1 Microsoft issues record Patch Tuesday - Security - News - ZDNet Australia

Microsoft issues record Patch Tuesday

Related gallery

2011: the year in photos

2011: the year in photos

Microsoft issued a record number of monthly patches on Tuesday, including fixes for eight critical holes affecting Windows, Internet Explorer, Microsoft Word and other programs that could be exploited to take control of a computer.

Of the 14 patches addressing a total of 34 vulnerabilities, four of them should be given priority, Microsoft said in its Security Response Center blog post:

  • MS10-052, which resolves a vulnerability in Microsoft's MPEG Layer-3 audio codecs that could allow remote code execution if a specially crafted media file were opened or a Windows user received specially crafted streaming content from a website.

  • MS10-055, which fixes a hole in Windows Media Player's Cinepak Codec that could allow remote code execution if a computer opens a specially crafted media file, or receives specially crafted streaming content from a website.

  • MS10-056, which resolves four flaws in Microsoft Office, including one that could allow remote code execution if a computer user opens or previews a specially crafted rich text format email.

  • MS10-060, which plugs two holes that could allow remote code execution, in Microsoft .NET Framework and Microsoft Silverlight.

None of those vulnerabilities has been seen exploited in the wild yet, Microsoft said. The six other bulletins are rated "Important", and two of them, MS10-047 and MS10-048, are Windows Kernel updates.

A chart-based breakdown of the vulnerabilities, their severity and other information is on the Microsoft TechNet blog. Additional details on all the fixes are in the August Security Bulletin Summary.

Microsoft Patch Tuesday priorities

This chart explains the priority Microsoft is assigning to each of the 14 bulletins released in August. (Credit: Microsoft)

Affected software includes: Windows 7; Windows XP; Vista; Windows Server 2003 and 2008; Windows Server 2008 release 2; IE6, 7 and 8; Office XP Service Pack 3; Office 2003 Service Pack 3; 2007 Microsoft Office System Service Pack 2; Office 2004 and 2008 for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel and PowerPoint; 2007 File Formats Service Pack 2; Microsoft Works 9; and Silverlight 2 and 3.

As part of Patch Tuesday, Microsoft also released Security Advisory 2264072, which warns of a problem affecting Windows XP, Vista, Windows 7, Server 2003 and 2008 that could be used to leverage the Windows Service Isolation feature to gain elevation of privilege on the machine. Windows Service Isolation feature is an optional configuration. The advisory also includes information about a non-security update addressing an attack vector through Windows Telephony Application Programming Interfaces.

Meanwhile, the August bulletins close Security Advisory 977377, which described a spoofing vulnerability. Microsoft worked with the Industry Consortium for Advancement of Security on the internet to develop a new standard to address the issue.

Last week, Microsoft released an emergency patch for a critical Windows vulnerability that was being exploited by a fast-spreading virus and other malware. The so-called "shortcut" vulnerability could be used by attackers to take control of a computer.

On Tuesday, Microsoft added Stuxnet and related Windows viruses Sality and Vobfus to its Malicious Software Removal Tool.

"It's another movies-to-malware month for Microsoft," said Andrew Storms, director of security operations at nCircle. "Four of the 14 bulletins this month fix bugs in media applications. Already this year Microsoft has fixed bugs in media applications or media file formats in February, March, April and June, so this month continues an obvious and growing trend. So much of what people do on the internet these days includes videos or music and malware writers continue to take advantage of the fact that people are less aware of malware embedded in these files."

Adobe also released security updates for 10 critical holes in Flash Player and Flash Media Server, as well as an important hole in ColdFusion on Tuesday.

Via CNET

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Hackers pounce on just-patched Windows Media vulnerability http://t.co/0n1UkpB7

http://t.co/F2EEvBgt 2012: #FreedomBox's privacy - Software - News - ZDNet Australia http://t.co/fd5zir4r #freedomtools

Apple's supply chain flap: It's really about us http://t.co/1Rom566s

PCAnywhere affected by hack: Symantec http://t.co/HjE9aozm

RT @ZDNet:
North Korea makes cellphone usage a 'war crime' under 100 days of mourning http://t.co/VldIrYRQ

Using Dragon Dictation on the iPad 2 with a Bluetooth headset http://t.co/gsEscTkP

Genius wireless mouse does away with batteries http://t.co/eweTJSTd

Groupon purchases Mertago to change social shopping: By Eileen Brown | January 27, 2012, 10:38am PST Summary: Gr... http://t.co/v39DwWu8

Groupon purchases Mertago to change social shopping: By Eileen Brown | January 27, 2012, 10:38am PST Summary: Gr... http://t.co/gujHDUPN

Listen to social media and find out what's trending http://t.co/nPV7wFRL

What does Google
s piracy
nonsense
and an extradited student have in common? - ZDNet (blog) - via http://t.co/TiW1Iwlt

“@applemacbookpro: 5 reasons why SOPA, PROTECT-IP and other legislative idiocy will never die http://t.co/XZrAspF4” they once fought VCRs...

What happens on your server at night? http://t.co/v4NK0WX2 #security

Seriously, Google+? MT @violetblue: If you missed it…Google’s Pseudonym Problem: New Implementation Revealed http://t.co/Y9wUArLQ

Facebook filing for IPO next week (rumor) http://t.co/VzEeKEfN

купить плюшевого медведя рисование мишек тедди плюшевые мишки кар...

2 hours ago by Eronsjeasse on Web porn blocking sparks war of words

http://t.co/LLtA10QV http://t.co/t3KAoSDK

Windows 7 tablets with 1.5 percent market share and other Microsoft news of the week http://t.co/XvWPcfpJ

Android tablet market share up 10% iPad down 10% through 2011 | ZDNet http://t.co/q7hMniz3

Groupon purchases Mertago to change social shopping: Groupon has purchased member shopping site Mertado. Will it... http://t.co/jdXRRRu9

http://t.co/U2DsVxRp i want the source code for my heart... what happens if yall go under?

Android tablet market share up 10%, iPad down 10% through 2011 http://t.co/ikUVkXgW

1/4 of IT budgets allocated to consumerization “@ZDNet: Accommodating personal devices at work and other IT 'myths' http://t.co/LKIp7gHf

RT @teksquisite: How SCADA highlights the futility of finding security vulnerabilities http://t.co/rBteb5UA

How SCADA highlights the futility of finding security vulnerabilities http://t.co/rBteb5UA

Wow. Reason to be thankful “@ZDNet: North Korea makes cellphone usage a 'war crime' under 100 days of mourning http://t.co/05SCa72v

view chanel collection 2011 online

4 hours ago by Dilitaug on Broadband Speedtest

Exploring: Fletcher to lead Opposition's cybersafety group: The Federal Opposition is set to devel... http://t.co/L9BgsmHS #ICTChallenge

Exploring: Fletcher to lead Opposition's cybersafety group: The Federal Opposition is set to devel... http://t.co/4nsq7GPA #ICTChallenge

The trouble with small to medium #cybercrime:
http://t.co/yIJ4Sg7B

Is your phone faster than a Windows Phone? http://t.co/j5TiFg6L

From ZDNet: Why did Facebook just hire a Managing Editor? http://t.co/f7tw3Pej via @zite

Australian Control Systems Exposed Online http://t.co/M1ys1sFh ZDnet highlights a couple of Internet accessible BMS

Introducing Evi: Siri's new worst enemy http://t.co/YehMYX0Y

Cutest, Weirdest iPad & iPhone Accessories at Macworld iWorld [Gallery] http://t.co/m92INQCi

Privacy vs. digital age: Where's the balance? http://t.co/i5KmzqSU

'Cash Mob' email helps Chagrin Hardware thrive: The owners of the Chagrin Hardware store had a really great trad... http://t.co/xr11SXzb

From the taste, Maccas and KFC have been printing food for years.

10 hours ago by meski on Pirate Bay to allow real-object downloads

Am using ncomputing x300 devices. I want to change to linux os but cannot find the drivers and the instructions on how to install then. c...

13 hours ago by khama on NComputing X300

A simile of your argument Mark: There are roads between Melbourne and Sydney so clearly airports are a waste of money.

15 hours ago by DavidN4 on CEOs, Libs still perplexed on govt NBN role

Parliament should have a day where every member has to quote lines from a movie or a song. It would probably make more sense than their u...

15 hours ago by Yoda7 on Albo learns: YouTube will find you out

buy chanel clutch bags online

15 hours ago by rixmoumn on NTI CD Maker Platinum: Simple burning

Apple's first, and biggest problem, was trying to have a Graphics computer emulate an I B M Compatible. After that let down, all that the...

16 hours ago by fredsan on Apple again looks to block Samsung

You say: 'Appelbaum complained about the spooks "tailing peaceful activists". But how could they know they're really peaceful unless the...

17 hours ago by AnonEmouse on Hacked or not, Ludlam's a target of spies

There are a few different depts(and now, private companies) that undertake constant monitoring of "dissenting" groups or groups that coul...

18 hours ago by DailyMagnet on Hacked or not, Ludlam's a target of spies

Why would releasing the source code of a product result in a security risk to it's end users? Surely if this was the case we'd see all so...

20 hours ago by moonhead on PCAnywhere affected by hack: Symantec

1. Can make good poker chips. Especially if you have the differnt looking tokesn. 2. Office hockey puck 3. Necklace if you string a...

1 day ago by JBriggs on Recycling your SecurID tokens

Encore, encore! While visiting his parliamentary secretary, Ballarat's Catherine King, Albs might check in to check over the 36 towers th...

1 day ago by community unity on Albo learns: YouTube will find you out

I was just seeking this info for some time. After 6 hours of continuous Googleing, at last I got it in your website. I wonder what is the...

1 day ago by astevechove on Study: Instant-messaging attacks rose in 2005

Thank you very much!
------------------------------------------------

1 day ago by Namlonrypaymn on iiNet undercuts Internode with NBN pricing

Setting up five straw dogs so you can dispose of them is no trick at all, especially when you don't attack the main one, that open source...

1 day ago by rsmits on Open source needed to save democracy

One other method for promoting your blog is posting comments on unique directories with your webpage link.

1 day ago by SCOOBOGOUTH on Broadband Speedtest

2.3GHz band is the interesting one as company like Qualcomm which was the leader in the IS-95 CDMA technology is new concentrating on the...

1 day ago by SW_Victoria on Vivid's wireless windfall

Thanks Marc, that's a bit different to the 4G dongle then. Odd.

2 days ago by JoshT on Full Spectrum: Telstra's HTC Velocity 4G

This story has been voted 5 times in the last 24 hours!

3 days ago, CEOs, Libs still perplexed on govt NBN role

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar