Microsoft, Adobe drop patches for dozens of bugs

Share this article:

Microsoft and Adobe on Tuesday both shipped security updates for their widely deployed products, with the former issuing seven patches to address 12 vulnerabilities and the latter distributing fixes for Reader, Acrobat and Flash.

Researchers said the two Microsoft bulletins to focus on are MS13-001, which corrects a single bug in Windows Print Spooler that could allow remote code execution, and MS13-002, which remedies two vulnerabilities in XML Core Services.

The XML flaws could be exploited via a malicious web page in Internet Explorer, according to Microsoft.

"This [patch] impacts a dog's breakfast of Microsoft operating systems and applications, including Windows 8, RT (which runs on mobile devices) and Server 2012," said Ross Barrett, senior manager of security engineering at Rapid7, a vulnerability management firm, in prepared comments. "One thing to watch out for in this type of vulnerability is applying all the patches that apply to a system...Administrators will have to patch for each affected component."

Left off the patch batch was a fix for a zero-day vulnerability in Internet Explorer which has been used to serve malware from a few high-profile websites. Microsoft has issued a temporary workaround, and IE 9 and 10 are not affected.

Meanwhile, Adobe on Tuesday updated Reader and Acrobat for 27 vulnerabilities, and Flash for a single weakness. The company said it was not aware of any of the bugs being used in active attacks.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Adobe exploit used to spread Dyre credential stealer

Adobe exploit used to spread Dyre credential stealer

Users running vulnerable Adobe software could be in danger of having credentials for Bitcoin websites stolen.

Staples is investigating a potential issue involving credit card data

Staples is investigating a potential issue involving credit ...

The company said it is investigating a potential issue involving credit card data and that customers are not responsible for fraudulent activity on cards if an issue is discovered.

Skills set a priority over legacy prejudices, experts say

Skills set a priority over legacy prejudices, experts ...

Cybersecurity expert Winn Schwartau and Robert Clark, a cyber law attorney at the Army Cyber Institute, discussed issues around hiring in the information security industry.