Categories: SecurityWorkspace

Microsoft Patch Tuesday: 11 Fixes, One Gap

Microsoft’s latest Patch Tuesday security update fixes 11 serious flaws, but the company has been criticised for leaving a one-week-old flaw that is being exploited in the wild.

The patche bundle fixes several new flaws (called “zero days” in the business), including one flaw that escaped November’s Patch Tuesday bundle, which allowed attackers to hit Microsoft Word users, with boobytrapped documents containing TIFF image files.

Flaws face a fix

Microsoft’s Patch Tuesday fixes, issued on the second Tuesday of the month, attempt to block all the most significant threats to software including Windows, Office and Internet Explorer. This time round, fixes include the TIFF vulnerability, as well as fixes for flaws in Lync, Exchange, Windows and Microsoft Developer Tools.

As always, a recently -notified flaw has slipped through the net. Dustin Childs, of Microsoft’s Trustworthy Security Group admitted that a security flaw affecting Windows XP and Windows Server 2003, known as CVE-2013-5065, is not yet patched.

This bug lets attackers with valid login credentials for these older Microsoft operating systems elevate their privileges.  Childs promises a fix soon, and Microsoft has offered a list of suggested workarounds to the problem.

Lets hope at-risk computer users don’t have to wait until 2014 for a fix for that serious problem,” commented security expert Graham Cluley.

Are you a security expert? Try our quiz!

Peter Judge

Peter Judge has been involved with tech B2B publishing in the UK for many years, working at Ziff-Davis, ZDNet, IDG and Reed. His main interests are networking security, mobility and cloud

Recent Posts

OpenAI Hit By Austrian Complaint Over ChatGPT ‘False Data’

Rights group argues ChatGPT tendency to generate false information on individuals violates GDPR data protection…

1 day ago

EU Designates Apple’s iPad OS As DMA ‘Gatekeeper’

European Commission says Apple's iPadOS is 'gatekeeper' due to large number of businesses 'locked in'…

1 day ago

Beating the Barbarians in the Cloud

As the cloud continues to be an essential asset for all businesses, developing and maintaining…

1 day ago

Austria Conference Calls For Controls On ‘Killer Robots’

Internatinal conference in Vienna calls for controls on AI-powered autonomous weapons to ensure humans remain…

1 day ago

Taiwanese Chip Giant Exits China Mainland

Major Taiwan chip assembly and test firm KYEC to sell Jiangsu subsidiary, exit mainland China…

1 day ago

Deepfakes: More Than Skin Deep Security

As deepfake technology continues to blur the lines between reality and deception, businesses and individuals…

1 day ago