Microsoft, Adobe drop patches for dozens of bugs

By
Follow google news

Microsoft issues seven patches for 12 vulnerabilities.

Microsoft and Adobe on Tuesday both shipped security updates for their widely deployed products, with the former issuing seven patches to address 12 vulnerabilities and the latter distributing fixes for Reader, Acrobat and Flash.

Microsoft, Adobe drop patches for dozens of bugs

Researchers said the two Microsoft bulletins to focus on are MS13-001, which corrects a single bug in Windows Print Spooler that could allow remote code execution, and MS13-002, which remedies two vulnerabilities in XML Core Services.

The XML flaws could be exploited via a malicious web page in Internet Explorer, according to Microsoft.

"This [patch] impacts a dog's breakfast of Microsoft operating systems and applications, including Windows 8, RT (which runs on mobile devices) and Server 2012," said Ross Barrett, senior manager of security engineering at Rapid7.

"One thing to watch out for in this type of vulnerability is applying all the patches that apply to a system...Administrators will have to patch for each affected component."

Left off the patch batch was a fix for a zero-day vulnerability in Internet Explorer which has been used to serve malware from a few high-profile websites. Microsoft has issued a temporary workaround, and IE 9 and 10 are not affected.

Meanwhile, Adobe on Tuesday updated Reader and Acrobat for 27 vulnerabilities, and Flash for a single weakness. The company said it was not aware of any of the bugs being used in active attacks.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?