Bumper set of security patches from Microsoft
By Miya Knights,
School’s not out for IT administrators, as Microsoft released a bumper crop of updates, patching 26 vulnerabilities late yesterday - the highest number addressed by its monthly round of security patches in two years.
The update includes six critical and five important patches, as previewed last week, ensuring the August summer holidays will be a busy time for IT security administrators, just like last year.
“This is a mammoth ‘Patch Tuesday,’ and we have not seen anything of this scale in a long time,” said Karthik Raman, a McAfee researcher.
The six critical patches have been given the software vendor’s highest security rating because the vulnerabilities could allow attackers to take complete control remotely over a computer running the vulnerable software.
“Many of the vulnerabilities addressed by the fixes could be exploited if a Windows user simply views a malformed image or visits a malicious website, a favourite attack method among cybercriminals,” Raman said.
The majority of the vulnerabilities addressed by the August security bulletin can be exploited through malicious websites or by tricking a computer user into opening a rigged image or Office file.
And two of these – MS08-041 and MS08-042 – cover vulnerabilities that had already been publicly disclosed and are actively being used in cyberattacks.
McAfee recommended organisations prioritise the updates that fix the image processing flaws (MS08-044) and the Internet Explorer update (MS08-045), because it said attackers were more likely to take advantage of these vulnerabilities in new attacks.
Andrew Clarke, Lumension Security international vice president, focused on the breadth of affected software products that will affect both desktops and servers: “All six critical patches are identified as fixing vulnerabilities relating to Microsoft Windows, Internet Explorer, Media Access Player, Access, Excel, PowerPoint and Microsoft Office,” he said.
Clarke urged IT departments to act quickly and carefully assess which patches should receive priority.
“Looking at the impact on IT groups managing servers, critical updates will be issued that apply to Windows 2000, 2003 and 2008, he advised. “For those managing desktops, critical updates will be released for XP, Vista, Office 2000, Office XP and Office 2003.”
He also highlighted another vulnerability for users of Windows Messenger: “MS08-050 is concerning as it allows unauthorised access to a user’s messenger account,” added Clarke.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- ICO: Fines for cookie law breakers
- Hutchison denies it will pull plug on Three UK
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- Open source software driving cloud-based innovation
- CIO: Career is over?
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell PowerEdge R820 review
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





