Microsoft set to deliver 11 patches next week

Share this article:
Microsoft said Thursday it plans to release 11 patches next week, including four to address "critical" vulnerabilities that could be remotely exploited to execute malicious code.

The critical fixes address flaws in Windows, Internet Explorer, Host Integration Server and Excel, according to Microsoft's advance notification document.

Six bulletins are labeled "important" and affect issues in Windows. Microsoft also has scheduled one "moderate" patch to fix bugs in Office.

The security update matches the number of fixes in August. September saw only four patches.

Along with the patches, next week Microsoft plans to release its monthly updated version of the Windows Malicious Software Removal Tool.

This month also marks the unveiling of two initiatives aimed at helping end-users patch more effectively: the Microsoft Active Protections Program (MAPP) and the Exploitability Index.

Under the former, Microsoft will share vulnerability details with approved software security providers prior to the monthly fixes being released. This will allow security firms to immediately protect their customers once the patches are delivered.

The Exploitability Index tool will be included with security updates to enable users to measure the likelihood of the flaw in question being exploited. Each vulnerability will be placed into one of the three categories, depending on whether "consistent" exploit code is likely, whether "inconsistent" exploit code is likely or whether exploit code is unlikely.
Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

Tinba variant aimed at U.S., international banks

Tinba variant aimed at U.S., international banks

Researchers at AVAST have unlocked a Tinba variant and discovered it has been customized to target U.S. financial institutions.

Adobe makes delayed updates for Reader, Acrobat available

The Reader and Acrobat fixes were delayed a week due to issues found during testing.

Nigerian police search for ringleader in major bank heist

The suspect, Godswill Oyegwa Uyoyou, conspired with others to hack bank systems and divert 6.28 billion Naira to mule accounts.