All the latest UK technology news, reviews and analysis

Microsoft revokes more DigiNotar certificates on Patch Tuesday

by Phil Muncaster

14 Sep 2011

Be the first to comment

  • Tweet this

Security administrators will be busy today after Microsoft's monthly Patch Tuesday update and Adobe's quarterly patch release fell on the same day, and Microsoft revoked certificates signed by two authorities in the wake of the DigiNotar breach.

Microsoft issued five patches to deal with flaws rated as 'important' in Windows and Office software.

Priority, according to vulnerability management firm Qualys, should be given to the MS11-072 patch which fixes an arbitrary code execution vulnerability in Excel that affects all versions of the software.

"To exploit this issue, attackers could create malicious Excel files which, when opened on vulnerable hosts, can take control of the system," explained Qualys chief technology officer Wolfgang Kandek.

"Priority should also be given to MS11-073 which fixes a code execution vulnerability in Microsoft Office versions 2003, 2007 and 2010, including Microsoft Word. Attackers could use a malicious word file (CVE-2011-1982) to execute code on victim machines."

Microsoft also made a move to secure Internet Explorer users by revoking six certificates signed by two Certificate Authorities, Entrust and Cybertrust, which had issued certificates on behalf of DigiNotar.

DigiNotar was hacked last month by cyber criminals who managed to issue false certificates for sites including Google and Facebook. Browser vendors including Google and Mozilla have already revoked the certificates in question.

Also on Tuesday, Adobe issued critical updates for Reader and Acrobat which could cause the apps to crash or allow an attacker to take control of an affected system.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Procurement/P2P Transformation Consultant

Premier Consulting Firm - Procurement/P2P Transformation...

IT Strategy and Transformation Professional

Premier consulting firm - IT Strategy and Cloud Consulting...

C# Developer- Shropshire, West Midlands

Software developer/ C# developer, (ASP.NET, C#, MVC...

Oracle Developer/ Programmer- Forms, Reports, PL-SQL

Oracle Developer/ Programmer- Oracle ebusiness suite...

To send to more than one email address, simply separate each address with a comma.