Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Plans to Release 8 Security Bulletins for May Patch Tuesday

Microsoft plans to release eight security bulletins next week as part of its Patch Tuesday release.

According to its Security Bulletin Advanced Notification, the company has two ‘critical’ bulletins on tap for next week, affecting Microsoft Server Software, Productivity Software, Windows and Internet Explorer. The remaining six bulletins are classified as ‘important’.

Microsoft plans to release eight security bulletins next week as part of its Patch Tuesday release.

According to its Security Bulletin Advanced Notification, the company has two ‘critical’ bulletins on tap for next week, affecting Microsoft Server Software, Productivity Software, Windows and Internet Explorer. The remaining six bulletins are classified as ‘important’.

“The busy month comes just one-week after the out-of-band patch for IE, MS14-021, released by Microsoft May 1,” said Russ Ernst, director, product management at Lumension. “Interestingly, a critical fix for IE is first on the advance notification list this month too. The bad guys continue to wage war on what remains one of the most popular browsers so, for organizations that rely on it, IT needs to patch monthly, at a minimum.”

SharePoint users will want to pay close attention to the second critical bulletin, which impacts 2007, 2010 and 2013 and Microsoft Web Apps, he said.

Qualys CTO Wolfgang Kandek blogged that the second bulletin allows for remote code execution, and should be high on an organization’s patch list in particular if any of the affected platforms are exposed to the Internet.

“The remaining bulletins,” Ernst noted, “are rated important and impact a wide-range of software categories. Bulletin 3 is a possible remote code execution that hits Office; bulletin 4 is for most versions of Windows. Windows and the .NET framework are covered off in bulletin 5 with an elevation of privilege issue. The sixth and seventh bulletins impact most versions of Windows with elevation of privilege and denial of service issues respectively. The last bulletin addresses a security feature bypass issue in Office.”

Advertisement. Scroll to continue reading.

In addition to the Microsoft advisory, Adobe Systems stated it plans to release updates for Adobe Reader and Acrobat XI (11.0.06) and earlier for Windows and Macintosh next week. Both the Microsoft and Adobe updates will be released May 13. 

Earlier this month, Microsoft released an out-of-band patch to fix a critical Internet Explorer vulnerability that had come under attack. 

Written By

Marketing professional with a background in journalism and a focus on IT security.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

Axonius has appointed Moshe Ben Simon as Chief Product Officer.

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.