Technology news and Jobs arrow Information Technology News arrow Another month, another 19 Microsoft flaws patched
Another month, another 19 Microsoft flaws patched E-mail
by Stan Beer   
Wednesday, 09 May 2007
Anyone who was still living under the illusion that the arrival of Windows Vista would mean a lessening of security holes for Microsoft to patch would have had rude awakening this month. Microsoft announced no less than 19 newly discovered flaws in its software, of which 15 are classed as critical.

The 15 critical vulnerabilities, classed as such because they could allow remote code execution if exploited, cover pretty much the gamut of Microsoft's most widely used software products, including Windows, Office, Excel, Word and Internet Explorer

Microsoft has issued seven security bulletins and associated patches covering the 19 vulnerabilities and the large number has prompted some outpourings of consternation from sectors of the security community.

"Of particular concern is the large number of Microsoft Office, Word, Excel and Internet Explorer vulnerabilities being patched today," said Dave Marcus, security research and communications manager, McAfee Avert Labs. "These applications are the most frequently targeted applications by malware writers, so we recommend that all customers evaluate their security coverage and policies to insure they have adequate protection in place."

Microsoft should be able to take some heart, however, that vulnerabilities in Vista itself have not arisen this month. However, flaws in both Office 2007 and Internet Explorer 7 have surfaced.

An overview of the Microsoft vulnerabilities is as follows:

  * MS07-023 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
  * MS07-024 - Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
  * MS07-025 - Vulnerability in Microsoft Office Could Allow Remote Code Execution
  * MS07-026 - Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution
  * MS07-027 - Cumulative Security Update for Internet Explorer
  * MS07-028 - Vulnerability in CAPICOM Could Allow Remote Code Execution
  * MS07-029 - Vulnerability in Windows DNS RPC Interface Could Allow Remote Code Execution

It looks like the Patch Tuesday cycle is with us for the foreseeable future.{moscomment}

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter