Home » News » Vulnerabilities » New Windows Security Update Patches Critical Flaws

New Windows Security Update Patches Critical Flaws

By Gina on February 12, 2010 | Vulnerabilities, Microsoft, Windows, security, update, patches, Miller, PowerPoint New Windows Security Update Patches Critical Flaws

Microsoft delivered huge Windows security update. This is one of companies records, which includes one more security updates, shipping 13 of them in February's Patch Tuesday.

New massive update is compacted of 13 separate security bulletins that patched 26 vulnerabilities. It also gives attackers different ways to compromise machines and hijack PCs. Microsoft stated, that 12 of the 26 vulnerabilities, or 46% of the total, were tagged with a „1“ in the company's exploitability index.

Jason Avery, manager of Tipping Point's Digital Vaccine group said: “The vulnerabilities in MS10-006 and MS10-012 will probably be exploited in just a few days. I think exploits for the PowerPoint vulnerabilities [in MS10-004 ] will also be disclosed within a few days, based on the information we have from ZDI and what we've heard through MAPP. “

Microsoft also has got an information reported by one of the biggest bug bounty programs in USA - Zero Day Initiative (ZDI) – that there are two of the six PowerPoint flaws. The PowerPoint update is released by Jason Miller, security and data team manager of patch management vendor Shavlik Technologies. He claimed: „PowerPoint Viewer 2003 is affected, but Microsoft's not patching it.“

„Microsoft's finally putting its foot down and saying that [Viewer 2003] is past its lifecycle, and that everyone should upgrade to PowerPoint Viewer 2007. But if word doesn't get out, users running the older version of the utility can be attacked at will, something attackers will surely use,“ Miller added.

More Vulnerabilities news

Denial-of-service flaw is fixed by Oracle

Denial-of-service flaw is fixed by Oracle

Recently, Oracle released a patch which fixed denial-of-service vulnerability in the Oracle WebLogic Server, Application Server and iPlanet Web Server. In a security bulletin Oracle warned that "vulnerability may be remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password." Oracle pointed out that a fix for the same vulnerability in the GlassFish Server was released last month. Read more.


News categories

Latest news

Related news