Microsoft Outlook flaw exploited with email preview

By

Redmond to issue 14 patches.

Microsoft Office, Windows and Server platforms suffer from remote code execution flaws, Redmond has revealed.

Microsoft Outlook flaw exploited with email preview

The vulnerabilities would be fixed as part of its Patch Tuesday set of 14 updates

It included a Microsoft Office 2007 and 2010 flaw that could be triggered by merely previewing an email in Outlook.

Qualys CTO Wolfgang Kandek said that flaw contained within second bulletin should be a prioirty fix.

"Bulletin two should be high priority for your desktop security team," Kandek said.

Other fixes deemed critical, Microsoft's highest rating, update the company's Sharepoint Server product, Internet Explorer versions 6 to 10, and operating systems Windows XP and Windows Server 2003.

Bulletins ranked “important” also included fixes for remote code execution flaws and vulnerabilities that could allow an attacker to carry out a denial-of-service, or give saboteurs elevated privileges.

Another security issue, which could allow users' private data to be disclosed to attackers, will also be plugged with the Patch Tuesday update.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

"Widespread data theft" hits Salesforce customers via third party

"Widespread data theft" hits Salesforce customers via third party

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Home Affairs adds SecOps to new cyber risk overhaul

Home Affairs adds SecOps to new cyber risk overhaul

Log In

  |  Forgot your password?