The Register® — Biting the hand that feeds IT

Feeds

Microsoft readies seven patches for Tuesday

Three are critical

Agentless Backup is Not a Myth

Microsoft plans to issue seven security patches next Tuesday, three of which are rated "critical" because they could allow an attacker to remotely execute malicious code on an end user's machine.

Two of the critical updates plug holes in the entire line of supported Windows operating system versions. The patches address components including DirectX, DirectShow and Windows Media Format Runtime. The third critical fix is for versions 6 and 7 of the Internet Explorer browser.

In all, five updates fix vulnerabilities in Vista, which was designed from scratch to be Microsoft's most secure OS.

The details were made available through Microsoft's Security Bulletin Advance Notification, which is released five days prior to Microsoft's regularly scheduled patch release, which occurs on the second Tuesday of every month.

Four patches carry a maximum rating of "important". They address security flaws in a wide range of Windows versions, including Vista.

Microsoft released only limited details of the vulnerabilities. It's a safe bet that one of the patches will include a fix for a flaw in the SafeDisc copy protection software from Macrovision, which comes bundled with Windows XP and 2003 and was <a href="a flaw in the SafeDisc copy protection software from Macrovision that comes bundled with Windows XP and 2003 and was missing in action from last month's Patch Tuesday.

It's possible another fix will involve a vulnerability in a Windows feature known as Web Proxy Autodiscovery (WPAD), which helps IT administrators automate the configuration of proxy settings. Reports of the bug first surfaced 10 days ago, and on Monday Microsoft confirmed it was investigating them.

Several of the updates will require a reboot. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

Microsoft's most secure OS...

... yeh, like cadbury's least fattening chocolate.

... or Paris' cleanest underwear.

How shallow is the ocean, how low is the sky?

0
0

More Malware from M$

MMM... Soon, I will have 80 PCs running GNU/Linux. When I have eliminated all of that other OS on my LAN the party will be at my place. You are all invited. Seriously, the few machines running that other OS cost me more hours every week than the 30 I now have running GNU/Linux because GNU/Linux is modular and configurable. I can fix something and it stays fixed, with few unintended consequences and no re-re-re-boots. The last XP machine I fixed took 2 re-installs (was owned before the first updates...) of 30 minutes and then updating for hours with many re-re-re-boots. The crashing that prompted the re-installation is still there... Another ME machine had no driver for a printer and M$'s license giving permission to install that driver had expired, so I installed Debian GNU/Linux and it worked smoothly. That liberation took 20 minutes, a bit of configuration and a reboot to make sure it survived a reboot. Why do people put up with that other OS in a production setting? Must be for the jobs it creates...

0
0

Actually 27 patches

We just bundled of the them and make six Bundles!

http://fakesteveballmer.blogspot.com

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?