Microsoft Plans Critical Patches For Internet Explorer, Exchange

  /     /     /  
Publicated : 22/11/2024   Category : security


Microsoft Plans Critical Patches For Internet Explorer, Exchange


Microsofts security patches Tuesday will fix three critical vulnerabilities, including one that affects all current versions of Internet Explorer.



10 Hidden Benefits of Windows 8.1 (click image for larger view)
Microsoft will issue eight security updates Tuesday, three of which are designated as critical, the companys most urgent category. Two of them stand out because of the crucial software they involve: Internet Explorer and Exchange Server.
As usual, Microsoft
previewed this months Patch Tuesday releases
in an advance notice. The precise nature of each vulnerability has yet to be detailed, but the critical update involving Internet Explorer will be an obvious priority for IT administrators.
The bundle will fix a remote execution exploit that spans all currently-supported versions of Internet Explorer, from IE 6, which is only supported on Windows XP, all the way to IE 10, which runs on Windows 7, Windows 8 and Windows RT. According to figures released this week by Microsoft,
Internet Explorer accounts for more than half of worldwide desktop traffic
. Given that browsers are already one of malware authors primary targets, such a widespread bug requires prompt attention.
[ How reliable are Microsoft cloud services? Read
Microsoft Office 365 Reveals Uptime Figures
. ]
Excluding the newest edition, Microsoft has issued seven Internet Explorer updates so far this year, including an unusual
out-of-band fix in January
.
The bug afflicting Exchange Server has drawn attention as well. In a blog post, Wolfgang Kandek, CTO of security vendor Qualys, said it will be interesting to see if the release is
related to a recent Oracle update involving the companys Outside In product
. Exchange uses Outside In to display an attached document without launching that documents native application.
Outside In has necessitated numerous security patches
in the last year
. Oracle released patches last month for Outside In, but because they arrived after Microsoft had already deployed Julys security updates, Kandek and other security professionals have inferred that Augusts Patch Tuesday is implementing the fix.
One things for certain: Given the amount of sensitive content that moves over email each day, a critical Exchange Server update is always important, whatever the bug.
The third critical fix involves Windows XP and Windows Server 2003. Both products will lose official support soon, with XP retiring in April and Windows Server to follow in July 2015. As such, these patches wont impact as many customers as the aforementioned ones. Theyll still keep plenty of Microsoft customers busy, though;
over 37% of the worlds computers still run Windows XP
, including
over 70% in China
.
The other five updates were each categorized as important, Microsofts second-highest designation. They fix bugs in various Windows versions that could allow attackers to launch denial-of-service attacks, execute malicious programs or otherwise gain illicit control of a machine. Four of the five updates require that machines be restarted.
Paul Henry, an analyst with security vendor Lumension, said in a blog post that Microsoft has
patched bugs more quickly in 2013
than it has in the past.
Security experts expected more security updates in 2013, he wrote, given Microsofts commitment to cleaning up the low hanging fruit out there. Including the eight bulletins Microsoft is releasing this week, Microsoft has released 65 security bulletins so far this year, or seven more than it had released through the same point in 2013, Henry noted.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Microsoft Plans Critical Patches For Internet Explorer, Exchange