Microsoft issues four critical patches
By Miya Knights,
Microsoft late yesterday issued 11 security bulletins as part of its regular monthly patching cycle, including four critical patches for mission-critical systems.
As suggested by last Friday’s preview, the products affected by the critical vulnerabilities include Active Directory, Internet Explorer, Host Integration Server and Excel.
Andrew Clarke, International senior vice president of Lumension Security, pointed out that the four critical updates deal with remote code vulnerabilities on Windows and Excel 2000, Internet Explorer 6 (IE6) and Microsoft Host Integration Server.
“These vulnerabilities could potentially allow unrestricted access to sensitive databases and need to be treated very seriously,” he said.
The Windows Active Directory and Excel Bulletins would be particularly critical for organisations running Windows 2000 and Office 2000 as implementations of these versions of the Microsoft products are extremely common.
Clarke added that special attention was needed in these instances as many users are still using their Active Directory and Office on the Windows 2000 platform. “Moreover, the Office issues also impact MAC users that have Office for the Mac 2004 and 2008,” he added.
Security experts also called out the Windows IE6 critical patch, again because it is still widely deployed within organisations. The flaw affected multiple versions across multiple platforms, which Clarke said could “spell trouble for IT administrators”.
“It is not as simple as patching IE for XP or Vista as it impacts 2000, XP, Vista as well as Microsoft Windows Server 2003 and 2008,” he said.
And the vulnerability affecting Windows Host Integration Server (HIS) – a gateway application between Microsoft networks to IBM mainframe and AS400 environments – should be patched as a matter of importance by any organisation using this kind of environment, as a hacker who gains control of the flow of data through the HIS can access some of their more closely guarded systems.
“The broad target range of this month’s vulnerabilities emphasises the need for IT departments to adopt multi-platform patch and vulnerability management solutions,” concluded Clarke.
In addition to the four critical patches, six were listed as important and one as moderate, affecting more versions of Windows, Excel, and Internet Explorer.
Microsoft also launched a new Exploitability Index to help administrators prioritise patch deployments according to the likelihood of functioning exploit code being released for each of the security updates.
Related Tags
advertisement
Latest Security Features
Lessons to learn from a year of data breaches
In the year since the HMRC data breach, many more have been made public – here’s a roundup of 11 lessons (we should have) learned.
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
- Chinese web control an Olympic challenge for tech firms
- SOS Bletchley Park
Latest Security Reviews
Boston 3000GP - AMD Shanghai Server
Rating: ![]()
- Fortinet FortiGate-3810A
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
advertisement
Latest News Videos in Security
Video: Q&A with Richard Archdeacon, Symantec
IT PRO speaks to Richard Archdeacon, director, global services, at the information security software vendor Symantec.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?