Microsoft has released the first round of security updates for 2016, patching critical software vulnerabilities that could allow remote code execution.
In total, the company issued 9 security bulletins, which address a total of 24 vulnerabilities in Windows, Office, Edge, Internet Explorer, Silverlight, Visual Basic and Exchange Server.
According to Wolfgang Kandek, CTO of security company Qualys, administrators should prioritize security bulletin MS16-005, primarily for systems running Windows Vista, Windows 7, and Server 2008.
This update addresses a remote code execution vulnerability (CVE-2016-0009) that has already been publicly disclosed, making it more likely that attackers could exploit it to carry out attacks.
The second most important bulletin, according to Qualys, is MS16-004, which fixes six vulnerabilities in Microsoft Office. This security bulletin has also been rated as highly critical, which is highly unusual for Office, judging from security bulletins from previous years.
The culprit for this year's criticality rating is the remote code execution vulnerability with the identifier CVE-2016-0010, which is present in all versions of Office, from 2007 to 2016, even in versions designed for Mac and Windows RT.
Finally, according to researchers at security firm Tripwire, patches to fix significant security holes in the Internet Explorer and Microsoft Edge browsers should also be prioritized, because they address critical vulnerabilities that could be exploited remotely via malicious or insecure websites.
These vulnerabilities are covered by security bulletins MS16-001 and MS16-002.

