Microsoft to release 7 security patches on Tuesday, 3 Remotely Exploitable

Microsoft will release seven security patches tomorrow (Tuesday 11 December) as part of its monthly patching cycle, with three of them deemed as "critical" by Redmond.

The critical patches fix vulnerabilities in Windows, with Windows elements DirectX, Windows Media Format Runtime, and Internet Explorer all affected. All the vulnerabilities allow remote hackers to breach users' systems without any interaction on their part.

The four "important" patches are also being released to address holes in Windows, and fix remote execution and elevated privileges flaws.

Alan Bentley, regional vice-president of web security firm Lumension EMEA, said, "After a light Patch Tuesday in November, security administrators will have their hands full this month. The three critical patches all address remote code execution and should be rolled out as quickly as possible."

He said, "The vulnerabilities are web-based, and hackers can prey on unsuspecting end-users by dropping malicious code into videos and other media on legitimate websites. This is particularly troublesome because attackers can prey on users as the weakest IT security link by posting seemingly harmless videos on YouTube, MySpace, Facebook or similar sites.


After a light Patch Tuesday

After a light Patch Tuesday in November, security administrators will have their hands full this month. The three critical patches all address remote code execution and should be rolled out as quickly as possible.

That's what Santa is giving this December, windows-administrators have been naughty this year :p

Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.