Microsoft to address IE, Stuxnet flaws, 38 others

Staff Writer
Follow google news

106 patches expected.

Microsoft is prepping 17 patches to close 40 vulnerabilities as part of its December security update.

The update, due Tuesday, will close holes in Windows, Office, Internet Explorer (IE), SharePoint and Exchange, according to an advanced notification bulletin. Of the 17 bulletins, two are rated "critical", 14 are deemed "important" and one is designated "moderate."

The patch batch will close two publicly known issues: an elevation-of-privilege flaw that has been used in conjunction with Stuxnet attacks – public exploit code is available – and an IE bug that was being exploited in the wild on at least one legitimate website.

"We encourage customers to review this month's bulletins and to prioritize their installation according to the needs of their environment," Mike Reavey, director of the Microsoft Security Response Center, wrote in a blog post.

2010 likely will close with Microsoft releasing a total of 106 patches. Reavey said the high number is due to a number of factors, including increasing vulnerability research and the long periods of time that Microsoft supports its products.

See original article on scmagazineus.com

Microsoft to address IE, Stuxnet flaws, 38 others

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Australia's critical infrastructure security laws "toothless"

Australia's critical infrastructure security laws "toothless"

"CanisterWorm" supply chain malware attacks npm

"CanisterWorm" supply chain malware attacks npm

Gov proposes disclosure delay for most serious cyberattacks

Gov proposes disclosure delay for most serious cyberattacks

US regulator bans imports of new foreign-made routers

US regulator bans imports of new foreign-made routers

Log In

  |  Forgot your password?