February 08, 2007

Big set of Microsoft security patches coming Tuesday

Set of patches primarily addresses vulnerabilities in Windows and Office

Microsoft plans to release 12 sets of security patches next Tuesday fixing critical vulnerabilities in a number of its products, including the company's new security software.

The bulk of the patches will fix flaws in the Windows operating system and Office, Microsoft said in a statement published Thursday on its Web site. Five of the updates will be for Windows, and two of them will be for Office. Microsoft also plans to release one less-critical update that addresses flaws in both Windows and Office.

The patches will be released as part of Microsoft's monthly cycle of security updates.

There will also be patches for Microsoft's Step-by-Step Interactive Training and Microsoft Data Access Components and an update that covers both Windows and Visual Studio.

Finally, Microsoft will also publish an update that patches critical flaws in its Windows Live OneCare, Antigen, Windows Defender, and ForeFront security software.

The Office patches have been anticipated as online criminals have been exploiting unpatched vulnerabilities in Word and Excel for several months now. These attacks, which are occurring on a limited scale according to Microsoft, try to trick the victim into opening a maliciously coded Office attachment in order to compromise the PC.

This story was corrected on February 8, 2007

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.