Microsoft to patch Internet Explorer 10

By

Pwn2Own bugs squashed?

Microsoft is readying nine patches to be released Tuesday as part of the software giant's monthly security update.

Microsoft to patch Internet Explorer 10

Security consultancy which cracked Microsoft's Surface Pro using two Internet Explorer zero day vulnerabilities and a sandbox bypass.  

Two of the nine fixes address vulnerabilities rated critical and could be exploited to execute remote code, while the remaining seven patches attend to flaws deemed important, according to an advance notification from Microsoft.

Security observers eyed Bulletin 1 as the most pressing because it involved vulnerabilities in all supported versions (6-10) of Internet Explorer (IE).

Security weaknesses in browsers are preferred vectors of attack for cyber criminals because often they can be successful by a victim merely visiting an infected web page.

Andrew Storms, director of security operations at nCircle, which recently was acquired by Tripwire, suspects one of the IE flaws being plugged was discovered last month at the Pwn2Own hacker contest at the CanSecWest show in British Columbia.

The update's remaining patches, address issues in Windows, Office, Server Software and Security Software.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Accenture to buy Australian cyber security firm CyberCX

Accenture to buy Australian cyber security firm CyberCX

TPG Telecom reveals iiNet order management system breached

TPG Telecom reveals iiNet order management system breached

"Shade BIOS" stealth malware hides below operating system

"Shade BIOS" stealth malware hides below operating system

Log In

  |  Forgot your password?