All the latest UK technology news, reviews and analysis

Admins braced for hefty Christmas Patch Tuesday from Microsoft

by Phil Muncaster

12 Dec 2011

Be the first to comment

  • Tweet this

Security administrators are in for a busy holiday season after Microsoft confirmed that the December Patch Tuesday release will include 14 bulletins covering 20 vulnerabilities in a range of products.

Microsoft said in the Security Bulletin Advance Notification for December 2011 that three of the 14 bulletins are rated 'critical', the highest severity rating, and could allow remote code execution on infected XP, Vista and Windows 7 systems.

Bulletins 1 and 2 also affect Windows Server 2003, while Windows Server 2008 is affected only by the first critical bulletin.

The remaining 11 bulletins are rated 'important' and cover remote code execution and elevation of privilege flaws.

"Five of the 'important' bulletins affect Office 2003, 2007 and 2010 including all Office versions for Macintosh as well," explained Wolfgang Kandek, chief technology officer at vulnerability management firm Qualys.

"One of the remaining bulletins addresses Internet Explorer 6 through 9, and the remaining bulletins apply to all versions of Windows."

Although not specifically referred to in the security bulletin, it is also believed that Microsoft will patch the flaw in TrueType font parsing which was exploited by the Duqu Trojan.

System administrators are likely to be kept doubly busy as Adobe is set to release an update for Reader and Acrobat 9.x for Windows this week to address a critical vulnerability which could cause a system crash and allow attackers to take control of an affected system.

The flaw is actively being exploited in the wild via malicious PDF email attachments, according to security researchers.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

39%

0%

10%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.