Microsoft has issued its monthly security bug fix

Patch Tuesday brings 26 fixes

Six critical patches highlight largest update in years

Written by Shaun Nichols in San Francisco

Microsoft has issued a hefty 11 bulletins addressing 26 vulnerabilities in its August security release.

The monthly security update includes six bulletins that address issues rated 'critical', the highest of Microsoft's security alert levels.

Advertisement

Four of the critical bulletins addressed vulnerabilities in Office. Those patches included fixes for an ActiveX control in Office 2003 and older, flaws in Office filters, Powerpoint and Excel. All four could be used by an attacker to remotely execute code.

The company also fixed remote code vulnerabilities in the Image Color Management software for Windows 2000, XP and Server 2003. The remaining critical bulletin was an update to a previous patch for Internet Explorer 6 and 7.

The five remaining vulnerabilities were all rated 'important'. Those included fixes for remote code flaws in Word and information disclosure risks in Outlook and Windows Messenger.

Also fixed was an information disclosure flaw in the IPSec software for Windows Vista and Server, as well as a remote code execution vulnerability in the Windows Event System component for all versions of the operating system.

McAfee researcher Karthik Raman said that the update was a "mammoth" release, noting that Microsoft has not patched so many vulnerabilities with a single update in some two years.

"We have not seen anything of this scale in a long time," he said.

"Many of the vulnerabilities addressed by the fixes could be exploited if a Windows user simply views a malformed image or visits a malicious website, a favourite attack method among cybercriminals."

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

BusinessGreen.com eco-entrepreneur podcast logo

03 Dec 2008

4.07 MBEco-entrepreneur Podcast: Atlantis Resource Corporation More...

Podcast image

28 Nov 2008

12.57 MBComputing podcast - Standard Life's offshoring plans; and the prospects for government IT More...

Shaun Nichols and Iain Thomson

28 Nov 2008

7.11 MBPodcast Special: Views from the Valley More...

Poll

Microsoft

Unified Communications: Collaboration

Unified Communications: Collaboration

What is the main advantage of using collaboration technologies?

Previous poll results

Spotlight

Computer virus

15 million new malware types discovered in 2008

Kaspersky Lab puts value of cyber-crime business at $100bn   More...

Iomega BlackBelt

Review: Iomega eGo BlackBelt drive

Iomega's ruggedised hard drive promises safe portability for mobile professionals   More...

Yahoo headquarters

Yahoo saga looks set to rumble on

Carl Icahn casts doubt on new Microsoft bid, and would...  More...

Sun Microsystems

Sun takes on Adobe and Microsoft with JavaFX

Vendor claims easy creation and deployment of rich internet applications   More...

Primary Navigation