Feeds

Worm fears over MS October patch batch

Nine patches - three critical - in latest monthly update

Beginner's guide to SSL certificates

Microsoft's patch train rolled into town on Tuesday carrying a cargo of nine updates. Three of the October batch fix critical vulnerabilities involving Windows, Internet Explorer, and Windows Media Player, Microsoft warned. Four of the patches address important flaws and two deal with moderate security bugs. Microsoft pulled plans to issue a patch last month so it doesn't come as much surprise that there's a bumper load this month.

Worst of the critical vulnerabilities is a flaw in the MSDTC and COM+ middleware components of Windows which might allow remote code execution (MS05-051.mspx). Both Windows 2000 and Win XP systems - even those running Service Pack 2 - are potentially at risk from the vulnerability, which security firm eEye warns is ripe for exploitation by an internet worm. A cumulative update to IE (MS05-052.mspx) and a fix to DirectShow (MS05-050.mspx), software in Windows which processes streaming media, are also deemed critical.

The four important fixes protect against flaws in Client Services for Netware, Microsoft Collaboration Objects, Windows PnP (Plug and Play) and Windows Shell. Windows's FTP client and Network connection manager are the subject of moderate flaws. Microsoft's overview of these various security vulns is here. ®

Remote control for virtualized desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.