Microsoft issues record Patch Tuesday

Microsoft issued a record number of monthly patches on Tuesday, including fixes for eight critical holes affecting Windows, Internet Explorer, Microsoft Word and other programs that could be exploited to take control of a computer.

Of the 14 patches addressing a total of 34 vulnerabilities, four of them should be given priority, Microsoft said in its Security Response Center blog post:

  • MS10-052, which resolves a vulnerability in Microsoft's MPEG Layer-3 audio codecs that could allow remote code execution if a specially crafted media file were opened or a Windows user received specially crafted streaming content from a website.

  • MS10-055, which fixes a hole in Windows Media Player's Cinepak Codec that could allow remote code execution if a computer opens a specially crafted media file, or receives specially crafted streaming content from a website.

  • MS10-056, which resolves four flaws in Microsoft Office, including one that could allow remote code execution if a computer user opens or previews a specially crafted rich text format email.

  • MS10-060, which plugs two holes that could allow remote code execution, in Microsoft .NET Framework and Microsoft Silverlight.

None of those vulnerabilities has been seen exploited in the wild yet, Microsoft said. The six other bulletins are rated "Important", and two of them, MS10-047 and MS10-048, are Windows Kernel updates.

A chart-based breakdown of the vulnerabilities, their severity and other information is on the Microsoft TechNet blog. Additional details on all the fixes are in the August Security Bulletin Summary.

Microsoft Patch Tuesday priorities

This chart explains the priority Microsoft is assigning to each of the 14 bulletins released in August. (Credit: Microsoft)

Affected software includes: Windows 7; Windows XP; Vista; Windows Server 2003 and 2008; Windows Server 2008 release 2; IE6, 7 and 8; Office XP Service Pack 3; Office 2003 Service Pack 3; 2007 Microsoft Office System Service Pack 2; Office 2004 and 2008 for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel and PowerPoint; 2007 File Formats Service Pack 2; Microsoft Works 9; and Silverlight 2 and 3.

As part of Patch Tuesday, Microsoft also released Security Advisory 2264072, which warns of a problem affecting Windows XP, Vista, Windows 7, Server 2003 and 2008 that could be used to leverage the Windows Service Isolation feature to gain elevation of privilege on the machine. Windows Service Isolation feature is an optional configuration. The advisory also includes information about a non-security update addressing an attack vector through Windows Telephony Application Programming Interfaces.

Meanwhile, the August bulletins close Security Advisory 977377, which described a spoofing vulnerability. Microsoft worked with the Industry Consortium for Advancement of Security on the internet to develop a new standard to address the issue.

Last week, Microsoft released an emergency patch for a critical Windows vulnerability that was being exploited by a fast-spreading virus and other malware. The so-called "shortcut" vulnerability could be used by attackers to take control of a computer.

On Tuesday, Microsoft added Stuxnet and related Windows viruses Sality and Vobfus to its Malicious Software Removal Tool.

"It's another movies-to-malware month for Microsoft," said Andrew Storms, director of security operations at nCircle. "Four of the 14 bulletins this month fix bugs in media applications. Already this year Microsoft has fixed bugs in media applications or media file formats in February, March, April and June, so this month continues an obvious and growing trend. So much of what people do on the internet these days includes videos or music and malware writers continue to take advantage of the fact that people are less aware of malware embedded in these files."

Adobe also released security updates for 10 critical holes in Flash Player and Flash Media Server, as well as an important hole in ColdFusion on Tuesday.

Via CNET

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Sac vuitton ehyop http://www.sacpascherloiusvuitton.com jbr http://saclouisvuittond.com kiw http://www.sacpascherloiusvuitton.com...

2 minutes ago by hlbwbluv on Conroy reveals NBN board

Zombies, Run for iOS turns your workout into a real-life action adventure game http://t.co/vRErZmmm #running #ipod

6 Good apps for the BlackBerry Playbook - http://t.co/jOB7Cpqo

RT @AnonyOps_: Yes, The Pirate Bay is down. It appears to have been hit by a 'massive' DDoS attack. http://t.co/zYzNgHYK #anonyops

The shame of owning an iPad http://t.co/WtEYmLSd

Avira update brings down millions of computers:
http://t.co/hSjEMmS0

RT @4BerryAddicts: 6 Good apps for the BlackBerry Playbook - ZDNet - This short list contains my favorites and the most heavily used ap... http://t.co/OrM8JjnL

Google to centralize Android development and sales http://t.co/ubH10fMX

Android users take note - malware has almost quadrupled. You may want to take a look at this. http://t.co/W141QwqW

Android users take note - malware has almost quadrupled. You may want to take a look at this. http://t.co/DfF7W0LO

#Mobile Mobile Phone Sales Sink for First Time in Three Years - PCWorld: ZDNet (blog)Mobile Phone Sales Sink for... http://t.co/TTwMEZ2h

Mobile Phone Sales Sink for First Time in Three Years - PCWorld: ZDNet (blog)Mobile Phone Sales Sink for First T... http://t.co/fAQwxvRM

Oracle, Google hammer out potential trial roadmap: Lawyers for Oracle and Google try to figure out where we coul... http://t.co/87Kgb6bL

RT @AnonyOps_: Yes, The Pirate Bay is down. It appears to have been hit by a 'massive' DDoS attack. http://t.co/zYzNgHYK #anonyops

Microsoft to charge customers $99 to remove OEM 'crapware' http://t.co/TEzHBI6f

With The Pirate Bay @tpb down the internet is now fun anymore. http://t.co/P5npsl5D #DDoS #thepiratebay #TPB

Microsoft to charge customers $99 to remove OEM 'crapware': By Adrian Kingsley-Hughes | May 16, 2012, 8:25am PDT... http://t.co/CZh04vDr

Microsoft to charge customers $99 to remove OEM 'crapware': By Adrian Kingsley-Hughes | May 16, 2012, 8:25am PDT... http://t.co/9UMX6KJr

Anatomy of an iTunes Store account hack | ZDNet http://t.co/LwATs25X

Nvidia Makes the GPU Virtual PCWorld - ZDNet UK Nvidia Makes the GPU Virtual PCWorld Nvidia's new Kepler GPU integr... http://t.co/yhNuDq3N

Anonymous denies it is behind The Pirate Bay DDoS attack - The Pirate Bay has been down for hours, up to a full 24 f... http://t.co/HXNEJE85

RT @SecurityXploded Anonymous denies it is behind The Pirate Bay DDoS #Attack... http://t.co/pzvx1qFx @SecurityP... http://t.co/wBH7Dwip

ZDNet (blog)Microsoft anti-bloatware service to apply to Windows 8 PCs, tooComputerworldBy Gregg Keizer Computer... http://t.co/TZ0qlCVo

ZDNet (blog)Microsoft anti-bloatware service to apply to Windows 8 PCs, tooComputerworldBy Gregg Keizer Computer... http://t.co/16CS7x8r

Anonymous 'crippled': where to for hacktivism? http://t.co/O855it3N via @zdnetaustralia

Microsoft to charge customers $99 to remove OEM 'crapware' http://t.co/7ojyIv2U

Thu plan: Reporting from #AusCERT 2012 http://t.co/ta2izp0X all day for @zdnetaustralia, and luck I'll survive. I'm in rather a lot of pain.

RT @AnonyOps_: Anonymous 'crippled': where to for hacktivism?
http://t.co/AnG0Jcr5 | Response: http://t.co/TkOOuApk #anonyops via .@DiscordiAnon

RT @adrianbritton: How much is your data worth to #Facebook http://t.co/hVHHVuEY #socialmedia

RT @ItsDaMedia: Barrett Fuckn Brown: #Anonymous 'crippled': where to for hacktivism? http://t.co/k9zYpVsv

RT @ItsDaMedia: Barrett Fuckn Brown: #Anonymous 'crippled': where to for hacktivism? http://t.co/k9zYpVsv

Anonymous 'crippled': where to for hacktivism? http://t.co/rBpIcu3n #BULL****

Learning to program at age 30: here’s how I’m approaching it ZDNet http://t.co/2k422QeG http://t.co/bDuEuXqf

How much is your data worth to Facebook? | ZDNet http://t.co/0qLAXiHr

How much is your data worth to #Facebook http://t.co/hVHHVuEY #socialmedia

After GM kills $10 million Facebook ad budget, Ford laughs | ZDNet http://t.co/UVFdLXPC

"NBN powered public WiFi " - what a joke!!! You are kidding surely??? There is no plan whatsoever for any such thing. Labor's concept ...

1 hour ago by FredShekel on NBN contracts may be left alone: Turnbull

Typical ignorami. The Labor NBN plan is this: 1. Build a monopoly network through NBN.co. 2. Sell the network to the highest bidder...

1 hour ago by FredShekel on Malaysia held up as NBN king

http://en.wikipedia.org/wiki/Patent_troll "Patent troll is a term used for a person or company who buys and enforces patents against one ...

2 hours ago by victim of patent troll on The world needs patents: Uniloc founder

You are a true member Humbert. You can use whatever word you like, however not when you are trying to imply that I said something I did ...

3 hours ago by FredShekel on NBN FUD: will Abbott ever learn?

Oh, just let me jump in here and pretend to be intelligent. Realismbias, you are a full on DORK!

3 hours ago by FredShekel on NBN FUD: will Abbott ever learn?

Beta Beta Beta Beta...... you are just stupid. Please show the World where I said anything about living in an Alcatel Lucent lab - you c...

3 hours ago by FredShekel on NBN FUD: will Abbott ever learn?

Humbert Humbert Humbert Humbert..... FTTN is fibre to the node. I am glad that at last we agree in that. Now, if you think you need fib...

4 hours ago by FredShekel on NBN FUD: will Abbott ever learn?

viditor you are giving him way too much credit. Let me explain to you something about posters like fred, they resort to lines like that ...

5 hours ago by Hubert Cumberdale on NBN FUD: will Abbott ever learn?

Would somebody kindly ban this troll FredShekel? He even boasts of trolling... "I'm not crying about the NBN Humbert, I just like to pla...

6 hours ago by viditor on NBN FUD: will Abbott ever learn?

For your (badly needed) education, Freddy... 1. Uploads are far more expensive to provide than downloads because of the price of backhaul...

6 hours ago by viditor on NBN FUD: will Abbott ever learn?

Beta, I read the site most days and only comment when i need some entertainment. Today about 8 hours ago comments were a bit slow so I th...

7 hours ago by Doubt on NBN FUD: will Abbott ever learn?

lol, that comment made my day too, they make it far to easy for us though. Seriously though there are many hardcore geeky types that find...

7 hours ago by Hubert Cumberdale on NBN FUD: will Abbott ever learn?

100% agree = Windows RT = Ios, Windows 8 = Mac OS.. why is this obvious to me and you... When IOS opens it's 'mobile' OSs, then lets tal...

7 hours ago by TonyD3 on Windows RT closed to browsers: Google, Mozilla

The problem with the patent system is the fraud written into it, which means that more that 95% of inventors rights are lost due to burea...

8 hours ago by Stuart Saunders on The world needs patents: Uniloc founder

Indeed RealismBias... Feel free to laugh "along with me" and my facetious niggles at people's stupidity... just as I'm sure everyone is ...

8 hours ago by Beta on NBN FUD: will Abbott ever learn?

Your blog post on m.zdnet.com.au offers the same submit as another article author but i much like your far better.

8 hours ago by appliance repair OC on MS, Adobe war in blogosphere

I actually cracked up laughing here: "He believes we should all live in the Alcatel-Lucent lab, so that we can receive commercially unav...

8 hours ago by RealismBias on NBN FUD: will Abbott ever learn?

Basic price is standard worldwide - then converted into local currency. If someone is 'gouging' then they are buying in bulk (currently n...

9 hours ago by Frotech on Only 57 Raspberry Pis in Aus: supplier

Exactly! Talk about your monopoly provider. That's what the Malaysian solution is - one network to rule them all, one company to provide...

9 hours ago by Gwyntaglaw on Malaysia held up as NBN king

This story has been voted 15 times in the last 24 hours!

11 hours ago, AusCERT 2012 kicks off: photos

This story has been voted 5 times in the last 24 hours!

11 hours ago, Up in cyber arms: AusCERT 2012

This story has been voted 5 times in the last 24 hours!

1 day ago, NBN FUD: will Abbott ever learn?

This story has been voted 10 times in the last 24 hours!

2 days ago, Apple drops 4G iPad label in Australia

This story has been voted 5 times in the last 24 hours!

2 days ago, Apple drops 4G iPad label in Australia

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar