Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Microsoft > Patches and Vulnerabilities

June 10th, 2011, 13:06 GMT · By

Critical Vulnerabilities in IE9 and Windows 7 SP1 to Be Patched Next Week

SHARE:

Adjust text size:

Windows Update
Enlarge picture
Users running Windows 7 Service Pack 1 (SP1) and Internet Explorer 9 will need to apply a number of Critical security bulletins which Microsoft plans to release next week as part of the company’s monthly patch cycle.

There are no less than Critical six patch packages planned for Windows 7 SP1, although there are seven in total, but customers will need to apply only one of the IE updates depending on the version of the browser they’re running, namely IE8 or IE9.

There are also additional security bulletins scheduled for release the coming week for all supported Windows releases, as well as for additional products from the software giant.

Angela Gunn, senior response communications manager, Trustworthy Computing, Microsoft, revealed that the Redmond company will provide “16 bulletins (nine Critical in severity, seven Important) addressing 34 vulnerabilities in Microsoft Windows, Microsoft Office, Internet Explorer, .NET, SQL, Visual Studio, Silverlight and ISA.

“All bulletins will be released on Tuesday, June 14, at approximately 10am PDT. Come back to this blog on Tuesday for our official risk and impact analysis, along with deployment guidance and a video overview of the release.”

June 2011 will mark the advent of the first security bulletin for Internet Explorer 9, and a Critical one at that.

According to the software giant, among the security flaws affecting IE, next week’s updates will also patch a zero-day (0-day) vulnerability, namely the hole which can potentially allow an attacker to perform cookiejacking.

Microsoft has said in the past that it doesn’t consider the cookiejacking vulnerability as posing much of a risk to IE users, and the company hasn’t changed its mind, it would appear.

“Given the prevalence of other types of social engineering methods in use by criminals, which provide access to much more than cookies, we believe this issue poses lower risk to customers. Further, based on a signature that has been released to millions of Microsoft Security Essentials and Forefront customers, the Microsoft Malware Protection Center (MMPC) has not detected attempts to use this technique,” Gunn added.



4,601 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Microsoft Botches Its Download Center with Upgrade

Fake Microsoft Updates Used in Attacks Targeting Firefox on Windows

Get Ready for Chrome 14.0, Download Chrome 13.0.782.13 Dev

Fix Windows 7 SP1 Issues with DRM Copyrighted Content Failing to Play

Windows 8 to Push ARM onto 40% of Netbooks in 2015, Says ARM’s CEO

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM