11 Apr 2012
Microsoft has released its April security bulletin, a six-patch update containing four critical fixes and addressing a total of 11 vulnerabilities.
This month’s critical bulletins address various remote code execution vulnerabilities in Microsoft Windows, Internet Explorer and Office. Considered to be the serious vulnerabilities, remote code execution flaws allow for an attacker to install malware on a targeted system without user consent.
Bulletins MS12-023 and MS12-027 address key issues in Internet Explorer and Microsoft Office.
With both programs playing a critical role in day-to-day business operations, experts say IT administrators should make them first priority patches.
"Two that really stand out to me are 023 and 027," McAfee threat intelligence service manager Jim Walters told V3, "the IE bulletin is the highest priority."
The other two non-critical Microsoft patches released today include resolutions for a vulnerability in Microsoft Forefront Unified Access Gateway (UAG) that could allow for information disclosure if an attacker sends a specially made query to the UAG server.
The remaining bulletin addresses a privately reported vulnerability in Microsoft Word that could allow for a remote code execution flaw.
Adobe also released a critical patch for its Acrobat and Reader programs. The patch fixes a vulnerability which could lead to remote code execution and potentially allow an attacker to take control of an affected system.
"Given the popularity of the PDF format in targeted attacks, priority should be placed on this update as well," Walters added.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Security Assurance Consultant ( CLAS ) with HMG and Information...
Solutions Design Architect - Oracle - Exadata - Dataguard...
My Client is a tier one investment bank based in Edinbugh...
Analyst Programmer Web Developer required to work for...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?