Six fixes this Patch Tuesday, but no mention of Word flaw

By
Follow google news

Microsoft is planning to push out six patches on Tuesday, presumably including one for a critically flawed ActiveX control in Visual Studio 2005.

Six fixes this Patch Tuesday, but no mention of Word flaw
The software giant is issuing five other patches to correct unnamed vulnerabilities in Windows, at least one of which is labelled critical.

Some security observers were upset Microsoft did not offer a patch for the Visual Studio bug in its November release.

First warnings of active attacks that take advantage of a flawed WMI Object Broker ActiveX control, appeared early last month. Attackers who exploit the vulnerability could take complete control of an affected system, with full user rights.

Experts have said the flaw needs a prompt fix because many developers use the Visual Studio platform.

It is unclear if Microsoft will offer a fix for a dangerous, zero-day flaw that exists in a number of Word versions. The company, which warned about the flaw this week, said it was investigating reports of proof-of-concept code.

In the Patch Tuesday release, Microsoft also is scheduled to release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update (WU), Microsoft Update (MU), Windows Server Update Services (WSUS) and the Download Center. However, the tool will not be distributed through Software Update Services (SUS).

It also plans to release 14 non-security, high-priority updates for WU, SUS, MU and WSUS.

Click here to email Dan Kaplan.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

Westpac factors post-quantum cryptography prep into "secure router" rollout

Westpac factors post-quantum cryptography prep into "secure router" rollout

Researcher trawls cybercrime sites, collects billions of stolen credentials

Researcher trawls cybercrime sites, collects billions of stolen credentials

Log In

  |  Forgot your password?