Microsoft readies first Patch Tuesday release of 2011

 

Three vulnerabilities to be addressed.

Microsoft will use the first Patch Tuesday of the New Year to address three vulnerabilities in its Windows architecture.

The company said it expected to issue two bulletins next week: one affecting Vista that was rated "important" and a second bulletin with an aggregate rating of "critical" that affected all supported versions of Windows.

The potential impact of all vulnerabilities was said to be remote code execution.

"As always, we recommend that customers deploy these updates as soon as possible," Microsoft trustworthy computing senior response communications manager Carlene Chmaj said in a blog post.

Microsoft confirmed that this month's release would not include fixes for the vulnerability in the Windows graphics rendering engine, nor a public vulnerability affecting Internet Explorer.

The IE vulnerability was caused by the "creation of uninitialised memory during a CSS function within Internet Explorer," the vendor said.

"It is possible under certain conditions for the memory to be leveraged by an attacker using a specially crafted web page to gain remote code execution," Microsoft said in a security advisory.

Chmaj said today that Microsoft had "started to see targeted attacks" using the IE vulnerability.

Copyright © iTnews.com.au . All rights reserved.


Microsoft readies first Patch Tuesday release of 2011
 
 
 
 
 
Top Stories
Australian miners send drones to work
In-depth: Unmanned aerial vehicles in the resources sector.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 511

Vote