Microsoft issues nine patches for Windows, Office Web
By Nicole Kobie,
Microsoft has issued nine patches to cover 19 flaws in its products, fixing vulnerabilities in Windows and Office.
Five of the patches are rated critical in severity, while six are rated critical for their "exploitability" - which means hackers will have solid code to attack the flaw within the month.
One of the patches fixes a flaw in Office Web Components - which already has an active exploit "in the wild" - while the rest are for various versions of Windows.
In the Microsoft Security Response Center blog, security researcher Jerry Bryant highlighted a patch for the Active Template Library, which includes a binary level update for Microsoft Video ActiveX. "We encourage you to deploy this update as soon as possible," he said.
Ben Greenbaum, senior research manager, Symantec Security Response, agreed. “All of the ActiveX issues patched this month could be easy to exploit and can impact even the average computer user,” he said.
“The potential danger is that many of these vulnerabilities can be exploited by simply getting a user to visit a Web page that contains malicious content,” he added. “Through a drive by download, even simply viewing a legitimate site that has been compromised by an attacker can lead to user’s machine being exploited via these vulnerabilities.”
Microsoft also announced Extended Protection for Authentication for the Windows platform, a safer new way of authenticating network connections.
"This is a non-security update that enables new protection technology that can be used to enhance the protection of credentials when authenticating network connections," Bryant wrote.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Dell EqualLogic PS6100XS review
- Chromebooks: What's gone wrong?
- ICO: Fines for cookie law breakers
- UK regulator shuts down Angry Birds scam
- Open source software driving cloud-based innovation
- Fujitsu targets enterprises with Android ICS tablet
- IBM bans use of Siri on iPhones
- Dell PowerEdge R820 review
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





