Additionally, Microsoft issued a fix for ISA Server and Forefront Threat Management gateway, along with a patch to prevent 'token kidnapping' attacks. Each of those bulletins are rated as 'important'.

The final bulletin was rated as 'moderate' and addresses a vulnerability in the SearchPath which could be targeted along with unpatched copies of the Safari browser to perform a 'blended threat' attack. That bulletin is being listed as a 'moderate' threat.

Because many of the flaws are previously unknown or are already being targeted, they could be especially dangerous, warned McAfee Avert Labs senior director of research and communications Dave Marcus.

"While the world is still reeling from Conficker, Microsoft today released its largest batch of security updates this year, including urgent fixes for vulnerabilities that are already being exploited," said Marcus. "This won’t be easy for many security professionals, especially in larger enterprises."

Copyright ©v3.co.uk


Microsoft brings April shower of patches
 
 
 
Top Stories
Content, cost & constant innovation: How Foxtel plans to take on Netflix
Nell Payne inhabits the “brave new world of blue strings and networking”. Just don't ask her to put a TV screen on your microwave.
 
Sending in the drones
Margins are getting tighter in the industrial services industry, so Transfield Services' Stephen Phillips looks offshore - and to the skies - for the solutions he needs to keep pace.
 
Westpac fires starting pistol on core banking upgrade
St George readies itself for move to Celeriti.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft launches Office for Android preview
May 22, 2015
Microsoft has launched a preview of Office for Android smartphones. Pre-release versions of ...
Microsoft is working on an iOS email chat feature called Flow
May 22, 2015
Microsoft is working on a new chat app, but at the moment we know more about what we DON'T know, ...
Windows 10 free upgrade: Microsoft details who gets what
May 22, 2015
Microsoft was meant to be streamlining its OS with Windows 10, so why is upgrading so confusing? ...
Windows 10 has an edition to suit everyone's needs
May 15, 2015
Microsoft unveils a mind-melting six editions of Windows 10 ahead of its Winter 2015 launch. ...
Firefox 38 FINAL released, debuts new tab-based preferences
May 13, 2015
Mozilla has unveiled the latest version of Firefox 38.0 FINAL for desktop, with Firefox for ...
Latest Comments
Polls
Should Optus make a bid for iiNet?

   |   View results
Yes
  43%
 
No
  57%
TOTAL VOTES: 541

Vote