All the latest UK technology news, reviews and analysis

Browser fixes cap 2007's 'Patch Tuesday'

by Shaun Nichols

More from this author

12 Dec 2007

Be the first to comment

  • Tweet this

Microsoft has released a series of seven patches in what is scheduled to be the final security update of 2007.

The monthly release includes three patches that address vulnerabilities rated by the company as 'critical', while the other three carry a maximum security rating of 'important'.

Among the three critical patches was a cumulative update for Internet Explorer. The patch fixes four vulnerabilities in the browser. Three of the flaws could allow an attacker to place fraudulent information in the browser's address bar, while a fourth vulnerability could allow an attacker to remotely execute malicious code.

The other critical patches include a fix for DirectX, the graphics software used by Windows. That update includes fixes for two vulnerabilities that could allow an attacker to remotely execute code on a target system.

A critical flaw in the way Windows handles Windows Media files was also addressed. If exploited, the flaw could be used by an attacker to execute code.

The four important fixes issued in the update included flaws within the Windows Vista kernel and SMB components, the Windows XP and Windows 2000 Message Queuing component, and the Windows XP and 2003 Macrovision driver.

The patches fixed vulnerabilities ranging from remote code execution to the escalation of privileges.

McAfee research and communications director Dave Marcus said that the Internet Explorer and Windows Media patches were among the most interesting this month.

"Today's Microsoft patches emphasise the need for proactive browser protection and the risk of surfing the web unprotected,” said Marcus.

"The vulnerability in the Windows Media File Format is another warning that media files potentially aren't safe and people should use caution when opening media files.”

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Dynamics AX/AXAPTA Functional Consultant, 55k! Home working!

My multi- national Partner client has charged me exclusively...

Senior IT Operations Engineer -MCSE, IIS7/7.5, SAN, CDN

Senior IT Operations Engineer -MCSE, IIS7/7.5, SAN, CDN...

Bitlocker Consultant

I have an urgent requirement for short term contract...

User Interface Developer x 1/2 - South West

User Interface Developer x 1/2 - Leading Organisation...

To send to more than one email address, simply separate each address with a comma.