HomeinetMicrosoft's new security updates

Microsoft's new security updates

Microsoft released 16 security bulletins on Tuesday, resolving a total of 44 security holes in its software, including Windows, Office, Exchange Server, Internet Explorer and Edge .

Microsoft
Five of these bulletins were rated "critical" where they could be used to perform remote code execution and affect the following: Windows, Internet Explorer, Edge, Microsoft Office and Office services and the remaining 11 were marked as important.

One of the critical issues, MS16-071 that has raised alarm bells among many security experts, includes a Use-After-Free bug (CVE-2016-3227) that affects the Microsoft Windows Domain Name System (DNS) for Windows Server 2012 and 2012 R2.

The vulnerability lies in the way the servers handle requests. Attackers could send a specially crafted request to a DNS server and convince it to execute arbitrary code under the Local System Account, Microsoft advisors warn.

Another critical vulnerability addresses MS16-070, which manages to patch some of the security holes in Microsoft Office.

The critical memory corruption vulnerability (CVE-2016-0025) resides in the Microsoft Word RTF format which could allow an attacker to execute arbitrary code and take control of the system if the user was logged on with administrator privileges.
The attacker could exploit this with a simple email containing a Microsoft Word RTF file without requiring user interaction.

The two remaining critical bulletins address multiple remote code execution vulnerabilities in Microsoft's Internet Explorer and Edge browsers.

The remaining bulletins address vulnerabilities in Windows SMB Server, Windows NetLogon, Web Auto-Discovery Proxy (WPAD), Microsoft Exchange, Active Directory, Windows PDF, and others.

At the same time, Adobe released security patches for DNG Software Development Kit, Brackets, and Creative Cloud Desktop App.

However, a patch for a zero-day vulnerability (CVE-2016 – 4.171) in Adobe Flash Player that Adobe claims is exploitable in limited targeted attacks will be available later this week.

Anton Ivanov and Costin Raiu of Kaspersky Labs discovered and reported a zero-day vulnerability in Flash Player version 21.0.0.24 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. The Flash zero-day vulnerability has been deployed against active espionage attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS