Microsoft to patch 19 vulnerabilities on Tuesday

Share this article:

Microsoft is prepping six patches that will rectify 19 vulnerabilities in Windows, Internet Explorer, Office and the .NET Framework.

Four of the six fixes, set to arrive on Tuesday as part of the software giant's monthly security update, are rated "critical," according to an advance notification

Researchers said that of all of the patches, the one that should garner the most attention involves issues in Internet Explorer. Bugs of this nature are quite easy for cyber crooks to exploit thanks to drive-by and targeted-style attacks, which only require directing unwitting users to a malicious web page.

"Most organizations will be affected by these critical bulletins as they relate to legacy codebase that is present even in Microsoft's most recent releases, such as Windows 8 and Windows Server 2012," Marcus Carey, a security researcher at vulnerability management firm Rapid7, said in prepared remarks. "This may come as a surprise to many who expected that Windows 8 and Windows Server 2012 to be much more secure than legacy versions. The truth is that Microsoft and other vendors have significant technical debt in their code base which results in security issues."

Another of the patches, this one designated as "important," addresses bugs in Office. The good news is that for users to be infected, they must be tricked into clicking on a malevolent Office file and can't be forced into opening it, Carey said.

The final fix is graded "moderate."
Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.