YOUR IT - Technology for you

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Another month, another 19 Microsoft flaws patched

Your IT - Home IT

Anyone who was still living under the illusion that the arrival of Windows Vista would mean a lessening of security holes for Microsoft to patch would have had rude awakening this month. Microsoft announced no less than 19 newly discovered flaws in its software, of which 15 are classed as critical.

The 15 critical vulnerabilities, classed as such because they could allow remote code execution if exploited, cover pretty much the gamut of Microsoft's most widely used software products, including Windows, Office, Excel, Word and Internet Explorer

Microsoft has issued seven security bulletins and associated patches covering the 19 vulnerabilities and the large number has prompted some outpourings of consternation from sectors of the security community.

"Of particular concern is the large number of Microsoft Office, Word, Excel and Internet Explorer vulnerabilities being patched today," said Dave Marcus, security research and communications manager, McAfee Avert Labs. "These applications are the most frequently targeted applications by malware writers, so we recommend that all customers evaluate their security coverage and policies to insure they have adequate protection in place."

Microsoft should be able to take some heart, however, that vulnerabilities in Vista itself have not arisen this month. However, flaws in both Office 2007 and Internet Explorer 7 have surfaced.

An overview of the Microsoft vulnerabilities is as follows:

  * MS07-023 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
  * MS07-024 - Vulnerabilities in Microsoft Word Could Allow Remote Code Execution
  * MS07-025 - Vulnerability in Microsoft Office Could Allow Remote Code Execution
  * MS07-026 - Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution
  * MS07-027 - Cumulative Security Update for Internet Explorer
  * MS07-028 - Vulnerability in CAPICOM Could Allow Remote Code Execution
  * MS07-029 - Vulnerability in Windows DNS RPC Interface Could Allow Remote Code Execution

It looks like the Patch Tuesday cycle is with us for the foreseeable future.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more