Microsoft bugs
Microsoft has issued 11 security fixes for October

Microsoft fixes 20 security flaws

Four 'critical' patches in monthly update

Written by Shaun Nichols in San Francisco, vnunet.com

Microsoft has issued the October instalment of its monthly 'Patch Tuesday' security update.

The latest release includes 11 bulletins addressing a total of 20 security vulnerabilities. Four of the bulletins are rated 'critical', six are listed as 'important' and one as 'moderate'.

Among the critical patches are a fix for a remote code execution flaw in Excel which could allow an attacker to perform a remote malware installation by way of a specially crafted Excel file.

Advertisement

The second critical fix addresses a remote code flaw in Microsoft's Host Integration Server product, while another addresses a problem in the Active Directory component for Windows Server 2000.

The final critical bulletin is a cumulative update for Internet Explorer which includes remote code execution fixes for IE 5, 6 and 7.

Three of the six bulletins rated 'important' address remote code execution, including fixes for the Windows Server Message Block and Internet Printing Service, along with a flaw in the Message Queuing component for Windows 2000.

Three more 'important' bulletins fix privilege-elevation flaws in the Windows Kernel, Virtual Address Descriptor and the Ancillary Function Driver.

The 'moderate' bulletin addresses a vulnerability in Microsoft Office XP SP3 which could be exploited for information disclosure.

David Marcus, security research and communications director at McAfee, warned that the remote code flaws pose the biggest risk to users who do not apply the patch.

"It is the month of remote code execution bugs," he said. "Many of the flaws could allow an attacker to gain complete control over a vulnerable computer by tricking a user into visiting a malicious web site or opening a rigged Office file."

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

NEW! Computeractive CD Rom 11
All 26 issues of Computeractive from 2008 on one CD-Rom.

Ultimate Guide to Disc Burning
Everything you need to know about creating your own discs.

Create your own calendars softwareCreate your own Calendars
The fun and easy way to create your own calendars!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

Outlook 2007 email controversy

One of the major changes in Outlook 2007 had nothing to do with the Ribbon but that Word was used to display...

Download Junkie

Download Junkie

Your daily dose of download discussion

Backup important data with SyncBack SE

Keeping certain files backed up helps to keep items safe in case anything disastrous happens to your computer, but although most of...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2009. Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in England and Wales with company registration number 04038503

Search computeractive.co.uk