View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
June 13, 2006

Big patch day from Microsoft

Microsoft Corp has released patches for 22 security vulnerabilities, most of which would allow remote code execution if exploited, its largest Patch Tuesday to date.

By CBR Staff Writer

Some of the vulnerabilities would appear to be suitable malware vectors. Windows, Internet Explorer, Office, Media Player and Exchange are affected.

There are 12 patches in total, covering 22 vulnerabilities. Eight of the bulletins and 17 of the vulnerabilities are rated critical by Microsoft.

Critical vulnerabilities mean they would be suitable for exploitation by automated malware, such as a worm.

However, most of the five important vulnerabilities would also allow remote code execution, though not necessarily by a worm.

Chris Andrew, senior security researcher at PatchLink Corp, said MS06-023 is probably the bulletin that will attract the most attention from malicious hackers.

That vulnerability is in the Jscript implementation in Windows. Because it’s in code that executes a scripting language, Andrew said, that will make it easier to exploit.

There are also several vulnerabilities in common Microsoft consumer software that could prove useful for malware writers looking for a file-based attack vector.

Content from our partners
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline
How hackers’ tactics are evolving in an increasingly complex landscape

Word, Windows Media Player and PowerPoint are affected by such vulnerabilities, as are at least two image rendering engines. Look at a picture, get infected.

About 18 separate sets of researchers were involved in finding the vulnerabilities, further evidence, if it were needed, of the growing industry linked to Patch Tuesday.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how New Statesman Media Group may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU