Security Advisor

RCE Fixes Win the Attention of June's Microsoft Patch

Microsoft's June security present arrived yesterday, and, as is now the norm, remote code execution fixes make up four of the seven bulletin items. That's because hackers prefer exploiting your system from a distance over having you look over their shoulders when they invade your home.

The consensus among security experts is that bulletin MS12-037, a "cumulative" security update for Internet Explorer should be taken care of immediately. That's because it takes care of a batch of 12 holes -- some that have already been seen being exploited in the wild. And a Web browser seems like an easier window into your system than, say, waiting for you to fall for an elaborate attack in Photoshop.

Along with this batch of fixes, Microsoft is also changing its policy on how your system identifies bogus Microsoft certificates. And if you guessed this is in response to the Flame malware hiding under fake certificates, you would be 100 percent correct.

The major change is that instead of asking for your permission before updating its certificate black list, it will automatically send the information to your system.

About the Author

Chris Paoli is the site producer for Redmondmag.com and MCPmag.com.

Featured

  • Microsoft Releases Windows 10 Version 1909

    Microsoft on Tuesday announced the release of Windows 10 version 1909, a new operating system product that's also known as the "Windows 10 November 2019 Update."

  • November Microsoft Security Bundle Addresses 75 Vulnerabilities

    Of that number, 13 vulnerabilities are rated "Critical" to patch, while 62 vulnerabilities are deemed "Important."

  • The Future of Office 365 Pricing

    With a raft of new Office 365 features in the pipeline, Microsoft also seems ready to change the way it bills its subscribers. Will it replicate Azure's pay-per-use model, or will it look like something else entirely?

  • Microsoft Offers 1 Year of Free Windows 7 Extended Security Updates to E5 Licensees

    Microsoft is offering one year of free support under its Extended Security Updates program to Windows 7 users if their organizations have E5 licensing.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.