Categories: SecurityWorkspace

Microsoft Issues 13 Bulletins In Hefty Patch Tuesday Release

This month’s Patch Tuesday is a fairly sizeable one, with 13 bulletins covering 47 vulnerabilities.

Microsoft pulled a vulnerability related to a  .Net issue, but a host of flaws remained in yesterday’s release, covering Windows, Office, Internet Explorer and SharePoint.

Four of the Patch Tuesday bulletins were ranked as critical, nine as important. Microsoft has singled out three flaws it believes should take priority.

Busy Patch Tuesday

The first is one that resides in Outlook and could be exploited to let a hacker execute code remotely.

“This privately reported issue could allow remote code execution if an email carrying a specially crafted S/MIME certificate is viewed or previewed on an affected system,” Microsoft said in a blog post.

“Creating S/MIME certificates is trivial, but creating the specific one in the precise manner needed to execute code will be difficult. Still, the possibility is there and that is why we listed this update as our highest priority for this month.”

The MS13-069 bulletin is also key, fixing 10 issues in all supported versions of Internet Explorer, which could be exploited if a user is directed to a specially-crafted malicious website.

There are 10 issues in SharePoint Servers too, allowing for remote code execution. To exploit them, an attacker could send specially-crafted content to an affected server, which would fail to properly validate the input and potentially let the hacker execute code on the server.

“The top three criticals should take priority this month but don’t forget about the balance of importants. It’s possible that a string of importants could be chained together and, with an escalation of privilege, you would have a big problem,” warned Paul Henry, security and forensics analyst at Lumension.

“Total Microsoft patches to-date for 2013 now sit at 79. This is well ahead of the 63 patches released through September, 2012.”

How much do you know about information security? Try our quiz and find out!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

9 hours ago

Former Policy Boss At X Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

11 hours ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

13 hours ago

FTX Co-Founder Gary Wang Spared Prison

Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…

14 hours ago