The Broadband Guide
SG
search advanced

Microsoft patches critical Windows drive-by bug

2012-01-10 18:04 by
Tags:

 

Microsoft today shipped seven security updates that patched eight vulnerabilities in Windows and a code library used to protect Web applications from cross-site scripting attacks.

Of the six bulletins this month, there are two that stand out: MS12-004 and MS12-006. MS12-004 is a "critical" security bulletin that addresses a vulnerability in Windows Media Player, and MS12-006 patches the flaw exploited by BEAST attacks. MS12-006 was originally slated for the December 2011 Patch Tuesday, but was pulled at the last minute due to conflicts.

"Historically, January has a been a light month for Microsoft patches and, so far, this year is no different," said Andrew Storms, director of security operations at nCircle.

As the media player vulnerability is a memory-corruption issue, it would be a bit difficult to exploit, according to Joshua Talbot, security intelligence manager of Symantec Security Response. Even though Microsoft rated it as "important," Talbot said he considered the flaw with the .NET packager (MS12-005) as the "most severe issue." To exploit the vulnerability, the attacker has to convince the user to open the maliciously crafted Office document, according to Microsoft.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About