News

Microsoft to Release 'Critical' Fixes for .NET Framework, Silverlight and IE

The fixes are part of an eight-release "Patch Tuesday" event next week.

A security vulnerability in the .NET Framework and Silverlight that Microsoft rates as "critical" will be patched next Tuesday.

Microsoft released information on eight patches in its advanced notification of the October monthly security bulletin.

There are two "critical" and six "important" items covering a range of products including Microsoft .NET Windows, Internet Explorer, Forefront and Microsoft Host Integration Server.

Remote code execution dominates the risk profile for all but two of the items on the patch slate. The remaining two are denial-of-service and elevation-of-privilege considerations.

The first critical bulletin affects the .NET Framework and Silverlight. Marcus Carey, a security researcher at Rapid7, says that this patch, along with all critical items, needs to be examined closely.

"This bulletin looks very close to MS11-039, which was patched in August. When exploit developers look for bugs disclosed in products, they usually find similar bugs which result in the same type of vulnerabilities," he said.

As for the other, an often-patched Internet Explorer once again will be receiving a fix.

Speaking on the Internet Explorer item, Carey said attackers will continue to get users to click on links to malicious Web sites. He says to expect the attackers to continue to explore these browsers and plug-in weaknesses, which have been the bane of Microsoft's browser for some time.

Paul Henry, security and forensic analyst for Lumension, called October's predicted batch of fixes a "trick and treat" patch.

The Treat is that there are less critical items and more Windows fixes, he said. The trick is in the operational challenges of rebooting systems. "Nearly all require a restart, which will cause widespread disruptions across both Internet-connected servers and user community desktops."

Consult Microsoft Knowledge Base Article 894199 for more information.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • AI for GitHub Collaboration? Maybe Not So Much

    No doubt GitHub Copilot has been a boon for developers, but AI might not be the best tool for collaboration, according to developers weighing in on a recent social media post from the GitHub team.

  • Visual Studio 2022 Getting VS Code 'Command Palette' Equivalent

    As any Visual Studio Code user knows, the editor's command palette is a powerful tool for getting things done quickly, without having to navigate through menus and dialogs. Now, we learn how an equivalent is coming for Microsoft's flagship Visual Studio IDE, invoked by the same familiar Ctrl+Shift+P keyboard shortcut.

  • .NET 9 Preview 3: 'I've Been Waiting 9 Years for This API!'

    Microsoft's third preview of .NET 9 sees a lot of minor tweaks and fixes with no earth-shaking new functionality, but little things can be important to individual developers.

  • Data Anomaly Detection Using a Neural Autoencoder with C#

    Dr. James McCaffrey of Microsoft Research tackles the process of examining a set of source data to find data items that are different in some way from the majority of the source items.

  • What's New for Python, Java in Visual Studio Code

    Microsoft announced March 2024 updates to its Python and Java extensions for Visual Studio Code, the open source-based, cross-platform code editor that has repeatedly been named the No. 1 tool in major development surveys.

Subscribe on YouTube