Jump to content

Microsoft to patch 26 holes in Windows, Office


DKT27

Recommended Posts

  • Administrator

Microsoft will patch 26 holes next week, including critical ones in Windows, one affecting the kernel of 32-bit versions and several holes in Office, the company said in a Patch Tuesday preview on Thursday.

Five of the 13 bulletins affect vulnerabilities that could lead to remote code execution and they are rated critical. The bulletins affect Windows 2000, XP, Vista and Windows 7, as well as Server 2003 and 2008, Office XP, Office 2003 and Office 2004 for Mac, according to the advisory.

"The Office-related bulletins are both rated Important and would require user action to be exploited (usually in the form of convincing a user to open a specially crafted file)," Jerry Bryant, a senior security communications manager at Microsoft, wrote in a blog post. "The vulnerabilities only affect older versions of Office so customers on Office 2007 or Office 2008 for Mac will have no actions this month."

Included in the bulletins will be a fix for a hole in the kernel of 32-bit versions of Windows that Microsoft disclosed two weeks ago, Bryant said.

Meanwhile, Microsoft will not have fixes ready by Tuesday for two other issues -- a hole in Internet Explorer that could lead to data leakage and which was disclosed on Wednesday, and a hole in the Server Message Block file-sharing protocol that was disclosed in November.

"We are not aware of any attacks on these vulnerabilities and continue to encourage customers to implement the mitigations and workarounds outlined in the advisories," Bryant wrote.

25iyv77.png

This chart shows the number of bulletins affecting the different versions of Windows and their rating of importance.

Source -

CNET

Link to comment
Share on other sites


  • Replies 9
  • Views 1.2k
  • Created
  • Last Reply

woww.then its a grt news.:dance2:

Link to comment
Share on other sites


I would hate to see the guys brain that can account for all of it with each line of code he writes.. and have the psychic ability to foretell future changes.. Oh and lets not forget .. the ability to learn as fast as it changes and implement that into a pre-existing product ahead of time.. I really would..

My view I am just glad they are pro-actively patching it..

Link to comment
Share on other sites


  • Administrator

Oh well. I remember that old days where I didn't had internet access, so no M$ patches and I only used to buy original CDs. :D

But hey if you remove M$ vuln. thingy, pirate life is smooth. :P

Link to comment
Share on other sites


  • Administrator

Haha. True. I love torrent life. :D

Link to comment
Share on other sites


Haha. True. I love torrent life. :D

hhhmm but i DIE for torrent life :P

Link to comment
Share on other sites


Not counting the out-of-band security bulletin released for Internet Explorer, January has been a rather slow month for Microsoft, when it comes down to its scheduled patch cycle. But the Redmond company will more than compensate for the small number of security updates released for its products, with the exception of IE the past month. Next week, on February 9, 2010, the software giant will make available patches for no less than 26 vulnerabilities affecting Windows and Office.

“This month, we will be releasing 13 bulletins - five rated Critical, seven rated Important, and one rated Moderate - addressing 26 vulnerabilities. Eleven of the bulletins affect Windows and the remaining two affect Office,” revealed Sr. Security Communications Manager – Lead, Jerry Bryant.

In the first half of January 2010, Microsoft released a single security bulletin impacting Windows. This month, that number has grown to 11. At the same time, the company’s latest versions of Windows will be impacted by the patches coming next week. No less than 3 Critical bulletins will plug security holes in both Windows 7 and Windows Server 2008 R2. Windows 7 customers will need to deploy two additional patch packages rated as Important. Windows Vista users will have to deploy 3 Critical and 3 Important security bulletins, with Windows XP being targeted by no less than 5 Critical updates.

“The Office related bulletins are both rated Important and would require user action to be exploited (usually in the form of convincing a user to open a specially crafted file). The vulnerabilities only affect older versions of Office so customers on Office 2007 or Office 2008 for Mac will have not actions this month,” Bryant added. “We encourage customers to upgrade to the latest versions of both Windows and Office.”

On February 9th, Microsoft will also patch a 17-year old vulnerability affecting the 32-bit (x86) versions of Windows, including Windows 7. “Advisory 979682, Vulnerability in Windows Kernel Could Allow Elevation of Privilege: we are on track to release an update for this issue next Tuesday,” Bryant added.

SOURCE

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...