Microsoft, Adobe drop patches for dozens of bugs

Microsoft and Adobe on Tuesday both shipped security updates for their widely deployed products, with the former issuing seven patches to address 12 vulnerabilities and the latter distributing fixes for Reader, Acrobat and Flash.

Researchers said the two Microsoft bulletins to focus on are MS13-001, which corrects a single bug in Windows Print Spooler that could allow remote code execution, and MS13-002, which remedies two vulnerabilities in XML Core Services.

The XML flaws could be exploited via a malicious web page in Internet Explorer, according to Microsoft.

"This [patch] impacts a dog's breakfast of Microsoft operating systems and applications, including Windows 8, RT (which runs on mobile devices) and Server 2012," said Ross Barrett, senior manager of security engineering at Rapid7, a vulnerability management firm, in prepared comments. "One thing to watch out for in this type of vulnerability is applying all the patches that apply to a system...Administrators will have to patch for each affected component."

Left off the patch batch was a fix for a zero-day vulnerability in Internet Explorer which has been used to serve malware from a few high-profile websites. Microsoft has issued a temporary workaround, and IE 9 and 10 are not affected.

Meanwhile, Adobe on Tuesday updated Reader and Acrobat for 27 vulnerabilities, and Flash for a single weakness. The company said it was not aware of any of the bugs being used in active attacks.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.