Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

January 13th, 2010, 12:46 GMT · By

Download the First Windows Patch in 2010

SHARE:

Adjust text size:


Windows Update
Enlarge picture
On January 12th, 2010, Microsoft has made available the first Windows security bulletin this year. Although MS10-001 comes with a maximum severity rating of Critical, fact is that only customers still running Windows 2000 Service Pack 4 are the most exposed to potential exploits targeting a Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor vulnerability impacting the company OS. For all other supported Windows releases, including Windows 7 and Vista SP2, MS10-001 has a rating of Low.

At the same time, the vulnerability mentioned above has been responsibly disclosed to Microsoft, and the software giant noted no attempts to exploit the flaw and no attacks in the wild. The first Windows security update for 2010 is already available to customers via Windows Update.
 
“As part of its routine monthly security update cycle, Microsoft released one bulletin, MS10-001, to address a vulnerability in Windows and Windows Server,” explained Jerry Bryant, senior security program manager lead, Microsoft. “We recommend customers deploy the update as soon as possible, specifically Windows 2000 customers given the Critical rating on this platform.”

On Windows 2000, successful exploits of the vulnerability would have to involve tricking the end user in viewing content rendered in a malformed Embedded OpenType (EOT) font in client applications. In this regard, such an exploit would need Internet Explorer, Office PowerPoint, or Office Word to be on the machine, as they are apps capable of rendering EOT fonts.

Customers that are still stuck running Windows 2000 should to their best to upgrade to a more recent release of Windows as soon as possible, preferably Windows 7. Windows 2000 has only six more months of support left in it, after which customers will be completely exposed to attacks targeting future vulnerabilities. “Extended support for Windows 2000 will also be retired on July 13, 2010. At that time, we will no longer provide security or any other updated for Windows 2000,” Bryant added.

Get Microsoft Silverlight

TELL US WHAT YOU THINK:

4,062 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Download Free Windows 7 RTM Application Compatibility Resource

VoIP Apps Can Hang on Windows 7

Download Google Chrome 4.0.249.64 Beta

Vista SP2 Upgrades on NVIDIA Chipset PCs Result in Crashes

Update Center for Office and Office Servers Now Live

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM