Four Microsoft fixes planned for Patch Tuesday

Microsoft is planning four patches -- two rated "critical -- in Tuesday's monthly security update.

Microsoft announced Thursday it plans to push out four fixes -- two rated "critical" -- as part of its monthly security update next week.

The "critical" patches address vulnerabilities in Internet Explorer (IE) and Microsoft Exchange Server, while the fixes labeled "important" involve bugs in SQL Server and Visio, a drawing software product.

The IE issue, though, only is "critical" in Windows XP and Vista, while it is labeled "moderate" in Windows Server 2003 and 2008. The Exchange issue is "critical" for all supported editions: 2000, 2003 and 2007.

Corey Thomas, vice president of product management at vulnerability assessment firm Rapid7, said he would not be surprised if more Exchange vulnerabilities emerge, considering the latest version contains more features, such as calendaring functionality and RSS feeds.

"The more code and the more things that you have turned on that you're actively managing or trying to keep up with...the more configuration issues you have," he said.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read