Feeds

Worm fears over MS October patch batch

Nine patches - three critical - in latest monthly update

Beginner's guide to SSL certificates

Microsoft's patch train rolled into town on Tuesday carrying a cargo of nine updates. Three of the October batch fix critical vulnerabilities involving Windows, Internet Explorer, and Windows Media Player, Microsoft warned. Four of the patches address important flaws and two deal with moderate security bugs. Microsoft pulled plans to issue a patch last month so it doesn't come as much surprise that there's a bumper load this month.

Worst of the critical vulnerabilities is a flaw in the MSDTC and COM+ middleware components of Windows which might allow remote code execution (MS05-051.mspx). Both Windows 2000 and Win XP systems - even those running Service Pack 2 - are potentially at risk from the vulnerability, which security firm eEye warns is ripe for exploitation by an internet worm. A cumulative update to IE (MS05-052.mspx) and a fix to DirectShow (MS05-050.mspx), software in Windows which processes streaming media, are also deemed critical.

The four important fixes protect against flaws in Client Services for Netware, Microsoft Collaboration Objects, Windows PnP (Plug and Play) and Windows Shell. Windows's FTP client and Network connection manager are the subject of moderate flaws. Microsoft's overview of these various security vulns is here. ®

Beginner's guide to SSL certificates

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.