Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Microsoft Releases 'Critical' Security Updates For Windows, Explorer

One of the key vulnerabilities involves a weakness in Microsoft's VBScript and JScript scripting engines.

Microsoft on Tuesday released eight software updates for the Windows operating system and Internet Explorer Web browser to patch security holes, five of which the company described as "critical."

PC users can determine if they need the updates by accessing the company's online Baseline Security Analyzer, Microsoft said.

The five critical updates are designed to address security vulnerabilities that could leave Windows or Explorer open to remote code execution -- a technique used by hackers to gain control of a target computer.

The updates apply to Windows Vista, Windows XP and Windows 2000, Windows Server 2003 and Windows Server 2008, as well as Explorer. Users will need to restart their systems after installing the updates, Microsoft said.

Bloggers at security software and research firm Symantec called one of the critical vulnerabilities, a weakness in the VBScript and JScript scripting engines, "the worst of the bunch."

"The components are installed on multiple flavors of Windows and are relatively easy to exploit," the Symantec blog said.

Microsoft typically releases major security updates in the second week of each month.

Microsoft also patched two "important" vulnerabilities that leave Windows open to spoofing and unauthorized user privilege elevation, and a vulnerability that could expose Microsoft Office to remote code execution.

Microsoft also released an updated version of the Windows Malicious Software Removal Tool. The tool is designed to check for, and remove, malware programs such as Blaster, Sasser and Mydoom.

The updated tool can be obtained from the online Windows Update service, Windows Server Update Services or Microsoft's Download Center.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4147
PUBLISHED: 2019-09-16
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
CVE-2019-5481
PUBLISHED: 2019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-5482
PUBLISHED: 2019-09-16
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-15741
PUBLISHED: 2019-09-16
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVE-2019-16370
PUBLISHED: 2019-09-16
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.