Menu
Microsoft fixes 46 flaws in Windows, IE, Office, other products

Microsoft fixes 46 flaws in Windows, IE, Office, other products

Companies should prioritize three security bulletins that are rated critical

Fourteen critical vulnerabilities in Internet Explorer were among the targets of Microsoft's monthly batch of security patches released Tuesday. In all, it fixed 46 vulnerabilities across products including Windows, Internet Explorer and Office.

The patches were organized in 13 security bulletins, three flagged as critical and ten as important. The critical bulletins, MS15-043, MS15-044 and MS15-045, cover remote code execution vulnerabilities in Windows, IE, Office, Microsoft .NET Framework, Microsoft Lync and Silverlight.

The priority for administrators should be MS15-043 which fixes 22 vulnerabilities in Internet Explorer, of which 14 are rated critical, said Wolfgang Kandek, the CTO of security firm Qualys, via email. Critical vulnerabilities in IE allow attackers to execute arbitrary code on machines when their users visit malicious Web pages, and attackers have a variety of techniques in their arsenal to achieve this, he said.

However, not all remote code execution vulnerabilities end up being exploited by criminals. Last year, only five percent of such vulnerabilities were targeted in real attacks.

"The difficulty is predicting which 5 percent," Kandek said. "I think it makes sense to look at the past to see what got attacked and what vulnerabilities are covered in exploit packs and prepare accordingly."

Next on the list of priorities should be MS15-044 because it fixes two vulnerabilities in a font parsing library used by many Microsoft products. Attackers could exploit these flaws by embedding a specially crafted font in documents or Web pages.

"Patch quickly, in less than two weeks if you can," Kandek said.

One reason for that is that criminals are quicker than ever to adopt exploits for popular programs, especially reliable ones they can use at scale. But companies should also start to get used to an accelerated patch tempo because Microsoft plans to push out updates for Windows 10 as they're ready instead of on a fixed schedule.

Companies will get the option to delay those updates for some systems by using a new service called Windows Update for Business. However, once a security patch reaches consumer deployments, the vulnerabilities it fixes are essentially revealed.

It's been known for a long time that attackers can reverse engineer patches to figure out where the bugs are and how to exploit them, so companies might not have the luxury of delaying patches for too long.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Microsoftpatch managementqualyspatchesExploits / vulnerabilities

Events

Why experience is the new battleground for partners

Join us for an exclusive webinar, in association with Hewlett Packard Enterprise and Technology Services Industry Association (TSIA) and learn about the latest industry insights and how technology services continue to evolve to deliver differentiated value, and how partners can be successful in 2021 and beyond.

Featured

Slideshows

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards

Hundreds of leaders from the New Zealand IT industry gathered at the Hilton in Auckland on 17 November to celebrate the finest female talent in the Kiwi channel and recognise the winners of the Reseller News Women in ICT Awards (WIICTA) 2020.

The Kiwi channel gathers for the 2020 Reseller News Women in ICT Awards
Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards

Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards

The leading female front runners of the New Zealand ICT industry joined together for the annual Reseller News Women in ICT Awards event at the Hilton in Auckland, during which hundreds of guests celebrated 13 outstanding individuals who won awards, chosen from more than 50 finalists representing over 30 organisations.

Leading female front runners honoured at the 2020 Reseller News Women in ICT Awards
Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

More than 500 channel leaders gathered in Auckland on 21 October at the ​Reseller News Innovation Awards ​2020 to celebrate the achievements of the New Zealand technology industry's top partners, start-ups, vendors, distributors and individuals.

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners
Show Comments