Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Another month, another 19 Microsoft flaws patched
Another month, another 19 Microsoft flaws patched PDF Print E-mail
Written by Stan Beer   
Wednesday, 09 May 2007
Anyone who was still living under the illusion that the arrival of Windows Vista would mean a lessening of security holes for Microsoft to patch would have had rude awakening this month. Microsoft announced no less than 19 newly discovered flaws in its software, of which 15 are classed as critical.

The 15 critical vulnerabilities, classed as such because they could allow remote code execution if exploited, cover pretty much the gamut of Microsoft's most widely used software products, including Windows, Office, Excel, Word and Internet Explorer

Microsoft has issued seven security bulletins and associated patches covering the 19 vulnerabilities and the large number has prompted some outpourings of consternation from sectors of the security community.

"Of particular concern is the large number of Microsoft Office, Word, Excel and Internet Explorer vulnerabilities being patched today," said Dave Marcus, security research and communications manager, McAfee Avert Labs. "These applications are the most frequently targeted applications by malware writers, so we recommend that all customers evaluate their security coverage and policies to insure they have adequate protection in place."

Microsoft should be able to take some heart, however, that vulnerabilities in Vista itself have not arisen this month. However, flaws in both Office 2007 and Internet Explorer 7 have surfaced.

An overview of the Microsoft vulnerabilities is as follows:

  * MS07-023 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
  * MS07-024 - Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
  * MS07-025 - Vulnerability in Microsoft Office Could Allow Remote Code Execution
  * MS07-026 - Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution
  * MS07-027 - Cumulative Security Update for Internet Explorer
  * MS07-028 - Vulnerability in CAPICOM Could Allow Remote Code Execution
  * MS07-029 - Vulnerability in Windows DNS RPC Interface Could Allow Remote Code Execution

It looks like the Patch Tuesday cycle is with us for the foreseeable future.{moscomment}



Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >
Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video