Internet Explorer patch heads Microsoft security update

Share this article:

Microsoft on Tuesday released nine patches to correct 21 vulnerabilities.

Though only four of the bulletins were deemed "critical," security experts said some of the patches need to be given high-priority status.

They include MS12-010, a cumulative security update for four previously unknown Internet Explorer vulnerabilities impacting all versions of the popular web browser. IE a preferred vector to spread malware, and an exploit of any of these flaws could result in drive-by download attacks in which users are infected simply by visiting a malicious website.

Bulletin MS12-013 is another one that prompted some concern from experts who surveyed the fixes. It corrects a vulnerability in the C Run-Time Library, which can be exploited if a user is tricked into opening a "specially crafted media file that is hosted on a website or sent as an email attachment," according to Microsoft.

"At first glance, this bulletin looks like bad news, but so far the only attack vector is via Microsoft Media Player," Andrew Storms, director of security operations at vulnerability management firm nCircle, said. "Patch this one right after you patch Internet Explorer -- attackers will probably have exploits for this very shortly.”

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

ISSA tackles workforce gap with career lifecycle program

ISSA tackles workforce gap with career lifecycle program ...

On Thursday, the group launched its Cybersecurity Career Lifecycle (CSCL) program.

Amplification DDoS attacks most popular, according to Symantec

Amplification DDoS attacks most popular, according to Symantec

The company noted in a whitepaper released on Tuesday that Domain Name Server amplification attacks have increased 183 percent between January and August.

Court shutters NY co. selling security software with "no value"

A federal court shut down Pairsys at the request of the Federal Trade Commission.