Microsoft Patch Tuesday bonanza: 13 fixes for 34 flaws

Share this article:

Microsoft on Tuesday pushed out 13 patches to rectify a whopping 34 security vulnerabilities as part of the software giant's monthly update.

Included are two fixes for zero-day vulnerabilities -- in the Server Message Block (SMB) version 2 and File Transfer Protocol (FTP) service in Internet Information Services (IIS).

In total, 22 of the bugs were rated "critical" (including several in the soon-to-be-released Windows 7 platform), which means they are ripe for remote code exploitation that would enable an attacker to install malware on victim machines.

The eight critical bulletins included the SMB fix, as well as patches for Windows Media Runtime, Media Player, Internet Explorer, Active Template Library (ATL), Graphics Device Interface (GDI), and .NET and Silverlight

The fix for the FTP flaw was rated "important," as were four other patches for issues in CryptoAPI, Indexing Service, Local Security Authority Subsystem Service and the Windows kernel.

According to Symantec, this marked the most number of vulnerabilities ever addressed by Microsoft, eclipsing the previous record of 31, established in June.

"There's a little something for everything," nCircle's Tyler Reguly said in a statement, "a mix of remote code execution, spoofing, denial-of-service and privilege escalation. Tonight is going to be a long night for researchers everywhere as they attempt to dig through this tangle of vulnerabilities and uncover useful information for their customers."

Workarounds have been assigned to both zero-day issues. Microsoft officials have said the company is aware of active attacks targeting the FTP flaw, though it could not confirm anything in the wild regarding the SMB bug.

Given the size of Tuesday's release, experts recommend that businesses evaluate risk when determining how to prioritize patch deployments.

Share this article:
close

Next Article in News

Sign up to our newsletters

More in News

Research shows vulnerabilities go unfixed longer in ASP

Research shows vulnerabilities go unfixed longer in ASP

A new report finds little difference in the number of vulnerabilities among programming languages, but remediation times vary widely.

Bill would restrict Calif. retailers from storing certain payment data

The bill would ban businesses from storing sensitive payment data, for any long than required, even if it is encrypted.

Amplification, reflection DDoS attacks increase 35 percent in Q1 2014

Amplification, reflection DDoS attacks increase 35 percent in ...

The Q1 2014 Global DDoS Attack Report reveals that amplification and reflection distributed denial-of-service attacks are on the rise.