Microsoft Sets New Patch Record, Fixes 26 Flaws - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News
News
10/10/2006
04:09 PM
50%
50%

Microsoft Sets New Patch Record, Fixes 26 Flaws

The flaws, more than half of which received a "critical" rating, run the gamut from Internet Explorer to Word, Excel, and PowerPoint.

Microsoft on Tuesday released 10 security updates, one less than anticipated, that patched a record 26 vulnerabilities in Windows, Office, and .Net. More than half of the flaws were pegged "critical" by the Redmond, Wash. developer.

Tuesday's tally was impressive by any count: 6 of the 10 updates were judged critical, with the remaining split among Microsoft's other rankings: "important" (1), "moderate" (2), and "low" (3). Of the 26 disclosed vulnerabilities, 15 were labeled critical, 6 important, 2 moderate, and 3 low. Both the total vulnerabilities and the number of critical vulnerabilities set new records for Microsoft in its monthly patch process.

"This is very rich lot," said Minoo Hamilton, a senior security researcher with patch management vendor nCircle. "There's everything in here from Windows Explorer and Internet Explorer to Word and Excel and PowerPoint."

Every one of the half-dozen bulletins marked critical should be paid attention, said Hamilton. "They're all remotely exploitable, and in some cases across the [OS] board."

Several of the updates fix flaws that hackers are already exploiting, including MS06-057, which patches the WebViewFolderIcon bug known -- and used -- since the end of September. Others patching already-exploited vulnerabilities include the MS06-058 update for Microsoft Office PowerPoint and MS06-060, a fix for Microsoft Word.

Office, in fact, accounted for 62 percent of the bugs patched Tuesday and 86 percent of those marked critical. Microsoft's suite has been under the gun since May, when a vulnerability in Word was fixed, and has been the subject of prognosticators for months.

"Attackers have an increasing tendency to exploit vulnerabilities in desktop applications rather than network infrastructure," said Oliver Friedrichs, director of the Symantec's security response team, in an e-mail. "The quantity of Microsoft Office vulnerabilities this month illustrates this emerging attacker focus and users should consider the installation of these patches to be critical."

The Office vulnerabilities make lucrative targets for attackers, added Don Leatham, the director of solutions and strategy at Patchlink. "The hacker community is driving more and more toward creating as many botnets as possible, and the easiest way to get them is in the end-user part of the enterprise. The number of bugs within Office shows that concerted effort."

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
State of the Cloud
State of the Cloud
Cloud has drastically changed how IT organizations consume and deploy services in the digital age. This research report will delve into public, private and hybrid cloud adoption trends, with a special focus on infrastructure as a service and its role in the enterprise. Find out the challenges organizations are experiencing, and the technologies and strategies they are using to manage and mitigate those challenges today.
Slideshows
10 RPA Vendors to Watch
Jessica Davis, Senior Editor, Enterprise Apps,  8/20/2019
Commentary
Enterprise Guide to Digital Transformation
Cathleen Gagne, Managing Editor, InformationWeek,  8/13/2019
Slideshows
IT Careers: How to Get a Job as a Site Reliability Engineer
Cynthia Harvey, Freelance Journalist, InformationWeek,  7/31/2019
Register for InformationWeek Newsletters
Video
Current Issue
Data Science and AI in the Fast Lane
This IT Trend Report will help you gain insight into how quickly and dramatically data science is influencing how enterprises are managed and where they will derive business success. Read the report today!
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll