Email this article   Print article 


Microsoft To Start New Year With Seven Security Bulletins

By Antone Gonsalves
January 05, 2012    6:54 PM ET

Microsoft plans to start the new year with a relatively large number of security bulletins covering eight vulnerabilities.

The company said Thursday it would release seven bulletins Jan. 10, the year's first set of patches that Microsoft releases on the second Tuesday of every month. The number of fixes is much larger than the more typical one or two bulletins in January, Wolfgang Kandek, chief technology officer for security vendor Qualys, said.

Six of the latest bulletins cover the Windows operating system from XP SP3 up to Windows 7 and Windows 2008 R2. The seventh bulletin covers Microsoft developer tools.

One of the bulletins is rated critical and fixes a remote code execution problem in Media Player within Windows.. The rest get the important label. Along with the critical patch, Kandek recommends that companies give equally high priority to two other bulletins that involve remote code execution, which would expose a computer to being commandeered by a hacker.

One bulletin is under a new category called Security Feature Bypass. "It will be interesting to see which exact Windows features are involved and how this vulnerability can be used by attackers," Kandek said on Qualys' blog.

As usual, more of the patches are targeted at older versions of Windows than the new versions of Windows 7 and 2008 R2.

Along with Microsoft, Adobe and Oracle are scheduled to release patches this month. Adobe's release is set for Jan. 10 and Oracle Jan. 17.

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

10 Security Companies That Have Scored CIA Funding

CIA-funded venture firm invests millions in technology startups, mostly security firms. Find out which security companies won In-Q-Tel funding.

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

  More Slide Shows




Related Videos
Loading...