Microsoft to plug 57 security holes next week

Share this article:

Microsoft next week plans to deliver a whopper of a security update, complete with 12 patches that address 57 vulnerabilities.

Five of the 12 bulletins are rated "critical," addressing flaws in Windows, Internet Explorer and Exchange Server, according to an advance notification bulletin. The remaining seven are designated "important" and deal with issues in Windows, Office, .NET Framework and Server Software.

Catching the eyes of security researchers were two of the critical patches that address vulnerabilities in Internet Explorer, a common vector through which criminals serve malware.

"Internet Explorer patches are always a top priority, and this month we're going to get two Internet Explorer bulletins," Andrew Storms, director of security operations at vulnerability and risk management firm nCircle, said in prepared comments. "That's unusual because generally, when Microsoft patches IE, the patch is delivered as a single bulletin."

Alex Horan, senior product manager at Core Security, which makes penetration testing solutions, said that because the IE bugs are being patched in all supported versions of the browser and operating system, "it's pretty much one-hack-fits-all in the Windows environment for attackers."
Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

President signs Executive Order to improve payment security

President signs Executive Order to improve payment security

President Obama signed an Executive Order at the Consumer Financial Protection Bureau calling for enhanced security measures, including microchips and PINs.

Security, tech firm coalition fights Hikit actors, other advanced groups

Security, tech firm coalition fights Hikit actors, other ...

The coalition began as an effort to stop the spread of the Hikit trojan, previously known for targeting U.S. defense contractors.

Phishing email delivers keylogger malware, also takes screenshots

Phishing email delivers keylogger malware, also takes screenshots

The malware has various features, including the ability to start persistently, take screenshots and bypass user access controls.