You are here: silicon.com > Software > Security Strategy

Security Strategy

Three dire Windows holes patched

But zero-day Word bugs remain freely exploitable...

Tags: windows, flaws, patches

By Joris Evers

Published: 13 December 2006 12:00 GMT

Microsoft on Tuesday released seven security updates with patches for 11 security vulnerabilities, most of which affect the Windows operating system.

The software maker originally planned to release only six security bulletins as part of its monthly patch cycle. However, it added a seventh to deliver a fix for two flaws that affect the Windows Media Format, including one zero-day bug, a company representative said.

Microsoft also provided a patch for a zero-day vulnerability that affects Visual Studio 2005 developer tools. This security hole was disclosed last month and, contrary to the Windows Media issue, has already been used in cyber attacks, the company said.

However, there were no fixes Tuesday for a pair of known flaws in Microsoft Word that are also being exploited in malicious software.

Amol Sarwate, a research manager at vulnerability management company Qualys, said: "While we see Microsoft making an attempt to patch zero-day vulnerabilities, they are still struggling to keep up with the continuous influx of zero-day attacks. Microsoft is making a genuine effort. However, users are still exposed to attacks via the unpatched Word vulnerabilities."

The Windows Media issues are addressed in bulletin MS06-078, one of three "critical" security updates published by Microsoft on this 'Patch Tuesday'. The other high-risk vulnerabilities lie in Internet Explorer and in Visual Studio 2005.

Joris Evers writes for CNET News.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
.NET Software Developer, Bedford, 30-40k; C#, Visual Studio, SQL

The successful .NET Developer will have excellent communication, presentation and client facing skills with 2+ years commercial experience in ...

Senior C# Visual Studio.NET Developer - Lichfield, West Mids

Senior C# Visual Studio.NET Developer required for Lichfield based software house. The successful candidate will be educated to degree level and have ...

ASP.Net Web Developer C# / Visual Studio, Milton Keynes To 26K

Websites in ASP/C#.Net with Visual Studio. My client is looking for a talented technically minded ASP / C#.Net Software Engineer. This is a permanent ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: