News

Six Security Fixes Expected on Patch Tuesday

On Tuesday, Microsoft is planning to roll out six fixes -- three "critical" and three "important" -- in its July security update.

The security issues expected to be addressed in this patch include four remote code execution (RCE) vulnerabilities and two elevation-of-privilege considerations. Affected programs range from Windows operating system components, to servers, to a fix for Microsoft Publisher.

"This is a critical month for Microsoft with published bug reports and attack code in the wild," noted Andrew Storms, director of security at nCircle.

Critical Patches
Critical patch No. 1 will be designed to stave off RCE exploits for all supported Windows OS versions.

The second critical item will be aimed at patching the DirectX multimedia control solution, a favorite complaint of security gadflies. This patch will affect DirectX versions 7.0, 8.1 and 9.0 running on systems using Windows XP, Windows 2000 and Windows Server 2003.

Microsoft has issued other security advisories about ActiveX in recent times. In May, Microsoft began an investigation of a DirectX bug in its DirectShow framework for multimedia files. In June, the company announced it was investigating a potential DirectX bug in Internet Explorer.

The final critical patch will be a Windows OS fix addressing RCE exploits. It's considered "critical" for Windows XP but "moderate" for Windows Server 2003.

Important Patches
First on the "important" list will be a virtualization fix -- something to be seen more often, perhaps. It will be a patch to stop potential elevation-of-privilege attacks in Microsoft Virtual PC 2004 and Microsoft Virtual PC 2007 editions, as well as Microsoft Virtual Server 2005 R2 and Virtual Server 2005 R2 x64.

The next important patch will address Microsoft Internet Security and Acceleration Server 2006. ISA Server provides application-layer firewalling and protects Web servers. The server is being rolled up into Microsoft Forefront Threat Management Gateway, which Redmond calls a "comprehensive secure Web gateway solution" protecting client-side users from Web-based threats.

The third important item deals with 2007 Microsoft Office System Service Pack 1 in general, and Microsoft Office Publisher 2007 Service Pack 1 in particular. It is the rollout's fourth RCE exploit fix.

Depending on which components are included in Tuesday's announcement, July looks to be a reasonably busy month for IT pros. The entire slate of patches may require restarts.

As usual, those interested in nonsecurity updates may want to check out the monthly knowledgebase article. Microsoft has accompanied every security patch release with nonsecurity updates for more than a year now. Those items include a new Malicious Software Removal Tool and spam filter updates. Changes for Vista and Windows Server 2008 are also on tap via Windows Update, Microsoft Update and Windows Server Update Services.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • VS Code v1.99 Is All About Copilot Chat AI, Including Agent Mode

    Agent Mode provides an autonomous editing experience where Copilot plans and executes tasks to fulfill requests. It determines relevant files, applies code changes, suggests terminal commands, and iterates to resolve issues, all while keeping users in control to review and confirm actions.

  • Windows Community Toolkit v8.2 Adds Native AOT Support

    Microsoft shipped Windows Community Toolkit v8.2, an incremental update to the open-source collection of helper functions and other resources designed to simplify the development of Windows applications. The main new feature is support for native ahead-of-time (AOT) compilation.

  • New 'Visual Studio Hub' 1-Stop-Shop for GitHub Copilot Resources, More

    Unsurprisingly, GitHub Copilot resources are front-and-center in Microsoft's new Visual Studio Hub, a one-stop-shop for all things concerning your favorite IDE.

  • Mastering Blazor Authentication and Authorization

    At the Visual Studio Live! @ Microsoft HQ developer conference set for August, Rockford Lhotka will explain the ins and outs of authentication across Blazor Server, WebAssembly, and .NET MAUI Hybrid apps, and show how to use identity and claims to customize application behavior through fine-grained authorization.

  • Linear Support Vector Regression from Scratch Using C# with Evolutionary Training

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of the linear support vector regression (linear SVR) technique, where the goal is to predict a single numeric value. A linear SVR model uses an unusual error/loss function and cannot be trained using standard simple techniques, and so evolutionary optimization training is used.

Subscribe on YouTube