Microsoft has issued its 14 August Patch Tuesday update that includes nine security bulletins, five of them critical.
Meanwhile Adobe issued patches for various versions of Reader and Acrobat for both Microsoft Windows and Apple Macintosh operating systems.
The Microsoft patches start with Internet Explorer, mostly IE6, 7 and 8, but also the current version, IE9. Microsoft continually advises users to update to the latest version of the Web browser, which is the most secure.
Another set of patches applies to the Windows OS, including “critical” ones for Windows Server 2003 and Windows XP, another labelled “important” for Windows Server 2003 and several packages labeled “moderate” for such versions as Windows 7, Windows Server 2008 R2, Windows Server 2008 and Windows Vista. Microsoft also introduced new patches that supersede earlier patches for the same systems.
Marcus Carey, a security researcher at Rapid7, provides some guidance on how to prioritise the patches. Carey says the IE patches, detailed in bulletin MS12-052, “should be No. 1 on organisations’ and consumers’ ‘must patch’ list.”
The second priority should be MS12-058, he said, which protects an Exchange Server vulnerability. “It appears to be an excellent option for spear-phishing attempts since it can compromise the server simply by a legitimate user opening a malicious document using Outlook Web App,” Carey notes. This fix addresses a vulnerability that was introduced by Oracle Outside In, which is used as part of Exchange.
Other priorities, he said, are bulletins MS12-053 affecting a Remote Desktop Protocol vulnerability, MS12-054 relating to Windows Network Components and MS12-060, which involves controls affecting Office and SQL Server.
The Adobe patches target the Adobe Reader for viewing documents created in the portable document format (PDF) and Adobe Acrobat, for creating PDFs.
Specifically, the patches are to fix “vulnerabilities in the software that could cause the application to crash and potentially allow an attacker to take control of the affected system.”
The highest-priority patches are for Adobe Reader and Acrobat users on versions 9.52 of each to upgrade to versions X (10.1.4) of the applications.
Of less urgency, though still important, is for users of Adobe and Acrobat X (10.1.3) running on either Windows or Macintosh machines to upgrade to (10.1.4). Users of Adobe and Acrobat versions 9.5.1 or earlier on either Windows or Macs, who cannot upgrade to 10.1.4, should upgrade to 9.5.2.
Are you a security expert? Try our quiz!
CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation
Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…
Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…