iTnews
  • Home
  • News
  • Technology
  • Security

Microsoft plans two patches, no SharePoint fix

By Dan Kaplan on May 7, 2010 9:55AM
Microsoft plans two patches, no SharePoint fix

Light load for admins.

Microsoft is prepping two patches for next week's monthly security update, according to an advance notification, but there are no plans to release a fix for a dangerous SharePoint flaw that was disclosed last week.

The patches fix one vulnerability each. One of the flaws resides in Windows, the other in Office. Users running Windows 7 and 2008 R2 are not impacted by either of the bugs, Jerry Bryant, group manager of response communications at Microsoft, said in a blog post.

Not scheduled for a fix is the vulnerability in Microsoft's business collaborative platform, SharePoint, which could allow hackers to elevate privileges and steal sensitive data. The flaw was disclosed to Microsoft in early April by Swiss security firm High-Tech Bridge. On April 29, High-Tech Bridge, whose policy is to go public with bug details two weeks after notifying the vendor, issued an advisory, which included a link to a proof-of-concept code that exploits the vulnerability.

Microsoft has said it is not aware of any in-the-wild attacks targeting the vulnerability. It has released its own advisory, offering suggested workarounds, such as restricting access to the SharePoint help.aspx XML files.

"Our teams are still working on an update for that issue," Bryant said. "In the meantime, we recommend customers review the advisory and apply the workarounds."

See original article on scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
fixmicrosoftnopatchesplanssecuritysharepointtwo

Partner Content

Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development
How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Why rethinking your CMS is crucial for customer retention
Promoted Content Why rethinking your CMS is crucial for customer retention
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Dan Kaplan
May 7 2010
9:55AM
0 Comments

Related Articles

  • Meraki firewalls blocked Office365 traffic as attempted intrusion
  • Patch Wednesday fixes two-year-old Dogwalk vulnerability
  • Austrian spy firm accused by Microsoft says hacking tool was for EU states
  • Microsoft says Austrian firm behind spyware targeting law firms, banks
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

Australian court finds insurer not liable for ransomware clean-up costs

Australian court finds insurer not liable for ransomware clean-up costs

ADHA extends Accenture's My Health Record support deal for $100m

ADHA extends Accenture's My Health Record support deal for $100m

Defence, DEWR drop $160m on Microsoft software, Azure

Defence, DEWR drop $160m on Microsoft software, Azure

Digital Nation

Criteo to fork out $94.7m for consent breaches
Criteo to fork out $94.7m for consent breaches
Metaverses on the agenda for Dominello, Husic ministerial meeting
Metaverses on the agenda for Dominello, Husic ministerial meeting
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
COVER STORY: How KPMG, Mirvac and ASX use blockchain to build trust in the property sector
Domino’s invests in observability for zero contact delivery
Domino’s invests in observability for zero contact delivery
Australia will lose 11 percent of jobs to automation by 2040: Forrester
Australia will lose 11 percent of jobs to automation by 2040: Forrester
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.