Microsoft's July Patch Tuesday to feature 2 critical fixes

Microsoft has notified users of upcoming security fixes, including two critical-rated vulnerabilities

Patch Tuesday

Microsoft will be rolling out two critical fixes during its monthly Patch Tuesday round of security updates.

There are six notifications in all, with two ranked critical, three important and one listed as only moderate.

The average since 2013 has been around nine per month, so the six announced for next week represent a lower bulletin count than usual.

Advertisement - Article continues below

Of the two labelled critical, one is related to Internet Explorer, and is more than likely to be a patch that collects a number of updates needed to the browser. This marks the sixth Patch Tuesday in a row that's featured updates for the browser.

Wolfgang Kandek, CTO of Qualys, highlighted the importance of the IE update in a blog post. "This patch should be top of your list, since most attacks involve your web browser in some way.

"Take a look at the most recent numbers in Microsoft SIR report v16, which illustrate clearly that web- based attacks, which include Java and Adobe Flash are the most common," he added.

The second critical bulletin resolves remote code execution issues with all versions of Windows currently available, including Windows RT and RT 8.1.

Arriving third, fourth and fifth, the "important" bulletins address issues around privilege elevation. All the vulnerabilities addressed by these bulletins are local, meaning they cannot be executed through  a network connection.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

That doesn't mitigate the danger, claims Kandek, as an attacker who gains access to a computer through stolen credentials can still control the user's computer with them.

Bulletin six, ranked the lowest in importance with a "moderate" rating, fixes denial-of-service vulnerabilities in Microsoft's server software.

"All of the vulnerabilities in this month's release were discovered by Microsoft or privately disclosed by security researchers," said Karl Sigler, threat intelligence manager at Trustwave. "The good news is that none of these vulnerabilities have been exploited in the wild yet."

Full details of each bulletin will be released when the patches go live next Tuesday

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Recommended

Visit/network-internet/web-browser/356369/dont-like-chromium-edge-you-can-revive-legacy-edge
web browser

Don't like Chromium Edge? Here's how to revive the old Edge

7 Jul 2020
Visit/cloud/356294/azure-digital-twins-previews-new-features
Cloud

Microsoft Azure Digital Twins previews new features

30 Jun 2020
Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020

Most Popular

Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/cloud/356260/the-road-to-recovery
Sponsored

The road to recovery

30 Jun 2020
Visit/business-strategy/it-infrastructure/356258/the-growing-case-for-it-flexibility
Sponsored

The growing case for IT flexibility

30 Jun 2020