Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Of the eight bulletins, five have been deemed 'critical', the highest of the company's security alert levels. If exploited, each could allow an attacker to remotely execute code on a targeted system.
Among the fixes is a bulletin to address a pair of flaws in Excel, both of which are being actively targeted by cyber criminals to perform attacks in the wild.
Microsoft noted that the 'critical' rating applies only to Office 2000 users, as later versions of the software will notify users before a potential attack file is launched.
Other critical fixes include updates to address flaws in Office, DirectX, Internet Explorer and the Windows HTTP Services component.
Additionally, Microsoft issued a fix for ISA Server and Forefront Threat Management gateway, along with a patch to prevent 'token kidnapping' attacks. Each of those bulletins are rated as 'important'.
The final bulletin was rated as 'moderate' and addresses a vulnerability in the SearchPath which could be targeted along with unpatched copies of the Safari browser to perform a 'blended threat' attack. That bulletin is being listed as a 'moderate' threat.
Because many of the flaws are previously unknown or are already being targeted, they could be especially dangerous, warned McAfee Avert Labs senior director of research and communications Dave Marcus.
"While the world is still reeling from Conficker, Microsoft today released its largest batch of security updates this year, including urgent fixes for vulnerabilities that are already being exploited," said Marcus. "This won’t be easy for many security professionals, especially in larger enterprises."
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.