Patch Tuesday: Routine For Microsoft, Adobe Is More Pressing

Microsoft has delivered a fairly routine Patch Tuesday security update for July, as experts warn that this month’s Adobe patches are the most pressing.

Microsoft has released 11 updates in total, six of which are rated as critical. Adobe meanwhile patched 52 vulnerabilities for its products.

Patch Tuesday

Todd Schell of HEAT Software explained that none of Microsoft’s 40 vulnerabilities patched this month are under active attack, which is a bit of good news for system administrators.

But he warned that the top priority has to be Adobe’s patches.

“The company patched 52 vulnerabilities for Flash Player and other Adobe products with APSB16-25 today and Microsoft made their updates with MS16-093,” said Schell.

“While this was one of the biggest updates made by Adobe this year, it thankfully does not include any active exploits. If you’re still using Flash Player regardless of OS, definitely get this update made first. There are also updates for Acrobat and Reader so if you use those tools, be sure to update those too using APSB16-26.”

Schell reckons that the priority for the Microsoft updates should be MS16-087, which fixes two flaws in Windows Print Spooler which could allow remote code execution via a man in the middle attack. His next critical update is MS16-086, which fixes a problem with JScript and VBScript in Vista and Server 2008.

It should be noted that web browsers and Office applications are not forgotten, as MS16-084 tackles 15 vulnerabilities with Internet Explorer, whilst MS16-085 fixes flaws with the Edge browser.

Loading ...

Quiet Month

“Overall, it is a quiet month from an attack perspective so you are best served to use this time to take a close look at all the bulletins and update your older systems,” said Schell.

Amol Sarwate, director of vulnerability research at Qualys meanwhile recommends that system admins should also pay attention to MS16-088 for Microsoft Office, as a flaw could allow remote code execution if a user opens a specially crafted Microsoft Office file.

Qualys Sarwate also warned system administrators to pay attention to the Adobe fixes.

Unfortunately, Adobe’s Flash player suffers frequent security problems, and its widespread presence in web browsers has made it an attractive target for online criminals.

Last month Adobe had to push out an update to fix a critical flaw that computer security experts had warned was being exploited in attacks since March.

Quiz: What do you know about cybersecurity in 2016?

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

TikTok Viewed As Chinese Influence Tool By Most Americans – Poll

Most people in the United States view TikTok as a Chinese influence tool a poll…

12 hours ago

Ofcom Confirms OnlyFans Investigation Over Age Verification

UK regulator confirms it is investigating whether OnlyFans is doing enough to prevent children accessing…

13 hours ago

Ex Google Staff Fired Over Israel Protest File NLRB Complaint

Dismissed staff file complaint with a US labor board, and allege Google unlawfully terminated their…

14 hours ago

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

15 hours ago

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

16 hours ago

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

20 hours ago