April's Patch Tuesday from Microsoft includes another Internet Explorer patch

April's Patch Tuesday from Microsoft includes another Internet Explorer patch
April's Patch Tuesday from Microsoft includes another Internet Explorer patch

Microsoft is readying nine patches to be released Tuesday as part of the software giant's monthly security update.

Two of the nine fixes address vulnerabilities rated "critical," meaning they could be exploited to execute remote code, while the remaining seven patches attend to flaws deemed "important," according to an advance notification from Microsoft.

Security observers eyed one of the critical fixes, "Bulletin 1," as the most pressing because it involves vulnerabilities in all supported versions (6-10) of Internet Explorer (IE). Security weaknesses in browsers are preferred vectors of attack for cyber criminals because often they can be successful by a victim merely visiting an infected web page.

Andrew Storms, director of security operations at nCircle, which recently was acquired by Tripwire, suspects one of the IE flaws being plugged was discovered last month at the Pwn2Own hacker contest at the CanSecWest show in British Columbia.

The update's remaining patches, address issues in Windows, Office, Server Software and Security Software. The update is due out around 2 p.m. EST on Tuesday.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.