23 Security Fixes Just Released: Experts Astounded
Microsoft's Patch Tuesday came and went yesterday, bringing 23 fixes for a number of issues with its popular Office programs Excel and Word. At least several of these have been marked critical and most users should certainly consider the download. (Source: theregister.co.uk)
The most critical of the patches fixes an Excel flaw that could potentially allow a hacker to take remote control of an unpatched system. If an unprotected user opens a malicious and specially crafted Excel file, they could find their computer controlled by someone else effectively exploiting something called an Unspecified Remote Code Execution Vulnerability in Excel. Those PC users employing Microsoft Office editions for the years 2002, 2003, and 2007 should apply the fix. Even Mac users online with Microsoft Office 2004 and 2008 are vulnerable, an MS bulletin suggests. (Source: cnet.com)
Remote Code Execution Threatens Office, Explorer
Similar remote execution flaws in WordPad and other Office utilities are also being patched with this most recent download. Word users running 2000 or 2002 editions of the popular word processing tool are most encouraged to update. Given that this is exam time at most universities across North America, it might be a good idea for students to follow the advice.
Windows 2000, XP, XP Professional, and Windows Server 2003 users are also informed that they are vulnerable to a remote attack.
The patch hardly stops there, however.
Microsoft's ubiquitous Internet Explorer browser is also vulnerable to a series of four critical issues, which collectively could lead to a remote code execution. This time the problem isn't linked to a malicious file, but a specially constructed web site that has the potential to attack a server through HTTP. Internet Explorer 5 through 7 are affected.
"We were astonished..." Say Security Experts
Other remote code execution fixes have been included addressing issues in DirectX 8 and 9. A less likely hack for Windows OS versions from 2000 to Vista and Server 2003 and 2008 have also been fixed; although the issue requires a hacker to log onto a system themselves before running a malicious application, it's still worth updating just in case your computer is lost, stolen, or misplaced. (Source: pcmag.com)
Most security experts are startled at the number of threats this patch addresses. "We were astonished to see how many zero-days are in [this past Tuesday's] release," said Wolfgang Kandek, Qualys' CTO. "For the IT guys, that means their window has just shrunk to zero to get these things fixed." (Source: cnet.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.