Microsoft mends 33 vulnerabilities in Patch Tuesday release, including Internet Explorer 8 zero-day

Share this article:
Microsoft mends 33 vulnerabilities in Patch Tuesday release, including Internet Explorer 8 zero-day
Microsoft mends 33 vulnerabilities in Patch Tuesday release, including Internet Explorer 8 zero-day

Microsoft on Tuesday patched a dangerous zero-day vulnerability affecting Internet Explorer 8, one of 10 fixes that the software giant released as part of its monthly security update.

The IE 8 hole, which has been actively exploited in attacks against the U.S. government workers, temporarily was plugged last week when Microsoft distributed a Fix-It workaround. The permanent patch, addressed by MS13-038, prevents victims from being hit with an exploit if they visit a web page that has been compromised to serve malware.

The other "critical" patch introduced Tuesday by Microsoft is bulletin MS13-037, which addresses 11 additional vulnerabilities in IE. None of the bugs were publicly known, but they are present in all supported versions of the popular web browser.

Microsoft also tapped MS13-039 as high-priority bulletin. It addresses a single vulnerability in the HTTP protocol stack, known as HTTP.sys, a core Windows component that receives and processes HTTP requests. According to the bulletin, "the vulnerability could allow denial-of-service if an attacker sends a specially crafted HTTP packet to an affected Windows server or client."

The remaining seven patches address flaws in the .NET Framework, Lync, Publisher, Word, Visio, Windows Essentials and kernel-mode drivers.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.