Your Guide to Broadband
Free PC Scan
 Username:
 Password:
Register
 forgot your password?
eBay auction monitoring, bidding and sniping

Microsoft patches critical Windows drive-by bug

2012.01.10 18:04 by Daniela
Keywords: Microsoft

 

Microsoft today shipped seven security updates that patched eight vulnerabilities in Windows and a code library used to protect Web applications from cross-site scripting attacks.

Of the six bulletins this month, there are two that stand out: MS12-004 and MS12-006. MS12-004 is a "critical" security bulletin that addresses a vulnerability in Windows Media Player, and MS12-006 patches the flaw exploited by BEAST attacks. MS12-006 was originally slated for the December 2011 Patch Tuesday, but was pulled at the last minute due to conflicts.

"Historically, January has a been a light month for Microsoft patches and, so far, this year is no different," said Andrew Storms, director of security operations at nCircle.

As the media player vulnerability is a memory-corruption issue, it would be a bit difficult to exploit, according to Joshua Talbot, security intelligence manager of Symantec Security Response. Even though Microsoft rated it as "important," Talbot said he considered the flaw with the .NET packager (MS12-005) as the "most severe issue." To exploit the vulnerability, the attacker has to convince the user to open the maliciously crafted Office document, according to Microsoft.

Read more -here-

 

  No user reviews/comments yet
    rate:
   avg:
comment discuss top

exec. time: 0.10467 s
Copyright © 1998-2012 Speed Guide, Inc. All rights reserved.
Terms of Use | Privacy Policy