Microsoft patches critical vulnerabilities in January update

By

First 2016 fix.

Microsoft's first Patch Wednesday update for the year has taken care of multiple vulnerabilities rated as critical.

Microsoft patches critical vulnerabilities in January update

No known exploits are available for the vulnerabilities, but Microsoft recommends that users apply the patches through Windows Update as soon as possible.

Internet Explorer 7, 8, 9, 10 and 11 see two common vulnerabilities and exploits (CVEs) fixed - CVE-2016-0002 and CVE-2016-0005 - as part of a cumulative update.

Supported version of the Windows client and server operating systems are all affected by the vulnerabilities, which Microsoft rates as critical and exploitable.

Microsoft's new Edge browser in Windows 10 is also being updated, with two critical vulnerabilites patched. 

The JScript and VBScript scripting languages receive an update to prevent remote code execution, along with five patches for Microsoft Office 2007 to 2016, that tighten up how the productivity suite handles objects in memory securely, and ensures memory addresses are properly randomised.

Microsoft said the most severe of the vulnerabilities could allow remote code execution, should an attacker be able to log onto target systems and run specially crafted applications.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?