Microsoft to open year with seven patches

Share this article:

Microsoft is set to kick off the New Year with seven patches, two rated "critical," to amend 12 vulnerabilities present in Windows, Office, Developer Tools, .NET Framework and server software.

It does not appear that a zero-day vulnerability in Internet Explorer, which has been used to spread malware on a limited number of targeted websites, will be fixed. Of those that will, the most pressing bulletins to address are the two critical ones, according to researchers.

One involves an issue with Server Core, an installation option for PCs running Windows Sever 2008.

"This is where I would prioritize patching efforts because this is potentially a wormable bug, and since Server Core is affected, it could apply to a very common service," Ross Barrett, senior manager of security engineering at Rapid7, a vulnerability management company, said in prepared comments.

The patches are set to be released approximately 1 p.m. EST on Tuesday.

Share this article:

Sign up to our newsletters

More in News

Zberp evolves, spreads through phishing campaign

Zberp malware was developed from the source code of Zeus and financial malware Carberp.

A possible attempt to revive the Gameover Zeus botnet

The Gameover variant of the nefarious Zeus trojan was disrupted in early June, but researchers with Malcovery are observing a return.

After takedown efforts, Cryptolocker fate still "undetermined," firm says

BitDefender, the firm that discovered the ransomware, detailed Cryptolocker's chances of making a comeback.