Microsoft critical patch hours away

By

Updates to arrive 3AM Saturday.

Microsoft will release an update to patch five flaws including a zero-day affecting Internet Explorer 9 and earlier versions.

Microsoft critical patch hours away

Attackers could exploit the holes to hijack Windows machines and inject malware.

Microsoft, which issued a stop gap for the zero day, would release the fix around 3am tomorrow.

"[The] remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated," Microsoft said in an advisory. The flaw could corrupt memory and allow an attacker to execute arbitrary code.

Microsoft Trustworthy Computing director Yunsun Wee said the vulnerabilities affected a small number of customers.

"The potential exists, however, that more customers could be affected," he wrote.

The fix will be available through Windows Update and the company recommends users install it as soon as it is available. Users with automatic updates enabled on their PC won't need to take any action.

nCircle security operations director Andrew Storms said Microsoft was "light years ahead of other vendors in providing clear, consistent, valuable communication to their users on security issues". 

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

International Criminal Court hit by cyber attack

International Criminal Court hit by cyber attack

Ex-student charged over Western Sydney University cyberattacks

Ex-student charged over Western Sydney University cyberattacks

Log In

  |  Forgot your password?