Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

February 15th, 2012, 10:39 GMT · By

Microsoft Patches Critical Vulnerabilities with February 2012 Security Update

SHARE:

Adjust text size:


Microsoft patches critical vulnerabilities with February 2012 security update
Enlarge picture
Today, Microsoft started to deliver a new security update for its users, solving a total of 21 vulnerabilities that have been reported in its products.

The new security update includes a number of no less than 9 bulletins, four of which are deemed Critical, while the other five are rated Important.

On February 9th, Microsoft released a bulletin advance notification to inform on the upcoming release of this security update, and has now just delivered some more detailed info on the matter.

The aforementioned four Critical security bulletins included in today’ update are meant to solve nine security breaches in Windows Kernel-Mode Drivers, Internet Explorer, C Run-Time Library and .NET Framework and Microsoft Silverlight that would affect Windows, Internet Explorer, and apps relying on.NET Framework and Silverlight.

These critical vulnerabilities were either privately reported or publicly disclosed and could allow Remote Code Execution, provided that the user visited a specific web page or viewed a specially crafted media file.

“An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user,” Microsoft announced.

As for the aforementioned important security bulletins in the new update, they are meant to solve 12 vulnerabilities in Ancillary Function Driver, Microsoft SharePoint, Color Control Panel, Indeo Codec and Microsoft Visio Viewer 2010 that affected Windows, Office and Server Software.

The first two of these bulletins fix five vulnerabilities that could allow Elevation of Privilege if an attacker “logs on to a user's system and runs a specially crafted application” or “if a user clicked a specially crafted URL.”

The other three bulletins fix security breaches that could allow Remote Code Execution. An attacker could gain the same rights as the logged-on user and run arbitrary code, install applications, or view, change, or delete data.

The new security update has already started to arrive on Windows PCs with the Automatic update feature turned on. Those who do not have this feature enabled should perform a manual update of their systems.

Detailed information on these bulletins and the vulnerabilities they resolve can be found in Microsoft’s Security Bulletin Summary for February 2012.

TELL US WHAT YOU THINK:

2,590 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft to Release 9 Security Bulletins on February 14th

Cloud Fundamentals Video: Comparing Security Controls to Evaluate Service Offerings

IE9 Still Most Effective at Blocking Social-Engineered Malware, NSS Labs Finds

IE9 Is Fast, Secure and Reliable on Windows 7

Microsoft’s Products Increasingly Influence the Security Ecosystem

READER COMMENTS:


Comment #1 by: graygee on 15 Feb 2012, 14:56 UTC reply to this comment

Thank you for your hard work to keep my "pc" safe from "jive-turkey's", as I like to call them.!! Can't we ALL just get along.!!! PEACE!!!!!!!!!!!!!!!!!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM