Patch Tuesday Lands With Critical Internet Explorer Fix

Today is the fourth Patch Tuesday of 2013 and Microsoft has delivered a small yet important batch of updates, including some for all supported versions of Internet Explorer.

Two of the patches are ranked critical, the other seven as important. The IE fix is for all supported version of Windows, from XP onwards, and for all versions of Internet Explorer from 6 upwards, including 10 for Windows 8 and RT.

Internet Explorer patch

Wolfgang Kandek, CTO of security firm Qualys, said the IE fix “should be on the top of your patching efforts”.

“It is rated ‘critical’ and allows Remote Code Execution through today’s most common attack vector: one of your users browsing to a malicious website,” Kandek said.

It’s currently unclear whether Microsoft is patching an Internet Explorer flaw discovered by exploit seller VUPEN in the PWN2OWN hacking contest.

One of the important updates is for Windows Defender, Microsoft’s malware scanner, whilst the others are for Windows and the Sharepoint server.

“The vulnerabilities addressed in these bulletins typically allow the attacker Escalation of Privilege from a normal user to an admin level user once they are already on the machine or can trick the user to open a specifically-crafted file.”

IT teams should be busy patching this month. On 16 April, Oracle will release an out-of-band update for Java, following a string of recent vulnerability finds.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

3 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

3 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

3 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago