Categories: PCSecurityWorkspace

Microsoft Patch Tuesday Fixes 34 Vulnerabilities

Microsoft has used its usual Patch Tuesday update to address a record number of vulnerabilities (34 in total), including six affecting its forthcoming replacement for the Vista operating system.

The vulnerabilities are covered by 13 security bulletins, and span Microsoft Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools and SQL Server. Eight of the bulletins were given a critical rating, Microsoft’s highest severity classification.

Six of the security bulletins affect the soon-to-be-released Windows 7 operating system, including MS09-054 and MS09-061, which are both rated critical. Those two bulletins include a critical update for Internet Explorer (MS09-054) and a fix for three vulnerabilities (MS09-061) in the Microsoft .NET Common Language Runtime that could be exploited to remotely execute code.

MS09-50 features fixes for three security vulnerabilities affecting Microsoft SMB (Server Message Block) protocol. Among the flaws is a zero-day bug disclosed in September that is due to the SMB implementation not properly parsing SMBv2 negotiation requests. Officials at Symantec said they have yet to see reliable exploits for the vulnerability in the wild, but there have been limited attempts to exploit the flaw.

Meanwhile, vulnerabilities in the FTP Service in IIS (Internet Information Services) have in fact come under attack, though the bulletin is only rated important. The vulnerabilities could allow RCE (remote code execution) on systems running FTP Service on IIS 5.0, or DoS (denial of service) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.

Additionally, the Patch Tuesday update includes fixes tied to ActiveX Controls compiled using a vulnerable version of Microsoft Active Template Library. The bulletin addresses three vulnerabilities affecting all supported editions of Microsoft Outlook versions 2002, 2003 and 2007, as well as Microsoft Visio Viewer versions 2002, 2003 and 2007.

Other critical bulletins dealt with issues affecting Windows Media Runtime, Windows Media Player, Internet Explorer, ActiveX Kill bits, Windows GDI+, the Microsoft .NET Framework and Microsoft Silverlight.

Beyond the FTP bulletin, four others were also rated important, and touched on the Windows CryptoAPI, Indexing Service, the local authority subsystem service and the Windows kernel.

Microsoft also used the opportunity to re-release MS 08-069, which dealt with a vulnerability in Microsoft XML Core Services.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

View Comments

Recent Posts

Boeing Starliner Set For First Crewed Flight After Delays

Boeing Starliner space capsule set for first crewed flight into orbit after years of delays,…

10 hours ago

Google, DOJ Closing Arguments Clash Over Search ‘Monopoly’

Google clashes with US Justice Department in closing arguments as government argues Google used illegal…

18 hours ago

Stanford AI Scientist Working On ‘Spatial Intelligence’ Start-Up

Prominent Stanford University AI scientist Fei-Fei Li reportedly completes funding round for start-up based on…

19 hours ago

Apple Shares Surge Ahead Of New AI Hardware Launches

Apple shares surge on optimism that new AI-focused hardware launches will drive renewed sales, starting…

19 hours ago

Biden Vetoes Republican Measure In Row Over Contractors’ Unions

Biden vetoes Republican-backed measure amidst dispute over 'joint employer' status for contract workers, affecting tech…

20 hours ago

Lawyers Say Strict Child Controls In China Show TikTok Could Do Better

Lawyers in US social media addiction action say strict controls on Douyin in China show…

20 hours ago