
But zero-day Word bugs remain freely exploitable...
By Joris Evers
Published: 13 December 2006 12:00 GMT
Microsoft on Tuesday released seven security updates with patches for 11 security vulnerabilities, most of which affect the Windows operating system.
The software maker originally planned to release only six security bulletins as part of its monthly patch cycle. However, it added a seventh to deliver a fix for two flaws that affect the Windows Media Format, including one zero-day bug, a company representative said.
Microsoft also provided a patch for a zero-day vulnerability that affects Visual Studio 2005 developer tools. This security hole was disclosed last month and, contrary to the Windows Media issue, has already been used in cyber attacks, the company said.
However, there were no fixes Tuesday for a pair of known flaws in Microsoft Word that are also being exploited in malicious software.
Amol Sarwate, a research manager at vulnerability management company Qualys, said: "While we see Microsoft making an attempt to patch zero-day vulnerabilities, they are still struggling to keep up with the continuous influx of zero-day attacks. Microsoft is making a genuine effort. However, users are still exposed to attacks via the unpatched Word vulnerabilities."
The Windows Media issues are addressed in bulletin MS06-078, one of three "critical" security updates published by Microsoft on this 'Patch Tuesday'. The other high-risk vulnerabilities lie in Internet Explorer and in Visual Studio 2005.
Joris Evers writes for CNET News.com.
Senior Software Engineers - C++ using Microsoft Visual Studio and MFC. Key technical skills will include strong skills in C++ using Microsoft Visual ...
C#, .NET 2.0, ASP.NET, Visual Studio, Web Services, XML & SQL Server 2005 My client requires a software developer who has strong skills in C#, .NET ...
Key: C#.NET Visual Studio N-unit T-SQL HTML HTML. They are looking for Software developers who have been working with the .NET Framework C#, T-SQL, ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...