
Microsoft to Release 'Critical' Fixes for .NET Framework, Silverlight and IE

The fixes are part of an eight-release "Patch Tuesday" event next week.

A security vulnerability in the .NET Framework and Silverlight that Microsoft rates as "critical" will be patched next Tuesday.

Microsoft released information on eight patches in its advanced notification of the October monthly security bulletin.

There are two "critical" and six "important" items covering a range of products including Microsoft .NET Windows, Internet Explorer, Forefront and Microsoft Host Integration Server.

Remote code execution dominates the risk profile for all but two of the items on the patch slate. The remaining two are denial-of-service and elevation-of-privilege considerations.

The first critical bulletin affects the .NET Framework and Silverlight. Marcus Carey, a security researcher at Rapid7, says that this patch, along with all critical items, needs to be examined closely.

"This bulletin looks very close to MS11-039, which was patched in August. When exploit developers look for bugs disclosed in products, they usually find similar bugs which result in the same type of vulnerabilities," he said.

As for the other, an often-patched Internet Explorer once again will be receiving a fix.

Speaking on the Internet Explorer item, Carey said attackers will continue to get users to click on links to malicious Web sites. He says to expect the attackers to continue to explore these browsers and plug-in weaknesses, which have been the bane of Microsoft's browser for some time.

Paul Henry, security and forensic analyst for Lumension, called October's predicted batch of fixes a "trick and treat" patch.

The Treat is that there are less critical items and more Windows fixes, he said. The trick is in the operational challenges of rebooting systems. "Nearly all require a restart, which will cause widespread disruptions across both Internet-connected servers and user community desktops."

Consult Microsoft Knowledge Base Article 894199 for more information.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus


  • Lessons Learned Building a GenAI-Powered App

    Sometimes, complex technical achievements are best explained through one example. That's the approach Mete Atamel, Developer Advocate at Google, is taking as he makes the rounds detailing the capabilities of Vertex AI and associated tooling on the Google Cloud Platform.

  • 30th Annual Visual Studio Magazine Reader's Choice Awards Announced

    For the 30th year in a row, Visual Studio Magazine readers have chosen the best tools and services for developers. The 2024 winners are honored in 43 categories, from component suites to testing tools to AI helpers.

  • Another Report Weighs In on GitHub Copilot Dev Productivity: 👎

    Several reports have answered "yes" to the question of whether GitHub Copilot improves developer productivity. A new one says "no."

  • Logistic Regression with Batch SGD Training and Weight Decay Using C#

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end program that explains how to perform binary classification (predicting a variable with two possible discrete values) using logistic regression, where the prediction model is trained using batch stochastic gradient descent with weight decay.

Subscribe on YouTube