Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Microsoft Releases 'Critical' Security Updates For Windows, Explorer

One of the key vulnerabilities involves a weakness in Microsoft's VBScript and JScript scripting engines.

Microsoft on Tuesday released eight software updates for the Windows operating system and Internet Explorer Web browser to patch security holes, five of which the company described as "critical."

PC users can determine if they need the updates by accessing the company's online Baseline Security Analyzer, Microsoft said.

The five critical updates are designed to address security vulnerabilities that could leave Windows or Explorer open to remote code execution -- a technique used by hackers to gain control of a target computer.

The updates apply to Windows Vista, Windows XP and Windows 2000, Windows Server 2003 and Windows Server 2008, as well as Explorer. Users will need to restart their systems after installing the updates, Microsoft said.

Bloggers at security software and research firm Symantec called one of the critical vulnerabilities, a weakness in the VBScript and JScript scripting engines, "the worst of the bunch."

"The components are installed on multiple flavors of Windows and are relatively easy to exploit," the Symantec blog said.

Microsoft typically releases major security updates in the second week of each month.

Microsoft also patched two "important" vulnerabilities that leave Windows open to spoofing and unauthorized user privilege elevation, and a vulnerability that could expose Microsoft Office to remote code execution.

Microsoft also released an updated version of the Windows Malicious Software Removal Tool. The tool is designed to check for, and remove, malware programs such as Blaster, Sasser and Mydoom.

The updated tool can be obtained from the online Windows Update service, Windows Server Update Services or Microsoft's Download Center.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
Architectural Analysis IDs 78 Specific Risks in Machine-Learning Systems
Jai Vijayan, Contributing Writer,  2/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2412
PUBLISHED: 2020-02-17
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4531. Reason: This candidate is a duplicate of CVE-2012-4531. Notes: All CVE users should reference CVE-2012-4531 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental u...
CVE-2014-4981
PUBLISHED: 2020-02-17
LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.
CVE-2014-7236
PUBLISHED: 2020-02-17
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
CVE-2014-8089
PUBLISHED: 2020-02-17
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
CVE-2015-8751
PUBLISHED: 2020-02-17
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.