
Security dozen tackles 'zero-day' backlog...
By Joris Evers
Published: 14 February 2007 09:15 GMT
Microsoft has released fixes for 20 vulnerabilities in a variety of products including Windows but none of the operating system flaws affect Vista.
The fixes arrived in a dozen security bulletins, released as part of Microsoft's monthly patch cycle. Six of the alerts were tagged "critical", the company's most serious rating. These flaws could enable an attacker to gain complete control over a vulnerable computer with no action, or minor action, on the part of the user, Microsoft warned.
The critical vulnerabilities are in Windows, Internet Explorer, Office and in Microsoft security tools such as Windows Live OneCare and Windows Defender. None of the Windows or Office flaws affect Vista or Office 2007, Microsoft's latest updates. However, Windows Defender ships as part of Vista, so the new operating system is at risk from that direction.
Microsoft used its February patch day to clear a backlog of "zero-day" flaws, or security holes that have been publicly disclosed but not fixed. Seven of the 20 vulnerabilities addressed by Tuesday's bulletins were zero-days, and five of those were in Office applications. Microsoft planned to issue patches for the Office zero-day bugs last month but postponed their delivery.
Most of the Patch Tuesday flaws are only potentially harmful if people with vulnerable PCs visit a malicious website or open an infected document. For example, the Microsoft security tools could be compromised when they scan a rigged PDF file, according to the company's advisory.
The updates will be pushed out to Windows PCs that have enabled Automatic Updates. They are also available for manual download from Microsoft's website.
Joris Evers writes for CNET News.com
Are you a highly-skilled vista programmer with 4 gl experience? If so, apply now for immediate consideration for a 3 month contract based in ...
A leading services provider in the publishing industry is looking for a Vista Programmer to join their expanding development team. You will be ...
A major Oil and Gas company in the UK are looking for a Win PCS completions technician on a contract basis with a competitive rate of pay. For this ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...
Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?