Feeds

Every single Internet Explorer at risk of drive-by hacks until Patch Tuesday

FIFTY-SEVEN gaping holes closed this month

Intelligent flash storage arrays

Microsoft has lined up a bumper Patch Tuesday this month to snap shut a backbreaking 57 security vulnerabilities in its products.

Five of the 12 software updates addressing the gaping holes will tackle critical flaws that allow miscreants to execute code remotely on vulnerable systems.

In all, the soon-to-be-patched vulnerabilities exist in the Windows operating system, Internet Explorer web browser, Microsoft Server Software, Microsoft Office and the .NET framework.

The Redmond giant normally bundles together fixes for Internet Explorer bugs into a single monthly update, but February's Patch Tuesday release will feature two bulletins both addressing critical IE vulnerabilities. All versions of IE from 6 to 10, including the ARM port running on Windows RT on the Surface tablet, will need patching.

A third critical update addresses a flaw in Windows XP, 2003 and Vista but not later versions of Microsoft's PC operating system. The fourth critical update covers Microsoft Exchange, which uses the vulnerable Outside In software library from Oracle. The fifth critical vulnerability only affects Windows XP.

The remaining seven bulletins are all rated as important and mostly allow logged-in users to elevate their privileges, with the exception of a Sharepoint-related update that is susceptible to code-injection attacks.

More details, as usual, will follow next week once the patches are published. Microsoft's pre-release alert is here. Further commentary by Qualys can be found here. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.