Record 64 flaws to be fixed on Patch Tuesday

Powered by SC Magazine
 

Long-awaited fix for MHTML flaw.

Microsoft is issuing a security update to fix a record 64 vulnerabilities, including a months-old MHTML flaw.

Of the 17 patches, nine are rated critical and eight are important, according to Microsoft. They cover flaws in Windows, Office, Internet Explorer, Visual Studio and more.

The update addresses a MHTML flaw uncovered in January. Google said last month that the vulnerability was being used in "politically motivated" attacks against its users.

"This is a huge update and system administrators should plan for deployment as all Windows systems including Server 2008 and Windows 7 are affected by critical bulletins," advised Amol Sarwate, manager of the vulnerability research lab for security firm Qualys.

"Frequently used office applications like Excel 2003 through 2010 and PowerPoint 2002 through 2010 are also affected."

Paul Voss, senior response communications manager with Microsoft, said the software giant would also shut down several security alerts, including a critical one in Server Message Block Browser.

"Microsoft assessed the situation and reported that although the vulnerability could theoretically allow Remote Code Execution, that was extremely unlikely," Voss said in a post on the Microsoft security blog.

"To this day, we have seen no evidence of attacks."

This article originally appeared at pcpro.co.uk

Copyright © PC Pro, Dennis Publishing


Record 64 flaws to be fixed on Patch Tuesday
 
 
 
Top Stories
NSW Govt gets ready to throw out the floppy disks
[Opinion] Dominic Perrottet says its time for government to catch up.
 
iiNet facing new copyright battle with Hollywood
Fighting to protect customer details.
 
The CISO’s dilemma: Do you trust your partner’s partner?
[Blog post] How far down the chain do you check?
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  25%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  22%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  26%
TOTAL VOTES: 317

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  57%
 
No
  43%
TOTAL VOTES: 121

Vote