Microsoft patches critical vulnerabilities in January update

By

First 2016 fix.

Microsoft's first Patch Wednesday update for the year has taken care of multiple vulnerabilities rated as critical.

Microsoft patches critical vulnerabilities in January update

No known exploits are available for the vulnerabilities, but Microsoft recommends that users apply the patches through Windows Update as soon as possible.

Internet Explorer 7, 8, 9, 10 and 11 see two common vulnerabilities and exploits (CVEs) fixed - CVE-2016-0002 and CVE-2016-0005 - as part of a cumulative update.

Supported version of the Windows client and server operating systems are all affected by the vulnerabilities, which Microsoft rates as critical and exploitable.

Microsoft's new Edge browser in Windows 10 is also being updated, with two critical vulnerabilites patched. 

The JScript and VBScript scripting languages receive an update to prevent remote code execution, along with five patches for Microsoft Office 2007 to 2016, that tighten up how the productivity suite handles objects in memory securely, and ensures memory addresses are properly randomised.

Microsoft said the most severe of the vulnerabilities could allow remote code execution, should an attacker be able to log onto target systems and run specially crafted applications.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

"Widespread data theft" hits Salesforce customers via third party

"Widespread data theft" hits Salesforce customers via third party

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Home Affairs adds SecOps to new cyber risk overhaul

Home Affairs adds SecOps to new cyber risk overhaul

Log In

  |  Forgot your password?