 |
|
|
Another Tuesday patch issued by the Redmond company resolves 19 security holes in
its products. Microsoft has issued sevede advisories, all rated critical, the
highest level on company’s rating system.
MS07-027 is a large bulletin for Internet Explorer 6 and 7,
in addition to version 5.01 on Windows 2000. Five separate vulnerabilities have
been addressed by the patch, and Microsoft is urging all users to update their
browsers. One zero-day vulnerability is among the fixes.
Three of the advisories affect Office. MS07-023 fixes three
separate flaws in Excel that could lead to remote code execution, while MS07-024
does the same for three vulnerabilities in Microsoft Word. MS07-025 patches a
critical vulnerability in Office related to the way the software handles a
specially crafted drawing object. An attacker could exploit this vulnerability
when Office parses a file and processes a malformed drawing object. All
versions of Microsoft Office from 2000 to 2007 are affected.
"Just like last month, security holes are being found
which impact Windows users, including adopters of Microsoft Windows
Vista," said Graham Cluley, senior technology consultant at Sophos.
"Whether you are using the latest version of Windows or not, it makes
sense to keep up-to-date with the latest security patches and roll them out
across your business as a matter of priority. Hackers have shown no mercy in
the past taking advantages of vulnerabilities in Microsoft's code, and taking
action now will help defend your network and keep your company out of trouble."
© 2007 - 2009 - eFluxMedia