Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Plans to Release 8 Security Bulletins for May Patch Tuesday

Microsoft plans to release eight security bulletins next week as part of its Patch Tuesday release.

According to its Security Bulletin Advanced Notification, the company has two ‘critical’ bulletins on tap for next week, affecting Microsoft Server Software, Productivity Software, Windows and Internet Explorer. The remaining six bulletins are classified as ‘important’.

Microsoft plans to release eight security bulletins next week as part of its Patch Tuesday release.

According to its Security Bulletin Advanced Notification, the company has two ‘critical’ bulletins on tap for next week, affecting Microsoft Server Software, Productivity Software, Windows and Internet Explorer. The remaining six bulletins are classified as ‘important’.

“The busy month comes just one-week after the out-of-band patch for IE, MS14-021, released by Microsoft May 1,” said Russ Ernst, director, product management at Lumension. “Interestingly, a critical fix for IE is first on the advance notification list this month too. The bad guys continue to wage war on what remains one of the most popular browsers so, for organizations that rely on it, IT needs to patch monthly, at a minimum.”

SharePoint users will want to pay close attention to the second critical bulletin, which impacts 2007, 2010 and 2013 and Microsoft Web Apps, he said.

Qualys CTO Wolfgang Kandek blogged that the second bulletin allows for remote code execution, and should be high on an organization’s patch list in particular if any of the affected platforms are exposed to the Internet.

“The remaining bulletins,” Ernst noted, “are rated important and impact a wide-range of software categories. Bulletin 3 is a possible remote code execution that hits Office; bulletin 4 is for most versions of Windows. Windows and the .NET framework are covered off in bulletin 5 with an elevation of privilege issue. The sixth and seventh bulletins impact most versions of Windows with elevation of privilege and denial of service issues respectively. The last bulletin addresses a security feature bypass issue in Office.”

In addition to the Microsoft advisory, Adobe Systems stated it plans to release updates for Adobe Reader and Acrobat XI (11.0.06) and earlier for Windows and Macintosh next week. Both the Microsoft and Adobe updates will be released May 13. 

Earlier this month, Microsoft released an out-of-band patch to fix a critical Internet Explorer vulnerability that had come under attack. 

Advertisement. Scroll to continue reading.
Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.