News

Microsoft Releases 12 Security Bulletins, 8 Critical

Microsoft on Tuesday delivered its promised heavy load of security bulletins, including two patches for critical flaws already in the public domain.

In all, Microsoft put out 12 security bulletins, one less than the company warned subscribers about last week in its Microsoft Security Bulletin Advanced Notification. Those bulletins covered 17 security vulnerabilities. Ten of the security vulnerabilities covered in eight of the bulletins are critical flaws, according to Microsoft's rating system.

Many of the flaws involved various flavors of the Windows operating system, with nine different bulletins addressing problems with Windows. Other Microsoft bulletins addressed problems in Office, Internet Explorer, .NET, Windows Media Player, Windows Messenger, MSN Messenger, Project and Visio.

Flaws in the public domain usually cause the most concern. Most vulnerabilities are secret until Microsoft patches them, giving attackers and users the same starting line in the race on the one hand to exploit the flaws and on the other hand to patch the vulnerabilities.

One of the critical public flaws patched Tuesday affects Windows and could allow remote code execution from a flaw in an ActiveX control. The bulletin, MS05-013, is critical for Windows 2000, Windows 98, Windows 98 Second Edition and Windows ME. It is classified important for Windows XP with Service Pack 2 and moderate for Windows Server 2003.

The other critical public flaw involves a vulnerability in PNG processing that could allow an attacker to take complete control of a user's system over the Internet. It is addressed in bulletin MS05-009, which covers Windows Messenger, MSN Messenger and Windows Media Player.

The bulletin that includes the most patches is MS05-014, a cumulative update for Internet Explorer. The cumulative update includes patches for two critical vulnerabilities, an important vulnerability and a moderate flaw.

To view Microsoft's summary of the month's patches, click here.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.