Thursday, June 1, 2017

Patch Day: Microsoft announces security bulletins for January 2017

Microsoft is approaching the new year rather quietly. For Patch Day on 14 January, the Redmonder have only announced four security bulletins, none of which should address a critical vulnerability. All four bulletins carry the risk classification “high” (important). This affects Windows, Office SharePoint Server and Dynamics AX.


Microsoft wants to eliminate a vulnerability, which is already used for attacks. A security vulnerability in Windows XP and Server 2003, known since the end of November 2013, is used to install Trojan horses that are infected via manipulated PDF files. The kernel gap allows you to extend the user rights so that the infected pest can be executed in the privileged kernel mode. A second Windows bulletin is designed to address one or more vulnerabilities in Windows 7 and Server 2008 R2.


The Office Bulletin, on the other hand, affects all supported Office versions (2003 to 2013), SharePoint Server 2010 and 2013, and Office Web Apps 2010 and 2013. The problem is a vulnerable Word component. Prepared Word documents could be used to inject malicious code.


A rare guest at Patch Day is Microsoft's ERP suite Dynamics AX (ERP: Enterprise Resource Planning). Microsoft wants to eliminate one or more vulnerabilities in Dynamics versions 4.0, 2009, 2012, and 2012 R2. They are vulnerable to DoS (denial of service) attacks.


The security bulletins are to be published on 14 January as usual around 7 pm CET. Microsoft will also distribute the "Windows Malicious Software Removal Tool" in a new version.


However, a quiet patch day it will be thanks to Oracle and Adobe nonetheless. With its quarterly updates, Oracle plans to close 147 security holes in its entire product range, including 36 in Java. Adobe has announced security updates for its PDF products Adobe Reader and Acrobat.

No comments:

Post a Comment