Microsoft sends security patches, urges fix-it for XML Core Services vulnerability

Jun 14, 2012 by Nancy Owano report

(Phys.org) -- Confirm, warn, patch. Microsoft has had a busy week, this being the week of Patch Tuesday, an event held on the second Tuesday of the month, when Microsoft releases security patches. On this latest Patch event, Microsoft issued seven security bulletins, three of which were termed as critical, warning users of twenty-six vulnerabilities in Microsoft products, a number of them involving Internet Explorer. The patches affect supported Windows versions, the .NET Framework, Remote Desktop, Lync and Dynamics AX. A patch that had been announced for Visual Basic for Applications has yet to be released.

MS12-037, especially, is being discussed as a critical bulletin that addresses 13 vulnerabilities in 6, 7, 8 and 9 that could allow for remote-code execution. Security managers have seen this bulletin as pertinent, as IE is so widely used in homes, businesses and public organizations.

In its IE security update, Microsoft said the most severe vulnerabilities could allow remote code execution if a person uses IE to visit a booby-trapped webpage. The attacker could gain control of the computer with the same user rights as the browser victim. Those especially vulnerable to the exploit are users operating with administrative rights; less so for users whose accounts are configured to have fewer rights.

The security update is rated Critical for IE 6, 7, 8, and 9 on Windows clients. As most customers have enabled automatic updating, the security update will be installed automatically. Customers who have not enabled automatic updating need to install this update manually.

Another advisory in the Patch lineup addresses in Microsoft XML Core Services, again opening the user up to remote code execution. Microsoft said it was still investigating this and plans to issue a solution through its monthly release process or if necessary an out of cycle security update. Meanwhile, Microsoft has issued a “Fix it” solution intended to block the attack vector. Microsoft encourages customers running an affected configuration to apply the Fix it solution as soon as possible. The vulnerability affects all supported versions of Windows and editions of Microsoft Office 2003 and Microsoft Office 2007.

The Microsoft update MS12-036, labeled as Critical, concerns denial of service and remote code execution vulnerabilities in the Remote Desktop features that are built into supported versions of Windows. Microsoft warns that in Remote Desktop allows remote code execution. This is when the attacker sends a sequence of crafted RDP packets to an affected system. Those who do not have the RDP enabled on Windows are not at risk. The update will be installed automatically for users whose systems have automatic updating.

Explore further: Mozilla lab wants scientists to step out of analog age

More information:
technet.microsoft.com/en-us/security/bulletin/ms12-037
technet.microsoft.com/en-us/security/advisory/2719615
technet.microsoft.com/en-us/security/bulletin/MS12-036
technet.microsoft.com/en-us/security/bulletin/ms12-jun

Related Stories

Microsoft patches 'critical' crack in Windows

Aug 03, 2010

Microsoft released an emergency patch for a "critical" crack in Windows operating system software that could let hackers take control of computers over the Internet.

Microsoft to patch 17-year-old bug

Feb 08, 2010

(PhysOrg.com) -- Microsoft's February security update will include a patch for a bug that dates back to Windows NT 3.1, which was released in July 1993. The vulnerability has been present but undetected in ...

Microsoft fixes browser flaw used in Google breach

Jan 21, 2010

(AP) -- Microsoft Corp. took the unsual step of issuing an unscheduled fix Thursday for security holes in its Internet Explorer browser that played a role in the recent computer attacks that led Google to threaten to leave ...

Recommended for you

Mozilla lab wants scientists to step out of analog age

Jun 18, 2013

(Phys.org) —Talk about big ideas. Not satisfied to rest on laurels of having brought forth the open source browser Firefox, Mozilla—defined by some as a global project, by others as one of the key open-source ...

'Watch Dogs' video game a sign of the times

Jun 17, 2013

Across the dizzying, colorful show floor at last week's Electronic Entertainment Expo, there were games on display where players could become all manner of things, like a throat-slashing 18th century pirate, ...

Winners and losers at this week's E3

Jun 15, 2013

Since the first battles over "Pong" machines in local arcades four decades ago, video gamers have loved good competition. And this year's Electronic Entertainment Expo—the industry's largest annual gathering—presented ...

User comments : 0

More news stories

Apple TV adds HBO Go, WatchESPN to line up

Apple on Wednesday added HBO GO and WatchESPN to the line-up of programming available on its Apple TV devices that stream shows from the Internet to living room screens.

Tech companies eye security that goes beyond passwords

In late February, a thief or thieves cracked into Evernote's digital vault filled with log-ins, passwords and email addresses belonging to 50 million users. It was a shocking cyberattack considering the Redwood City, Calif., ...

Multiview 3-D photography made simple

Computational photography is the use of clever light-gathering tricks and sophisticated algorithms to extract more information from the visual environment than traditional cameras can.