Feeds

Windows Help update stars in MS Patch Tuesday

3 critical, 1 important address 2 zero-days

Remote control for virtualized desktops

Microsoft plans to fix a Windows Help and Support Center vulnerability as part of next week's Patch Tuesday update batch.

The flaw, which has been the target of hacking attacks over recent weeks, was disclosed to Microsoft's displeasure by Google engineer Tavis Ormandy last month, in a move to renew the age old debate about responsible disclosure of security flaws.

The critical Windows Help fix is one of a planned release of four updates, three of which earn Microsoft's most severe security rating. A second critical update covers a zero-day flaw in the AERO display driver component of Windows 7 and Windows Server 2008 R2, which was first publicised back in May.

The two other bulletins - one ranked critical and the other important - cover security vulnerabilities in Microsoft Office.

Wolfgang Kandek, CTO at Qualys, notes that July marks an important milestone in Microsoft security support, with the termination of patches and updates for Windows XP SP2 and Windows 2000.

"Windows XP SP2 users are advised to upgrade to SP3, which will be supported throughout 2014," Kandek said. "Windows 2000 users need to upgrade to a different version of the operating system altogether, as the entire Windows 2000 line is discontinued."

Microsoft's pre-alert notice can be found here. ®

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.