Microsoft to address flaws in Windows, Office for Mac

Article

Microsoft to address flaws in Windows, Office for Mac

SearchSecurity.com Staff

Microsoft on Thursday said it plans to release six bulletins next week, including three critical bulletins, addressing flaws in Windows and Microsoft Office products.

SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

The announcement was part of Microsoft's Advance Notification to customers. The security updates will be released Nov. 10 as part of the software maker's monthly Patch Tuesday cycle.

The three bulletins identified as critical could allow remote code execution, Microsoft said. The security updates affect Microsoft Windows 2000, XP, Vista and Windows Server 2008. The updates affecting Microsoft Office components are identified as important and affect Microsoft Office Excel and Word viewer. The update also affects Microsoft Office 2004 and 2008 for Mac.

Microsoft updates:
Microsoft fixes security update that breaks Internet Explorer: An update released Monday corrects two issues that affect the proper display of Web pages.

Oct. - Microsoft addresses critical SMBv2 flaw, fixes record number of flaws: Microsoft addressed three critical vulnerabilities in Windows Server Message Block. Thirteen bulletins addressed a record 34 flaws.

Sept. - Microsoft repairs Windows media, TCP/IP vulnerabilities: Microsoft released five critical updates fixing a serious flaw in the Windows Media Format Runtime engine and TCP/IP processing errors that could crash Web and mail servers. 

Security experts said one of the bulletins, flaws that could result in a denial-of-service condition, applies to nearly all Windows versions and may be the most serious. HD Moore, chief security officer and chief architect of Metasploit said the flaw could be to a common API such as a graphics display interface (GDI),

Last month Microsoft issued 13 bulletins, patching a record 34 vulnerabilities across its product line. One of the October bulletins, MS09-054, which addressed four flaws in Internet Explorer, was reissued by Microsoft this week to repair a problem with the patch. The update caused IE to render Web pages improperly by miscalculating objects on the page. The October Microsoft bulletins also contained the first security update for Windows 7, addressing ActiveX control issues as a result of components built using a flawed version of Microsoft Active Template Library.


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.