
Just another Patchy Tuesday...
By Joris Evers
Published: 10 November 2006 09:00 GMT
Microsoft plans to issue six security bulletins on Tuesday, including at least one with a fix for a security vulnerability that is actively being used in cyber attacks.
As part of its monthly patching cycle, Microsoft will release a bulletin with a "critical" fix for a security hole in its XML Core Services software, the company said in a note on its website. The vulnerability is a so-called zero-day flaw that's already being exploited for attacks.
The other five security bulletins will deliver updates for Windows, some of which will be rated "critical", Microsoft said. Security companies are tracking several flaws in the operating system and in its web browser component, Internet Explorer, that have yet to be put right.
Got two seconds?
Make your voice heard - take our latest poll.
Microsoft did not specify how many vulnerabilities in total its security updates will tackle, or say which components of Windows are being repaired. Additionally, the company appears to have no patch ready for a flaw in Visual Studio 2005, which is also already being used in attacks.
Last month, the software maker delivered 10 security bulletins, six of which were deemed "critical", the company's most serious risk rating. Critical vulnerabilities typically can allow a worm to spread or allow a Windows system to be fully compromised with minor or no interaction from the person using it.
Also on Tuesday, Microsoft will release an updated version of its Windows Malicious Software Removal Tool. The program detects and removes common malicious code placed on computers.
The software behemoth gave no further information on the upcoming bulletins, other than stating the fixes may require restarting the computer or server.
Joris Evers writes for CNET News.com
Microsoft fixes faulty IE patch
Alert over "extremely critical" Word flaw
"Critical" Office update on the way
Attack code alert over unpatched IE flaw
Security group issues emergency IE patch
Redmond working "non-stop" on IE patch
Attackers 'making hay with Windows flaw'
Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...
Ability to perform SQL queries Watir Automation tool Knowledge of Cross Browser issues Experience of configuration management tools Any exposure to ...
This exclusive C++ client designs and manufactures portable digital ultrasonic flaw detectors and are in need of an C++ engineer due to expansion and ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Maximizing Revenues in Troubled Times: Proven Methods of Extracting Water From a...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Service Management Companies: Will You Grow With or Outgrow QuickBooks?
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?