You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft patches 20 holes - none affecting Vista

Security dozen tackles 'zero-day' backlog...

Tags: microsoft, patch tuesday, vista, patch

By Joris Evers

Published: 14 February 2007 09:15 GMT

Microsoft has released fixes for 20 vulnerabilities in a variety of products including Windows but none of the operating system flaws affect Vista.

The fixes arrived in a dozen security bulletins, released as part of Microsoft's monthly patch cycle. Six of the alerts were tagged "critical", the company's most serious rating. These flaws could enable an attacker to gain complete control over a vulnerable computer with no action, or minor action, on the part of the user, Microsoft warned.

The critical vulnerabilities are in Windows, Internet Explorer, Office and in Microsoft security tools such as Windows Live OneCare and Windows Defender. None of the Windows or Office flaws affect Vista or Office 2007, Microsoft's latest updates. However, Windows Defender ships as part of Vista, so the new operating system is at risk from that direction.

Microsoft used its February patch day to clear a backlog of "zero-day" flaws, or security holes that have been publicly disclosed but not fixed. Seven of the 20 vulnerabilities addressed by Tuesday's bulletins were zero-days, and five of those were in Office applications. Microsoft planned to issue patches for the Office zero-day bugs last month but postponed their delivery.

Most of the Patch Tuesday flaws are only potentially harmful if people with vulnerable PCs visit a malicious website or open an infected document. For example, the Microsoft security tools could be compromised when they scan a rigged PDF file, according to the company's advisory.

The updates will be pushed out to Windows PCs that have enabled Automatic Updates. They are also available for manual download from Microsoft's website.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Penetration Testing Consultant - UK Wide

Use of a variety of network security testing tools and exploits to identify vulnerabilities and recommend corrective action ? Penetration Testing ...

Business Systems Platform Support Engineer

Understanding of user service provision Design and documentation of projects Ability to produce and maintain high quality documentation Behaviours ...

Windows Engineer GALWAY

Proven expertise in Windows Kernel Mode Device Drivers under Windows NT/2K/2K3/XP, along with experience developing Windows Kernel Mode Device ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: