Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Slates Critical Patch Tuesday Updates for Windows, Security Software

Microsoft is planning to release five security bulletins next week for this month’s Patch Tuesday, including two that are rated ‘critical.’

Microsoft is planning to release five security bulletins next week for this month’s Patch Tuesday, including two that are rated ‘critical.’

According to the company, the critical bulletins address remote code execution issues in Microsoft Windows and Security Software, while the other bulletins – which are all rated ‘important’ – address various issues in Windows and the .NET Framework.

“Microsoft continues the trend they started last month of keeping Patch Tuesday relatively light,” said Ross Barrett, senior manager of security engineering at Rapid7. 

“The two critical advisories are unusual in that they don’t touch older versions of Windows or Internet Explorer,” he added. “The first patches a remote code execution vulnerability that affects Windows 7 through to Windows 8.1, including 8.1 RT.  The second, also a remote code execution, is actually an issue in Forefront Protection for Exchange Server (2010). Given a remote code execution in a perimeter service like Forefront, I’d have to say that this is the highest priority patching issue this month.  The second is, not surprisingly, the critical in Windows 7 and later.”

Researchers with CORE Security suggested organizations treat the second bulletin with the highest priority.

“It would be tragic to let the Forefront software protecting your Exchange Server be part of the attack path an attacker uses as the open door,” said Tommy Chin, technical support engineer, CORE Security. “Bulletin 4 seems to be interesting as well. The type of information disclosed by this vulnerability would be interesting to know since it affects all major Windows operating systems.”

The security updates will be released Feb. 11. So far, 2014 has been a quiet one for Microsoft updates. In January, the company issued just four security bulletins, and none of them were classified as ‘critical.’ But IT departments have other security updates to worry about.

“Adobe released an emergency fix this week to patch vulnerabilities in the Flash Player plug in for IE and other browsers,” noted Russ Ernst, director of product management at Lumension, in a blog post. “These vulnerabilities are under active attack and given the wide spread use of Flash in browsers, this will create a cascading affect for companies like Firefox, Google and others to also address it.”

Advertisement. Scroll to continue reading.
Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.