dcsimg

No Love for IT this February Patch Tuesday

  • No Love for IT this February Patch Tuesday

    No Love for IT this February Patch Tuesday-

    MS14-005

    Next on the list should be MS14-005, a vulnerability in MS XML Core Services that could allow information disclosure. The bulletin is rated as Important, but the vulnerability covered has been publicly disclosed and has known active attacks. This is a browser-initiated attack vector and the bulletin is applicable to all currently supported Windows platforms. The likely goal for an attacker would be to grab an OS version and use that information for a more targeted exploit against a different vulnerability.

1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9

No Love for IT this February Patch Tuesday

  • 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9
  • No Love for IT this February Patch Tuesday-3

    MS14-005

    Next on the list should be MS14-005, a vulnerability in MS XML Core Services that could allow information disclosure. The bulletin is rated as Important, but the vulnerability covered has been publicly disclosed and has known active attacks. This is a browser-initiated attack vector and the bulletin is applicable to all currently supported Windows platforms. The likely goal for an attacker would be to grab an OS version and use that information for a more targeted exploit against a different vulnerability.

Microsoft was looking to deliver a light Patch Tuesday this month, but added two last-minute bulletins to the mix. February now includes seven bulletins, four critical and three important, that cover a total of 32 CVEs. The patches address vulnerabilities in Windows, Internet Explorer, Security Software and the .NET framework. Russ Ernst, director of product management at Lumension, takes a closer look at this February's Patch Tuesday.