Windows bug
Microsoft has patched several critical flaws in Office

Eight December fixes delivered by Microsoft

Release closes out 2008 security schedule

Shaun Nichols in San Francisco

Microsoft has issued its final scheduled security update of 2008.

The December Patch Tuesday release includes updates for 27 separate vulnerabilities spread out over eight bulletins.

Advertisement

Six of the bulletins have been rated as critical, the highest of Microsoft's four security alert levels. If exploited, each could allow an attacker to remotely execute code by way of a specially-crafted file or web page.

One of the bulletins addresses remote code flaws in Internet Explorer, while another addresses an ActiveX component flaw in Visual Basic. Other bulletins address issues in the handling of Windows WMF files and a remote code execution flaw in Windows Search.

Office also received several critical bulletins. Microsoft issued fixes for remote code execution vulnerabilities in Office's handling of Excel spreadsheets, Word documents and Rich Text Files.

The two remaining bulletins were classified as "important", the third of the company's four alert levels. Those two addressed remote code execution flaws in the handling of Windows Media Format components as well as a vulnerability in SharePoint that could be used to obtain elevated privileges.

Barring the release of an out-of-cycle security patch, the December update will be the final set of bulletins issued by Microsoft this year.

Users can obtain the updates from Windows automatic updates component or manually download the update from the company's web site.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Hacker

Web site owners warned of growing attacks

Sophos identified a new infected web page every four and a half seconds during 2008

Microsoft bugs

Eight bulletins wrap up Microsoft's security year

Six critical fixes in December update

Apple criticised for pulling anti-virus advice

Sophos argues that updating rather than removing the post would have been best course of action

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation