Categories: PCSecurityWorkspace

Microsoft Patch Tuesday Provides Critical Windows Patch

Microsoft has issued its 14 August Patch Tuesday update that includes nine security bulletins, five of them critical.

Meanwhile Adobe issued patches for various versions of Reader and Acrobat for both Microsoft Windows and Apple Macintosh operating systems.

Microsoft Patches

The Microsoft patches start with Internet Explorer, mostly IE6, 7 and 8, but also the current version, IE9. Microsoft continually advises users to update to the latest version of the Web browser, which is the most secure.

The company says the latest patches address vulnerabilities in IE “that could allow an attacker to compromise a system that is running Microsoft Internet Explorer and gain control over it,” Microsoft stated. One of the fastest-growing threats for computer networks comes from malware delivered through a Web browser, including instances in which companies use software through the browser.

Another set of patches applies to the Windows OS, including “critical” ones for Windows Server 2003 and Windows XP, another labelled “important” for Windows Server 2003 and several packages labeled “moderate” for such versions as Windows 7, Windows Server 2008 R2, Windows Server 2008 and Windows Vista. Microsoft also introduced new patches that supersede earlier patches for the same systems.

Marcus Carey, a security researcher at Rapid7, provides some guidance on how to prioritise the patches. Carey says the IE patches, detailed in bulletin MS12-052, “should be No. 1 on organisations’ and consumers’ ‘must patch’ list.”

The second priority should be MS12-058, he said, which protects an Exchange Server vulnerability. “It appears to be an excellent option for spear-phishing attempts since it can compromise the server simply by a legitimate user opening a malicious document using Outlook Web App,” Carey notes. This fix addresses a vulnerability that was introduced by Oracle Outside In, which is used as part of Exchange.

Other priorities, he said, are bulletins MS12-053 affecting a Remote Desktop Protocol vulnerability, MS12-054 relating to Windows Network Components and MS12-060, which involves controls affecting Office and SQL Server.

Adobe Fixes

The Adobe patches target the Adobe Reader for viewing documents created in the portable document format (PDF) and Adobe Acrobat, for creating PDFs.

Specifically, the patches are to fix “vulnerabilities in the software that could cause the application to crash and potentially allow an attacker to take control of the affected system.”

The highest-priority patches are for Adobe Reader and Acrobat users on versions 9.52 of each to upgrade to versions X (10.1.4) of the applications.

Of less urgency, though still important, is for users of Adobe and Acrobat X (10.1.3) running on either Windows or Macintosh machines to upgrade to (10.1.4). Users of Adobe and Acrobat versions 9.5.1 or earlier on either Windows or Macs, who cannot upgrade to 10.1.4, should upgrade to 9.5.2.

Are you a security expert? Try our quiz!

Robert J Mullins, eWeek USA 2013. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Robert J Mullins, eWeek USA 2013. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Pentagon Adds Tencent, CATL To Military Blacklist

US Defense Department says EV battery maker CATL, tech giant Tencent are suppliers to China's…

5 hours ago

Meta Appoints Trump Friend To Board

Meta Platforms appoints UFC chief Dana White, close friend of Donald Trump, to board as…

6 hours ago

New Orleans Attacker Wore Meta Smart Glasses

Man who drove pickup truck into New Orleans crowd on New Year's Day used Meta…

6 hours ago

Silicon UK In Focus Podcast: Humanware in 2025

Learn how businesses can balance AI with human judgment, address bias, empower employees through training,…

6 hours ago

Apple To Update AI After False Headlines Reported

Apple update to clarify when notification summaries are AI-generated after false headlines reported from BBC,…

7 hours ago

Italy Negotiating 1.5bn Euro Government Comms Deal With Starlink

Italian government in advanced negotiations with SpaceX's Starlink to provide secure government communications via satellite

7 hours ago