09 Mar 2011
Microsoft has issued three bulletins to address four vulnerabilities in its latest monthly security release.
The March edition of the Patch Tuesday update includes two bulletins for issues rated 'important' and a third for flaws considered 'critical'.
The 'critical' patch addresses flaws in the Microsoft Windows Media platform. If exploited, the vulnerability could allow an attacker to use a specially crafted .dvr file to trigger a crash and remotely execute code on a targeted system.
Microsoft said that the attack cannot be automatically triggered, meaning that an attacker would need to use social engineering to trick a target into launching the malicious file.
Microsoft still lists the vulnerability as a top patching priority for Windows XP, Vista and Windows 7 systems.
The patch is considered an 'important' update for Windows Server 2008 R2 x64. Other versions of Windows Server are not believed to be vulnerable.
The remaining two patches address DLL preloading issues in Microsoft Office and Windows Remote desktop Connection which could allow remote code execution. Both have been classified as 'important'.
However, there is one omission from the March update that has raised eyebrows among security experts.
Dave Marcus, director of security research and communications at McAfee Labs, noted that a recently disclosed flaw in Internet Explorer's MHTML component remains unpatched.
"We haven't seen evidence that the impact of the MHTML vulnerability is any more significant than the other zero-day code execution vulnerabilities we've seen recently," Marcus said.
"This month's Patch Tuesday does not address this Internet Explorer zero-day, which could allow hackers to take advantage of this vulnerability."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Development Manager / PHP Developer / MySQL / LAMP...
Process Expert for Information/Content Management...
SQL Server / SSIS / ETL / T-SQL Data Migration A...
Linux Systems Administrator / Linux CentOS / Network...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?