Microsoft to patch critical Windows, Office flaws

By Dawn Kawamoto, CNET News.com
Friday, October 06, 2006 09:48 AM

Microsoft plans to issue nearly a dozen security patches on Tuesday, including critical fixes for Windows and Office.

The company will release six updates for the operating system and four for the office suite, according an advance notice sent out Thursday by the software giant. Some of the patches will be deemed "critical," the company's highest severity rating. The company also plans to send out a security bulletin for Microsoft .Net that will be tagged moderate, it said.

The updates, part of Microsoft's regularly scheduled monthly patch cycle, come after sample attack code has surfaced for vulnerabilities in the Windows Shell component of the operating system. Those flaws could enable attackers to use a Web site to load malicious software onto systems.

The past few weeks have seen the arrival of third-party patches for the Windows Shell problem. The Zeroday Emergency Response Team, or ZERT, delivered its own fix, aiming to help people protect their PCs until Microsoft issued an official update. In addition, security company Determina provided an outside patch for the same issue.

Microsoft has said it will provide a patch for the Windows Shell vulnerability in its October bunch of bulletins. It is expected to announce more details regarding the flaws once the patches are released next week.

In September, the company delivered a critical fix for Office, one of three security bulletins in that monthly patch cycle.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web