Microsoft Patch Tuesday bonanza: 13 fixes for 34 flaws

Microsoft on Tuesday pushed out 13 patches to rectify a whopping 34 security vulnerabilities as part of the software giant's monthly update.

Included are two fixes for zero-day vulnerabilities -- in the Server Message Block (SMB) version 2 and File Transfer Protocol (FTP) service in Internet Information Services (IIS).

In total, 22 of the bugs were rated "critical" (including several in the soon-to-be-released Windows 7 platform), which means they are ripe for remote code exploitation that would enable an attacker to install malware on victim machines.

The eight critical bulletins included the SMB fix, as well as patches for Windows Media Runtime, Media Player, Internet Explorer, Active Template Library (ATL), Graphics Device Interface (GDI), and .NET and Silverlight

The fix for the FTP flaw was rated "important," as were four other patches for issues in CryptoAPI, Indexing Service, Local Security Authority Subsystem Service and the Windows kernel.

According to Symantec, this marked the most number of vulnerabilities ever addressed by Microsoft, eclipsing the previous record of 31, established in June.

"There's a little something for everything," nCircle's Tyler Reguly said in a statement, "a mix of remote code execution, spoofing, denial-of-service and privilege escalation. Tonight is going to be a long night for researchers everywhere as they attempt to dig through this tangle of vulnerabilities and uncover useful information for their customers."

Workarounds have been assigned to both zero-day issues. Microsoft officials have said the company is aware of active attacks targeting the FTP flaw, though it could not confirm anything in the wild regarding the SMB bug.

Given the size of Tuesday's release, experts recommend that businesses evaluate risk when determining how to prioritize patch deployments.

close

Next Article in News

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.